Governance meeting reviewing data classification and retention policy
Microsoft Security Technology

Data Protection & Information Governance

We deploy Microsoft Purview to classify sensitive data, control how it leaves your organisation, and apply retention that stands up to a UK GDPR audit, without smothering staff in policies they'll work around.

Data sources classified
6
DLP policies in enforcement
12
Retention policy coverage
90%
Illustrative figures
The challenge

You can't protect data you can't find, and you can't prove compliance you can't evidence.

Most organisations we meet don't have a clear picture of where their sensitive data actually lives. Personal data, client files and financial records accumulate across SharePoint, email, file shares and increasingly personal OneDrive folders, without any consistent classification. When a subject access request or a regulator's enquiry arrives, the honest answer to 'where is this person's data' is often 'we're not entirely sure' — which is a poor position to be in under UK GDPR.

Data loss prevention is frequently either absent or configured so broadly that staff learn to route around it, sending sensitive files through personal email or unsanctioned file-sharing tools because the sanctioned route keeps blocking legitimate work. An NHS supplier or a fintech with FCA obligations can't afford either extreme: no controls at all, or controls so clumsy that staff actively bypass them.

Insider risk is a genuinely sensitive topic to configure well. Departing employees taking client lists or intellectual property before resigning is a real and recurring problem, but monitoring configured without proportion or transparency creates a trust problem with staff that can outweigh the risk it's meant to address. Getting the scope and staff communication right matters as much as the technical configuration.

Retention is the area most often left entirely unmanaged. Without a defined policy, organisations either delete nothing — creating unnecessary risk and cost from years of data with no ongoing business purpose — or delete inconsistently, unable to demonstrate a defensible, documented reason for what was kept and what was removed when a regulator or a litigant asks.

  • Sensitive and personal data scattered across systems with no consistent classification
  • DLP either absent or broad enough that staff route around it
  • Insider risk monitoring configured without proportion or staff transparency
  • No defensible retention and deletion policy for personal or regulated data
Our approach

We classify first, then apply proportionate controls around what we find.

We start by mapping where sensitive data actually sits across your Microsoft 365 tenant and connected sources, then apply sensitivity labelling so data is classified consistently rather than left to individual staff judgement. This classification step underpins everything else — DLP, retention and insider risk policies are only as good as the labelling behind them.

Data loss prevention policies go live in audit or notify mode first. We review what the policy would have blocked over a set period, check it against genuine business workflows, and only move to enforcement once we're confident it stops risk without constantly interrupting people trying to do their jobs. This staged approach is the difference between DLP that gets embraced and DLP that gets quietly disabled by a frustrated user six weeks in.

Insider risk management, where it's appropriate for your organisation, is scoped narrowly around specific indicators — bulk downloads ahead of a resignation, data movement to unsanctioned locations — rather than blanket activity monitoring. We help draft the staff-facing policy communication so the approach is transparent and proportionate, which matters both ethically and for staff trust.

Retention policies are built around your actual regulatory obligations rather than a generic template — UK GDPR's requirement to justify retention and delete data once its purpose has ended, sector-specific requirements for financial services or healthcare records, and your own operational need to keep some data longer for legitimate business reasons.

  • Sensitivity classification mapped across Microsoft 365 and connected sources
  • DLP staged from audit mode into enforcement to avoid disrupting legitimate work
  • Insider risk scoped narrowly with transparent staff communication
  • Retention built against your actual regulatory obligations, not a generic template
What's included

Everything in the engagement, set out up front.

A governance engagement covering discovery, classification, policy configuration and staff communication.

Data discovery and mapping

Identification of where sensitive and personal data actually sits across your Microsoft 365 tenant and connected sources.

Sensitivity labelling

A classification scheme applied consistently, prioritising the highest-risk data types first.

Data loss prevention configuration

Policies staged from audit mode into enforcement, tuned against your real business workflows.

Insider risk management

Narrowly scoped monitoring for specific risk indicators, with transparent, staff-facing policy communication.

Retention and deletion policy

Documented, defensible retention rules aligned to UK GDPR and sector-specific record-keeping requirements.

eDiscovery readiness

Configuration that speeds up response to subject access requests, litigation holds and regulatory enquiries.

Deliverables

What you receive.

  • Data discovery and classification map
  • Sensitivity labelling scheme and rollout plan
  • DLP policy set, staged from audit to enforcement
  • Insider risk policy scope and staff communication draft
  • Retention and deletion policy documentation
  • eDiscovery configuration and access guide
  • UK GDPR alignment summary for audit purposes
  • Quarterly governance review recommendation
Who it suits

Built for organisations that need the work done properly.

