Microsoft 365How-To & HardeningRetrospectives

How to Use Microsoft Purview to Find and Govern Personal Data

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2018, written in 2026 with the benefit of hindsight.

Privacy laws such as GDPR require you to know where personal data lives and to control it. In Microsoft 365, Microsoft Purview provides the tools. Here is a practical starting sequence.

Step 1: Discover personal data

Use sensitive information types (built-in detectors for passport numbers, national IDs, financial data and more) and review results in Content explorer and Activity explorer in the Purview portal. Start with the data types most relevant to your regions and industry.

Step 2: Classify with sensitivity labels

Create a simple label taxonomy — for example Public, General, Confidential, Highly Confidential — and publish it to users. Add auto-labeling policies (E5 or equivalent add-on) to label content containing personal data automatically.

Step 3: Prevent leakage

Create data loss prevention (DLP) policies for Exchange, SharePoint, OneDrive and Teams that warn or block when personal data is shared externally.

Step 4: Keep only what you need

Apply retention policies and retention labels so personal data is kept for a defined period and then deleted. Involve legal and records management to set periods.

Step 5: Respond to data subject requests

Use eDiscovery (Standard or Premium) or Priva Subject Rights Requests to find, review and export a person's data across Microsoft 365.

Step 6: Prove it

Use Compliance Manager to track controls against GDPR and record evidence of what you have implemented.

Common mistakes

  • Creating dozens of labels nobody understands.
  • DLP policies in "block" mode on day one, frustrating users. Start with policy tips and audit mode.
  • Retention without deletion — keeping everything forever is a liability.
microsoft purview personal dataGDPR enforcement2018

More on this story