01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name tenant, subscription, workload, platform, security and data owners.
- Separate Entra directory roles, Azure RBAC roles, managed identities and data-plane permissions.
- Record Microsoft and managed-service roles from current agreements and architecture.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Application endpoints, databases, storage, messaging and analytics.
- Developer operations, support, monitoring and diagnostic logs.
- Backups, geo-replication, data factories and cross-tenant access.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Map data classes to necessary resources, regions and diagnostic fields.
- Avoid personal data in resource names, tags and verbose logs.
- Limit test copies, shared keys and analytics duplication.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Carry collection and purpose evidence from the application.
- Do not treat RBAC as the individual’s consent.
- Confirm downstream analytics and AI uses match the recorded purpose.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review Entra roles, Azure RBAC, managed identities, service principals and shared keys.
- Separate management-plane and resource data-plane access.
- Exercise role removal, secret rotation and privileged activation review.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define deletion for live resources, soft delete, versions, replicas and backups.
- Test restore paths and record resource-specific retention.
- Document region and diagnostic-log retention decisions.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve current Microsoft terms, DPA and sub-processor information.
- Inventory marketplace, managed-service, support and cross-tenant parties.
- Record assistance, exit, deletion and incident expectations.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Confirm Activity Log, resource-log and Entra-log coverage separately.
- Create diagnostic settings where longer or data-plane evidence is required.
- Protect exports and connect alerts to investigation evidence.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Translate verified person identifiers into application and storage keys.
- 02
Search live resources, analytics stores and owned pipelines.
- 03
Apply exceptions and execute correction or deletion through the application.
- 04
Track soft-delete, versions, replicas, backups and downstream confirmations.
10
Bounded configuration
Configuration checklist
Directory, resource and data-plane access are reviewed separately.
- Admin path
- Verify in the current admin console
- Evidence to save
- Role assignments, app identities and exceptions.
Control- and data-plane evidence have deliberate coverage and retention.
- Admin path
- Verify in the current admin console
- Evidence to save
- Diagnostic settings and sample events.
Soft-delete, versions, replicas and restore paths follow owned rules.
- Admin path
- Verify in the current admin console
- Evidence to save
- Resource lifecycle map and test.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Tenant, subscription and resource map
Directory/RBAC/data-plane access review
Activity Log and diagnostic-setting record
Managed identity and secret review
Backup/soft-delete lifecycle
Rights-search and restore exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Azure Activity Log generally covers control-plane operations, not every data-plane action.
- Resource logs require service-specific diagnostic configuration.
- Default retention and available features change by log and subscription.
Questions to resolve
- Which tenants, subscriptions and regions are in scope?
- Which principals have data-plane access?
- Which diagnostic settings are enabled?
- What can restore a deleted record?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionMicrosoft Azure and Microsoft Entra are trademarks of Microsoft Corporation. References are nominative and do not imply endorsement. No affiliation or endorsement is implied.