SOLVED

How do you configure sharepoint to be GDPR compliant?

%3CLINGO-SUB%20id%3D%22lingo-sub-88068%22%20slang%3D%22en-US%22%3EHow%20do%20you%20configure%20sharepoint%20to%20be%20GDPR%20compliant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-88068%22%20slang%3D%22en-US%22%3E%3CP%3EHow%20do%20you%20configure%20sharepoint%20to%20be%20GDPR%20compliant%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-132082%22%20slang%3D%22en-US%22%3ERe%3A%20How%20do%20you%20configure%20sharepoint%20to%20be%20GDPR%20compliant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-132082%22%20slang%3D%22en-US%22%3E%3CP%3EAnswers%20in%20this%20French%20slide%20deck%20%3A%20%3CA%20href%3D%22https%3A%2F%2Fwww.slideshare.net%2FSbastienPaulet%2Frgpd-comment-o365-va-vous-aider-26102017-aoslarunion%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.slideshare.net%2FSbastienPaulet%2Frgpd-comment-o365-va-vous-aider-26102017-aoslarunion%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EAnd%20this%20interview%20%3A%20%3CA%20href%3D%22https%3A%2F%2Fwww.digital-inside.fr%2Fsingle-post%2F2017%2F11%2F05%2FS%25C3%25A9bastien-Paulet-se-pr%25C3%25A9parer-%25C3%25A0-la-RGPD-avec-Office-365%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.digital-inside.fr%2Fsingle-post%2F2017%2F11%2F05%2FS%25C3%25A9bastien-Paulet-se-pr%25C3%25A9parer-%25C3%25A0-la-RGPD-avec-Office-365%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EAnd%20just%20in%20case%20you%20don't%20read%20french%20(just%20in%20case%20%3B)%3C%2Fimg%3E%20)%2C%20few%20main%20points%20to%20get%20in%20mind%20(the%20topic%20may%20need%20a%20book)%20%3A%3C%2FP%3E%0A%3CP%3E-%20If%20you're%20using%20O365%2C%20Microsoft%20has%20already%20modified%20his%20contract%20to%20assume%20his%20role%20as%20sub%20contractor%20(role%20described%20in%20GDPR)%3C%2FP%3E%0A%3CP%3E-%20First%20thing%20to%20do%20is%20to%20get%20a%20clear%20map%20of%20all%20sources%20of%20personal%20information%20stored%20in%20your%20SharePoint%20(is%20there%20specific%20site%20collection%20%2Fdoc%20libs%2Flist%2Fcontenttype%20%2F%20fields%20containing%20personal%20info%20of%20european%20citizen%3F%20Which%20one%3F%20Why%3F).%20It's%20not%20technical%2C%20but%20it%20may%20irequest%20you%20to%20modify%20your%20classification%20plan%20(adding%20a%20column%20to%20get%20name%20and%20first%20name%20of%20passport%20copies%20for%20instance.%20Doing%20so%2C%20you%20will%20be%20able%20to%20quickly%20retreive%20this%20document%20in%20case%20passeport%20owner%20ask%20you%20to%20delete%20all%20his%20personal%20data)%3C%2FP%3E%0A%3CP%3E-%20If%20you're%20onPrem%20with%20enterprise%20license%2C%20you%20have%20eDiscovery%20centers.%20For%20O365%2C%20it's%20included%20by%20E3.%20With%20this%20feature%2C%20you%20can%20quickly%20search%20among%20all%20your%20mailboxs%2Fonedrives%2Fsharepoints%20to%20retreive%20content%20(by%20ex%20%3A%20the%20name%20of%20a%20european%20citizen%20asking%20you%20to%20update%2Fexport%2Fdelete%20his%20personal%20data).%20eDiscovery%20will%20definitively%20be%20helpful%20to%20be%20compliant%20with%20GDPR.%3C%2FP%3E%0A%3CP%3E-%20If%20you%20are%20using%20O365%2C%20have%20also%20a%20look%20about%20%22Labels%22%20and%20%22DLP%22%20(by%20E3%20I%20think)%20which%20allow%20you%20to%20%22tag%22%20any%20content%20and%20apply%20retention%20policies%20on%20content%20(document%20or%20email)%3C%2FP%3E%0A%3CP%3E-%20Retention%20policies%20(by%20content%20type%2C%20by%20document%20library%2C%20by%20label)%20will%20be%20helpful%20as%20you%20have%20to%20retain%20documents%20only%20during%20the%20minimum%20necessary%20period.%3C%2FP%3E%0A%3CP%3E-%20Microsoft%20has%20also%20annouced%20many%20features%20on%20O365%20as%20security%20audit%2C%20Disclaimer%20for%20external%20users%2C%20etc.%3C%2FP%3E%0A%3CP%3E-%20And%2C%20as%20mentioned%20before%20by%20Cian%2C%20have%20a%20look%20on%20Compliance%20manager.%20This%20new%20feature%20is%20currently%20available%20in%20preview.%3C%2FP%3E%0A%3CP%3EBe%20prepared...%20May%2025%202018%2C%20GDPR%20is%20coming%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-109384%22%20slang%3D%22en-US%22%3ERe%3A%20How%20do%20you%20configure%20sharepoint%20to%20be%20GDPR%20compliant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-109384%22%20slang%3D%22en-US%22%3E%3CP%3EAre%20you%20talking%20about%20On-premises%20or%20Office%20365%3F%20On-premises%20you%20would%20have%20to%20elimanate%20certain%20types%20of%20personally%20identifiable%20information%20(PII)%20of%20European%20citizens%20(let's%20include%20UK%20in%20that%20too)%20from%20any%20non%20EU%20environment.