Skip to content
Browse all topics

Does Microsoft 365 comply with GDPR?

Microsoft 365 provides the controls needed for a GDPR-compliant deployment and Microsoft signs the standard EU Data Protection Addendum as a data processor. Compliance itself is a shared responsibility: Microsoft runs the platform in line with its commitments, and the tenant is the data controller responsible for configuring retention, DSAR handling, DPIA records, and lawful basis for the data it stores.

What Microsoft provides

  • The EU Data Protection Addendum (DPA) signed as part of the Microsoft Product Terms — the standard processor commitment.
  • The Microsoft EU Data Boundary — Microsoft's commitment to store and process most Microsoft 365 customer data in the EU / EFTA.
  • Purview DSR (data subject request) tools for finding, exporting, and deleting a subject's content across mailboxes, sites, chats, and Copilot interactions.
  • Audit logging and retention that can evidence controls for supervisory authorities.
  • Compliance Manager templates for GDPR and other frameworks.

What the tenant is still responsible for

  • Records of processing activities (Article 30) — what data lives in the tenant, why, and for how long.
  • Lawful basis and consent capture for personal data collected in the tenant's own apps and forms.
  • Data-subject request handling within the 30-day window — Purview DSR speeds it up but the process is yours.
  • Sensitive-data DPIAs where processing is high-risk (biometrics, health, cross-border transfers).
  • Retention policies that actually delete data — a mailbox on a Litigation Hold does not honour a retention policy set to delete.
  • Sub-processor management for any third parties reading data out of the tenant.

The most common gap is treating Microsoft's platform commitments as compliance in themselves. The Microsoft DPA is a prerequisite; the operational programme is not.

Read next

Other questions