en|de
Microsoft Purview · Data Protection and Compliance in Microsoft 365

Microsoft Purview for data protection, compliance, and information protection in Microsoft 365

Microsoft Purview helps you find, classify, protect, and retain sensitive data in Microsoft 365 in a traceable way. ReByteIT supports small and medium-sized companies in introducing this interplay technically and making it usable in everyday work.

Direct Microsoft Partner
Microsoft Security and Compliance Focus
Personal Consulting
24-Hour Response
Starting Point

Microsoft 365 alone does not mean data protection is under control

Microsoft 365 is used productively every day – often without reliable control over which sensitive data is stored where, who can share it, and how long it is retained.

01

Sensitive data without a recognizable structure

Customer, HR, and financial data is often stored unstructured in Teams, SharePoint, OneDrive, and Outlook.

02

External sharing and legacy permissions

Sharing has grown over time and is rarely documented in an audit-ready way.

03

Retention on paper only

Deletion and retention periods exist legally but are often not implemented technically.

In Short

Is Microsoft 365 automatically GDPR compliant?

No. Microsoft 365 provides security and compliance capabilities – whether these actually meet your data protection requirements depends on roles, policies, retention, sharing, and protective measures that have to be configured appropriately. Microsoft Purview helps implement this technically and make it traceable – it does not replace a legal assessment or an interpretation of the GDPR.

In-depth: “GDPR & Compliance” · available soon
Operating Model

How Microsoft Purview works together – not just Data Loss Prevention

Purview is not a single tool, but an interplay of information protection, data classification, governance, compliance, and risk transparency.

01

Discover

Make sensitive data visible in Exchange, SharePoint, OneDrive, and Teams.

02

Classify

Introduce data classification and sensitivity labels.

03

Protect

Protect against unwanted disclosure with Data Loss Prevention and encryption concepts.

04

Monitor

Make activities traceable with audit logging and Activity Explorer.

05

Retain

Implement retention and deletion rules technically.

06

Demonstrate

Document your status with a compliance baseline and a Compliance Manager review.

Scope of Services

Purview Security Foundation Assessment

Not a rigid fixed-price package, but an individually tailored assessment across four core areas. Scope, duration, and the required access rights are defined together with you.

Information Protection

  • Data classification
  • Sensitivity Labels
  • Encryption concepts

Data Loss Prevention

  • Exchange, SharePoint, OneDrive, Teams
  • Endpoint DLP

Audit & Visibility

  • Audit Logging
  • Activity Explorer
  • Reporting

Compliance Baseline

  • Compliance Manager Review
  • Gap Assessment
  • Quick Wins

Information Protection, Data Loss Prevention, and audit are also configured technically as part of the assessment. Data lifecycle management, records management, eDiscovery, and Compliance Manager are primarily evaluated and set up from a governance and compliance perspective. This assessment is the Purview-specific implementation of what we offer across services as an Onboarding Assessment within Microsoft 365 Consulting .

Optional add-ons: Insider Risk Management, Communication Compliance, Copilot Data Protection, and Data Security Posture Management (DSPM) for AI. According to current Microsoft documentation, DSPM for AI is still partly in preview and is deliberately not promoted as a standard service.
Target Group

Who is this service suited to?

The service is aimed primarily at small and medium-sized companies that use Microsoft 365 productively. What matters is not company size, but the actual data risk.

Classification is missing

Sensitive data is not classified in any recognizable way.

Sharing is unclear

External sharing and permissions have grown over time.

Retention is open

Retention and deletion obligations are not implemented technically.

Copilot rollout planned

The data foundation for secure Copilot use has not yet been clarified.

Approach

How the collaboration works

01

Scoping workshop

Clarify the starting situation, existing licenses, and maturity level together.

02

Evaluate classification

Define the protection requirements and classification model for your data.

03

Policies in test mode

Test DLP and retention policies in a controlled way first, before they enforce anything.

04

Document & hand over

Document the results and pass them on to your team in a knowledge transfer session.

Results

Which results you receive

Technical documentation

Policy overview, architecture overview, permission model, configuration settings, and recommended actions.

Tested policies

DLP and retention policies introduced and validated in a controlled way.

Knowledge transfer for your team

A handover session or administrator training on labels, DLP policies, retention, and the role and permission model.

Legal or compliance opinions are not part of the service.
Decision Guide

Microsoft Purview or a different Microsoft service?

In-Depth Topics

GDPR & compliance and Data Loss Prevention in detail

GDPR & Compliance

An in-depth look at retention, records management, eDiscovery, audit, and Compliance Manager.

Learn More →

Data Loss Prevention

In-depth policies for Exchange, SharePoint, OneDrive, Teams, and endpoint DLP, including the Copilot context.

Learn More →
FAQ

Questions about Microsoft Purview

Are we automatically GDPR compliant with Microsoft 365?

No. Microsoft 365 provides security and compliance capabilities, but roles, policies, retention, sharing, and protective measures have to be configured appropriately. Purview helps implement this technically and make it demonstrable.

Which data should we classify first?

In practice, usually customer, HR, and financial data first, along with documents subject to contractual or statutory retention obligations. The specific prioritization is defined together in the scoping workshop.

Can Purview prevent external sharing?

Purview can detect and label sensitive content and protect it against unwanted sharing through Data Loss Prevention policies. Whether sharing is blocked, only flagged, or triggers a warning depends on the configured policy.

Does Purview help against data leakage by departing employees?

Through classification, DLP policies, and optionally Insider Risk Management, Purview can help make unusual data movements visible and limit them. Complete prevention of data leakage cannot be guaranteed.

Can we use Copilot without sensitive data leaking?

Copilot should only be used productively once permissions, sensitivity labels, and classification have been reviewed. Purview can support this control, but it does not replace prior data and permission clean-up.

Is Microsoft Purview also worthwhile for smaller companies?

Yes. The service is aimed primarily at small and medium-sized companies that use Microsoft 365 productively. What matters is not company size, but the actual data risk: external sharing, customer and HR data, financial data, and retention obligations.

Which licenses do we need, and do you advise us on that?

The available Purview capabilities depend on the Microsoft 365 licensing model in use. Basic capabilities such as sensitivity labels, Data Loss Prevention, and retention policies are available in various Microsoft 365 plans; advanced capabilities such as Insider Risk Management, Communication Compliance, Audit (Premium), eDiscovery (Premium), and Endpoint DLP generally require Microsoft 365 E5 or corresponding add-on licenses. The consulting includes the technical assessment of the licenses required for the recommended Purview capabilities. Final licensing advice, contractual evaluation, and procurement are not part of this consulting service, but can be handled through the CSP business.

Does Purview replace our data protection officer or legal advice?

No. The consulting focuses on the technical capabilities of Microsoft Purview and Microsoft 365 for supporting data protection, compliance, and security requirements – such as data classification, information protection, Data Loss Prevention, auditing, and retention policies. Legal assessment, interpretation of the GDPR, and binding compliance or legal advice are not part of the offering and should be handled by your legal department, data protection officer, or specialized legal advisors. Technical implementation can, however, help demonstrate that organizational and regulatory requirements are met.

Initial Consultation

How should Microsoft Purview be used in your environment?

In a free initial consultation, we clarify whether a Purview Security Foundation Assessment, a targeted DLP configuration, or a structured review of your data protection and compliance requirements is the right next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, as a direct Microsoft partner with no intermediaries.