Skip to content

Commit e6a2ae1

Browse files
authored
Merge branch 'main' into repo_sync_working_branch
2 parents c36fb55 + 0bc51b5 commit e6a2ae1

6 files changed

Lines changed: 415 additions & 36 deletions

File tree

microsoft-365/enterprise/TOC.yml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -400,10 +400,13 @@
400400
href: turn-off-directory-synchronization.md
401401

402402
- name: Compliance
403-
href: ../compliance/index.yml
403+
href: essentials-compliance.md
404404

405405
- name: Security
406-
href: ../security/index.yml
406+
href: essentials-security.md
407+
408+
- name: Privacy
409+
href: essentials-privacy.md
407410

408411
- name: Cloud services
409412
items:
Lines changed: 129 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,129 @@
1+
---
2+
title: Compliance for Microsoft 365
3+
f1.keywords:
4+
- NOCSH
5+
ms.author: kvice
6+
author: kelleyvice-msft
7+
manager: scotv
8+
ms.date: 03/18/2024
9+
audience: ITPro
10+
ms.topic: article
11+
ms.service: microsoft-365-enterprise
12+
ms.localizationpriority: high
13+
ms.collection:
14+
- scotvorg
15+
- must-keep
16+
- essentials-compliance
17+
ms.custom:
18+
- it-pro
19+
- intro-overview
20+
description: Learn about compliance for Microsoft 365 for enterprise.
21+
---
22+
23+
# Compliance for Microsoft 365 for enterprise
24+
25+
Most organizations have business or legal requirements that govern how data is used, shared, and retained. Some organizations also have data residency requirements or regulatory requirements that restrict communication between certain users and groups.
26+
27+
[Microsoft Compliance](/compliance) contains a plethora of information to help organizations understand how we as a cloud service provider can satisfy those requirements. See the [comprehensive list of compliance offerings](/compliance/regulatory/offering-home) for information detailing how Microsoft complies with national, regional, and industry-specific requirements governing the collection and use and data.
28+
29+
## Shared responsibility model
30+
31+
Security and compliance in the cloud is a [shared responsibility](/compliance/assurance/assurance-risk-assessment-guide) and the division of those responsibilities between the cloud service provider and customer depends on the cloud offering utilized. Microsoft works to ensure that we are compliant with industry and international standards, and customers are responsible for ensuring their data within the [Microsoft Cloud](https://www.microsoft.com/en-us/trust-center/compliance/compliance-overview#compliance) is protected in a manner that is compliant with the standards and regulations imposed on the customer.
32+
33+
## Inheritance of compliance features and settings
34+
35+
Microsoft 365 apps, depending on the app, inherit compliance features and settings from Microsoft Teams, Exchange Online, SharePoint Online, Azure, and Viva Engage. In addition, all Microsoft 365 services are built on the [Microsoft Graph API](/graph/overview).
36+
37+
For detailed information on each service, see:
38+
39+
**Microsoft 365** [Plan for security and compliance](/microsoft-365/compliance/plan-for-security-and-compliance)
40+
41+
**Microsoft Teams** [Overview of security and compliance in Microsoft Teams](/microsoftteams/security-compliance-overview)
42+
43+
**Microsoft SharePoint** [Plan compliance requirements for SharePoint and OneDrive](/SharePoint/compliant-environment)
44+
45+
**Microsoft Graph** [Use the Microsoft Graph compliance and privacy APIs](/graph/api/resources/complianceapioverview)
46+
47+
**Viva Engage** [Overview of security and compliance in Viva Engage](/viva/engage/manage-security-and-compliance/security-and-compliance)
48+
49+
**Microsoft Entra ID** [Microsoft Entra security baseline for Microsoft Entra ID](/security/benchmark/azure/baselines/aad-security-baseline)
50+
51+
**Azure** [Azure, Dynamics 365, Microsoft 365, and Power Platform compliance offerings](/azure/compliance/offerings/)
52+
53+
## General Data Protection Regulation (GDPR)
54+
55+
All Microsoft 365 apps and services support compliance with EU General Data Protection Regulation (GDPR) requirements.
56+
For detailed information, see [the GDPR Overview](/compliance/regulatory/gdpr).
57+
58+
## Data residency
59+
60+
Multi-Geo is Microsoft 365 feature that allows organizations to span their storage over multiple geo locations and specify where to store users' data. For multinational customers with data residency requirements, you can use this feature to ensure that each user's data is stored in the geo location necessary for compliance. For more info about this feature, see [Multi-Geo Capabilities in OneDrive and SharePoint](/office365/enterprise/multi-geo-capabilities-in-onedrive-and-sharepoint-online-in-office-365/).
