Consulting Module

Module 4 โ€” Data Governance & Compliance

Data does not stay where you put it. It is copied, forwarded, synced, and shared โ€” and in most tenants, nobody can enumerate where it went or pull it back. This module makes data flows visible, governable, and auditable.

What It Delivers

๐Ÿท๏ธ

Sensitivity Label Deployment

A practical label taxonomy deployed across M365 โ€” not the six-tier compliance architecture that nobody uses, but a scheme your organisation will actually apply. Labels flow through email, Teams, SharePoint, and Office applications. Classification becomes a signal every downstream control can act on.

๐Ÿ“…

Retention Policies for All M365 Workloads

Retention configured for Exchange, SharePoint, OneDrive, Teams messages, and Teams meeting recordings. Regulatory minimums met. Over-retained data that creates unnecessary eDiscovery scope identified and scheduled for deletion. Retention gaps that expose you to "we don't have it" responses closed.

๐Ÿšซ

DLP Policies

Data Loss Prevention policies targeting your actual regulated data โ€” payment card numbers, national IDs, health data, or proprietary classifications โ€” with alert-before-block staged deployment. Auto-forward to external addresses blocked. "Anyone with the link" sharing scoped or removed.

โš–๏ธ

eDiscovery Readiness

Content search scope validated, custodian identification process documented, legal hold workflow tested. If you receive a regulatory request or litigation hold tomorrow, you can respond without improvising under pressure.

๐Ÿ‘ฅ

Teams Governance and Guest Access Controls

Teams lifecycle policy deployed so abandoned Teams do not accumulate as forgotten data stores. Guest access permissions tightened. External sharing settings reconciled across tenant, site, and Teams channel levels โ€” the three layers that routinely disagree and produce unexpected exposure.

Standards Alignment

This module produces direct compliance evidence for NIS2 Article 21 (data security, access control), DORA Article 9 (ICT security policies โ€” data classification and handling), GDPR Articles 5 and 25 (data minimisation, privacy by design), and ISO 27001 A.5.12โ€“A.5.13 (classification, labelling). External auditors receive the retention logs, sensitivity label reports, and DLP policy documentation as artefacts โ€” not manual screenshots.

Scope and Prerequisites

Duration45โ€“90 days
EnvironmentM365 E3+
PrerequisitesModule 2 (Identity) completed โ€” guest access and external sharing controls depend on a clean identity baseline
Natural follow-onModule 7 (Recovery) to ensure retained data is backed up independently of Microsoft’s native retention

Make your data flows visible

Every share is a copy of your blast radius handed to a party you do not fully control. Module 4 makes that visible and governable.