Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

Work + storageSystem guide · implementation aid

Microsoft 365: follow the evidence.

Map personal data across Exchange, SharePoint, OneDrive, Teams, Entra and Purview.

00 What usually flows through Microsoft 365

A working data journey, not a legal conclusion.

Mail, files, chats, meeting content, identities, sites, audit records and connected applications. Replace this editorial model with the systems, data and roles your organisation can actually evidence.

Typical Microsoft 365 data journeySix stages show information moving from collection through operational systems, evidence and an end-of-lifecycle decision.010203040506
  1. 01Collectmail · Teams · forms
  2. 02Entrauser · guest · app
  3. 03Workloadsmail · site · drive
  4. 04Connectlink · Graph · Power
  5. 05Purviewaudit · search · retain
  6. 06Endhold · transfer · delete
Illustrative operating model. Verify actual fields, destinations, contracts, regions, retention and access.

01

Accountability

Role map

Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.

  • Name owners for Exchange, SharePoint, Teams, Entra and compliance configuration.
  • Separate global administrators, workload administrators, records roles and service principals.
  • Assess Microsoft and connected app roles from current contracts and actual data flows.

02

Collection surfaces

Collection and notice touchpoints

Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.

  • Mail, Teams meetings and messages, SharePoint forms, file sharing and directory sync.
  • Employee notes, recordings, transcripts, attachments and exported reports.
  • Graph API, Power Platform, add-ins and third-party backup or security tools.

03

Purpose discipline

Purpose and data minimisation checks

Every field and copy should have a named operating reason, accountable owner and review event.

  • Map authoritative repositories and discourage uncontrolled channel or mailbox copies.
  • Review recording, transcription, guest access and telemetry choices against named purposes.
  • Challenge broad Graph permissions and indefinite team or site creation.

04

Choice evidence

Consent and preference evidence

When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.

  • Link collection surfaces to the correct notice and preference workflow.
  • Test whether marketing or communications preferences reach connected sending systems.
  • Keep employee monitoring or recording assessments separate from access permission.

05

Least privilege

Access control and privileged roles

Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.

  • Review privileged roles, PIM where used, guest users, sharing links and service principals.
  • Test least privilege at tenant, site, team and file levels.
  • Exercise departure, access revocation, mailbox handling and OneDrive transfer.

06

Lifecycle

Retention, deletion, backup and export behaviour

A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.

  • Map retention labels and policies to workload, record category and trigger.
  • Test deletion with recycle bins, holds, inactive mailboxes, backups and external exports.
  • Record licence dependencies and policy precedence.

07

Service chain

Processor, sub-processor and contract checks

Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.

  • Retrieve current terms, DPA, location commitments and sub-processor information.
  • List Power Platform environments, add-ins, backups and Graph-integrated services.
  • Document assistance, exit, deletion and incident commitments.
Open the processor-register guide

08

Detection + response

Logs, monitoring and breach evidence

Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.

  • Confirm audit availability, licensing and retention for needed event types.
  • Save samples for privileged changes, sharing, search and export.
  • Route detections to an investigation and breach-decision record.

09

Request workflow

Rights-request search, export, correction and erasure workflow

  1. 01

    Search by verified identifiers across mail, sites, drives, Teams and connected systems.

  2. 02

    Coordinate correction where the same record appears in directories and business repositories.

  3. 03

    Apply documented hold and retention exceptions.

  4. 04

    Re-run search and record residual copies and downstream responses.

10

Bounded configuration

Configuration checklist

Role governance

Privileged roles and service principals are reviewed at the right scope.

Admin path
Verify in the current admin console
Evidence to save
Dated role assignment export and decision log.
Retention coverage

Policies and labels cover intended workloads with known precedence.

Admin path
Verify in the current admin console
Evidence to save
Policy export, licence note and test record.
Audit availability

Required events are searchable for the planned period.

Admin path
Verify in the current admin console
Evidence to save
Audit sample, event coverage and retention note.

No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.

11

Retrievable proof

Evidence to save

Workload and repository map

Privileged role and app-permission review

Guest and sharing sample

Retention coverage matrix

Audit export sample

Account-exit and rights-search exercise

Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.

12

Do not overclaim

Known limitations and questions for the vendor

Known limitations

  • Purview, audit and identity features depend on subscription and licence.
  • Workload retention and deletion behaviours are not identical.
  • Third-party backups and exports can remain after tenant-side action.

Questions to resolve

  1. Which workloads and licences are in use?
  2. Which service principals have broad Graph access?
  3. Where do holds override deletion?
  4. Which system owns a person’s authoritative record?

13

Traceable record

Official vendor sources, DPDP sources and corrections

Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.

Editorial status

Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.

Report or inspect a correction

Microsoft, Microsoft 365, Entra and Purview are trademarks of Microsoft Corporation. References are nominative and do not imply endorsement. No affiliation or endorsement is implied.

14 Continue the workspace

Turn this system review into owned gaps.

The browser-only readiness map can capture what is evidenced, partial, unknown or missing. It does not produce a pass, certificate or legal conclusion.

Answer the linked readiness itemTrace SEC-01 to evidence Read: Processor contracts in operation
Related system guides

Google WorkspaceWork + storage

All system guidesSearch the complete stack