Home›Guides›Sovereignty

Sovereignty

GDPR and Microsoft 365: what a business needs to check

Microsoft 365 can be used within a GDPR framework. The regulation does not prohibit US software vendors. It requires you to know who processes what, on what basis data leave the Union, and how individuals exercise their rights. Here is what a business needs to check, in order, and what it needs to write in its record.

Updated October 20269 min readOfficial sources cited

1. The role of each party

For the content of the mailboxes, files and teams you administer, the customer is generally the controller. Microsoft is the processor. For certain account, billing, security and service measurement data, Microsoft may be a separate controller. The Data Processing Addendum and the Microsoft Privacy Statement distinguish between these cases.

How to check. The role determines the obligations. Read the two documents side by side and place each category of data in a box. A 25-person accounting firm, for example, will have on one side emails and client files (Microsoft as processor), and on the other the billing of the subscription (Microsoft as separate controller).

In the record. One line per processing activity, with Microsoft’s role and the document on which it is based.

Common mistake. Writing “Microsoft is our processor” for the service as a whole.

2. The DPA is signed, and it covers the services actually enabled

The Microsoft DPA is incorporated into the online terms. Check that it covers the services you have switched on: Exchange, SharePoint, OneDrive, Teams, Planner, Copilot, Power Automate, and any connector.

How to check. A tenant evolves beyond the initial order. Compare the list of services switched on in the admin center with the scope of the DPA, and archive the version of the DPA in force on the date of the check.

In the record. The service, the activation date, the purpose. A service enabled by an administrator “to try it out” enters the record on the day it processes data of your employees or your customers.

Common mistake. Assuming that a connector to a third-party tool falls under the Microsoft DPA. The third party has its own terms, which must be read separately.

3. Where the data are, service by service

For an eligible tenant, Microsoft describes the EU Data Boundary: customer data and pseudonymised personal data stored and processed in the EU or EFTA, professional services data stored at rest in that area. Three checks avoid mistaking the announcement for a complete scope.

  • Is the tenant within the scope? A Multi-Geo customer is not, according to Microsoft’s documentation, even if the country of registration is European.
  • Which exceptions continue? Remote access by support from outside the area for certain incidents, elements of escalated tickets stored outside the area, support voicemails, optional features.
  • Which services outside the core (Copilot, Teams telephony, connectors) cause a transfer because the administrator has enabled them?

Why. The boundary is a scope with published exceptions, and it is these exceptions that your record must account for. The page data hosted in Europe explains why this list is the real issue.

How to check and record. Compare the tenant’s configuration (Multi-Geo or not, optional features enabled) with Microsoft’s exceptions page, line by line, and note in the record those that apply to you.

Common mistake. Copying “data in Europe” into the privacy policy without mentioning support or optional features.

4. The legal basis for the transfer

When personal data are accessible from the United States or transferred to a US organisation, the transfer must have a legal basis: an adequacy decision, standard contractual clauses, or another tool under Article 46 of the GDPR.

As of 5 October 2026, Decision (EU) 2023/1795 (Data Privacy Framework) is in force for certified US organisations. It is being challenged before the Court of Justice and is the subject of a political review. According to a commentary by the law firm WilmerHale, the General Court of the European Union dismissed an action for annulment on 3 September 2025, and an appeal was lodged before the Court of Justice on 31 October 2025. The law firm DAC Beachcroft sums up the situation in the title of its own commentary: stability for now, uncertainty ahead. Until the decision is withdrawn or annulled, the transfers it covers can rely on it.

The precedent explains the caution. On 16 July 2020, in judgment C-311/18 (known as Schrems II), the Court of Justice invalidated Decision 2016/1250 (Privacy Shield), owing in particular to the scope of US surveillance programmes and the lack of effective redress. Standard contractual clauses remained valid, but they require a case-by-case assessment.

The CLOUD Act is not something that is “signed” in the DPA. It applies, where relevant, to Microsoft as a US company that holds or controls the data. Article 48 of the GDPR provides, for its part, that a judgment of a court or a decision of an authority of a third country requiring the disclosure of personal data may only be recognised or enforceable if it is based on an international agreement, such as a mutual legal assistance treaty, in force between that country and the Union or the Member State. A US provider operating in Europe may therefore find itself caught between two rules. Article 48 describes this conflict; it does not resolve it.

On 10 June 2025, before the French Senate commission of inquiry on public procurement, the director of public and legal affairs of Microsoft France was asked whether he could guarantee under oath that the data of French citizens entrusted to Microsoft via Ugap would never be transmitted, following an order from the US government, without the explicit consent of the French authorities. He replied: “No, I cannot guarantee it, but, once again, it has never happened yet.” The details are in protect a business from the CLOUD Act.

In the record. The legal basis for each transfer, and the fallback plan: the Article 46 tool you would rely on if the decision fell.

Common mistake. Confusing location (point 3) with the legal basis for the transfer. Data stored in Europe may remain accessible from the United States.

5. Data subject rights, in practice

An employee or a customer may request access, rectification, erasure, restriction or portability. On Microsoft 365, part of this is done in the admin center and the content search tool.

How to check. The time limit is one month. The processor provides the means; the controller answers the individual. Run a dry test: the designated person extracts, for a test account, the mailbox, the OneDrive and the Teams files.

In the record. The procedure, and the names of the person in charge and their deputy.