61+
62+
For more information about Microsoft 365 Multi-Geo, see [Microsoft 365 Multi-Geo](/microsoft-365/enterprise/microsoft-365-multi-geo).
63+
64+
## Microsoft Purview
65+
66+
[Microsoft Purview](/purview/purview) is a family of data governance, risk, and compliance solutions that can help your organization govern, protect, and manage your entire data estate.
67+
68+
### Data lifecycle management
69+
70+
Use data lifecycle management capabilities in Microsoft Purview to govern your OneDrive and SharePoint content for compliance or regulatory requirements. The following table describes the capabilities to help you keep the content you need you and delete what you don't need.
71+
72+
|Capability|What problems does it solve?|Get started|
73+
|:------|:------------|:----------------------------|
74+
|[Retention policies and retention labels](/microsoft-365/compliance/retention)<br /><br />[Learn about retention for SharePoint and OneDrive](/microsoft-365/compliance/retention-policies-sharepoint) | Retain or delete content with policy management for SharePoint and OneDrive documents | [Create and configure retention policies](/microsoft-365/compliance/create-retention-policies) <br /><br /> [Create retention labels for exceptions to your retention policies](/microsoft-365/compliance/create-retention-labels-information-governance)|
75+
76+
#### Deleted users' data
77+
78+
When a user leaves your organization and you've deleted that user's account, what happens to the user's data? When considering data retention compliance, determine what needs to happen with the deleted user's data. For some organizations, retaining deleted user data could be important continuity and preventing critical data loss.
79+
80+
If a user's Microsoft 365 account is deleted, their OneDrive files are preserved for 30 days. To change this setting, [Set the OneDrive retention for deleted users](/onedrive/set-retention).
81+
82+
By default, when a user is deleted, the user's manager is automatically given access to the user's OneDrive. To change this, see [OneDrive retention and deletion](/onedrive/retention-and-deletion).
83+
84+
### Information protection
85+
86+
Microsoft Purview Information Protection capabilities help you discover, classify, and protect sensitive information in OneDrive and SharePoint. The following table describes these capabilities. Consider if you want to implement any of these capabilities as part of your OneDrive and SharePoint rollout.
87+
88+
|Capability|What problems does it solve?|Get started|
89+
|:------|:------------|:--------------------|
90+
|[Sensitive information types](/microsoft-365/compliance/sensitive-information-type-learn-about)| Identifies sensitive data by using built-in or custom regular expressions or a function. Corroborative evidence includes keywords, confidence levels, and proximity.| [Customize a built-in sensitive information type](/microsoft-365/compliance/customize-a-built-in-sensitive-information-type)|
91+
|[Trainable classifiers](/microsoft-365/compliance/classifier-learn-about)| Identifies sensitive data by using examples of the data you're interested in rather than identifying elements in the item (pattern matching). You can use built-in classifiers or train a classifier with your own content.| [Get started with trainable classifiers](/microsoft-365/compliance/classifier-get-started-with) |
92+
|[Sensitivity labels](/microsoft-365/compliance/sensitivity-labels)| A single solution across apps, services, and devices to label and protect your data as it travels inside and outside your organization. <br /><br /> Sensitivity labels can be used to protect files themselves or individual SharePoint sites and teams.|[Enable sensitivity labels for Office files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files) <br /><br /> [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 Groups, and SharePoint sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites)|
93+
|[Data loss prevention](/microsoft-365/compliance/dlp-learn-about-dlp)| Helps prevent unintentional sharing of sensitive items. | [Get started with the default DLP policy](/microsoft-365/compliance/get-started-with-the-default-dlp-policy)|
94+
95+
### File sync
96+
97+
The OneDrive sync app has policies that you can use to help you maintain a compliant environment. Consider configuring these policies before you roll out SharePoint and OneDrive.
98+
99+
|Policy|Windows GPO|Mac|
100+
|:-----|:----------|:--|
101+
