GDPR Data Inventory Checklist for Microsoft 365
Retrospective: this article looks back at events from May 2018, written in 2026 with the benefit of hindsight.
A data inventory is the foundation of GDPR compliance and of any serious data protection program. Use this checklist to build one for Microsoft 365.
Scope
- List the categories of personal data you process (customers, employees, prospects, suppliers).
- Identify which Microsoft 365 workloads hold each category: Exchange, SharePoint, OneDrive, Teams.
- Identify other systems that sync data into Microsoft 365 (CRM exports, HR reports).
Discovery
- Sensitive information types relevant to your regions are enabled.
- Content explorer has been reviewed for where personal data is concentrated.
- High-concentration SharePoint sites and Teams have named owners.
- Personal data stored in personal OneDrive accounts has been reviewed for business processes that should move elsewhere.
Controls
- A sensitivity label taxonomy is published.
- Sites with personal data have appropriate access restrictions and sharing settings.
- DLP policies cover external sharing of personal data.
- Guest access to sites containing personal data is reviewed.
Retention
- Retention periods are agreed with legal for each data category.
- Retention policies or labels apply those periods.
- Deletion actually occurs at the end of the period.
Rights and incidents
- A process exists for data subject requests, using eDiscovery or Priva.
- Audit logging is enabled and retained long enough to investigate a breach.
- Breach notification responsibilities and timelines are documented.
Review
- The inventory is reviewed at least annually or when major systems change.
- GDPR Enforcement Begins (May 2018): What It Changed for Microsoft 365 Data Governance Platform Changes
- How to Use Microsoft Purview to Find and Govern Personal Data How-To & Hardening
- CIO Brief: GDPR Fines and Your Cloud Data Map CIO Briefings