Common mistake. Waiting for a former employee in a dispute to make a request before discovering the search tool.

6. Retention and exit

Retention of shared mailboxes, logs, meeting recordings, legal hold copies (litigation hold). On termination, what happens to the tenant, within what time frame, and in what format do you recover messages, files and what cannot be exported (full history of Teams conversations, certain Power Automate flows)?

How to check. Record the retention periods actually configured, not those in the internal policy, and test the full export of an account.

In the record. A retention period per category, the justification for each legal hold, the exit procedure.

Common mistake. Leaving a legal hold active for years after the end of the dispute that justified it.

7. Instructions to users

Copilot and analysis features process the content you give them. If you enable them, informing employees and setting a framework for use are part of compliance. This point is internal to your business. It does not depend on the country of the datacenter.

How to check. Is there an information notice, and does a rule state which data may be submitted to these features?

Common mistake. Opening a Copilot pilot to one team without informing the other people whose data appear in the files processed.

Frequently asked questions

Does the GDPR prohibit Microsoft 365?

No. The regulation governs roles, transfers and data subject rights. It does not prohibit a software vendor on the grounds of its nationality; it requires you to document what you do and on what legal basis.

Does the EU Data Boundary settle the CLOUD Act question?

No. It describes where certain data are stored and processed. Microsoft remains a US company, and 18 U.S.C. § 2713 targets the data that a provider holds or controls, wherever they are.

What should we do if the Data Privacy Framework is annulled?

The record should already say so. After Schrems II, standard contractual clauses remained valid, with a case-by-case assessment. Preparing it in advance avoids having to draft it in a hurry.

Who answers an employee who asks for their data?

You do, as the controller. Microsoft provides the extraction tools; the answer and the one-month time limit are your responsibility.

When the check concludes with “we are staying”

It concludes this way when Microsoft tools are at the core of the business, the DPA is in place, the residency scope is understood, and the record documents the residual transfers. Changing suites does not become a GDPR obligation merely because the software vendor is American.

The arguments for staying are serious. An engineering firm that lives in advanced Excel, Power BI and Teams would lose features by changing suites, and a migration carries its own risks. A well-documented Microsoft tenant is more compliant than a poorly documented alternative. The decision should be reviewed if the legal basis for transfers changes. The trade-offs are detailed in staying with or leaving Microsoft 365.

When the check concludes with “we are changing operator”

It concludes this way when management wants a European company to hold the content, or when the transfer and support access exceptions exceed what the record can account for. It can also come from customers: a tender that requires a European operator settles the question for the scope concerned.

This conclusion has its arguments. When the operator is European and does not depend on a US group for possession of the data, the conflict described in point 4 no longer arises for those data, provided that its sub-processors do not reintroduce a US provider. It exempts you from nothing else: a processing agreement, the record, a procedure for data subject rights and a tested exit remain necessary. The page migrate from Microsoft 365 describes what this change involves, without presenting it as an automatic step, and the migration checklist breaks it down into stages.

Klytic, operated by the French company Dedicace Software, is one of the options if your uses fit within email, documents (sharing, online editing alone or with others, version history), video conferencing, CRM and telephony. The services are purchased separately; you can also keep Microsoft 365 and add only Klytic MTA filtering, placed in front of it. Hosting is provided in any geographical area corresponding to the applicable jurisdiction, subject to the availability of the required services, for example in Europe or Mauritius, or on the customer’s servers. The data are held by the customer, or by Klytic on the customer’s behalf, and encrypted natively or according to the customer’s choice; the key is held by the customer or kept in the customer’s account, and Klytic has no access to it. The stages where encryption is managed by Klytic are detailed on the page protect a business from the CLOUD Act. The contract must describe this possession and this encryption. Klytic does not replicate advanced Excel, Power BI or Teams. It does not hold the SecNumCloud qualification, and a French operator remains subject to French law.

This page describes a general framework. It does not constitute legal advice.

Sources

Accessed in October 2026.

  • Regulation (EU) 2016/679, Articles 28 (processor), 44 to 49 (transfers), including Article 48 (decisions of third-country authorities). EUR-Lex
  • Microsoft, Data Protection Addendum (DPA). Microsoft Licensing
  • Microsoft, EU Data Boundary: scope, eligibility, exclusion of Multi-Geo. Microsoft Learn
  • Microsoft, transfer exceptions, including support. Microsoft Learn
  • Decision (EU) 2023/1795. EUR-Lex
  • Court of Justice of the European Union, 16 July 2020, C-311/18 (Schrems II). EUR-Lex
  • On the Data Privacy Framework litigation, lawyers’ commentary, not a decision: WilmerHale, “European Court of Justice to Review Challenge to EU-U.S. Data Privacy Framework”, 1 December 2025. wilmerhale.com
  • On the litigation and the ongoing review, lawyers’ commentary, not a decision: DAC Beachcroft, “The EU–US Data Privacy Framework: stability for now, uncertainty ahead”. dacbeachcroft.com
  • 18 U.S.C. § 2713. govinfo
  • French Senate, commission of inquiry on public procurement, record of the week of 9 June 2025 (hearing of 10 June 2025). senat.fr

A French operator for your data

Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.

Talk to an advisor →

Klytic hosting

Welcome offer

30-day free trial, assisted migration

No-commitment trial offer. An advisor will call you back to understand your needs and prepare your Klytic space.