Microsoft 365Platform ChangesRetrospectives

GDPR Enforcement Begins (May 2018): What It Changed for Microsoft 365 Data Governance

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2018, written in 2026 with the benefit of hindsight.

On May 25, 2018, the European Union's General Data Protection Regulation (GDPR) became enforceable. It applied to any organization processing personal data of people in the EU, wherever the organization was based, with fines of up to 4% of global annual revenue.

What changed for Microsoft 365 customers

GDPR required organizations to know what personal data they held, why, where it lived and who could access it. For most companies, much of that data lived in email, SharePoint, OneDrive and Teams. Suddenly, data governance in Microsoft 365 was a legal requirement, not a best practice.

Key obligations with direct Microsoft 365 implications:

  • Data subject requests: finding and exporting or deleting a person's data across mailboxes and sites.
  • Breach notification within 72 hours, which requires audit logs to understand what was accessed.
  • Data minimization and retention: keeping personal data only as long as needed.
  • Security of processing: appropriate technical measures such as access control and encryption.

How Microsoft responded

Microsoft updated its contractual terms to act as a data processor, published compliance documentation and expanded tools that later became Microsoft Purview: content search and eDiscovery, retention policies, sensitivity labels, data loss prevention and Compliance Manager.

In hindsight

GDPR raised the floor worldwide. Similar laws followed in California and many other jurisdictions. It also laid the groundwork for today's challenges: the same data governance gaps that made GDPR compliance hard are the ones that make Microsoft 365 Copilot oversharing risky. Organizations that invested in classification and retention in 2018 were far better prepared for AI.

gdpr microsoft 365GDPR enforcement2018

More on this story