Home About Us Expertise Our Work Insight Book a Consultation
Insight & Opinion

Microsoft 365 compliance: what UK organisations actually need to know about GDPR and data governance

Published
July 2026
Reading Time
8 minutes
Topic
Compliance & Governance
Audience
IT & Ops Directors
Scroll to read
Microsoft 365 compliance and GDPR for UK organisations
£17.5m
Maximum UK GDPR fine
6
Key M365 compliance tools
72hrs
ICO breach notification window

Having Microsoft 365 does not mean you are compliant

This is one of the most common misconceptions we encounter. An organisation migrates to Microsoft 365, ticks the cloud migration box, and assumes the compliance obligations are handled. They are not.

Microsoft 365 is a powerful compliance platform — but it requires deliberate configuration to work. The tools are there: sensitivity labels, retention policies, data loss prevention, audit logs, eDiscovery, and more. But out of the box, most of them are either switched off, set to defaults that do not reflect your organisation's needs, or simply not deployed.

"Microsoft provides the compliance infrastructure. Your organisation is responsible for configuring and operating it correctly. That distinction matters enormously — especially when the ICO comes knocking."

UK GDPR, which came into force after the UK's departure from the EU, places clear obligations on organisations to demonstrate that personal data is processed lawfully, stored securely, retained only as long as necessary, and deleted when it is no longer needed. Microsoft 365, properly configured, can help you meet every one of those obligations. Improperly configured, it can actively work against you.

Important

This article provides a practical overview of compliance considerations in Microsoft 365 for UK organisations. It is not legal advice. For specific regulatory guidance, you should consult a qualified legal professional or your Data Protection Officer.

What UK GDPR actually requires of your organisation

UK GDPR is built around six core principles for the handling of personal data. Understanding how these map to your Microsoft 365 environment is the starting point for any compliance programme.

Lawfulness, fairness and transparency
  • You must have a lawful basis for processing personal data — consent, legitimate interest, contractual necessity, and so on.
  • In Microsoft 365 terms, this means understanding what data you hold, where it lives, and ensuring you have the right to process it. Microsoft Purview's data map and content explorer tools help you locate personal data across your environment.
Purpose limitation and data minimisation
  • Data should only be collected for specified, explicit purposes — and only as much as is necessary for those purposes.
  • In practice, this means not storing personal data in ad hoc SharePoint lists, Teams chats, or Power BI datasets without a clear justification and governance process.
Accuracy, storage limitation and integrity
  • Data must be accurate, kept up to date, and not retained longer than necessary. This is where retention policies in Microsoft 365 become critical — automatically archiving or deleting content when it reaches the end of its retention period.
  • Equally important is data integrity: sensitivity labels and encryption ensure that personal data is protected throughout its lifecycle, not just at the point of collection.
Accountability
  • UK GDPR requires organisations to be able to demonstrate compliance — not just claim it. Audit logs, eDiscovery capabilities, and compliance reports in Microsoft Purview are your evidence base.
  • If the ICO investigates a breach, your ability to produce a clear audit trail of who accessed what, when, and what controls were in place will significantly affect the outcome.

Six Microsoft 365 compliance tools every UK organisation should be using

Microsoft 365 includes a comprehensive set of compliance and governance tools under the Microsoft Purview umbrella. Here are the six that have the greatest practical impact for UK organisations:

Sensitivity Labels
Classify and protect documents and emails based on their content — from public information through to highly confidential. Labels can apply encryption, watermarks, and access restrictions automatically.
Retention Policies
Automatically retain or delete content based on rules you define — by document type, location, age, or label. Essential for demonstrating storage limitation compliance under UK GDPR.
Data Loss Prevention (DLP)
Detect and prevent sensitive information — National Insurance numbers, financial data, health records — from being shared inappropriately via email, Teams, or SharePoint. DLP policies can block, warn, or notify automatically.
Audit Logs
A detailed record of user and admin activity across your Microsoft 365 environment — who accessed what, when files were modified, when permissions changed. Your primary evidence base for ICO investigations.
eDiscovery
Search, hold, and export content across Exchange, SharePoint, Teams, and OneDrive for legal investigations, subject access requests, or regulatory enquiries. Critical for demonstrating accountability under UK GDPR.
Purview Data Map
Discover, classify, and understand the personal data held across your Microsoft 365 environment. Particularly useful for Data Protection Impact Assessments and managing subject access requests efficiently.

The compliance gaps we see most often in UK Microsoft 365 environments

After working with over 50 UK organisations on their Microsoft 365 environments, these are the compliance failures that come up again and again — often in organisations that believe they are already compliant.

