Back to BlogMicrosoft 365 Tips

Microsoft Purview Compliance Guide: Data Governance for UK Organisations 2026

28 September 2026 6 min read
Photo by dlxmedia.hu on Unsplash

What is Microsoft Purview and why does it matter for UK compliance?

Microsoft Purview is Microsoft's unified data governance and compliance platform. It sits within Microsoft 365 and integrates with Azure to give organisations real-time visibility into where sensitive data lives, who can access it, and whether it complies with regulations like GDPR, ICO guidelines, and sector-specific standards (NHS Data Security and Protection Toolkit, PCI-DSS, ISO 27001).

If your organisation holds customer data, employee records, or financial information, Purview isn't optional anymore. By 2026, regulatory bodies across the UK expect organisations to demonstrate active data governance. The ICO has made it clear: passive compliance isn't enough. You need to show automated controls, audit trails, and documented risk management.

The real value? Purview detects compliance gaps before regulators do. It classifies sensitive data automatically, maps data flows, and can quarantine or delete data on policy triggers. For healthcare organisations, charities, and financial services, this is a game-changer.

The core compliance challenges Purview solves

1. GDPR and Data Subject Rights

GDPR requires you to know where personal data sits, why you hold it, and how long you keep it. Many UK organisations still struggle to locate data across cloud and on-premises systems.

Purview's Data Map scans your entire Microsoft 365 estate (SharePoint, OneDrive, Teams, Exchange) and identifies personal data automatically using built-in classifiers. If a data subject requests access or deletion (a Subject Access Request), Purview helps you find and action it within the 30-day GDPR window.

2. Data Retention and Lifecycle

Holding onto data longer than you need isn't just wasteful; it's a compliance violation. UK organisations often over-retain email, documents, and records because deleting them feels risky.

Purview's retention policies let you set automatic disposal schedules. A finance department's invoices can be retained for 7 years (tax law requirement), while marketing email lists expire after 2 years (GDPR lawful basis end). No manual intervention needed, and you have an audit trail proving compliance.

3. Incident Response and Breach Notification

The ICO expects breach notification within 72 hours. If a dataset containing customer addresses and payment card details leaks, can you confirm what's gone, who it affects, and what data loss prevention controls failed?

Purview's Alert Management and Content Explorer tools let you search for specific data patterns (credit card numbers, NHS numbers, company financials) across your entire tenant. When a breach occurs, you can quantify it, respond faster, and demonstrate due diligence to regulators.

4. Regulatory Audit Readiness

Auditors (internal and external) increasingly ask for automated evidence of compliance. Excel spreadsheets and manual log files don't cut it anymore.

Purview generates compliance reports mapped to specific regulations. If you're audited for GDPR, you can pull a report showing data discovery, retention policies, data access logs, and DLP policy triggers all in one place. Auditors see real systems, not reconstructed stories.

How to set up Purview compliance in your Microsoft 365 tenant

Step 1: Assign the right roles

Purview requires dedicated admins. Roles include:

  • Compliance Administrator: Can access all Purview features, set policies, and run reports.
  • Compliance Data Administrator: Can manage data retention, labels, and data map discovery.
  • Insider Risk Management Admin: Manages alerts and investigations if you use that module.
  • Don't assign Global Admin to Purview work. It's too broad and creates audit risk. In Azure AD / Entra ID, create a dedicated security group for compliance admins and assign them via the Microsoft Purview compliance portal.

    Step 2: Enable and configure data classification

    Data classification is where Purview starts. You define what "sensitive" means in your organisation, then let Purview find it.

    Go to Microsoft Purview > Information Protection > Labels. Create labels for:

  • Personal data (names, addresses, employee IDs)
  • Financial data (invoices, contracts, payroll)
  • Healthcare data (patient records, medical history)
  • Business-critical data (strategic plans, IP)
  • Once labels exist, Purview can auto-apply them to documents and emails based on content analysis. For example, a SharePoint document containing "NHS number" gets marked as healthcare data automatically. Users see a banner warning them and can't share it externally without approval.

    Step 3: Set up data retention policies

    Navigate to Microsoft Purview > Data Lifecycle Management > Retention Policies.

    Create policies tied to content type and location. Examples:

  • Retain all Teams channel messages for 7 years (regulatory requirement), then auto-delete.
  • Retain SharePoint documents in the Finance folder for 10 years; all others for 3 years.
  • Hold email for litigation purposes indefinitely if a legal case flag is applied.
  • Test policies on a pilot team or SharePoint site first. Retention policies are powerful; deleting data accidentally is hard to reverse.

    Step 4: Enable Data Loss Prevention (DLP)

    DLP prevents sensitive data from leaving your organisation accidentally or maliciously.

