Microsoft Purview is Microsoft's unified data governance and compliance platform. It sits within Microsoft 365 and integrates with Azure to give organisations real-time visibility into where sensitive data lives, who can access it, and whether it complies with regulations like GDPR, ICO guidelines, and sector-specific standards (NHS Data Security and Protection Toolkit, PCI-DSS, ISO 27001).
If your organisation holds customer data, employee records, or financial information, Purview isn't optional anymore. By 2026, regulatory bodies across the UK expect organisations to demonstrate active data governance. The ICO has made it clear: passive compliance isn't enough. You need to show automated controls, audit trails, and documented risk management.
The real value? Purview detects compliance gaps before regulators do. It classifies sensitive data automatically, maps data flows, and can quarantine or delete data on policy triggers. For healthcare organisations, charities, and financial services, this is a game-changer.
GDPR requires you to know where personal data sits, why you hold it, and how long you keep it. Many UK organisations still struggle to locate data across cloud and on-premises systems.
Purview's Data Map scans your entire Microsoft 365 estate (SharePoint, OneDrive, Teams, Exchange) and identifies personal data automatically using built-in classifiers. If a data subject requests access or deletion (a Subject Access Request), Purview helps you find and action it within the 30-day GDPR window.
Holding onto data longer than you need isn't just wasteful; it's a compliance violation. UK organisations often over-retain email, documents, and records because deleting them feels risky.
Purview's retention policies let you set automatic disposal schedules. A finance department's invoices can be retained for 7 years (tax law requirement), while marketing email lists expire after 2 years (GDPR lawful basis end). No manual intervention needed, and you have an audit trail proving compliance.
The ICO expects breach notification within 72 hours. If a dataset containing customer addresses and payment card details leaks, can you confirm what's gone, who it affects, and what data loss prevention controls failed?
Purview's Alert Management and Content Explorer tools let you search for specific data patterns (credit card numbers, NHS numbers, company financials) across your entire tenant. When a breach occurs, you can quantify it, respond faster, and demonstrate due diligence to regulators.
Auditors (internal and external) increasingly ask for automated evidence of compliance. Excel spreadsheets and manual log files don't cut it anymore.
Purview generates compliance reports mapped to specific regulations. If you're audited for GDPR, you can pull a report showing data discovery, retention policies, data access logs, and DLP policy triggers all in one place. Auditors see real systems, not reconstructed stories.
Purview requires dedicated admins. Roles include:
Don't assign Global Admin to Purview work. It's too broad and creates audit risk. In Azure AD / Entra ID, create a dedicated security group for compliance admins and assign them via the Microsoft Purview compliance portal.
Data classification is where Purview starts. You define what "sensitive" means in your organisation, then let Purview find it.
Go to Microsoft Purview > Information Protection > Labels. Create labels for:
Once labels exist, Purview can auto-apply them to documents and emails based on content analysis. For example, a SharePoint document containing "NHS number" gets marked as healthcare data automatically. Users see a banner warning them and can't share it externally without approval.
Navigate to Microsoft Purview > Data Lifecycle Management > Retention Policies.
Create policies tied to content type and location. Examples:
Test policies on a pilot team or SharePoint site first. Retention policies are powerful; deleting data accidentally is hard to reverse.
DLP prevents sensitive data from leaving your organisation accidentally or maliciously.
Set rules like:
DLP rules can block, warn, or audit. Start with audit mode to see violations without disrupting users, then tighten enforcement over time.
Purview's Assessment Manager and Compliance Manager let you map your actual controls to regulatory requirements.
For GDPR, create an assessment, then track which Purview controls (data discovery, retention, encryption, DLP) address each GDPR article. You'll see compliance gaps visually. If you're missing controls, prioritise them.
Generate reports quarterly. Share them with leadership and your Data Protection Officer (DPO). This demonstrates active governance and helps with audit preparation.
An NHS trust manages thousands of patient records across email, OneDrive, and SharePoint. Before Purview, they:
After implementing Purview:
The outcome? Faster compliance cycles, lower audit costs, and staff time freed up for strategic data governance work instead of firefighting.
Purview is powerful but not a replacement for a compliance strategy. You still need:
If you're moving into IT compliance roles or want to build expertise in Microsoft 365 governance, start by understanding the M365 ecosystem itself. Our Microsoft 365 Administrator Programme covers compliance, security, and data governance as core modules. You'll get hands-on lab time with real Purview scenarios and leave ready to manage compliance in production environments.
Book a free 2-hour live session here: smoothops365.com/courses/it-helpdesk#free-session. We cover Microsoft 365 architecture, then dive into a real compliance scenario. No pressure, just clarity on whether M365 administration fits your career plan.
Purview focuses on data governance, classification, and lifecycle management. Defender for Office 365 protects against email threats and malware. They complement each other: Purview tells you what data you have and where; Defender stops malicious actors from stealing it. Both are essential in a complete security posture.
No. Most organisations start with Data Map and Retention Policies, then layer in DLP and Compliance Manager over 3 to 6 months. Start with your highest-risk data (personal, financial, healthcare) and expand from there. A phased approach reduces implementation risk and gives staff time to adapt.
Purview is a strong foundation, but auditors expect more: a written data protection policy, Staff training records, incident response procedures, and a Data Protection Impact Assessment for high-risk processing. Purview provides evidence and automation; you provide governance structure and oversight. Together, they create a credible compliance programme.
Purview's core features (Data Map, Retention, DLP, basic alerts) are included with Microsoft 365 business standard and above. Advanced features like Compliance Manager and Insider Risk Management require separate licences (around £5 per user per month). Costs depend on tenant size and feature scope; discuss with your Microsoft account manager to estimate.
Yes. Purview's automated discovery, encryption, and audit trail capabilities directly support DSPT requirements. You still need to document your data security measures and conduct risk assessments separately, but Purview automates many of the technical controls auditors look for, saving time and reducing compliance burden.
SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 50 contact hours. Keep your job while you train.