Planning for regulatory compliance in Microsoft 365
In order to meet the requirements of GDPR when using a Microsoft 365 environment, Microsoft recommends that all organizations undertake a three-phase action plan to achieve the following outcomes.
Phase 1 – the first 30 days
In the first phase of your action plan, compliance administrators should focus on achieving the following:
- Gain an understanding of your GDPR requirements by using the Microsoft GDPR assessment tool, which can be accessed from https://discover.microsoft.com/gdpr-readiness-assessment.
- Begin a discovery exercise to identify the types of personal data stored within your Microsoft 365 environment.
- Assess risks by using the Microsoft Compliance Score tool, which can be found within Microsoft Service Trust Portal (STP) at https://servicetrust.microsoft.com/.
In order to gain the level of understanding that you require, you may wish to consider engaging a specialist GDPR consultancy...