"We use Microsoft 365, so we are GDPR-compliant." I hear that sentence in roughly every second first meeting, and it is wrong in a specific and expensive way. Microsoft gives you a compliant platform and a set of controls. Whether your organisation is compliant depends entirely on which of those controls you switched on — and on one setting most SMBs discover only when they need it and it is too late.

This is what actually needs configuring, in the order that matters, for a company without a compliance department.

In short

Microsoft 365 is not compliant out of the box — it is a compliant platform with controls you have to configure. Under the shared responsibility model, Microsoft secures the infrastructure and acts as processor; classifying data, setting retention, answering data subject requests and proving who did what stays with you. The three that matter first: verify audit logging is on and know your retention window, set retention policies deliberately, and rehearse a data subject request before you get one. Compliance Manager gives you the scored checklist.

Why using Microsoft 365 is not the same as compliance

GDPR splits responsibility. Microsoft is your processor: it runs the infrastructure, holds the certifications, offers a Data Processing Addendum and EU data residency options, and publishes its sub-processors. You are the controller: you decide what personal data you collect, why, how long you keep it, who can reach it, and how you answer a person who asks what you hold about them.

Nothing Microsoft ships can make those decisions for you. That is why the platform can be fully certified while your tenant is still non-compliant — because a retention policy was never set, audit logging was never verified, or nobody could answer a data subject request within the deadline.

Practical consequence: a signed DPA and an EU data boundary are necessary and not sufficient. The configuration is the compliance.

Audit logs: the one nobody checks until it is too late

Audit logging is the control that quietly decides whether you can investigate anything at all. When an incident happens — a suspected data leak, a departing employee accused of taking files, a regulator asking who accessed a record — the audit log is your only source of truth. If the events aged out, the answer is "we cannot say", and in a GDPR context that is a genuinely bad answer.

What to do, in order:

  1. Verify auditing is on for your tenant. Audit logging is on by default for most Microsoft 365 organisations — but not for Business Basic, Business Standard or Business Premium, and not for unmanaged tenants on enterprise trials. On those plans you have to turn it on yourself, and until you do, the log you are counting on during an incident does not exist. Check it, do not assume.
  2. Know your actual retention window. Audit (Standard) keeps audit records for 180 days. Audit (Premium) raises that to one year for Entra ID, Exchange, SharePoint and OneDrive records, but only for users holding an E5-class or Purview Suite licence; everything else stays at 180 days, and 10-year retention needs a separate per-user add-on. On Business Premium you are on Audit (Standard) unless you buy the Purview add-on, so plan for 180 days.
  3. Decide whether that window is long enough for your risk. Breaches are frequently discovered months after the fact. If your window is shorter than your realistic detection time, extend retention or export the log to somewhere that keeps it.
  4. Test one search now. Look up a file access or a sign-in from last month. You will find out in five minutes whether this works before you need it under pressure.
The audit log is not a compliance checkbox. It is the difference between "here is exactly what happened" and "we believe nothing was taken".

Retention: keep what you must, delete what you may not keep

GDPR pulls in two directions at once. Storage limitation says do not keep personal data longer than necessary. Other obligations — tax, contract, employment law — say keep certain records for years. Retention policies in Microsoft Purview are how you resolve that contradiction as an automated rule instead of a hope.

Two warnings worth more than the rest of this section:

  • A delete-after-X-years policy removes everything already older than X the moment it takes effect. Not gradually. Communicate and scope before you submit, never after.
  • Retention creates a hidden copy. Content under retention that a user deletes or edits is preserved in the Preservation Hold Library where nobody sees it — and it counts against your storage. A forgotten "retain indefinitely" policy is the most common cause of storage bills nobody can explain. I unpacked that in the SharePoint storage article.

Start narrow: one policy for mail, one for the SharePoint sites holding personnel or customer records, with periods your legal side has actually signed off. Broad tenant-wide policies applied early are hard to unwind later.

Data subject requests: rehearse before you need it

A person has the right to know what you hold about them, get a copy, and in many cases have it deleted — and you have a legal deadline to respond. The failure mode in small companies is never the law; it is that nobody has ever tried to find all data about one person across Exchange, SharePoint, OneDrive and Teams, and the first attempt happens under a running clock.

Do the dry run instead. Pick a name, open eDiscovery in the Microsoft Purview portal and run a search across the tenant — classic Content Search was retired on 31 August 2025 and its functionality now lives inside eDiscovery, either in the search experience of a case or in the system-generated Content Search case. You will learn three things fast: where personal data has spread that you did not expect, whether your search skills are up to it, and how long the process actually takes. Verify which premium eDiscovery features your subscription unlocks — review sets, analytics and case-level hold need an E5-class entitlement. An eDiscovery search is the right tool for the dry run, and Microsoft points data subject request investigations at it directly, but it is not a finished DSR process: check with counsel what your answer has to contain.

