Microsoft 365 and GDPR: Criticism, Challenges and Solutions

02. October 2026 Laura DSGVO Microsoft 365 KI Datenschutz

Microsoft 365 and GDPR: Criticism, Challenges and Solutions

The GDPR, the EU General Data Protection Regulation, has fundamentally changed the way companies handle personal data. Microsoft 365, a popular cloud office package, offers many data storage and processing capabilities, but GDPR compliance requires careful planning and continuous monitoring. The article critically discusses the data protection aspects of Microsoft 365 and describes solutions to meet the requirements of the GDPR.

## What does this mean for your company?

The GDPR requires companies to protect the data of their customers and employees and to treat it transparently. When using Microsoft 365, you must ensure that all data processing steps comply with the requirements of the GDPR. This includes the establishment of access rights, the documentation of data processing and the involvement of data protection officers. Without a clear strategy and the right actions, you can take legal risks.

## What does this mean for your company?

The DSG, the EU General Data Protection Regulation, obliges companies to protect the data of their customers and employees and to treat it transparently. When using Microsoft 365, you must ensure that all data processing steps comply with the requirements of the GDPR. This includes the establishment of access rights, the documentation of data processing and the involvement of data protection officers. Without a clear strategy and the right actions, you can take legal risks.

AI models and the GDPR: What should be considered?

AI models used in Microsoft 365 or other systems can play a role in data processing. While they can perform tasks such as accounting or data analytics more efficiently, they require special attention in terms of GDPR. AI models must be set up in such a way that they do not process sensitive data or transmit it unauthorized. It is also important to make data processing transparent through AI models and to document the consent of those affected.

Agentic Engineering and the Future of Software Development

A new approach to software development, Agentic Engineering, could change the way companies handle data and AI. Coding agents are used to help create and optimize code in a professional workflow. This concept could help reduce the complexity of data processing and AI integration while improving GDPR compliance. However, it is still under development and requires careful implementation.

AI developments and applications in practice

AI developments such as Gemini 4 Argon, Manus Cue and ChatGPT advertising show how fast technology is advancing. In practice, these models are used in various industries, including rehab clinics. The application of AI can help to optimize processes and support decisions. Nevertheless, it is important to recognize the limitations of AI models and ensure that they are used in accordance with data protection regulations.

## How ISN/xynap supports this

The modules **infrastructure** and **ai** from xynap offer a GDPR-compliant, self-hosted infrastructure and AI tools that are data protection-friendly and transparent. They enable secure and traceable data processing without relying on external providers.

Sources (4)

  1. www.dr-datenschutz.de
  2. www.microsoft.com
  3. www.heise.de
  4. the-decoder.de