You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/design-solutions-regulatory-compliance/includes/4-address-privacy-requirements-microsoft-priva.md
-**Data overexposure** — Detects personal data that is publicly accessible or has overly broad access. Remediation options include making content private, notifying content owners, or tagging items for review.
37
-
-**Data transfer** — Monitors transfers of personal data across geographic boundaries, departmental boundaries, or outside your organization. Users receive email notifications with corrective actions they can take directly.
38
-
-**Data minimization** — Identifies personal data stored beyond a configured retention threshold, helping reduce privacy risk from aging data. Items can be marked for deletion, or owners notified for review.
36
+
-**Data overexposure:** Detects personal data that is publicly accessible or has overly broad access. Remediation options include making content private, notifying content owners, or tagging items for review.
37
+
-**Data transfer:** Monitors transfers of personal data across geographic boundaries, departmental boundaries, or outside your organization. Users receive email notifications with corrective actions they can take directly.
38
+
-**Data minimization:** Identifies personal data stored beyond a configured retention threshold, helping reduce privacy risk from aging data. Items can be marked for deletion, or owners notified for review.
39
39
40
40
When policy matches are found, admins review alerts and create issues for further action. Email and Teams notifications inform content owners directly about policy matches. The Reports page presents consolidated insights on policy trends and data classification.
41
41
@@ -49,38 +49,38 @@ Priva Subject Rights Requests provides automation, insights, and workflows to fu
Priva automates the SRR lifecycle through stages—data estimation, retrieval, review, report generation, and closure. When designing your SRR solution, focus on:
62
62
63
-
-**Data scope and volume** — Priva retrieves content from Exchange Online, SharePoint Online, OneDrive for Business, and Teams into Azure Blob Storage. Plan storage and review capacity based on expected data volumes per request.
64
-
-**Review process design** — A dedicated Teams channel is automatically created for each request. Design your review process around who should be assigned as collaborators, how priority items (content with sensitivity labels, multi-person data, or retention labels) are escalated, and how built-in redaction tools fit into your data handling procedures.
65
-
-**Approval workflows for delete requests** — Delete requests require an additional approval substage. Define who has authority to approve deletions and how this integrates with your organization's data governance policies.
66
-
-**Integration and automation** — Use Power Automate templates to connect SRR workflows with ticketing systems like ServiceNow, and use the Microsoft Graph subject rights request API for programmatic access when building custom integrations.
63
+
-**Data scope and volume:** Priva retrieves content from Exchange Online, SharePoint Online, OneDrive for Business, and Teams into Azure Blob Storage. Plan storage and review capacity based on expected data volumes per request.
64
+
-**Review process design:** A dedicated Teams channel is automatically created for each request. Design your review process around who should be assigned as collaborators, how priority items (content with sensitivity labels, multi-person data, or retention labels) are escalated, and how built-in redaction tools fit into your data handling procedures.
65
+
-**Approval workflows for delete requests:** Delete requests require an additional approval substage. Define who has authority to approve deletions and how this integrates with your organization's data governance policies.
66
+
-**Integration and automation:** Use Power Automate templates to connect SRR workflows with ticketing systems like ServiceNow, and use the Microsoft Graph subject rights request API for programmatic access when building custom integrations.
-**Start with Priva and Purview together** — Use Priva for privacy-specific operations and Purview solutions for data protection, classification, and lifecycle management to address privacy requirements holistically
75
-
-**Review default policies first** — The default privacy risk management policies are automatically enabled; customize them based on your highest privacy risks
76
-
-**Configure anonymization** — Turn on anonymization in Priva settings to show anonymized usernames when reviewing privacy risk alerts
77
-
-**Define response SLAs** — Establish service level agreements for subject rights requests that meet regulatory timeframes (default completion deadline is two weeks past creation)
78
-
-**Automate where possible** — Use Power Automate templates to connect Priva with ticketing systems, and use the Microsoft Graph subject rights request API for programmatic integration
79
-
-**Plan for scale** — Design workflows that can handle increased request volumes; purchase subject rights requests in blocks of 1, 10, or 100
80
-
-**Train content owners** — Enable user notification emails so data owners can remediate privacy risks directly from email notifications
81
-
-**Configure data retention** — Set retention periods (30 or 90 days) for subject rights request data after requests are closed
82
-
-**Integrate with Compliance Manager** — Priva actions contribute to your compliance score; automated detection of Priva improvement actions is in preview
83
-
-**Set appropriate permissions** — Assign users to Priva role groups following the principle of least privilege
74
+
-**Start with Priva and Purview together:** Use Priva for privacy-specific operations and Purview solutions for data protection, classification, and lifecycle management to address privacy requirements holistically
75
+
-**Review default policies first:** The default privacy risk management policies are automatically enabled; customize them based on your highest privacy risks
76
+
-**Configure anonymization:** Turn on anonymization in Priva settings to show anonymized usernames when reviewing privacy risk alerts
77
+
-**Define response SLAs:** Establish service level agreements for subject rights requests that meet regulatory timeframes (default completion deadline is two weeks past creation)
78
+
-**Automate where possible:** Use Power Automate templates to connect Priva with ticketing systems, and use the Microsoft Graph subject rights request API for programmatic integration
79
+
-**Plan for scale:** Design workflows that can handle increased request volumes; purchase subject rights requests in blocks of 1, 10, or 100
80
+
-**Train content owners:** Enable user notification emails so data owners can remediate privacy risks directly from email notifications
81
+
-**Configure data retention:** Set retention periods (30 or 90 days) for subject rights request data after requests are closed
82
+
-**Integrate with Compliance Manager:** Priva actions contribute to your compliance score; automated detection of Priva improvement actions is in preview
83
+
-**Set appropriate permissions:** Assign users to Priva role groups following the principle of least privilege
0 commit comments