Skip to content
Browse all topics
Microsoft Purview (Compliance)

Microsoft Priva privacy management

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

Microsoft Priva is the data-privacy management product in Microsoft 365 — risk management and subject rights requests.

6 min read

Share as imagePNG

Microsoft Priva is the data privacy management product in Microsoft 365, addressing regulatory privacy concerns like GDPR, CCPA, and similar regimes. It sits alongside Purview but focuses on privacy specifically: where personal data is, who has access, and how to handle subject rights requests.

Priva is a privacy-focused sibling of the Purview solutions, relying on sensitive information types from DLP and retention; subject rights requests overlap with eDiscovery, and residency questions with tenant isolation and data residency.

What Priva does

Priva has two main capabilities:

Privacy Risk Management

Continuously evaluates personal data in your Microsoft 365 environment and flags risks:

  • Data overexposure — personal data shared with too many people internally.
  • Data transfers — personal data crossing geographic or organisational boundaries inappropriately.
  • Data minimisation — personal data being collected or retained without clear purpose.
  • Sensitive types in unusual locations — credit cards in OneDrives, government IDs in chat.

Risk findings drive policies — automated controls that warn users, restrict actions, or alert admins when risks are detected. For example: "Block sharing of a document containing more than 100 customer records to anyone outside the organisation."

Subject Rights Requests

When a customer or employee submits a subject rights request under GDPR / CCPA / equivalents (right to access, right to deletion, right to correction), Priva orchestrates the response:

  • Define the request — what kind, what subject, what scope.
  • Identify data — Priva searches across Microsoft 365 for content related to the subject.
  • Review — reviewer assesses what to include, what to redact.
  • Generate response — package the data for the requester.
  • Audit trail — every step is logged for compliance evidence.

Built on top of eDiscovery infrastructure, with privacy-specific workflows.

Why this matters

GDPR went live in 2018 and subject rights requests have grown steadily. CCPA, China PIPL, India DPDP, and many others have followed. For organisations subject to these regimes, a structured way to respond is necessary — and "we'll search email manually when someone asks" doesn't scale.

Priva offers the structured workflow that legal teams can run repeatedly.

How it integrates

  • Microsoft Purview handles general compliance (retention, eDiscovery, DLP); Priva specifically addresses privacy.
  • Defender signals contribute to risk detection in Priva.
  • Sensitivity labels in Purview can drive Priva risk assessments.
  • Subject Rights Requests in Priva are technically eDiscovery cases with a privacy-specific UI on top.

Licensing

Priva is licensed as a per-user add-on, with separate skus for Privacy Risk Management and Subject Rights Requests. Included with Microsoft Priva standalone licences or bundled in Microsoft 365 E5 Compliance for some scenarios.

For organisations handling significant personal data — anyone with European customers, anyone in healthcare, anyone in financial services — Priva is increasingly part of the compliance baseline.

Practical rollout

  1. Inventory personal data across Microsoft 365 — use Priva's automatic discovery.
  2. Set up the SRR workflow with named reviewers (legal, privacy officer, HR).
  3. Define risk policies for high-priority data classes (customer PII, employee records, payment data).
  4. Train the team on running SRRs through Priva rather than ad-hoc.
  5. Audit and report quarterly on SRRs handled, risks closed, policy effectiveness.

Priva doesn't make privacy management easy — privacy is inherently a structured legal / process exercise — but it makes the Microsoft 365 side of it dramatically more manageable than doing it by hand.

Decision matrix — do you need Priva now?

| Situation | Verdict | |---|---| | EU customer base of any size, no SRR process yet | Priva SRR is the fastest path off spreadsheets and manual mailbox searches. | | Existing SRR process running through outside counsel | Priva for the internal collection, hand the review off to counsel — cheaper per request. | | Very small tenant, one SRR every couple of years | Skip Priva; run the request as a Purview eDiscovery Standard case with a privacy checklist. | | Regulated (health, finance) with a privacy officer | Both Priva SRR and Priva Risk Management. The risk-management side is what a privacy officer will actually use daily. | | B2C org with heavy consent management | Priva plus a dedicated consent platform (OneTrust, TrustArc). Priva does not manage consent itself. |

Wrong-fit warnings

  • Priva is not a consent management platform. It will not host your cookie banner, capture opt-ins, or maintain a preference centre.
  • Priva SRR reaches Microsoft 365 content, not everything. Data in Salesforce, HubSpot, on-prem file shares, or a customer database is out of scope; SRR fulfilment for those needs its own path.
  • Priva Risk policies are noisy at first. Expect a quiet-mode rollout period where you tune signal-to-noise before enforcement. Rolling out with block actions on day one produces a slack-ticket avalanche.
  • Priva SRR is not eDiscovery for legal cases. Do not repurpose it for litigation; the audit trail and export shape are tuned for privacy responses, not for court production.
  • A subject rights request is not always a deletion request. Priva distinguishes access, portability, correction and deletion — make sure your reviewers understand which is which; a wrong response is a regulator-worthy incident.

Worked example — first-year Priva rollout at a mid-market SaaS

Scenario: 1,200 employees, EU + US customers, GDPR + CCPA in scope, no formal SRR tooling.

  • Month 1: Turn on Priva Privacy Risk Management in report-only. Baseline emerges: personal-data spread by department, the top overexposed sites, the "shadow HR" folders in team OneDrives.
  • Month 2: Publish the first three privacy policies in warn-only: overexposure of employee records, external sharing of files with named customer PII types, transfers of personal data to unmanaged locations.
  • Month 3: Stand up SRR reviewers — one privacy officer, one legal, one HR. Rehearse a synthetic SRR end to end. Time the response and record it.
  • Month 4: Publish the SRR intake form on the public site or in-app. All new requests route through Priva SRR from day one.
  • Month 6: Flip the top privacy policies from warn to enforce. Publish a quarterly privacy metrics report — requests handled, median time, closed risks — as the board-level artefact.

FAQ for MSPs

  • Can we run Priva SRR on behalf of a customer? Yes with GDAP and role assignments in the customer tenant. Restrict yourselves to case setup and workflow; the customer's privacy officer should be the reviewer who sees the personal data.
  • Multi-tenant Priva view? No unified view across tenants. Report per-tenant and roll up in your own PSA/BI stack.
  • How do we price Priva engagements? Priva add-ons are per-user, so incremental to the customer's E3/E5 base. Bundle "SRR fulfilment SLA" as an outcome, not "hours in Priva."
  • What is the fastest first-value win for a customer? Turn on the personal-data overexposure risk in report-only for a week and hand them the top-20 sites report. Concrete, cheap, and it earns the follow-on rollout conversation.

Was this useful?

Spot something wrong or want a topic covered? Send it through the contact form.