The General Data Protection Regulation (GDPR) introduces new rules for organizations that offer goods and services to people in the European Union (EU), or that collect and analyze data for EU residents no matter where you or your enterprise are located. Additional details can be found in the GDPR Summary article.
Similarly, the California Consumer Privacy Act (CCPA), provides privacy rights and obligations to California consumers, including rights similar to GDPR's Data Subject Rights, such as the right to delete, access, and receive (portability) their personal information. The CCPA also provides for certain disclosures, protections against discrimination when electing exercise rights, and "opt-out/ opt-in" requirements for certain data transfers classified as "sales". This document guides you to information on the completion of Data Subject Requests (DSRs) under the GDPR and CCPA using Microsoft products and services.
Helpful definitions for GDPR terms used in this document:
Data Controller (Controller): A legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Personal data and data subject: Any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly.
Processor: A natural or legal person, public authority, agency, or other body, which processes personal data on behalf of the controller.
Customer Data: Data produced and stored in the day-to-day operations of running your business.
What is a DSR?
The General Data Protection Regulation (GDPR) gives rights to people (known in the regulation as data subjects) to manage the personal data that has been collected by an employer or other type of agency or organization (known as the data controller or just controller). The GDPR gives data subjects specific rights to their personal data; these rights include obtaining copies of it, requesting changes to it, restricting the processing of it, deleting it, or receiving it in an electronic format so it can be moved to another controller.
As a controller, you're obligated to promptly consider each DSR and provide a substantive response either by taking the requested action or by providing an explanation for why the DSR can't be accommodated by the controller. A controller should consult with its own legal or compliance advisers regarding the proper disposition of any given DSR.
Several processes may be involved completing a DSR, subject to your organization's GDPR-compliance rules.
Discovery. The process of determining what data is needed to complete a DSR.
Access. Retrieval and potential transmission to the data subject of discovered information.
Rectify. Implement changes or other requested personal data changes.
Restrict. Changing the access or processing of personal data by restricting access, or removing data from the Microsoft cloud.
Export. Providing a "structured, commonly used, machine-readable format" of personal data to the data subject, as provided by the GDPR's "right of data portability."
Delete. Permanent removal of personal data from the Microsoft cloud.
Specific DSR Considerations
Insights generated by Microsoft Products or Services
Insights may be generated by services (Viva Personal Insights, etc.) Office 365 includes online services that provide insights to users and organizations that use them. Data generated by these services may produce personal data relevant to a DSR. Follow the link in the list below for details regarding service-specific DSR processes.
DSRs for system-generated logs
Logs and related data generated by Microsoft may contain data deemed personal under GDPR's definition of "personal data." Restricting or rectifying data in system-generated logs isn't supported. Data in system-generated logs constitutes factual actions conducted within the Microsoft cloud and diagnostic data; modifications would compromise the historical record of actions and increase fraud and security risks. Microsoft provides the ability to access, export, and delete system-generated logs that may be necessary to complete a DSR. Examples of such data may include:
Product and service usage data such as user activity logs
User search requests and query data
Data generated by product and services resulting from system functionality and interaction by users or other systems.
Viva Engage
Deleting a user's account won't remove system-generated logs for Viva Engage. To remove the data from these applications, see one of the following resources:
In some circumstances, your organization's users may access Microsoft products or services for which Microsoft is the data controller. In those cases, your users need to initiate their own DSRs directly to Microsoft, and Microsoft fulfills the requests directly to the user.
Third-party Products
For third-party products and services accessed through Microsoft account authentication, any data subject requests should be directed to the applicable third party.
Demuestre los aspectos básicos de la seguridad de los datos, la administración del ciclo de vida, la seguridad de la información y el cumplimiento para proteger una implementación de Microsoft 365.
Obtenga información sobre cómo el Soporte técnico de Microsoft y los servicios profesionales tratan la solicitudes de interesados para el RGPD y la CCPA.
Comprenda los derechos de usuario según el RGPD y la CCPA y cómo Office 365 ayuda a las empresas a buscar y actuar en datos como respuesta a solicitudes del interesado.
Obtenga información acerca de cómo los servicios Microsoft protegen contra una infracción de datos personales y cómo Microsoft responde y le notifica si se produce una infracción.
Obtenga información sobre cómo buscar y actuar sobre datos personales y responder a las solicitudes de DSR y CCPA por parte de los clientes que usan Microsoft Windows 365