GDPR Article 32 asks something deceptively simple of every organisation that processes personal data: ensure its confidentiality, and guard against "unauthorised disclosure of, or access to" it. In a Microsoft 365 tenant, the fastest route to unauthorised disclosure isn't an exotic breach — it's ordinary sharing: an "Anyone" link on an HR export, a guest grant that outlived a project, a folder share quietly reaching every file beneath it.
Why external sharing is squarely in scope
SharePoint and OneDrive hold personal data almost by definition: HR documents, customer lists, contracts, support exports, payroll spreadsheets. Every external share of such a file is a disclosure decision. Article 32 doesn't forbid sharing — it requires that access be controlled, appropriate, and demonstrable. The demonstrable part is where most organisations struggle: when a DPO or auditor asks "who outside the organisation can access personal data, and who reviewed that?", a shrug is not a compliant answer.
What good evidence looks like
An access review over your sharing state needs to show, credibly:
- Inventory — every external exposure across SharePoint and OneDrive, including access that arrives indirectly through inheritance or group membership;
- Review — that a person looked at each exposure and made a decision (kept, flagged for removal);
- Recency — that this happens on a cadence, not once before an audit;
- Change awareness — that new or expanded sharing gets looked at again.
The manual route
Everything above is possible with native tooling — per-site reports and PowerShell for the inventory, spreadsheets for the review trail, calendar discipline for the cadence. It works the way manual controls always work: brilliantly on the week someone owns it, not at all the quarter they're busy. And the raw output problem is real — a reviewer facing 50,000 repeated rows performs no meaningful review at all.
How TRACER365 helps
TRACER365 produces the access-control evidence Article 32 asks about, as a working practice rather than a heroic one-off:
- Complete inventory, read-only: every external exposure across all SharePoint sites and OneDrives — anonymous links, guest grants, inherited guest access, pending invitations — from a locally installed app that changes nothing in the tenant.
- A review a human can perform: cascade de-duplication collapsed roughly 91% of raw findings as duplicates in our testing. A review control is only meaningful if the reviewer can actually get through the list.
- Cadence built in: scheduled scans and email reports to the person responsible — including a non-IT reviewer via the viewer role.
- Point-in-time and change-over-time: scan history shows an auditor both the state and the trend; expanded sharing re-flags for review automatically.
- No new transfer created: because the audit runs locally and its data never leaves your environment, the evidence-gathering itself doesn't add a processor or a data flow to your Article 30 record.