Also write down the trivial part everyone forgets: who receives the request when it arrives by mail to the info@ address on a Friday afternoon, and who is allowed to act on it. One boundary belongs in that procedure too: where Microsoft is the controller rather than your processor, an admin cannot fulfil the request at all — the user has to raise it with Microsoft directly, and they lose that ability once you delete their account, so the offboarding order matters.

Compliance Manager: the scored checklist

Microsoft Purview Compliance Manager is the closest thing to a free consultant in the tenant. It maps your configuration against regulatory templates — GDPR included — and produces a score with concrete improvement actions, each marked as Microsoft-managed or yours.

Use it as a work queue, not as a target. Two caveats worth stating plainly: the score is a relative indicator, not a legal certification — a high score does not make you compliant, and no auditor accepts it as evidence on its own. And some actions are genuinely irrelevant to a 30-person company. Filter by "your actions", sort by impact, and work down the list. Even at that, it beats a blank page by a wide margin.

A 90-day roadmap for a small team

Days 1–30 — know where you stand. Verify audit logging and record your real retention window. Run one test audit search. Open Compliance Manager and read your assessment — every organisation gets the Microsoft Data Protection Baseline, which already draws on GDPR alongside NIST CSF, ISO and FedRAMP, while the dedicated GDPR template is a premium one that E5-class subscriptions can pick for free and others license separately. Confirm your DPA and note which data residency you are actually on.

Days 31–60 — close the obvious gaps. Publish a small sensitivity label set. Set your first two retention policies with legal sign-off. Do the data subject request dry run and write the one-page procedure that comes out of it.

Days 61–90 — make it durable. Add the DLP policies for your highest-risk data (audit-first, as described here). Document who owns which control. Put a recurring quarterly review in the calendar — compliance decays silently, and the review is what catches it.

Much of this can start without E5 or a compliance officer, but the exact audit, eDiscovery, retention and governance capabilities are licence-dependent. It requires someone deciding to own the controls for three months.

Glossary

Controller vs processor
Under GDPR, you (the controller) decide why and how personal data is processed; Microsoft (the processor) processes it on your instructions. Certification of the processor does not make the controller compliant.
DPA (Data Processing Addendum)
The contract governing how Microsoft processes personal data on your behalf, including sub-processors and safeguards.
Unified audit log
The tenant-wide record of user and admin activity across Microsoft 365 — your only evidence base during an investigation. Retention length depends on licence tier.
Retention policy
A Purview rule that keeps content for a defined period and/or deletes it afterwards, applied automatically across mail, SharePoint, OneDrive and Teams.
Preservation Hold Library
A hidden library holding copies of content that was deleted or modified while under retention. Invisible to users and counted against your storage quota.
DSR (Data Subject Request)
A person's request to access, correct, export or delete the personal data you hold about them, subject to a statutory response deadline.
Compliance Manager
Microsoft Purview's scored assessment mapping your tenant configuration to regulatory templates, with improvement actions split between Microsoft-managed and yours.

Frequently Asked Questions

Is Microsoft 365 GDPR-compliant out of the box?

No. Microsoft provides a compliant platform — certifications, a Data Processing Addendum, EU data residency options — and acts as your processor. As the controller you remain responsible for classifying data, setting retention, controlling access, keeping audit evidence and answering data subject requests. The platform can be fully certified while your tenant is non-compliant because those controls were never configured.

What do SMBs actually need to configure for GDPR in Microsoft 365?

Start with three: verify the unified audit log is enabled and find out your real retention window for your licence tier; set deliberate retention policies with legal sign-off (knowing a delete-after-X policy removes everything already older than X immediately); and rehearse a data subject request with an eDiscovery search before a real one arrives. Then use Compliance Manager's assessment as your work queue.

How long does Microsoft 365 keep audit logs?

180 days on Audit (Standard) — the tier most SMB plans are on. Audit (Premium) raises that to one year for Entra ID, Exchange, SharePoint and OneDrive activity, but only for users holding an E5-class or Purview Suite licence; other activities stay at 180 days unless you create a custom audit log retention policy, and 10-year retention needs a separate add-on. And on Business Basic, Business Standard and Business Premium, auditing is not even on by default — check that first.

Does a high Compliance Manager score mean we are compliant?

No. The score is a relative indicator of how many recommended actions you have implemented, not a legal certification, and no auditor will accept it as standalone evidence. Use it as a prioritised work queue — filter to 'your actions', sort by impact — and be prepared to skip actions that genuinely do not apply to a small organisation.


References

  1. Microsoft Learn: Microsoft Purview compliance solutions overview
  2. Microsoft Learn: Microsoft Purview Auditing solutions
  3. Microsoft Learn: Learn about retention policies and retention labels
  4. Microsoft Learn: Microsoft Purview Compliance Manager
  5. Microsoft Learn: Microsoft 365 and the GDPR