|Allow syncing OneDrive accounts for only specific organizations|[AllowTenantList](/onedrive/use-group-policy#allow-syncing-onedrive-accounts-for-only-specific-organizations)|[AllowTenantList](/onedrive/deploy-and-configure-on-macos#allowtenantlist)|
102+
|Block syncing OneDrive accounts for specific organizations|[BlockTenantList](/onedrive/use-group-policy#block-syncing-onedrive-accounts-for-specific-organizations)|[BlockTenantList](/onedrive/deploy-and-configure-on-macos#blocktenantlist)|
103+
|Prevent users from syncing libraries and folders shared from other organizations|[BlockExternalSync](/onedrive/use-group-policy#prevent-users-from-syncing-libraries-and-folders-shared-from-other-organizations)|[BlockExternalSync](/onedrive/deploy-and-configure-on-macos#blockexternalsync)|
104+
|Prevent users from syncing personal OneDrive accounts|[DisablePersonalSync](/onedrive/use-group-policy#prevent-users-from-syncing-personal-onedrive-accounts)|[DisablePersonalSync](/onedrive/deploy-and-configure-on-macos#disablepersonalsync)|
105+
|Exclude specific kinds of files from being uploaded|[EnableODIgnoreListFromGPO](/onedrive/use-group-policy#exclude-specific-kinds-of-files-from-being-uploaded)|[EnableODIgnore](/onedrive/deploy-and-configure-on-macos#enableodignore)|
106+
107+
### Information barriers
108+
109+
Microsoft Purview Information Barriers is a compliance solution that allows you to restrict two-way communication and collaboration between groups and users in Microsoft Teams, SharePoint, and OneDrive. Often used in highly regulated industries, information barriers can help to avoid conflicts of interest and safeguard internal information between users and organizational areas.
110+
111+
When information barrier policies are in place, users who shouldn't communicate or share files with other specific users won't be able to find, select, chat, or call those users. Information barrier policies automatically put checks in place to detect and prevent unauthorized communication and collaboration among defined groups and users.
112+
113+
If your business requires information barriers, see [Learn about information barriers](/microsoft-365/compliance/information-barriers) and [Use information barriers with SharePoint](/sharepoint/information-barriers) to get started.
114+
115+
## Related articles
116+
117+
[Implement compliance in Microsoft 365](/training/paths/implement-data-governance-microsoft-365-intelligence/)
118+
119+
[Compliance in Microsoft Teams](/microsoftteams/security-compliance-overview#compliance)
120+
121+
[Compliance in Microsoft Viva](/viva/viva-compliance)
122+
123+
[Compliance in SharePoint and OneDrive](/sharepoint/compliant-environment)
124+
125+
[Compliance in Microsoft Cloud for Retail](/industry/retail/compliance-overview)
126+
127+
[Windows Privacy Compliance Guide](/windows/privacy/windows-10-and-privacy-compliance)
128+
129+
[Microsoft Purview Compliance Portal](/purview/purview-compliance-portal)
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
---
2+
title: Privacy for Microsoft 365
3+
f1.keywords:
4+
- NOCSH
5+
ms.author: kvice
6+
author: kelleyvice-msft
7+
manager: scotv
8+
ms.date: 05/13/2024
9+
audience: ITPro
10+
ms.topic: article
11+
ms.service: microsoft-365-enterprise
12+
ms.localizationpriority: high
13+
ms.collection:
14+
- scotvorg
15+
- must-keep
16+
- essentials-privacy
17+
ms.custom:
18+
- it-pro
19+
- intro-overview
20+
description: Learn about privacy for Microsoft 365 for enterprise.
21+
---
22+
23+
# Privacy for Microsoft 365 for enterprise
24+
25+
When an organization is considering relying on Microsoft 365 for communication and collaboration, privacy is something that needs to be addressed at every level. The topics we discuss in this article should address your privacy concerns when planning your Microsoft 365 implementation, or at any point during Microsoft 365 usage.
26+
27+
## What personal data does Microsoft 365 collect and for what purposes does Microsoft 365 use this data?
28+
29+
Microsoft processes the personal data in Microsoft 365 to deliver the services and for the purposes outlined in the [Product Terms](https://www.microsoft.com/licensing/terms/product/PrivacyandSecurityTerms/all) and the [Microsoft Online Services Data Protection Addendum (DPA)](https://aka.ms/dpa). Microsoft 365, as an integrated set of cloud-based services, processes various types of personal data as part of delivering the services.
30+
31+
To the extent Microsoft 365 processes personal data with Microsoft's legitimate business operations, Microsoft is an independent data controller for such use and is responsible for complying with all applicable laws and controller obligations.
