Learn about subject rights requests for data beyond Microsoft 365 (preview)

Microsoft Priva Subject Rights Requests for data beyond Microsoft 365 (preview) supports request management and fulfillment for personal data beyond your organization’s Microsoft 365 environment. Subject rights requests enable and empower your organization to automate the governance of subject rights requests across your entire data landscape at scale.

  • Efficiently manage subject rights requests: Automate the fulfillment of key tasks using configurable settings, providing end-to-end oversight of subject rights request operations.

  • Discover personal data across extensive sources: Discover and manage requests across multicloud data estates including Microsoft Azure and non-Microsoft data sources, such as Amazon Web Services, Google Cloud Platform, and Snowflake.

  • Continuously evaluate subject right request process performance: Streamline request report monitoring and request tracking to strengthen your compliance posture.

How it works

Having a comprehensive subject rights requests fulfillment strategy relies on knowing where the personal data managed by your organization exists throughout your data landscape. Subject rights requests work by searching for data classifications within your Microsoft Purview Data Map so that data owners can efficiently look for the right personal data to extract or delete in order to fulfill the request.

Subject rights request allows organizations to easily build a request intake form for data subjects to submit online. Requests can also be manually created by a user in your organization. When a request is created, a workflow automatically starts working to identify classifications within your data landscape that map to the classifications provided by the data subject. When specific data assets are identified as containing those classifications, tasks are automatically created that alert the data owner to look for and either export or delete the data.

Easy-to-create, customizable templates help your organization to define exactly how request fulfillment should be carried out. All stakeholders in your organization can easily determine what stage the request is in, triage work in order to meet deadlines, and provide the right level of review and approval so that requests can be completed with efficiency and confidence by their due date.

Workflow at a glance

The steps below outline the process for fulfilling subject rights requests for data beyond Microsoft 365:

  1. Your organization creates a request intake form and a template for processing requests.

  2. A request is submitted via the external request for or by manual creation inside your organization.

  3. Data analysis identifies classifications related to the data subject and tasks are created for data owners.

  4. Data owners look within their data assets for the data subject’s personal data and perform the necessary work of extracting or deleting data.

  5. Task completion work is reviewed and approved by the request owner.

  6. Your organization replies to the data subject with the final export package or with confirmation that the data has been deleted.

  7. The request is completed.

Next steps

EU Data Boundary disclaimer

In public preview, Microsoft Priva processes and stores most customer data within the region where Microsoft Priva is deployed. Some personal data will be stored outside of the deployed geographic boundary. Microsoft Priva will meet all data residency requirements by general availability. If you have specific questions related to your data storage, please reach out to your Microsoft contact for more information.

Learn more about the EU Data Boundary.

Microsoft Priva legal disclaimer