01
No retention policies configured
Content accumulates indefinitely across SharePoint, Teams, and Exchange with no automated lifecycle management. Personal data is retained far longer than necessary — a clear UK GDPR breach. The fix is straightforward, but it requires deliberate configuration and a retention schedule that reflects your organisation's obligations.
02
Sensitivity labels deployed but unused
Many organisations have sensitivity labels configured but not enforced — staff can ignore them or apply them incorrectly. Without mandatory labelling on high-risk content and DLP policies that act on those labels, the entire system provides no real protection.
03
Overly broad permissions and guest access
SharePoint sites with "Everyone except external users" permissions, Teams with unreviewed guest members, and document libraries shared via anonymous links. Each of these creates a route for personal data to reach people who have no business need to access it — and each is a potential breach waiting to happen.
04
Audit logging switched off or not reviewed
Unified audit logging in Microsoft 365 is not always enabled by default on older tenants, and even where it is enabled, the logs are rarely reviewed proactively. Without audit logs, demonstrating what happened — and who did what — in the event of a breach becomes extremely difficult.
05
Personal data in the wrong places
HR records in a general SharePoint site. Customer data in a Teams channel. Medical information in an unclassified email attachment. Personal data scattered across your Microsoft 365 environment without governance is both a compliance risk and a security exposure. A data map is the starting point for understanding what you actually hold and where.

A practical approach to Microsoft 365 compliance for UK organisations

Compliance is not a project with an end date — it is an ongoing programme. But it has to start somewhere. Here is the sequence we recommend for organisations who need to get their Microsoft 365 environment into a defensible compliance position:

Phase 1 — Understand what you have
  • Run a data discovery exercise using Microsoft Purview to identify where personal data lives across your environment.
  • Review your current permissions model — who has access to what, and whether those permissions are still appropriate.
  • Check whether unified audit logging is enabled and that logs are being retained for an appropriate period.
Phase 2 — Build your governance framework
  • Define a retention schedule aligned to your legal and regulatory obligations — what types of content need to be kept for how long, and what should be deleted.
  • Design a sensitivity label taxonomy that reflects your content categories — typically public, internal, confidential, and highly confidential as a starting point.
  • Document your data processing activities and map them to the six UK GDPR principles.
Phase 3 — Configure and enforce
  • Deploy retention policies to SharePoint, Exchange, and Teams — prioritising locations where personal data is most likely to accumulate.
  • Implement DLP policies targeting the personal data types most relevant to your organisation — financial data, health information, identification numbers.
  • Enable mandatory sensitivity labelling for new documents and emails, and run a remediation exercise on existing content.
  • Tighten guest access policies, review external sharing settings, and implement conditional access policies for high-risk content.
Phase 4 — Monitor and maintain
  • Set up regular compliance reviews — quarterly at a minimum — to review DLP alerts, audit log activity, and any changes to permissions or sharing.
  • Assign clear ownership: a named Data Protection Officer or compliance lead, and content owners for high-risk document libraries.
  • Train your people. Technology controls are only as effective as the people operating within them. Staff who understand why the controls exist are far more likely to follow them.

"Compliance is not a configuration exercise. It is a culture. The technology gives you the tools — but only leadership commitment and ongoing governance makes it work."

Where Cordapse can help

Microsoft 365 compliance is an area where the gap between what organisations think they have in place and what they actually have in place tends to be significant. We have seen this consistently across every sector we work in — finance, healthcare, professional services, and beyond.

At Cordapse, we help UK organisations assess their current Microsoft 365 compliance posture, design a governance framework that reflects their specific regulatory obligations, and implement the technical controls that make it real. Our Compliance & Governance service covers the full lifecycle — from data discovery through to ongoing monitoring and staff adoption.

Free consultation

Not sure how compliant your Microsoft 365 environment actually is?

Book a free, no-obligation consultation and we will help you understand your current compliance posture — and what it would take to close the gaps. No jargon, no pressure.

Book a free consultation →
Microsoft 365 compliance and data governance for UK organisations

"Microsoft provides the compliance infrastructure. Your organisation is responsible for configuring and operating it correctly. That distinction matters enormously."

Cordapse · Insight & Opinion · Compliance & Governance

The business case for getting Microsoft 365 compliance right

The ICO's enforcement activity has increased significantly in recent years, and the expectation that organisations can demonstrate proactive compliance — not just respond to breaches reactively — is now firmly established. Getting your Microsoft 365 compliance posture right is not just a regulatory obligation. It is a genuine business advantage.

Reduced Breach Risk
DLP policies, sensitivity labels, and tightened permissions significantly reduce the risk of personal data reaching people who should not have access to it.
Faster Breach Response
With audit logs, eDiscovery, and a clear data map in place, identifying what was affected in a breach and notifying the ICO within 72 hours becomes achievable rather than chaotic.
Stronger Client Trust
Demonstrable compliance — particularly in regulated sectors — is increasingly a commercial differentiator. Clients and procurement teams ask about data governance. Being able to answer confidently matters.
AI Readiness
A well-governed Microsoft 365 environment is a prerequisite for deploying AI tools like Microsoft 365 Copilot safely. Compliance work done now directly enables AI adoption later.

Ready to get your Microsoft 365 compliance in order?

We have spent over 30 years helping UK organisations get more from their technology investments. Book a free consultation and find out how Cordapse can help you build a compliant, governed Microsoft 365 environment.

Book a Free Consultation