Hi BradH,
Thanks for the feedback. GDPR is a very important feature for us.
For your first question "At present if I am signed into O365, even for your form, I get my companies Privacy statement... that's not right. It should be Microsoft." There is a setting in admin portal for Privacy Statement, if your admin set the customized privacy URL for your company, then it will show up in all O365 products in the company.
For your second question "If I am external user (not signed into O365) and I put our a form, they get Microsoft Privacy statement and it SHOULD be my companies." If admin set the customized privacy URL, it should also show up for all forms created in your company. The behavior you have mentioned sounds like a bug. Could you share the form URL with us so we could troubleshoot?
Regards,
Zhongzhong