Compliance

SharePoint external sharing and GDPR: gathering the access-control evidence

GDPR Article 32 asks something deceptively simple of every organisation that processes personal data: ensure its confidentiality, and guard against "unauthorised disclosure of, or access to" it. In a Microsoft 365 tenant, the fastest route to unauthorised disclosure isn't an exotic breach — it's ordinary sharing: an "Anyone" link on an HR export, a guest grant that outlived a project, a folder share quietly reaching every file beneath it.

Why external sharing is squarely in scope

SharePoint and OneDrive hold personal data almost by definition: HR documents, customer lists, contracts, support exports, payroll spreadsheets. Every external share of such a file is a disclosure decision. Article 32 doesn't forbid sharing — it requires that access be controlled, appropriate, and demonstrable. The demonstrable part is where most organisations struggle: when a DPO or auditor asks "who outside the organisation can access personal data, and who reviewed that?", a shrug is not a compliant answer.

What good evidence looks like

An access review over your sharing state needs to show, credibly:

  • Inventory — every external exposure across SharePoint and OneDrive, including access that arrives indirectly through inheritance or group membership;
  • Review — that a person looked at each exposure and made a decision (kept, flagged for removal);
  • Recency — that this happens on a cadence, not once before an audit;
  • Change awareness — that new or expanded sharing gets looked at again.

The manual route

Everything above is possible with native tooling — per-site reports and PowerShell for the inventory, spreadsheets for the review trail, calendar discipline for the cadence. It works the way manual controls always work: brilliantly on the week someone owns it, not at all the quarter they're busy. And the raw output problem is real — a reviewer facing 50,000 repeated rows performs no meaningful review at all.

How TRACER365 helps

TRACER365 produces the access-control evidence Article 32 asks about, as a working practice rather than a heroic one-off:

  • Complete inventory, read-only: every external exposure across all SharePoint sites and OneDrives — anonymous links, guest grants, inherited guest access, pending invitations — from a locally installed app that changes nothing in the tenant.
  • A review a human can perform: cascade de-duplication collapsed roughly 91% of raw findings as duplicates in our testing. A review control is only meaningful if the reviewer can actually get through the list.
  • Cadence built in: scheduled scans and email reports to the person responsible — including a non-IT reviewer via the viewer role.
  • Point-in-time and change-over-time: scan history shows an auditor both the state and the trend; expanded sharing re-flags for review automatically.
  • No new transfer created: because the audit runs locally and its data never leaves your environment, the evidence-gathering itself doesn't add a processor or a data flow to your Article 30 record.
The honest boundary: compliance is an organisational property, not a product feature. TRACER365 provides evidence for the access-control side of Article 32 — it does not read sensitivity labels, does not classify data, and no tool makes you "GDPR compliant". The same access-review evidence also serves NIS2, DORA access-control obligations, and ISO 27001 access-rights reviews (A.5.18), where those apply to you.

Make the access review performable

Complete external-sharing evidence, de-duplicated, on a schedule, without your data leaving your environment. Free 30-day trial at launch.