Datenschutz und Informationsschutz

← Data protection & information protection

Data classification and Microsoft Purview

Translate protection needs into understandable rules, labels, protection controls and retention.

Data classification begins with a technically responsible model for protection needs and permitted use. Microsoft Purview can technically support this model with sensitivity labels, data loss prevention (DLP), and retention features. The sensible order is: understand data and risks, define classes and rules, publish labels, use DLP in a targeted manner and control retention for each specialist process. Purview is not GDPR compliant.

Relationship to services and technologies

Datenschutz und Informationsschutz

Microsoft Purview is a possible means of implementing a previously defined protection requirement. Product features, licensing and implementation services are below Technologies and Solutions described.

Background

In Microsoft 365, information is often distributed across Exchange, Teams, SharePoint and OneDrive. Without a common classification model, employees are left to their own devices when it comes to approvals, protection rules are inconsistent and sensitive data may be shared too widely. Conversely, too many or unclear label levels create acceptance problems and incorrect assignments.

The task is therefore primarily governance, not product configuration: departments, data protection, information security and IT must determine which information should be treated, shared, retained and deleted and how. Only then can Purview map rules consistently in the supported workloads.

Technical context

Abstrakte Illustration: Shield/Check und Dokumente in Blau.

Classification describes the need for protection of information. Sensitivity labels identify content and, depending on configuration, can apply protective measures such as encryption or content tagging. Retention labels and retention policies, on the other hand, control retention or deletion. Records Management serves the professionally regulated, particularly controlled management of records. A piece of content can have a sensitivity label and a retention label; the purposes remain separate.

DLP policies are intended to identify and address unwanted distribution or use based on defined conditions; they are neither classification nor preservation. Sensitivity labels can be a DLP condition in supported scenarios. However, supported workloads, file types, functions and license requirements differ depending on the tenant status and Microsoft documentation and must be checked for the specific scenario before rollout.

What companies need to clarify specifically

  • Which information classes can be distinguished from a business perspective, and which protection rules follow from them?
  • Who owns a class, who can change labels, and who handles exceptions?
  • When do employees label content themselves and when do standard or automatic assignments help?
  • Which shares, recipients, endpoints and transmission paths should DLP rules cover?
  • What retention and deletion requirements apply for each type of information and specialist process?

From requirements to implementation

Managementteam trifft nachvollziehbare Entscheidungen in einem IT-Projekt anhand gemeinsamer Informationen.
Express protection needs consistently

Risk: Uneven treatment of sensitive data
Organisational measure: Classification scheme and label governance
Technical implementation: Sensitivity labels and publication guidelines
Possible evidence: Model, approvals, policy configuration

Address unauthorized disclosures

Risk: Data leakage or misdirected transmission
Organisational measure: DLP rules, exceptions and escalation path
Technical implementation: DLP by location, content or label
Possible evidence: Rule tests, incident reports, exceptions

Control retention

Risk: Deletion too early or unnecessary retention
Organisational measure: Technical retention decision
Technical implementation: Retention Policies or Retention Labels
Possible evidence: Retention plan, policy status

Effectiveness received

Risk: Misclassification or policy bypass
Organisational measure: Training, review and metrics
Technical implementation: Audit and DLP analysis
Possible evidence: Review records, training records

Pilot process

A compartmentalized pilot reduces misclassifications and technical surprises:

  1. Define information class and functional owner.
  2. Design sensitivity label and publication policy.
  3. Test with a test group and evaluate feedback.
  4. First run DLP as a simulation and evaluate events.
  5. Specify exception and incident process.
  6. Review metrics for usage, hits, misclassifications, and exceptions.

Limitations and dependencies

Abstrakte Illustration: Dokumente, DSGVO/Compliance und Checkmark in Blau.

Technical labeling does not replace data inventory or technical decisions. Purview features, coverage and license requirements may vary per workload and must be validated before implementation. Even correctly configured labels and DLP rules do not prevent all errors; Comprehensibility, training and regulated exception processes remain necessary.

Further official sources

Orientation

Frequently asked questions

Are sensitivity labels and retention labels the same thing?

No. Sensitivity labels express the need for protection and can apply protection mechanisms for content. Retention labels control retention or deletion in the corresponding Microsoft 365 context. An element can carry both types of labels; the technical regulation should separate the purposes.

Can DLP be connected to labels?

Yes. Microsoft Purview documents sensitivity labels as a condition for DLP policies, including for Exchange, SharePoint, OneDrive, devices, and Microsoft 365 Copilot. The specific supported scenarios and limitations must be tested before rollout.

Where do identities and permissions belong?

Classification and DLP complement permissions, but do not replace them. Addresses identity, access, and device controls Entra, Conditional Access and Intune. ADIUMENTO offers product and technology context under Microsoft technologies.

Next sensible step

Abstrakte Illustration: Datenqualität und Governance als Fundament in Blau.

Start with a limited class of information and a clear usage scenario. For the classification of Purview in Microsoft technologies and IT Security & Compliance the existing information pages are available.