Try For Free
GDPR, Regulation (EU) 2016/679

Prove GDPR control of your Microsoft 365 and AI estate

Copilot and agents read your tenant at the permissions they inherit, so years of quiet oversharing can surface as personal data in AI answers no one authorized.

Rencore Governance policy SharePoint file is shared with external users: 13,566 files found and rising over three months, the detection rule reading every file sharing where Is External is true and Expiration is default or past, and an alert prompting to add automations that solve violations automatically

Trusted by the world’s leading organizations

  • MAPAL
  • bam
  • VDL
  • Wacker
  • Grundfos
  • Amgen
  • Lufthansa
  • thyssenkrupp
  • Sunrise
  • Pattern

What GDPR requires

GDPR has applied since 25 May 2018 to anyone processing the personal data of people in the EU. Six of its duties land on the Microsoft estate, on access and accountability rather than cookie banners:

Art. 32

Security of processing

Control who, and which agents, can reach personal data across the estate.

Art. 30

Records of processing

Keep a live register of where personal data lives and what reads it.

Art. 5(2)

Accountability

Show the controls are demonstrably in place, not just written down.

Art. 24

Controller responsibility

Put technical and organizational measures in place, then keep reviewing them.

Art. 35

DPIA for high-risk AI

Assess before rolling AI out over stores of personal data.

Art. 33

Breach notification

Detect and evidence a personal-data breach in time to notify within 72 hours.

Who it applies to

Applies to any organization that processes the personal data of people in the EU, wherever it is based, in force since 25 May 2018.

Where the Microsoft estate breaks it

Most Microsoft tenants carry years of collaboration history, and GDPR’s access duties fail quietly inside it:

Oversharing surfaces through Copilot

An agent answers at the asker’s permissions, so a 2019 overshare surfaces in an answer today.

Ownerless workspaces keep personal data

The project ended, the data stayed, and no one enforces storage limitation (Art. 5(1)(e)).

Guest access never expires

External accounts keep their reach for years, and no one re-reviews the personal data behind it.

No evidence trail

When an authority asks who could reach the data and when it was reviewed, tenant history has no answer.

How Rencore maps to GDPR

Rencore inventories, governs and evidences the Microsoft slice of your GDPR scope, from Copilot and AI agents to Power Platform and Microsoft 365 collaboration; classification stays Microsoft Purview’s job.

GDPR Art. 30, 35

Full-estate inventory, agents included

Every workspace, app, automation and agent in your tenant, with its owner and the personal data it can reach.

The Rencore Governance Objects inventory listing every object type with its count, including users, groups, sites, Teams, apps and flows, so the estate can be read as a single register
GDPR Art. 32

Access reviews on a schedule

Recertify who, including guests and agents, can reach each workspace, with a dated record of what was checked and revoked.

The Rencore Governance Review Builder for a review named Review all Teams: Review Settings with owners as the reviewers, a required comment on completion and a 14-day completion window, and Review Scope toggles covering owners, members, visitors, site access and file access
GDPR Art. 5(2), 24

Policies and continuous monitoring

Policies run across workspaces, apps and agents, routing violations to accountable owners so the measures stay demonstrably in place.

Rencore Governance user inventory: a three-month trend chart of total, new and removed users next to a violated-policies panel counting 800 over-licensed user accounts, 110 disabled user accounts with assigned licenses, 8 Copilot licenses assigned to disabled accounts and 1 administrator without MFA
GDPR Art. 5(1)(e)

Lifecycle automation

Inactive and ownerless workspaces are flagged, archived or retired by policy, so personal data stops outliving its purpose.

Rencore Governance automation templates for workspace lifecycle: Delete Group, Delete Group with Approval where a designated approver must grant the request before any action is taken, Archive Microsoft Team which sets its SharePoint site to read-only, and a notification for users creating Microsoft Loop components

Mapping at a glance

How each Rencore capability answers a specific article of GDPR.

  • Full-estate inventory Art. 30, 35

    See every workspace, app and agent, and the personal data it reaches.

  • Access reviews Art. 32

    Recertify who and which agents can reach each workspace.

