Microsoft 365 GDPR
Where is personal data, and who can open it? Answered in minutes.
In a typical Microsoft 365 tenant, personal data sits in thousands of files across dozens of sites, an ordinary account can reach hundreds of thousands of them, and "who touched what" needs history that reaches back further than a few months. 1Security finds the personal data, counts who can reach it, and keeps up to three years of access history - so a DSAR, a regulator or a 72-hour breach clock meets a filter instead of a project.
The problem
GDPR asks precise questions. The answers should be one filter away.
The obligations are operational: know where personal data is, show who can access it, respond to a data subject in a month, notify a breach in 72 hours with a defensible view of what was exposed. The raw material for those answers is spread across files, mailboxes, directory data and activity history - and pulling it together by hand is a project each time the question is asked. 1Security keeps it in one place, with up to three years of access history instead of the 180 days you start with.
Most organizations answer with snapshots: a discovery project, a permissions export, a spreadsheet that was correct the day it was made. When the supervisory authority asks "who could access this person's data in March?", the spreadsheet from January is not an answer - and the March logs are gone.
What we see on the first day of a connection is consistent: personal data in 5-15% of all files, concentrated in a handful of sites, hundreds of files with IDs or bank details behind "anyone" links, and third-party apps that can read personal data and appear in no processing register. 1Security puts all of it in one list on the first day.
The same connection also grades the tenant against GDPR itself. On the Compliance screen, GDPR is one of eleven frameworks measured from live tenant data: the requirements behind Article 32 - label protection, restricted-data reachability, dormant accounts, log retention - carry a live Met, At risk or Not met status, and "not evaluated" is never counted as a pass. The readiness you would show a regulator is visible before you have remediated anything.
In practice
Five GDPR questions, answered from one place.
How GDPR work runs in 1Security when the answers are live and exportable.
- 01
Locate personal data
Open Sensitive info and filter to the GDPR framework. Over 300 detection types - EU IDs, IBANs, passport numbers, health data - scanned by our own engine in files and emails, with OCR for scanned forms and photos of documents. Each type shows how many files carry it and which sites concentrate it: two sites holding 90% of it means two remediation projects, not two hundred.
- 02
Count who can reach it
Every finding is crossed with the permission graph: which users, groups, apps and sharing links can open the file, and through what path. Sort by the apps column and you have every third-party app that can read personal data - most tenants find several nobody documented.
- 03
Answer the processor question
Article 28 asks who processes personal data on your behalf, and the register usually stops at signed DPAs. Two live inventories answer from the tenant instead: Apps lists every third-party application with a foothold and what it can read, with the admin who consented on record, and Domains resolves every external organisation you exchange data with to the real company behind it - flagging drift like a domain blocked in one admin center yet active through another, with a trusted, watched or blocked verdict you can enforce.
- 04
Reconstruct who touched it
Open Activity logs and filter to the person's files, or to the account that was compromised. Up to three years of activity, each event tied to an actor, app, device and location - a data-subject request or "who accessed this in March" becomes a filter, not a forensics project.
- 05
Serve the 72-hour clock
When an incident opens, the blast radius is a lookup: what the affected account could reach, whether regulated data was in scope, from which device and network the activity came - in minutes. Then revoke the links and permissions from the same screen and Actions keeps the remediation trail for the final report.
What makes it work
Three parts of the platform, one GDPR file.
GDPR operations run on capabilities you can read about in depth.
Compliance monitoring
GDPR graded next to ten other frameworks from the same tenant data - measured requirements, weekly snapshots and a per-framework evidence pack.
Explore the feature →Audit history
Up to three years of searchable, attributed activity on a standard license - the memory the 72-hour clock depends on.
Explore the feature →Access management
Effective access resolved through groups, links and inheritance - who can reach personal data, and one place to take it away.
Explore the feature →
FAQ
Common questions.
Does 1Security make us GDPR compliant?
No tool does. 1Security supplies the operational half: locating personal data, counting who can reach it, and keeping the attributed history your evidence depends on. Legal interpretation, notification decisions and the compliance program stay with your counsel and your DPO.
Do we need a premium license for the personal-data detection?
No. Detection runs on our own scanning engine with 300+ detectors and OCR, on standard Microsoft 365 licenses. If you already have Purview, its detections are imported alongside ours, so you get an independent check instead of a second silo.
Where is our data processed, and what is stored?
Each customer runs in their own dedicated database, never shared across customers. File content is streamed into analysis and discarded - only the detection type, match count and confidence are kept; the matched values themselves are never written to the database. Cloud, bring-your-own-Azure and air-gapped on-premise deployments are all supported.
Can we quote the findings to a regulator?
Yes. Every detection carries a confidence level, so you can build reports from high-confidence matches only, and export the exact view you quoted with the filter state that produced it.
How do we show an auditor our status on a past date?
The compliance status is captured automatically every week and on demand, and each framework exports a dated evidence pack - also served over the API. "What did our GDPR posture look like in March" is answered by opening the March snapshot, not by reconstructing it.
Know where personal data is before someone with a deadline asks.
Connect read-only and see where personal data lives, who can reach it, and what the last three years of access look like - the same day.
Or rebuild the spreadsheet for the next request.