Skip to content
Microsoft 365 Privacy

Find the files that require a data protection assessment

Files containing information about customers, employees, or other individuals can easily accumulate in OneDrive and SharePoint. Vahti helps identify personal data signals, risks related to external sharing, and files whose retention needs to be assessed.

You get a prioritized view of what to check first—without Vahti making any changes to your Microsoft 365 environment.

  • OneDrive and SharePoint
  • For Small and Medium-Sized Businesses
  • For entrepreneurs
  • For IT teams
1
An Overview of the M365 Data Set

Do you know where your company's personal data is stored?

In the Microsoft 365 environment, files are constantly being created. They are stored in users’ OneDrive accounts, on SharePoint sites, and in project folders. In practice, no one necessarily has a complete picture of:

  • where files containing personal data are located
  • who is responsible for the files
  • how old the files are
  • with whom they have been shared
  • whether the data needs to be retained

Vahti helps you start reviewing the files and situations that require the most attention.

What does the scan find?

See what content in Microsoft 365 is worth reviewing

The monitor generates deterministic insights from Microsoft 365 files and displays the underlying context.

Files containing personal data

Files may contain indicators of personal information. This finding helps focus the review, but does not, on its own, determine what action should be taken regarding the file.

Candidates for Sensitive Information

Some files may contain indicators suggesting that they require more sensitive handling than usual.

Files that require an assessment of retention needs

Old files or those that have remained unchanged for a long time may require an assessment of their retention needs.

Files shared widely or externally

It is especially important to review a file containing personal data if it has been shared with an external party.

Here's how the review process works

Turn file findings into practical decisions

You don't need to be an IT or cybersecurity expert to use Vahti.

Identify

The monitor looks for signals related to personal data, storage, and sharing.

Understand

You can see the owner, location, age, context of the post, and the rationale behind the observation.

Decide

Note whether the finding requires, for example, restrictions on access rights or the establishment of retention policies.

Follow

Record the person in charge, the deadline, and any notes regarding the matter.

The monitor indicates that security settings must be configured correctly.
PDF Report Supporting the Audit

Compile the results of the review to support the GDPR audit

You can generate a downloadable PDF report from the completed GDPR data review. It compiles the open findings retained in Vahti, findings that were no longer detected in a subsequent review, the scope of the review, and the organization’s most recent recorded decisions.

The report documents the status at the time of the review and facilitates the sharing of the material with, for example, the data protection officer, management, or an external auditor. The report can be used in preparation for a GDPR audit and as supporting documentation. However, it is not a GDPR audit, certification, or proof of compliance.

Decision-Making

The monitor assists with the evaluation—the organization makes the decisions

A review of GDPR data does not provide an automatic legal answer as to what should be done with the data. The organization itself assesses the purpose of use, access, retention period, and any potential restriction, deletion, or anonymization.

Vahti makes it visible

  • What to check
  • What the observation is based on
  • To whom can the work be assigned?

The organization decides

  • What is the permitted use?
  • How long will the material be needed?
  • What will ultimately be done with the file?
To whom?

Who should review GDPR-related materials?

For Small and Medium-Sized Enterprises

When there are more M365 files than anyone can go through manually.

For IT Partners

When you want to provide customers with a prioritized view of their inspection needs.

To Those Responsible for Data Protection

When you need a starting point for reviewing files that contain personal information.

To Management

When you want to see open tasks, the people in charge, and how the situation is progressing.

Trust and Boundaries

What does Vahti check, and what doesn't it do?

A review of GDPR-related data does not provide an automatic legal answer as to what should be done with the data. The organization itself assesses the purpose of use, access, retention period, and any potential restriction, deletion, or anonymization.

Vahti does

  • check supported OneDrive and SharePoint files
  • identify signals related to personal information and retention
  • display the owner, location, age, and sharing context
  • prioritize findings and provide recommendations for next steps
  • generate a downloadable PDF report from the scan to support the audit

Vahti doesn't do

  • ensures compliance with all GDPR requirements
  • determine retention periods or deletion
  • automatically delete or modify files
  • detect a data breach based solely on the signal

Vahti as part of M365 security

GDPR compliance checks complement other M365 security measures

A file containing personal data is not a risk solely because of its content. The risk is also influenced by users, access rights, external sharing, and the detection of anomalies.

  • Unusual Logins
  • Excessive access rights
  • External sharing links
  • High-risk application permissions
  • Security configuration gaps

Would you like to know what you should check in Microsoft 365 files?

Request a demo, and we'll show you how GDPR compliance checks work in a small or medium-sized business's Microsoft 365 environment.

Frequently Asked Questions

Is a GDPR data review the same thing as a GDPR audit?

No. Vahti identifies audit requirements related to personal data, sharing, and retention in Microsoft 365 files. You can generate a PDF report from the scan to prepare for a GDPR audit and as supporting documentation, but Vahti does not perform a legal audit nor does it guarantee compliance with GDPR requirements.

What does the PDF report on the GDPR audit contain?

The report compiles all open findings stored in Vahti and those that were no longer observed during a subsequent review. In addition, it describes the scope of the review and the organization’s most recent documented decisions. The report also contains information on owners, locations, and notes, so it must be treated as confidential.

What files does Vahti scan?

This check applies to supported OneDrive and SharePoint files. Coverage depends on the Microsoft 365 environment, access permissions, and supported file formats.

Does Vahti save the contents of files?

The monitor does not store raw file content. The findings are based on metadata and deterministically generated personal data and retention signals.

Does Vahti automatically delete files?

No. Vahti helps document the organization’s decision. Any restrictions, deletions, and anonymizations are carried out as part of the organization’s own Microsoft 365 management process.

Could a personal data alert indicate a data breach?

Not on its own. The personal data indicator suggests that the file should be reviewed. A potential data breach also requires separate evidence of unauthorized access to or use of the data.