Files containing personal data
Files may contain indicators of personal information. This finding helps focus the review, but does not, on its own, determine what action should be taken regarding the file.
Files containing information about customers, employees, or other individuals can easily accumulate in OneDrive and SharePoint. Vahti helps identify personal data signals, risks related to external sharing, and files whose retention needs to be assessed.
You get a prioritized view of what to check first—without Vahti making any changes to your Microsoft 365 environment.
In the Microsoft 365 environment, files are constantly being created. They are stored in users’ OneDrive accounts, on SharePoint sites, and in project folders. In practice, no one necessarily has a complete picture of:
Vahti helps you start reviewing the files and situations that require the most attention.
The monitor generates deterministic insights from Microsoft 365 files and displays the underlying context.
Files may contain indicators of personal information. This finding helps focus the review, but does not, on its own, determine what action should be taken regarding the file.
Some files may contain indicators suggesting that they require more sensitive handling than usual.
Old files or those that have remained unchanged for a long time may require an assessment of their retention needs.
It is especially important to review a file containing personal data if it has been shared with an external party.
You don't need to be an IT or cybersecurity expert to use Vahti.
The monitor looks for signals related to personal data, storage, and sharing.
You can see the owner, location, age, context of the post, and the rationale behind the observation.
Note whether the finding requires, for example, restrictions on access rights or the establishment of retention policies.
Record the person in charge, the deadline, and any notes regarding the matter.

You can generate a downloadable PDF report from the completed GDPR data review. It compiles the open findings retained in Vahti, findings that were no longer detected in a subsequent review, the scope of the review, and the organization’s most recent recorded decisions.
The report documents the status at the time of the review and facilitates the sharing of the material with, for example, the data protection officer, management, or an external auditor. The report can be used in preparation for a GDPR audit and as supporting documentation. However, it is not a GDPR audit, certification, or proof of compliance.
A review of GDPR data does not provide an automatic legal answer as to what should be done with the data. The organization itself assesses the purpose of use, access, retention period, and any potential restriction, deletion, or anonymization.
When there are more M365 files than anyone can go through manually.
When you want to provide customers with a prioritized view of their inspection needs.
When you need a starting point for reviewing files that contain personal information.
When you want to see open tasks, the people in charge, and how the situation is progressing.
A review of GDPR-related data does not provide an automatic legal answer as to what should be done with the data. The organization itself assesses the purpose of use, access, retention period, and any potential restriction, deletion, or anonymization.
A file containing personal data is not a risk solely because of its content. The risk is also influenced by users, access rights, external sharing, and the detection of anomalies.
Request a demo, and we'll show you how GDPR compliance checks work in a small or medium-sized business's Microsoft 365 environment.
No. Vahti identifies audit requirements related to personal data, sharing, and retention in Microsoft 365 files. You can generate a PDF report from the scan to prepare for a GDPR audit and as supporting documentation, but Vahti does not perform a legal audit nor does it guarantee compliance with GDPR requirements.
The report compiles all open findings stored in Vahti and those that were no longer observed during a subsequent review. In addition, it describes the scope of the review and the organization’s most recent documented decisions. The report also contains information on owners, locations, and notes, so it must be treated as confidential.
This check applies to supported OneDrive and SharePoint files. Coverage depends on the Microsoft 365 environment, access permissions, and supported file formats.
The monitor does not store raw file content. The findings are based on metadata and deterministically generated personal data and retention signals.
No. Vahti helps document the organization’s decision. Any restrictions, deletions, and anonymizations are carried out as part of the organization’s own Microsoft 365 management process.
Not on its own. The personal data indicator suggests that the file should be reviewed. A potential data breach also requires separate evidence of unauthorized access to or use of the data.