Organisations facing UK GDPR audit pressure

Businesses that need to demonstrate, not just assert, where personal data lives and how long it's kept.

Regulated sectors with record-keeping duties

A fintech with FCA obligations or an NHS supplier needing evidenced retention and access control.

Firms concerned about data leaving with staff

Organisations that have had, or want to prevent, sensitive data walking out the door with a departing employee.

Legal and professional services firms

Practices handling client-confidential information across email and document management that needs consistent classification.

Outcomes & benefits

What changes once the work is done.

What changes once classification, DLP and retention are properly in place.

You can answer 'where is this data' with confidence

Classification and discovery mean subject access requests and regulator enquiries can be answered from evidence, not guesswork.

Sensitive data leaves through fewer unsanctioned routes

Tuned DLP policies catch genuine risk without blocking legitimate work, so staff aren't incentivised to bypass them.

Defensible retention, not accumulated risk

Documented retention and deletion rules reduce the volume of unnecessary data held and the exposure it represents.

Insider risk addressed proportionately

Narrowly scoped monitoring catches genuine indicators of data exfiltration without a blanket surveillance approach that damages trust.

Faster, cleaner compliance audits

UK GDPR, and where relevant sector-specific frameworks, supported by documented classification, access and retention evidence.

Reduced legal and reputational exposure

Fewer unclassified sensitive files sitting unmanaged reduces the impact if a breach or data loss incident does occur.

Why choose Secure Chain to configure Purview.

Purview is a genuinely broad product, and it's easy to either under-configure it — leaving classification and DLP largely theoretical — or over-configure it in ways that frustrate staff and get quietly worked around. Our approach is built around getting the balance right for your organisation specifically, not applying a one-size template.

We treat information governance as an ongoing discipline rather than a one-off project. Data classification needs revisiting as new systems and data types are introduced, DLP rules need periodic review as workflows change, and retention policy needs checking against evolving regulatory guidance. We build that review cycle into the engagement rather than leaving you with a static configuration that drifts out of date.

We deliver this work for organisations across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, often alongside our wider compliance support for ISO 27001, NHS DSPT or FCA-driven obligations, since data governance is usually one part of a broader compliance picture rather than a standalone exercise.

Where you're also running Microsoft Sentinel or Defender, we make sure insider risk and DLP signal feeds into the same operational view your security team already monitors, rather than sitting in a separate compliance silo nobody in the SOC ever looks at.

Frequently asked questions

Questions we are asked most often.

What is Microsoft Purview and what does it cover?

Purview is Microsoft's data governance and compliance suite, covering data classification and sensitivity labelling, data loss prevention, insider risk management, records retention and eDiscovery, across Microsoft 365 and connected data sources. Which components you need depends on your regulatory obligations and how sensitive data moves through your organisation.

Do we need Purview if we're already UK GDPR compliant?

Being compliant on paper and being able to demonstrate it with evidence are different things. Purview helps with the demonstrable part — knowing where personal and sensitive data actually lives, who can access it, and being able to produce records for a subject access request or a regulator's enquiry without a manual, time-consuming search.

Is insider risk management the same as spying on staff?

No, and it shouldn't be configured that way. Insider risk management looks for patterns like unusual bulk downloads before a resignation or data leaving through unsanctioned channels, using policies scoped to specific risk indicators rather than blanket monitoring of everyone's activity. We help set proportionate scope and make sure staff-facing policies are transparent.

How long does data classification take to set up properly?

Initial sensitivity labelling and DLP policy configuration typically takes four to six weeks for a mid-sized organisation. Getting classification accurate across historical data — years of documents and emails that predate any labelling — takes considerably longer and is usually phased, prioritising the highest-risk data first.

What's the retention requirement for UK GDPR?

UK GDPR doesn't set fixed retention periods; it requires you to justify how long you keep personal data and delete it when the purpose for holding it has ended. Purview's retention policies let you apply defensible, documented retention and deletion rules automatically, rather than relying on staff to remember to delete things manually.

Will this slow down how staff work with documents and email?

Poorly scoped DLP rules can, which is why we start policies in audit or notify mode rather than blocking outright. We review what would have been stopped, refine the rule against genuine business workflows, and only move to enforcement once we're confident it catches risk without constantly interrupting legitimate work.

Not sure where your sensitive data actually lives?

Book a free data discovery scoping call and we'll outline what a proper classification and retention project would involve for your organisation.

Book a free scoping call