
← Data protection & information protection
Implement GDPR in IT and Cloud in practice
Process personal data in IT and cloud environments in a controlled manner, protect it and operate it in a traceable manner.
The GDPR does not require a blanket “compliant” cloud solution, but rather risk-oriented processing with clear responsibilities and verifiable measures. For IT and the cloud, roles and authorisations, protective measures, retention and deletion, logging as well as contracts and data flows need to be clarified in particular. Microsoft 365 can support technical features; However, the specific assessment depends on usage, configuration, contract and operation.
Relationship to services and technologies

This classification does not replace legal advice or an assessment of data protection law. She translates coordinated requirements into technical and organisational control questions for IT and cloud.
Background
In cloud and Microsoft 365 environments, personal data is not only created in specialist applications: it can be found in emails, teams, files, identity data, devices, logs and backups. Teams therefore need a common picture of who processes which data, who has administrative rights and how decisions in the life cycle remain traceable.
Data protection documentation alone does not control permissions. Conversely, a technical configuration does not in itself prove that processing is permitted. Data protection, IT, information security and specialist departments must combine their respective responsibilities.
Technical context

The GDPR requires those responsible to implement appropriate technical and organisational measures and to be able to demonstrate their effectiveness and compliance with the regulation (in particular Article 5 Para. 2 and Article 24 GDPR). Data protection through technology design and data protection-friendly default settings must be taken into account when determining means and processing (Article 25 GDPR). Art. 32 GDPR requires a level of protection appropriate to the risk.
The distribution of roles is central for cloud services: a company can be the controller, while a service provider processes personal data as a processor. Art. 28 GDPR sets requirements for its selection and contractual binding. Whether this classification is correct, which transfers take place and which legal bases apply must be checked for the specific processing operation.
Cloud roles, order processing and third country transfers are separate test questions: The role and contract test according to Art. 28 does not automatically answer whether data is transferred to a third country and what requirements apply. If transfers come into consideration, the recipient, transmission channel and additional protective measures must be assessed based on the specific processing.
A data protection impact assessment (DPIA) is also not a standard consequence of every cloud use. It must be included as a test question if processing is likely to result in a high risk for the rights and freedoms of natural persons. The standard data protection model (SDM) from BfDI and DSK offers a structure to translate GDPR requirements into technical and organisational measures; it does not replace a legal assessment.
What companies need to clarify specifically
- Which processing, data categories, systems, cloud services and data flows are in the area of investigation.
- Who is responsible professionally, data protection and technically and which roles receive privileged access.
- How identities, authentication, permissions, administrative activities and external access are controlled and regularly reviewed.
- Which protection measures for data, devices, transmissions and backups are appropriate to the risk.
- What retention purposes and deletion rules apply – including copies, archives and backups.
- What logs are required, who can view them, and how they are used for operations, security incidents, and evidence.
From requirements to implementation

Roles and responsibilities
Risk: unclear responsibility
Organisational measure: RACI for specialist processes, data protection, IT and service providers
Technical implementation: separate admin roles and approvals
Possible evidence: Role model, data processing agreement, approval records
Access control
Risk: excessive or orphan rights
Organisational measure: Eligibility concept and recertification
Technical implementation: MFA, Conditional Access, Least Privilege
Possible evidence: Access reviews, role and login logs
Protection of processing
Risk: Loss, disclosure or manipulation
Organisational measure: Protection needs and risk assessment
Technical implementation: Encryption, endpoint protection, data classification
Possible evidence: Risk decision, configuration and test evidence
Retention and deletion
Risk: unnecessarily long storage
Organisational measure: professional retention and deletion concept
Technical implementation: Labels, retention, deletion flows and controlled exceptions
Possible evidence: Deletion rules, approvals, deletion and exception protocols
Accountability and operation
Risk: Measures not understandable
Organisational measure: Review, incident and change process
Technical implementation: Audit protocols, monitoring, central evidence storage
Possible evidence: Directory reference, reports, reviews, event documentation
Limitations and dependencies
Whether processing is GDPR-compliant cannot be answered based on a single product. The assessment depends, among other things, on the purpose, legal basis, data categories, contracts, recipients, data transfers and the actual configuration. Microsoft and other vendor features support controls but do not replace legal review or corporate responsibility.
Retention and deletion periods often arise from technical law, contracts and business processes. They cannot be determined exclusively technically. In the case of backups, immediate individual deletion may not be technically possible. The deletion concept must therefore evaluate immutability, recovery processes and renewed deletion or quarantine of recovered data in the specific concept.
Further official sources
Orientation
Frequently asked questions
Is Microsoft 365 GDPR compliant?
This question cannot be answered with a general yes or no. The decisive factors include the specific processing, roles, settings, contracts, data flows, technical measures and ongoing operations. Vendor documentation is an important source of information, but not a complete legal assessment.
Do we need to store all logs indefinitely?
No. The purpose, access rights, storage periods and protection of the log data must be specified. Logging should enable traceable operations and security investigations, but should not itself become an uncontrolled data collection.
Where does the deletion concept belong?
It combines specialist processes, data protection and technology. The concept should describe data types, triggers, deadlines, responsibilities, exceptions as well as technical deletion and control methods - also for archives and backup copies.
Next sensible step

Clarify technical data protection requirements in Microsoft 365 with data protection managers and IT: data flows, roles, access, deletion and evidence for a delimited area. Lead for technical context IT Security & Compliance and Microsoft technologies on.

