What GDPR requires
GDPR has applied since 25 May 2018 to anyone processing the personal data of people in the EU. Six of its duties land on the Microsoft estate, on access and accountability rather than cookie banners:
Security of processing
Control who, and which agents, can reach personal data across the estate.
Records of processing
Keep a live register of where personal data lives and what reads it.
Accountability
Show the controls are demonstrably in place, not just written down.
Controller responsibility
Put technical and organizational measures in place, then keep reviewing them.
DPIA for high-risk AI
Assess before rolling AI out over stores of personal data.
Breach notification
Detect and evidence a personal-data breach in time to notify within 72 hours.
Who it applies to
Applies to any organization that processes the personal data of people in the EU, wherever it is based, in force since 25 May 2018.
Where the Microsoft estate breaks it
Most Microsoft tenants carry years of collaboration history, and GDPR’s access duties fail quietly inside it:
Oversharing surfaces through Copilot
An agent answers at the asker’s permissions, so a 2019 overshare surfaces in an answer today.
Ownerless workspaces keep personal data
The project ended, the data stayed, and no one enforces storage limitation (Art. 5(1)(e)).
Guest access never expires
External accounts keep their reach for years, and no one re-reviews the personal data behind it.
No evidence trail
When an authority asks who could reach the data and when it was reviewed, tenant history has no answer.
How Rencore maps to GDPR
Rencore inventories, governs and evidences the Microsoft slice of your GDPR scope, from Copilot and AI agents to Power Platform and Microsoft 365 collaboration; classification stays Microsoft Purview’s job.
Full-estate inventory, agents included
Every workspace, app, automation and agent in your tenant, with its owner and the personal data it can reach.

Access reviews on a schedule
Recertify who, including guests and agents, can reach each workspace, with a dated record of what was checked and revoked.

Policies and continuous monitoring
Policies run across workspaces, apps and agents, routing violations to accountable owners so the measures stay demonstrably in place.

Lifecycle automation
Inactive and ownerless workspaces are flagged, archived or retired by policy, so personal data stops outliving its purpose.

Mapping at a glance
How each Rencore capability answers a specific article of GDPR.
- Full-estate inventory Art. 30, 35
See every workspace, app and agent, and the personal data it reaches.
- Access reviews Art. 32
Recertify who and which agents can reach each workspace.
- Policy monitoring Art. 5(2), 24
Prove the measures are in place, not just written down.
- Lifecycle automation Art. 5(1)(e)
Retire personal data that has outlived its purpose.
Inventory, control and exportable evidence for your Microsoft estate.
No tool makes you GDPR-compliant on its own; that judgement stays with your organization and its supervisory authority, on the evidence.
Rencore is EU-built, GDPR-conformant software. See our trust page.
Trusted by security, IT, and platform leaders
Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.
Frequently asked questions
Does Copilot create new GDPR risk or expose existing risk?
What does an access review prove to a supervisory authority?
How does this relate to Microsoft Purview?
Does the EU AI Act replace GDPR duties for AI?
Related reading
The neighboring EU regulations converge on the same Microsoft inventory. These cover the obligations next door:



