Microsoft 365How-To & HardeningRetrospectives

GDPR Data Inventory Checklist for Microsoft 365

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2018, written in 2026 with the benefit of hindsight.

A data inventory is the foundation of GDPR compliance and of any serious data protection program. Use this checklist to build one for Microsoft 365.

Scope

  • List the categories of personal data you process (customers, employees, prospects, suppliers).
  • Identify which Microsoft 365 workloads hold each category: Exchange, SharePoint, OneDrive, Teams.
  • Identify other systems that sync data into Microsoft 365 (CRM exports, HR reports).

Discovery

  • Sensitive information types relevant to your regions are enabled.
  • Content explorer has been reviewed for where personal data is concentrated.
  • High-concentration SharePoint sites and Teams have named owners.
  • Personal data stored in personal OneDrive accounts has been reviewed for business processes that should move elsewhere.

Controls

  • A sensitivity label taxonomy is published.
  • Sites with personal data have appropriate access restrictions and sharing settings.
  • DLP policies cover external sharing of personal data.
  • Guest access to sites containing personal data is reviewed.

Retention

  • Retention periods are agreed with legal for each data category.
  • Retention policies or labels apply those periods.
  • Deletion actually occurs at the end of the period.

Rights and incidents

  • A process exists for data subject requests, using eDiscovery or Priva.
  • Audit logging is enabled and retained long enough to investigate a breach.
  • Breach notification responsibilities and timelines are documented.

Review

  • The inventory is reviewed at least annually or when major systems change.
gdpr data inventory checklistGDPR enforcement2018

More on this story