Is OneDrive GDPR compliant? What universities should check
OneDrive and SharePoint are where most files end up at universities that run Microsoft 365 Education, including research data that was never meant to leave a project. This page sets out what Microsoft publicly documents about where that data lives, the contract, sharing with external collaborators and encryption options, and what it means for a university.
Short answer
For a university, OneDrive and SharePoint sit inside a Microsoft 365 Education tenant. The contract is Microsoft's Product Terms and its Products and Services Data Protection Addendum (May 2026 version). Tenants signed up in the EU or EFTA fall within Microsoft's EU Data Boundary, with limited documented exceptions, and Microsoft states it is certified under the EU-US Data Privacy Framework. The questions that decide most risk are local ones: how far external sharing is opened, whether Anyone links are allowed, what happens to a departing researcher's files, and whether sensitive research data needs encryption keys under the university's own control. Microsoft provides controls for each; the university has to set them.
What Microsoft documents publicly
The table summarises Microsoft's privacy statement, Data Protection Addendum, EU Data Boundary documentation and SharePoint and OneDrive admin documentation, read on 7 October 2026. It covers OneDrive for work or school and SharePoint Online in a commercial or education tenant, not personal OneDrive accounts.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Microsoft Ireland Operations Limited in Dublin is the EU contact point for data protection, with Microsoft Corporation as the US parent. The privacy statement (September 2026) says that, for enterprise products, the customer's agreements with Microsoft control where they conflict with the statement. | Privacy Statement [1] |
| Where data is stored and processed | Tenant-dependent Microsoft commits to store and process customer data and pseudonymised personal data for Microsoft 365 within the EU Data Boundary (EU and EFTA countries) for customers whose sign-up location is in the EU or EFTA, subject to limited documented transfers. Customers who bought Multi-Geo are not in scope. | EU Data Boundary [2] |
| Data processing agreement | Documented The Products and Services Data Protection Addendum defines the data processing and security terms for products bought under the Product Terms. The current version is dated 22 May 2026. | DPA page [3] |
| International transfers (DPF, SCCs) | Documented The privacy statement says Microsoft Corporation has certified compliance with the EU-US DPF, the UK Extension and the Swiss-US DPF (DPF status read from Microsoft's privacy statement; the official DPF list API returned an error for every query on the check date). | [1] |
| External sharing | Documented Organisation-wide levels are Anyone, New and existing guests, Existing guests and Only people in your organisation. OneDrive can be more restrictive than SharePoint, not more permissive. Anyone links can be forced to expire and limited to view only. Domains can be allowed or blocked (up to 5,000) and guest access can expire automatically. | Sharing settings [4] |
| Retention and deletion | Documented When a user is deleted, the OneDrive is kept for 30 days by default (configurable), the manager or a secondary owner gets access, and the OneDrive then stays 93 days in the recycle bin. Retention policies and eDiscovery holds take precedence. Unlicensed OneDrive accounts are archived on day 93. | Retention and deletion [5] |
| Customer-held encryption keys | Licence-dependent Double Key Encryption keeps one key under the customer's control. Microsoft says it comes with Microsoft 365 E5, is intended for a small share of highly sensitive data, and that SharePoint and OneDrive cannot open DKE files in the browser or support co-authoring, search or eDiscovery for them. | Double Key Encryption [6] |
| AI features | Documented Microsoft Copilot can ground answers in OneDrive and SharePoint content the user has at least view permission for. Microsoft says prompts, responses and Graph data are not used to train foundation models; Anthropic models are currently excluded from the EU Data Boundary. | Copilot privacy [7] |
| Security certifications | Documented OneDrive and SharePoint Online are listed among in-scope commercial services for Microsoft's ISO/IEC 27001 certification; a statement of applicability also covers ISO 27017, 27018 and 27701. | ISO 27001 offering [8] |
The most detailed independent review comes from the Netherlands. In February 2022 Privacy Company published a DPIA on Teams, OneDrive and SharePoint for the Dutch Ministry of Justice and Security and SURF. It found six low risks and one high risk: processing special categories of personal data without encryption under the organisation's own control, because of possible access from the United States even when data stays in the EU. Its recommended measures include Double Key Encryption for sensitive files, Customer Key and Customer Lockbox, minimal telemetry and strict retention [9]. That work reflects Dutch contracts and the product in early 2022, before the EU Data Boundary was completed.
What this means for a university
Validemic's analysis
Research data is the hard case. Administrative files and teaching material rarely cause trouble. Interview recordings, health data, data on ethnicity or political opinions, and pseudonymised datasets with a key file are different: they fall under Article 9 GDPR [10], and research ethics approvals often promise a specific storage location and access list. A tenant-wide default that suits a press office may not suit a clinical research group. Many universities handle this with dedicated SharePoint sites for sensitive projects, set more restrictively than the tenant default.
Sharing links are the main leak path. An Anyone link works for whoever holds it, and Microsoft notes that you cannot track who has accessed items shared that way [4]. For research data, the safer pattern is specific-people sharing with authenticated guests, guest expiry, and domain allow lists for partner institutions. If Anyone links stay on for convenience, mandatory expiry and view-only defaults reduce the damage of a forwarded link.
External collaborators. Guests from partner universities become accounts in your directory when Microsoft Entra B2B integration is enabled [4]. That creates a record you must manage: who invited them, for which project, and when access ends. Joint projects may also need a joint controller arrangement or data sharing agreement, which no storage setting replaces.
