Skip to content
Microsoft 365 Blog GDPR

Your company’s GDPR responsibilities — and how Vahti helps with Microsoft 365 files

Teemu Tapper
Teemu Tapper

Publishing a privacy notice is only one part of meeting your GDPR responsibilities. An organisation also needs to know what personal data it processes, why it is needed, where it is stored, who can access it and how long it should be kept. Vahti's GDPR File Review helps an organisation identify and manage review work in supported Microsoft 365 files, while the organisation remains responsible for deciding what action to take.

Key points

  • Personal data must be processed for a specified purpose and on a valid legal basis.
  • An organisation should know where personal data is stored, who is responsible for it and who can access it.
  • Personal data should be kept only for as long as it is needed.
  • Reviews, decisions and follow-up actions should be documented so the organisation can demonstrate what it has done.

GDPR responsibilities go beyond the privacy notice

When an organisation determines why and how personal data is processed, it normally acts as the controller. The controller must not only comply with data protection rules but also be able to demonstrate that compliance. This is known as the GDPR's accountability principle.

In practice, accountability means defining and documenting purposes, legal bases, retention periods, safeguards, responsibilities and decisions. It also means reviewing whether the measures in place remain appropriate as systems, people and business needs change.

Software can support this work, but it does not transfer the controller's responsibility to the software provider. Under Vahti's Data Processing Agreement, the customer acts as controller and Vahti Service Oy as processor when Vahti processes personal data from the customer's Microsoft 365 environment on the customer's behalf.

1. Know what personal data you process and why

Personal data is not limited to national identity numbers or health information. Names, email addresses, employment details, customer numbers and other information relating to an identifiable person may also be personal data.

An organisation should know why the data is used, which legal basis applies, who is responsible for it, where it is held and who receives it. These questions cannot be answered from a privacy notice alone. They require an up-to-date understanding of the organisation's actual processing activities.

Vahti can surface predefined signals that may indicate personal data in supported OneDrive and SharePoint files, helping the organisation focus its review. It does not determine why a file is used or which legal basis applies.

2. Keep only the data you need

The data minimisation principle means that personal data should be adequate, relevant and limited to what is necessary for its purpose. Data should not be collected or retained simply because it might become useful later.

A file containing personal data is not automatically a problem. A customer agreement, employment document or contact list may be entirely necessary. The organisation must assess why the file is needed, whether its contents are accurate and how it is protected. A signal surfaced by Vahti therefore indicates a need for review, not a legal conclusion.

The storage limitation principle also requires personal data to be kept in identifiable form only for as long as necessary. There is no single retention period for every type of data. The appropriate period depends on the purpose, applicable law and the organisation's own documented policies.

Vahti can show a file's age and flag older files, or files that have not changed for a long time, for retention review. Age alone does not mean that a file must be deleted. The organisation decides whether the material should be retained, archived, anonymised or deleted.

3. Restrict access and protect the data

Access to personal data should be limited to people who need it for their work, and permissions should be reviewed regularly. The organisation also needs safeguards—both technical measures and agreed working practices—that match the risks involved.

Sharing a file from OneDrive or SharePoint outside the organisation does not automatically make the sharing unlawful or mean that a personal data breach has occurred. External sharing may be necessary for legitimate work with customers, employees or partners. The important question is whether the access is justified, appropriately limited and still needed.

Vahti provides review context such as the file owner, location, age and how the file has been shared. It can bring forward widely or externally shared files with signals that may indicate personal data. The organisation assesses whether access remains necessary and makes any permission changes in its own Microsoft 365 environment.

4. Prepare for data subject requests and personal data breaches

An organisation needs a process for responding when a person asks to access, correct or erase their personal data. A Microsoft 365 file review is not a complete map of all personal data. Other systems, email, paper records and data handled by service providers must also be considered.

The organisation also needs a process for personal data breaches. A controller must document every personal data breach. It must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to people's rights and freedoms. If the breach is likely to result in a high risk, the controller must generally also inform affected people without undue delay.

Vahti recommends assessing a possible breach only when strong personal-data signals appear alongside separate exposure evidence. The organisation assesses what happened, its effects and any notification duties.

5. Document decisions and follow up

GDPR work should not depend on somebody remembering that a file was reviewed. The organisation should be able to show what was assessed, what was decided, who is responsible for the next step, what action was taken and when.

In Vahti, a finding can include the organisation's decision and reasoning, an owner, a due date, notes and a review history. A later scan can show whether the underlying signal has changed or whether an earlier decision should be reconsidered.

Vahti can also produce a confidential audit-support PDF. It brings together the review scope, findings recorded in Vahti and the organisation's latest decisions to support audit preparation. The report is not a GDPR audit, certification or proof of compliance.

How Vahti's GDPR File Review helps

1. Identify

Vahti reviews supported OneDrive and SharePoint files and uses rules to surface signals relating to personal data, retention and sharing.

2. Understand

The file owner, location, age, how the file has been shared and the reason for the signal help the organisation start with the most relevant files.

3. Decide

The organisation decides whether a file is still needed and adequately protected, and whether access should be restricted, a retention period set, or the file anonymised or deleted.

4. Follow up and document

The organisation can assign responsibility, set a due date and add notes.

During a review, Vahti temporarily reads supported file content to detect predefined personal-data signals and uses file metadata to provide retention and sharing context. It does not store raw file content, text matches or detected personal-data values in the Vahti service.

What remains the organisation's responsibility

Vahti does not:

  • find all personal data across all systems;
  • provide legal advice or perform a GDPR audit;
  • determine a legal basis or permitted purpose for processing;
  • set retention periods;
  • change permissions or delete Microsoft 365 files;
  • conclude from a signal alone that a personal data breach has occurred;
  • handle data subject requests on the organisation's behalf; or
  • guarantee that GDPR requirements are met.

The review covers only supported file formats within the OneDrive and SharePoint locations that Vahti can access with the available permissions.

Make GDPR file review easier to manage

Managing personal data in line with GDPR is ongoing work. Vahti highlights review needs in supported Microsoft 365 files, helps prioritise findings and supports consistent follow-up.

Learn more about Vahti's GDPR File Review or request a demo.

Frequently asked questions

Does a personal-data signal mean that GDPR requirements have not been met?

No. A signal means that the file should be reviewed. The organisation assesses why the file is needed, which legal basis applies, how it is protected and how long it should be kept.

Does Vahti find all personal data held by the organisation?

No. The review covers supported OneDrive and SharePoint files. Other systems and records must be assessed separately.

Does the PDF report prove GDPR compliance?

No. The PDF supports internal documentation and audit preparation. It is not an audit, certification or proof of compliance.

Sources

Share this post