Is Dynamics 365 GDPR compliant?
By Emil Björk · Microsoft business apps consultant, Gothenburg
Microsoft provides the platform capabilities and contractual commitments (data processing terms, EU data residency options, tools for subject access and deletion requests) that let a properly configured Dynamics 365 deployment meet GDPR obligations — but compliance itself is a shared responsibility, not something the product delivers automatically. How you classify data, configure retention, and handle a real subject access request in your own tenant is on you, not Microsoft.
Microsoft publishes its own compliance commitments and certifications for the underlying platform, and Dynamics 365 includes features that support GDPR obligations directly — data export tools, deletion capabilities, audit logging, and (depending on region) EU data residency. None of that substitutes for an organisation actually doing its own data-protection work: classifying what personal data lives where, setting retention and deletion policy, and having a real process for subject access requests.
Treat 'is the product GDPR compliant' as the wrong question — the right one is 'have we configured and operated our specific tenant in a way that meets our GDPR obligations,' which depends entirely on decisions your organisation makes, not a checkbox Microsoft ships turned on.
Go deeper
- Data classification for Dynamics 365How to classify data in Dynamics 365 to drive security, retention, and compliance decisions — classification tiers, where to record them.
- Data residency and compliance in Dynamics 365Where Dynamics 365 data lives, how compliance certifications stack up, GDPR and country-specific rules, and the customer's responsibilities.
- Data protection and compliance for Dynamics 365How to address data protection and compliance requirements for Dynamics 365 — GDPR, HIPAA, SOX, industry regulations, and the operational practices.