Ein Azure-Dienst, mit dem Benutzer Inhalte ermitteln können, die potenziell anstößig, riskant oder anderweitig unerwünscht sind. Dieser hieß früher Azure Content Moderator.
Thank you for your detailed explanation.
However, the situation in our case is different from what you described, so I would like to clarify a very important legal and technical point regarding Azure OpenAI and §203 StGB:
1. Yes, the law was reformed – but §203 StGB still strictly prohibits access by non-authorized persons
The reform allows outsourcing only under the condition that:
- all persons who have potential access to confidential data (including cloud personnel, subcontractors, support engineers) are contractually bound to secrecy in the same way as the professional.
This requires a specific confidentiality agreement for the cloud provider and all its employees.
Microsoft addresses this requirement for Germany via:
the Microsoft Cloud Agreement – Professional Secrecy Amendment (Germany)
This amendment is the contractual basis that legally enables German secrecy-bound professions to use Microsoft cloud services.
2. Why this is still a compliance blocker for Azure OpenAI
Azure OpenAI performs Abuse Monitoring with mandatory 30-day retention, during which:
Microsoft engineers
and abuse-monitoring staff
can access customer prompts and outputs.
This constitutes:
→ “Zugangnahme durch unbefugte Dritte” (unauthorized access)
under §203 StGB if the Professional Secrecy Amendment or Opt-Out is not in place.
The reform did not remove this requirement. It only made it possible to outsource — if strict secrecy contracts are in place.
Without these contracts, the disclosure remains illegal.
3. This is why we require the Modified Abuse Monitoring Opt-Out
If Microsoft cannot ensure that no employee can access the data, then the only legally compliant option is:
Zero Data Retention,
No retention logs,
No access by Microsoft personnel.
This is exactly what the Modified Abuse Monitoring Opt-Out provides.
Two Azure Sales representatives confirmed that:
the Opt-Out is available for cases like ours,
it requires an internal compliance escalation,
it is only available for managed customers,
and an escalation has already been created.
4. Our request
We are not asking for a general explanation of §203 StGB.
We are specifically asking:
How can we receive the Modified Abuse Monitoring Opt-Out or the Professional Secrecy Amendment for Germany so that Azure OpenAI becomes legally usable under §203 StGB?
This is necessary because:
Without Opt-Out → Microsoft retains data for 30 days
Retained data is accessible by Microsoft staff
This violates §203 StGB without the secrecy amendment
Therefore, we cannot legally use Azure OpenAI in its default configuration
5. Why this is urgent
We want to continue building our product on Azure.
But unless we receive the amendment and/or the Opt-Out, we are legally required to migrate to another cloud provider that supports zero retention.
Please advise on how we can move forward with the compliance escalation or which Microsoft team is responsible for enabling the Opt-Out in Germany.