Having Microsoft 365 does not mean you are compliant
This is one of the most common misconceptions we encounter. An organisation migrates to Microsoft 365, ticks the cloud migration box, and assumes the compliance obligations are handled. They are not.
Microsoft 365 is a powerful compliance platform — but it requires deliberate configuration to work. The tools are there: sensitivity labels, retention policies, data loss prevention, audit logs, eDiscovery, and more. But out of the box, most of them are either switched off, set to defaults that do not reflect your organisation's needs, or simply not deployed.
"Microsoft provides the compliance infrastructure. Your organisation is responsible for configuring and operating it correctly. That distinction matters enormously — especially when the ICO comes knocking."
UK GDPR, which came into force after the UK's departure from the EU, places clear obligations on organisations to demonstrate that personal data is processed lawfully, stored securely, retained only as long as necessary, and deleted when it is no longer needed. Microsoft 365, properly configured, can help you meet every one of those obligations. Improperly configured, it can actively work against you.
This article provides a practical overview of compliance considerations in Microsoft 365 for UK organisations. It is not legal advice. For specific regulatory guidance, you should consult a qualified legal professional or your Data Protection Officer.
What UK GDPR actually requires of your organisation
UK GDPR is built around six core principles for the handling of personal data. Understanding how these map to your Microsoft 365 environment is the starting point for any compliance programme.
- You must have a lawful basis for processing personal data — consent, legitimate interest, contractual necessity, and so on.
- In Microsoft 365 terms, this means understanding what data you hold, where it lives, and ensuring you have the right to process it. Microsoft Purview's data map and content explorer tools help you locate personal data across your environment.
- Data should only be collected for specified, explicit purposes — and only as much as is necessary for those purposes.
- In practice, this means not storing personal data in ad hoc SharePoint lists, Teams chats, or Power BI datasets without a clear justification and governance process.
- Data must be accurate, kept up to date, and not retained longer than necessary. This is where retention policies in Microsoft 365 become critical — automatically archiving or deleting content when it reaches the end of its retention period.
- Equally important is data integrity: sensitivity labels and encryption ensure that personal data is protected throughout its lifecycle, not just at the point of collection.
- UK GDPR requires organisations to be able to demonstrate compliance — not just claim it. Audit logs, eDiscovery capabilities, and compliance reports in Microsoft Purview are your evidence base.
- If the ICO investigates a breach, your ability to produce a clear audit trail of who accessed what, when, and what controls were in place will significantly affect the outcome.
Six Microsoft 365 compliance tools every UK organisation should be using
Microsoft 365 includes a comprehensive set of compliance and governance tools under the Microsoft Purview umbrella. Here are the six that have the greatest practical impact for UK organisations:
The compliance gaps we see most often in UK Microsoft 365 environments
After working with over 50 UK organisations on their Microsoft 365 environments, these are the compliance failures that come up again and again — often in organisations that believe they are already compliant.
A practical approach to Microsoft 365 compliance for UK organisations
Compliance is not a project with an end date — it is an ongoing programme. But it has to start somewhere. Here is the sequence we recommend for organisations who need to get their Microsoft 365 environment into a defensible compliance position:
- Run a data discovery exercise using Microsoft Purview to identify where personal data lives across your environment.
- Review your current permissions model — who has access to what, and whether those permissions are still appropriate.
- Check whether unified audit logging is enabled and that logs are being retained for an appropriate period.
- Define a retention schedule aligned to your legal and regulatory obligations — what types of content need to be kept for how long, and what should be deleted.
- Design a sensitivity label taxonomy that reflects your content categories — typically public, internal, confidential, and highly confidential as a starting point.
- Document your data processing activities and map them to the six UK GDPR principles.
- Deploy retention policies to SharePoint, Exchange, and Teams — prioritising locations where personal data is most likely to accumulate.
- Implement DLP policies targeting the personal data types most relevant to your organisation — financial data, health information, identification numbers.
- Enable mandatory sensitivity labelling for new documents and emails, and run a remediation exercise on existing content.
- Tighten guest access policies, review external sharing settings, and implement conditional access policies for high-risk content.
- Set up regular compliance reviews — quarterly at a minimum — to review DLP alerts, audit log activity, and any changes to permissions or sharing.
- Assign clear ownership: a named Data Protection Officer or compliance lead, and content owners for high-risk document libraries.
- Train your people. Technology controls are only as effective as the people operating within them. Staff who understand why the controls exist are far more likely to follow them.
"Compliance is not a configuration exercise. It is a culture. The technology gives you the tools — but only leadership commitment and ongoing governance makes it work."
Where Cordapse can help
Microsoft 365 compliance is an area where the gap between what organisations think they have in place and what they actually have in place tends to be significant. We have seen this consistently across every sector we work in — finance, healthcare, professional services, and beyond.
At Cordapse, we help UK organisations assess their current Microsoft 365 compliance posture, design a governance framework that reflects their specific regulatory obligations, and implement the technical controls that make it real. Our Compliance & Governance service covers the full lifecycle — from data discovery through to ongoing monitoring and staff adoption.
Not sure how compliant your Microsoft 365 environment actually is?
Book a free, no-obligation consultation and we will help you understand your current compliance posture — and what it would take to close the gaps. No jargon, no pressure.
Book a free consultation →