Is Dynamics 365 GDPR compliant?

By Emil Björk · Microsoft business apps consultant, Gothenburg

Microsoft provides the platform capabilities and contractual commitments (data processing terms, EU data residency options, tools for subject access and deletion requests) that let a properly configured Dynamics 365 deployment meet GDPR obligations — but compliance itself is a shared responsibility, not something the product delivers automatically. How you classify data, configure retention, and handle a real subject access request in your own tenant is on you, not Microsoft.

Microsoft publishes its own compliance commitments and certifications for the underlying platform, and Dynamics 365 includes features that support GDPR obligations directly — data export tools, deletion capabilities, audit logging, and (depending on region) EU data residency. None of that substitutes for an organisation actually doing its own data-protection work: classifying what personal data lives where, setting retention and deletion policy, and having a real process for subject access requests.

Treat 'is the product GDPR compliant' as the wrong question — the right one is 'have we configured and operated our specific tenant in a way that meets our GDPR obligations,' which depends entirely on decisions your organisation makes, not a checkbox Microsoft ships turned on.

Go deeper

Other questions