32+
33+
## Legal Basis of Processing
34+
35+
Our customers are controllers for the data provided to Microsoft, as set forth in the [Product Terms](https://www.microsoft.com/licensing/terms/product/PrivacyandSecurityTerms/all) and the [Microsoft Online Services Data Protection Addendum (DPA)](https://aka.ms/dpa), and they determine legal basis of processing. Microsoft, in turn, processes the data on the customers' instructions, as a processor.
36+
37+
## What third parties have access to personal data?
38+
39+
Microsoft won't disclose personal data except:
40+
41+
1. as the customer directs (including as required to complete phone calls);
42+
1. as described in the Online Service Terms (such as the use of authorized subcontractors to provide certain components of services);
43+
1. as required by law.
44+
45+
If law enforcement contacts Microsoft with a demand, Microsoft will attempt to redirect the law enforcement agency to request that personal data directly from the customer. If compelled to disclose personal data to law enforcement, Microsoft will promptly notify the customer and provide a copy of the demand unless legally prohibited from doing so. For more information about data that we disclose in response to requests from law enforcement and other government agencies, please see our [Law Enforcement Requests Report](https://www.microsoft.com/corporate-responsibility/law-enforcement-requests-report).
46+
47+
## Where does Microsoft 365 transfer and store personal data?
48+
49+
Personal data is transferred and stored as set forth in the [Online Service Terms](https://go.microsoft.com/fwlink/p/?linkid=2050263), the [Product Terms](https://www.microsoft.com/licensing/terms/product/PrivacyandSecurityTerms/all) and the [Microsoft Online Services Data Protection Addendum (DPA)](https://aka.ms/dpa).
50+
51+
We have information on the [Microsoft 365 Data Residency overview and definitions](m365-dr-overview.md) if you need to learn more.
52+
53+
## How long does Microsoft 365 retain personal data?
54+
55+
Microsoft 365 retains your data for the minimum amount of time necessary to deliver the service.
56+
57+
Because this data is required to provide the service, this typically means that we retain personal data until the user stops using Microsoft 365, or until the user deletes personal data. If a user (or an administrator on the user's behalf) deletes the data, Microsoft will ensure that all copies of the personal data are deleted within 30 days.
58+
59+
If a company terminates service with Microsoft, corresponding personal data will all be deleted between 90 and 180 days of service termination.
60+
61+
In some circumstances, local laws require that Microsoft 365 retains telephone records (for billing purposes) for a specific period of time, in those circumstances Microsoft 365 follows the law for each region.
62+
63+
Additionally, if a company requests that Microsoft 365 holds a user's data to support a legal obligation, Microsoft will respect the company administrator's request.
64+
65+
### Right to withdraw consent
66+
67+
If Microsoft 365 processes any personal data based on consent, you may have the right to withdraw your consent at any time. You should direct your request to withdraw consent to your administrator, where your administrator is the controller of the personal data at issue.
68+
69+
## Contact Details of Microsoft's Data Protection Officer
70+
71+
If you have a privacy concern, complaint or question for the Microsoft Chief Privacy Officer and EU Data Protection Officer, contact us by using [our web form](https://go.microsoft.com/fwlink/?LinkId=321116). Our EU Data Protection Officer is located at Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Telephone: +353 1 706 3117. You can also raise a concern or lodge a complaint with a data protection authority or other official with jurisdiction.
72+
73+
## Related articles
74+
75+
[Windows Privacy Compliance Guide](/windows/privacy/windows-10-and-privacy-compliance)
76+
77+
[Understand how privacy works in Microsoft Viva](/viva/viva-privacy)
78+
79+
[Microsoft Teams privacy](/microsoftteams/teams-privacy)
80+
81+
[Overview of privacy controls for Microsoft 365 Apps for enterprise](/deployoffice/privacy/overview-privacy-controls)
82+
83+
[Online Service Terms](https://go.microsoft.com/fwlink/p/?linkid=2050263)
84+
85+
[Product Terms](https://www.microsoft.com/licensing/terms/product/PrivacyandSecurityTerms/all)
86+
87+
[Microsoft Online Services Data Protection Addendum (DPA)](https://aka.ms/dpa)

0 commit comments

Comments
 (0)