    Set rules like:

  • Block external sharing of files labeled as "Personal Data" unless approved by a compliance manager.
  • Prevent credit card numbers (16-digit patterns) being copied into Slack or external email.
  • Alert admins if someone downloads more than 100 files from SharePoint in one hour (potential data theft).
  • DLP rules can block, warn, or audit. Start with audit mode to see violations without disrupting users, then tighten enforcement over time.

    Step 5: Run compliance assessments and generate reports

    Purview's Assessment Manager and Compliance Manager let you map your actual controls to regulatory requirements.

    For GDPR, create an assessment, then track which Purview controls (data discovery, retention, encryption, DLP) address each GDPR article. You'll see compliance gaps visually. If you're missing controls, prioritise them.

    Generate reports quarterly. Share them with leadership and your Data Protection Officer (DPO). This demonstrates active governance and helps with audit preparation.

    Real-world example: NHS trust using Purview

    An NHS trust manages thousands of patient records across email, OneDrive, and SharePoint. Before Purview, they:

  • Couldn't find patient data across their tenant reliably.
  • Manually handled Subject Access Requests (took 3 weeks per request).
  • Had no automated way to prove HIPAA and GDPR compliance to auditors.
  • After implementing Purview:

  • Data Map catalogued 2.3 million sensitive records in 10 days.
  • Retention policies auto-delete non-critical records after 3 years, reducing storage costs by 22%.
  • Subject Access Requests now take 4 days; Purview exports all relevant data in minutes.
  • Audit readiness improved: they pulled a GDPR compliance report in 2 hours instead of weeks of manual log review.
  • The outcome? Faster compliance cycles, lower audit costs, and staff time freed up for strategic data governance work instead of firefighting.

    Common Purview compliance pitfalls to avoid

  • Over-classifying data: If everything is marked "sensitive," the system becomes noise. Be selective.
  • Ignoring on-premises data: Purview focuses on cloud. If you have a legacy SharePoint on-premises or file servers, use a separate discovery tool or plan a migration.
  • Setting retention without testing: A poorly configured retention policy can delete data you meant to keep. Always pilot in a test environment first.
  • Forgetting user training: Purview policies only work if staff understand them. Train users on DLP warnings, label application, and why data governance matters.
  • Not reviewing alerts regularly: Purview generates alerts and incidents. If admins ignore them, compliance gaps go undetected.
  • Your next step: Embed Purview in your compliance program

    Purview is powerful but not a replacement for a compliance strategy. You still need:

  • A documented data retention schedule (linked to business and legal requirements).
  • A Data Protection Impact Assessment (DPIA) for high-risk processing.
  • Incident response procedures (so you can act fast if a breach occurs).
  • Staff training on data handling and security.
  • If you're moving into IT compliance roles or want to build expertise in Microsoft 365 governance, start by understanding the M365 ecosystem itself. Our Microsoft 365 Administrator Programme covers compliance, security, and data governance as core modules. You'll get hands-on lab time with real Purview scenarios and leave ready to manage compliance in production environments.

    Book a free 2-hour live session here: smoothops365.com/courses/it-helpdesk#free-session. We cover Microsoft 365 architecture, then dive into a real compliance scenario. No pressure, just clarity on whether M365 administration fits your career plan.

    Frequently asked questions

    What's the difference between Purview and other Microsoft compliance tools like Defender for Office 365?

    Purview focuses on data governance, classification, and lifecycle management. Defender for Office 365 protects against email threats and malware. They complement each other: Purview tells you what data you have and where; Defender stops malicious actors from stealing it. Both are essential in a complete security posture.

    Do I need to implement all Purview features at once?

    No. Most organisations start with Data Map and Retention Policies, then layer in DLP and Compliance Manager over 3 to 6 months. Start with your highest-risk data (personal, financial, healthcare) and expand from there. A phased approach reduces implementation risk and gives staff time to adapt.

    Is Purview enough to pass a UK compliance audit?

    Purview is a strong foundation, but auditors expect more: a written data protection policy, Staff training records, incident response procedures, and a Data Protection Impact Assessment for high-risk processing. Purview provides evidence and automation; you provide governance structure and oversight. Together, they create a credible compliance programme.

    How much does Purview cost?

    Purview's core features (Data Map, Retention, DLP, basic alerts) are included with Microsoft 365 business standard and above. Advanced features like Compliance Manager and Insider Risk Management require separate licences (around £5 per user per month). Costs depend on tenant size and feature scope; discuss with your Microsoft account manager to estimate.

    Can Purview help with healthcare compliance like NHS Data Security and Protection Toolkit?

    Yes. Purview's automated discovery, encryption, and audit trail capabilities directly support DSPT requirements. You still need to document your data security measures and conduct risk assessments separately, but Purview automates many of the technical controls auditors look for, saving time and reducing compliance burden.

    Ready to start your IT career?

    SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 50 contact hours. Keep your job while you train.