Microsoft 365 GDPR

Where is personal data, and who can open it? Answered in minutes.

In a typical Microsoft 365 tenant, personal data sits in thousands of files across dozens of sites, an ordinary account can reach hundreds of thousands of them, and "who touched what" needs history that reaches back further than a few months. 1Security finds the personal data, counts who can reach it, and keeps up to three years of access history - so a DSAR, a regulator or a 72-hour breach clock meets a filter instead of a project.

The problem

GDPR asks precise questions. The answers should be one filter away.

The obligations are operational: know where personal data is, show who can access it, respond to a data subject in a month, notify a breach in 72 hours with a defensible view of what was exposed. The raw material for those answers is spread across files, mailboxes, directory data and activity history - and pulling it together by hand is a project each time the question is asked. 1Security keeps it in one place, with up to three years of access history instead of the 180 days you start with.

Most organizations answer with snapshots: a discovery project, a permissions export, a spreadsheet that was correct the day it was made. When the supervisory authority asks "who could access this person's data in March?", the spreadsheet from January is not an answer - and the March logs are gone.

What we see on the first day of a connection is consistent: personal data in 5-15% of all files, concentrated in a handful of sites, hundreds of files with IDs or bank details behind "anyone" links, and third-party apps that can read personal data and appear in no processing register. 1Security puts all of it in one list on the first day.

In practice

Four GDPR questions, answered from one screen.

How GDPR work runs in 1Security when the answers are live and exportable.

  1. 01

    Locate personal data

    Open Sensitive info and filter to the GDPR framework. Over 300 detection types - EU IDs, IBANs, passport numbers, health data - scanned by our own engine in files and emails, with OCR for scanned forms and photos of documents. Each type shows how many files carry it and which sites concentrate it: two sites holding 90% of it means two remediation projects, not two hundred.

  2. 02

    Count who can reach it

    Every finding is crossed with the permission graph: which users, groups, apps and sharing links can open the file, and through what path. Sort by the apps column and you have every third-party app that can read personal data - most tenants find several nobody documented.

  3. 03

    Reconstruct who touched it

    Open Activity logs and filter to the person's files, or to the account that was compromised. Up to three years of activity, each event tied to an actor, app, device and location - a data-subject request or "who accessed this in March" becomes a filter, not a forensics project.

  4. 04

    Serve the 72-hour clock

    When an incident opens, the blast radius is a lookup: what the affected account could reach, whether regulated data was in scope, from which device and network the activity came - in minutes. Then revoke the links and permissions from the same screen and Actions keeps the remediation trail for the final report.

What makes it work

Three parts of the platform, one GDPR file.

GDPR operations run on capabilities you can read about in depth.

  • Reporting

    Numbers you can quote to a regulator: confidence levels per detection, framework filters, exportable saved views.

    Explore the feature
  • Audit history

    Up to three years of searchable, attributed activity on a standard license - the memory the 72-hour clock depends on.

    Explore the feature
  • Access management

    Effective access resolved through groups, links and inheritance - who can reach personal data, and one place to take it away.

    Explore the feature

FAQ

Common questions.

Does 1Security make us GDPR compliant?

No tool does. 1Security supplies the operational half: locating personal data, counting who can reach it, and keeping the attributed history your evidence depends on. Legal interpretation, notification decisions and the compliance program stay with your counsel and your DPO.

Do we need a premium license for the personal-data detection?

No. Detection runs on our own scanning engine with 300+ detectors and OCR, on standard Microsoft 365 licenses. If you already have Purview, its detections are imported alongside ours, so you get an independent check instead of a second silo.

Where is our data processed, and what is stored?

Each tenant gets its own dedicated database. File content is streamed into analysis and discarded - only the detection type, match count and confidence are kept; the matched values themselves are never written to the database. Cloud, bring-your-own-Azure and air-gapped on-premise deployments are all supported.

Can we quote the findings to a regulator?

Yes. Every detection carries a confidence level, so you can build reports from high-confidence matches only, and export the exact view you quoted with the filter state that produced it.

Know where personal data is before someone with a deadline asks.

Connect read-only and see where personal data lives, who can reach it, and what the last three years of access look like - the same day.

Or rebuild the spreadsheet for the next request.