  • Policy monitoring Art. 5(2), 24

    Prove the measures are in place, not just written down.

  • Lifecycle automation Art. 5(1)(e)

    Retire personal data that has outlived its purpose.

Inventory, control and exportable evidence for your Microsoft estate.

No tool makes you GDPR-compliant on its own; that judgement stays with your organization and its supervisory authority, on the evidence.

Rencore is EU-built, GDPR-conformant software. See our trust page.

Trusted by security, IT, and platform leaders

Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.

  • With Rencore's scalable automation solutions, organizations can not only meet current challenges but also prepare themselves for future technological advancements.
    Case Study
    Philipp Widmer Philipp Widmer Head of Platform Services Universitätsspital Basel
  • 26% vs 3%

    Organizations that govern Microsoft 365 well realize significant Copilot value 26% of the time, versus 3% for those that do not.

    Gartner, 2025 Microsoft 365 Copilot Survey
  • As we continue to expand our cloud capabilities, the foundation laid by Rencore Governance will undoubtedly play a crucial role in ensuring that each step forward is taken with confidence, security, and compliance in mind.
    Case Study
    Claude Bisdorff Claude Bisdorff Head of IT Systems Ville de Luxembourg
  • 116%

    ROI from Microsoft 365 Copilot once the program is adopted and governed, in Forrester’s Total Economic Impact study.

    Forrester Total Economic Impact
  • I currently estimate that we save around €80k per year by freeing up our IT admin team to do the work that counts.
    Case Study
    Undisclosed Undisclosed Former Lead O365 Competence Center Royal BAM
  • 71%

    of enterprises name security and governance among their top challenges to deploying Microsoft 365 Copilot.

    Gartner
  • Rencore's centralized governance tool excelled at ensuring secure data in Microsoft 365 and minimizing the risk of unauthorized access.
    Case Study
    Greg Bowles Greg Bowles IT Operations Manager Specialist Risk Group
  • 150,000+

    AI agents in use at the average Fortune 500 company by 2028. Agent sprawl is the next sprawl.

    Gartner
  • With Rencore Governance we are able to reduce manual governance activities, improve our service quality and generate valuable insights across our Microsoft service stack.
    Undisclosed Undisclosed Head of AI & Process Automation Wacker Chemie AG

Frequently asked questions

Does Copilot create new GDPR risk or expose existing risk?
Mostly it exposes what was already there. Copilot and agents retrieve content at the permissions the user or agent already holds, which is Microsoft’s documented security model, so oversharing that sat unnoticed for years becomes personal data in an answer. What is new is the processing itself: where deploying AI over personal data is likely to result in high risk, Art. 35 requires a data protection impact assessment first.
What does an access review prove to a supervisory authority?
Art. 5(2) makes you responsible for demonstrating compliance, and Art. 58(1) lets authorities order the information they require. A completed access review is that demonstration for the access-control duty in Art. 32: a dated record of who, including guests and agents, could reach which personal data, who confirmed it was still needed, and what was revoked. Rencore exports those records as reports.
How does this relate to Microsoft Purview?
Purview classifies and protects the data with sensitivity labels, DLP and retention. Rencore governs the estate around it: which workspaces exist, who owns them, who and which agents can reach them, and when that access was last reviewed. A label on a document does not tell you the site is overshared. You need both layers, and Rencore complements Purview rather than replacing any part of it.
Does the EU AI Act replace GDPR duties for AI?
No, the two stack. The EU AI Act regulates the AI system and its risk class; GDPR keeps applying to every piece of personal data that system processes. An agent can be in order under the AI Act and still breach Art. 32 because it reads an overshared site. One current inventory of your agents and the data they depend on serves both, which is why the same Rencore inventory backs our DORA and EU AI Act coverage.

See your estate the way a supervisory authority will

Start with the inventory: every workspace, agent and automation in your Microsoft tenant, with owners, access and the personal data sources they reach, ready to stand behind your records of processing.

Rencore Governance inventory tile for Microsoft 365 counting 1,150 users, 380 groups, 12 sensitivity labels, 13 subscriptions, 527 service assignments, 428 message center messages, 77 apps, 6,918 user activities and 50 deleted users