%20It's%20also%20possible%20that%20some%20of%20that%20data%20shouldn't%20even%20reside%20in%20SharePoint%20on-premises%20within%20the%20EU%20either.%20GDPR%20is%20less%20about%20technology%20than%20it%20is%20about%20document%20classification.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-88077%22%20slang%3D%22en-US%22%3ERe%3A%20How%20do%20you%20configure%20sharepoint%20to%20be%20GDPR%20compliant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-88077%22%20slang%3D%22en-US%22%3E%3CP%3EThat's%20an%20interesting%20question%2C%20I%20am%20not%20aware%20of%20any%20specific%20steps%20right%20now%20to%20take%20for%20GDPR%20compliance%20in%20SharePoint.%20%26nbsp%3BSaying%20that%2C%20here%20is%20some%20related%20information%2C%20Office%20365%20and%26nbsp%3BGDPR%20-%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Ftrustcenter%2Fprivacy%2Fgdpr%2Fsolutions%23office-365%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EHow%20our%20products%20help%20with%20GDPR%20compliance%20-%20Office%20365%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20from%20%3CA%20href%3D%22https%3A%2F%2Fblogs.microsoft.com%2Fblog%2F2017%2F05%2F24%2Faccelerate-gdpr-compliance-microsoft-cloud%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAccelerate%20your%20GDPR%20compliance%20with%20the%20Microsoft%20Cloud%3C%2FA%3E%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%22In%20February%20of%20this%20year%2C%20we%20announced%20that%20Microsoft%20cloud%20services%20%3CSTRONG%3Ewill%20comply%20with%20GDPR%3C%2FSTRONG%3E%20%3CSTRONG%3Eby%20May%2025%2C%202018%3C%2FSTRONG%3E%2C%20across%20%3CSTRONG%3EOffice%20365%3C%2FSTRONG%3E%2C%20Dynamics%20365%2C%20Azure%2C%20including%20Azure%20data%20services%2C%20Enterprise%20Mobility%20%2B%20Security%2C%20and%20Windows%2010.%20We%E2%80%99ve%20backed%20this%20up%20with%20our%20contractual%20commitments%20to%20customers.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThe%20Microsoft%20Cloud%20also%20has%20a%20range%20of%20compliance%20controls%2C%20audited%20by%20third%20parties.%20Through%20these%20investments%2C%20we%20will%20also%20help%20you%20validate%20that%20when%20you%20are%20using%20the%20Microsoft%20Cloud%2C%20you%20are%20using%20services%20compliant%20with%20the%20GDPR.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELater%20in%20the%20year%2C%20there%20will%20be%20new%20dashboard%20that%20allows%20you%20to%20check%20your%20GDPR%20compliance%2C%20similar%20to%20Office%20365%20Secure%20Score%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F17330iFCBDA04C0916AA7F%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22THIS-4%22%20title%3D%22THIS-4%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKeep%20an%20eye%20of%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Ftrustcenter%2Fcloudservices%2Foffice365%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Office%20365%20Trust%20Center%3C%2FA%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Ftrustcenter%2Fcloudservices%2Foffice365%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%26nbsp%3B%3C%2FA%3E(plus%20Office%20Blogs)%20for%20updates%20as%20there%20is%20more%20news%2C%20which%20I%20imagine%20there%20will%20be%20lots%20and%20the%20main%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2FTrustCenter%2FPrivacy%2Fgdpr%2Fdefault.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20GDPR%20site%3C%2FA%3E%20is%20a%20good%20resource%20including%20readiness%20assessment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%2C%20by%20the%20way%2C%20there%20is%20a%20semi-related%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FSharePoint%2Fsp-dev-gdpr-activity-hub%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Eresource%3C%2FA%3E%20available%20that%20you%20might%20want%20to%20check%20out%20-%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F17329iD697722E52380159%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22Starter%20kit%20for%20building%20a%20management%20hub%20for%20EU%20GDPR.jpg%22%20title%3D%22Starter%20kit%20for%20building%20a%20management%20hub%20for%20EU%20GDPR.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67593%22%20target%3D%22_blank%22%3E%40Steve%20Howlett%3C%2FA%3E%26nbsp%3BJust%20to%20say%20I%20have%20edited%20my%20answer%20a%20few%20times!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

How do you configure sharepoint to be GDPR compliant?

3 Replies
best response confirmed by Deleted
Solution

That's an interesting question, I am not aware of any specific steps right now to take for GDPR compliance in SharePoint.  Saying that, here is some related information, Office 365 and GDPR -

 

How our products help with GDPR compliance - Office 365

 

Also from Accelerate your GDPR compliance with the Microsoft Cloud:

"In February of this year, we announced that Microsoft cloud services will comply with GDPR by May 25, 2018, across Office 365, Dynamics 365, Azure, including Azure data services, Enterprise Mobility + Security, and Windows 10. We’ve backed this up with our contractual commitments to customers.


The Microsoft Cloud also has a range of compliance controls, audited by third parties. Through these investments, we will also help you validate that when you are using the Microsoft Cloud, you are using services compliant with the GDPR."

 

Later in the year, there will be new dashboard that allows you to check your GDPR compliance, similar to Office 365 Secure Score:

 

THIS-4

 

Keep an eye of the Microsoft Office 365 Trust Center (plus Office Blogs) for updates as there is more news, which I imagine there will be lots and the main Microsoft GDPR site is a good resource including readiness assessment.

 

Also, by the way, there is a semi-related resource available that you might want to check out - 

 

Starter kit for building a management hub for EU GDPR.jpg

 

@Steve Howlett Just to say I have edited my answer a few times!

Are you talking about On-premises or Office 365? On-premises you would have to elimanate certain types of personally identifiable information (PII) of European citizens (let's include UK in that too) from any non EU environment. It's also possible that some of that data shouldn't even reside in SharePoint on-premises within the EU either. GDPR is less about technology than it is about document classification.

Answers in this French slide deck : https://www.slideshare.net/SbastienPaulet/rgpd-comment-o365-va-vous-aider-26102017-aoslarunion

And this interview : https://www.digital-inside.fr/single-post/2017/11/05/S%C3%A9bastien-Paulet-se-pr%C3%A9parer-%C3%A0-l...

And just in case you don't read french (just in case ;) ), few main points to get in mind (the topic may need a book) :

- If you're using O365, Microsoft has already modified his contract to assume his role as sub contractor (role described in GDPR)

- First thing to do is to get a clear map of all sources of personal information stored in your SharePoint (is there specific site collection /doc libs/list/contenttype / fields containing personal info of european citizen? Which one? Why?). It's not technical, but it may irequest you to modify your classification plan (adding a column to get name and first name of passport copies for instance. Doing so, you will be able to quickly retreive this document in case passeport owner ask you to delete all his personal data)

- If you're onPrem with enterprise license, you have eDiscovery centers. For O365, it's included by E3. With this feature, you can quickly search among all your mailboxs/onedrives/sharepoints to retreive content (by ex : the name of a european citizen asking you to update/export/delete his personal data). eDiscovery will definitively be helpful to be compliant with GDPR.

- If you are using O365, have also a look about "Labels" and "DLP" (by E3 I think) which allow you to "tag" any content and apply retention policies on content (document or email)

- Retention policies (by content type, by document library, by label) will be helpful as you have to retain documents only during the minimum necessary period.

- Microsoft has also annouced many features on O365 as security audit, Disclaimer for external users, etc.

- And, as mentioned before by Cian, have a look on Compliance manager. This new feature is currently available in preview.

Be prepared... May 25 2018, GDPR is coming ;)