Departing researchers. The default 30-day retention after account deletion [5] is short for a research group. Unless retention policies or a planned handover apply, project data held in a personal OneDrive can disappear when a postdoc's contract ends. Storing project data in project sites rather than personal OneDrives avoids most of this.
Copilot and oversharing. Copilot only surfaces what a user can already open [7], so it does not widen permissions. It does make existing over-broad permissions much easier to find. Reviewing site permissions before enabling Copilot is a sensible step.
Transfers. The European Commission adopted its adequacy decision for the EU-US Data Privacy Framework on 10 July 2023 [11]. With an EU tenant, the EU Data Boundary limits routine transfers, but Microsoft documents exceptions [2]. Keep the DPA's SCCs and Microsoft's documentation on file, and check the official DPF list yourself.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to settle before approving OneDrive for research data
- Is our tenant's sign-up location in the EU or EFTA, and have we bought Multi-Geo (which takes us out of EU Data Boundary scope)?
- What is our organisation-wide external sharing level, and is OneDrive set at the same or a more restrictive level?
- Are Anyone links allowed? If so, what is the maximum expiry, and are they view only?
- Which partner domains are on an allow list, and does guest access expire automatically?
- Where should special category research data go: a restricted SharePoint site, sensitivity-labelled libraries, Double Key Encryption, or a different service altogether?
- What retention applies to a OneDrive after a researcher leaves, and who receives access?
- Have we reviewed site permissions before turning on Copilot, and are Anthropic models left off?
- Which measures from the 2022 SURF DPIA have we applied in our own tenant?
The EU AI Act angle
OneDrive and SharePoint are storage services. They are not among the education uses listed as high-risk in Annex III of the AI Act [12], and adding Copilot search or summaries does not change that by itself. The obligation that applies today is AI literacy: Article 4, as amended by Regulation (EU) 2026/1744, requires deployers to take measures to support the AI literacy of staff using AI systems on their behalf [13]. High-risk obligations for Annex III systems apply from 2 December 2027 [14].
Sources
- Microsoft Privacy Statement (September 2026), retrieved 7 October 2026
- What is the EU Data Boundary?, Microsoft Learn, retrieved 7 October 2026
- Microsoft Products and Services Data Protection Addendum (22 May 2026 version), retrieved 7 October 2026
- Manage sharing settings for SharePoint and OneDrive in Microsoft 365, Microsoft Learn, retrieved 7 October 2026
- OneDrive retention and deletion, Microsoft Learn, retrieved 7 October 2026
- Double Key Encryption (DKE), Microsoft Learn, retrieved 7 October 2026
- Data, Privacy, and Security for Microsoft Copilot, Microsoft Learn, retrieved 7 October 2026
- ISO/IEC 27001 offering, Microsoft Learn, retrieved 7 October 2026
- New DPIA for the Dutch government and universities on Microsoft Teams, OneDrive and SharePoint Online, Privacy Company, 21 February 2022, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Articles 9 and 35, text read from the Publications Office copy, retrieved 7 October 2026
- EU-US data transfers, European Commission, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk (as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
About this page
We read Microsoft's privacy statement, the DPA page, EU Data Boundary documentation, SharePoint and OneDrive admin documentation on sharing and retention, the Double Key Encryption and Copilot privacy pages, Microsoft's ISO 27001 offering page, the Privacy Company DPIA summary and the relevant EU legal texts on 7 October 2026. Statements about Microsoft come from those pages; our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of OneDrive or SharePoint complies with the GDPR. Microsoft updates its documentation often, so check the linked sources before relying on a detail. If you spot an error, please contact us and we will correct it.
Frequently asked questions
Is OneDrive GDPR compliant?
No tool is GDPR compliant on its own. In a Microsoft 365 Education tenant, OneDrive and SharePoint are covered by Microsoft's Products and Services Data Protection Addendum, fall within the EU Data Boundary for tenants signed up in the EU or EFTA, and Microsoft states it is certified under the EU-US Data Privacy Framework. Whether a university's use complies depends on its sharing settings, retention, lawful basis and the sensitivity of what staff store.
Is OneDrive data stored in the EU?
Microsoft says Microsoft 365 customers with a sign-up location in the EU or EFTA are in scope for the EU Data Boundary, so customer data and pseudonymised personal data are stored and processed there, with limited documented exceptions. Tenants that bought Multi-Geo are not in scope even if listed in an EU country.
Can researchers share OneDrive files with external collaborators?
Yes, if the administrator allows it. SharePoint and OneDrive support four organisation-wide levels: Anyone links, new and existing guests, existing guests only, or no external sharing. OneDrive can be set more restrictive than SharePoint but not more permissive. Administrators can force Anyone links to expire, limit them to view only, and allow or block specific domains.
Can OneDrive be used for sensitive or special category research data?
That is a decision for the university after a risk assessment. The 2022 Dutch DPIA by Privacy Company for SURF and the Dutch government found one high risk for special category data stored without encryption keys under the organisation's own control, and recommended measures such as Double Key Encryption. Microsoft says Double Key Encryption comes with Microsoft 365 E5 and limits features such as web viewing and co-authoring.
What happens to a OneDrive when a researcher leaves?
When the user account is deleted, Microsoft keeps the OneDrive for a retention period of 30 days by default, which administrators can change, and gives the user's manager or a secondary owner access. It then sits in the recycle bin for 93 days. Microsoft 365 retention policies and holds take precedence over this process.