Skip to content

Commit cde6eb4

Browse files
authored
Merge pull request #49003 from MicrosoftDocs/NEW-priva-subject-rights-requests
New priva subject rights requests
2 parents 71c4f1d + dc525d5 commit cde6eb4

17 files changed

+746
-0
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.priva-subject-rights-requests.configure-prerequisites-beyond-m365
3+
title: Configure prerequisites for requests for data beyond Microsoft 365 (preview)
4+
metadata:
5+
title: Configure prerequisites for requests for data beyond Microsoft 365 (preview)
6+
description: "Configure prerequisites for requests for data beyond Microsoft 365 (preview)"
7+
ms.date: 01/24/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 6
14+
content: |
15+
[!include[](includes/configure-prerequisites-beyond-m365.md)]
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.priva-subject-rights-requests.create-subject-rights-request-beyond-m365
3+
title: Create and manage subject rights requests for data beyond Microsoft 365 (preview)
4+
metadata:
5+
title: Create and manage subject rights requests for data beyond Microsoft 365 (preview)
6+
description: "Create and manage subject rights requests for data beyond Microsoft 365 (preview)."
7+
ms.date: 01/24/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 7
14+
content: |
15+
[!include[](includes/create-subject-rights-request-beyond-m365.md)]
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.priva-subject-rights-requests.create-subject-rights-request-m365
3+
title: Create and manage data requests for Microsoft 365
4+
metadata:
5+
title: Create and manage data requests for Microsoft 365
6+
description: "Create and manage data requests for Microsoft 365."
7+
ms.date: 01/24/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 10
14+
content: |
15+
[!include[](includes/create-subject-rights-request-m365.md)]
Lines changed: 78 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,78 @@
1+
Subject rights requests for data beyond Microsoft 365 allow organizations to manage privacy-related requests across multicloud and on-premises environments. To get started, you need to ensure the solution is properly configured with essential prerequisites.
2+
3+
## Confirm access to the Data Map
4+
5+
The Microsoft Purview Data Map is a foundational tool for managing subject rights requests. It enables the service to search for data classifications and helps data owners locate and act on personal data. Verify that your organization has access to the [Microsoft Purview Data Map](/purview/concept-elastic-data-map?azure-portal=true) to use these capabilities effectively.
6+
7+
## Register assets in the Unified Catalog
8+
9+
To fully utilize subject rights requests, register your organization's data assets in the [Microsoft Purview Unified Catalog](/purview/unified-catalog-search?azure-portal=true). Registered assets must include classifications and data owners, which ensures:
10+
11+
- Relevant classifications can be searched efficiently.
12+
- Tasks are automatically assigned to the appropriate data owners.
13+
14+
Registering assets improves the task creation process and ensures a streamlined workflow for fulfilling requests.
15+
16+
## Assign roles and permissions
17+
18+
Roles determine the tasks users can perform within the subject rights requests solution. Assign roles based on the responsibilities required for managing requests:
19+
20+
| Role | Access | Description |
21+
|-----|-----|-----|
22+
| **Data Reader** | Read-only access | Allows access to Data Map classifications and Unified Catalog details for scoped assets. |
23+
| **Privacy Curator** | Read-write access | Enables creation and management of subject rights requests. |
24+
| **Privacy Reader** | Read-only access | Provides view-only access to requests and tasks but doesn't allow modifications. |
25+
26+
For more information, see [Microsoft Purview governance roles and permissions](/purview/roles-permissions?azure-portal=true).
27+
28+
## Set up request forms and templates
29+
30+
To process subject rights requests, your organization must first create request forms and templates. These components define how requests are submitted and processed.
31+
32+
### Create request forms
33+
34+
Request forms are publicly available web forms that data subjects use to submit requests. These forms are customized with:
35+
36+
- **Contact details**: Include a privacy contact and organization privacy statement.
37+
- **Questionnaire**: Add fields such as name, email address, and additional identifiers to locate the data subject's information.
38+
- **Validation steps**: Implement identity validation, such as a one-time PIN (OTP) sent to the data subject's email.
39+
40+
Follow these steps to build a request form in the Microsoft Purview portal:
41+
42+
1. Navigate to **Subject Rights Requests** in the Microsoft Purview portal (preview).
43+
1. Under **Data beyond Microsoft 365**, select **Request forms and templates**.
44+
1. On the **Request forms** tab, select **New** and complete the required fields, such as form name, description, and privacy contact.
45+
1. Customize the layout and questionnaire, then preview and finalize the form.
46+
47+
### Create templates
48+
49+
Templates establish the parameters for fulfilling subject rights requests. Each template defines:
50+
51+
- **Fulfillment deadlines**
52+
- **Connected request forms**
53+
- **Workflow requirements**
54+
55+
Templates define the fulfillment workflow for requests submitted through connected forms, ensuring that the request process aligns with organizational requirements and deadlines.
56+
57+
Steps to create a template:
58+
59+
1. Navigate to **Request forms and templates** in the Microsoft Purview portal.
60+
1. On the **Templates** tab, select **New** and provide a name, description, and contacts.
61+
1. Define the request workflow, including identity validation and storage locations for export packages.
62+
1. Save and publish the template.
63+
64+
Once completed, templates and forms enable seamless request submission and processing.
65+
66+
## Ensure a strong data governance foundation
67+
68+
For subject rights requests to be effective, your organization needs a well-structured data governance solution. Strong governance ensures data is classified, understood, and actionable, which directly impacts your ability to manage requests efficiently. Key steps include:
69+
70+
- **Establishing glossary terms**: Use business-friendly terms to make data more discoverable and understandable for stakeholders.
71+
- **Defining objectives and outcomes (OKRs)**: Align data usage with organizational goals to enhance compliance and decision-making.
72+
- **Improving data quality**: Address issues like accuracy, consistency, and completeness to build trust in your data.
73+
74+
Implementing these practices helps your team maximize the value of subject rights requests and ensures a sustainable approach to managing data privacy.
75+
76+
## Legal disclaimer
77+
78+
[Microsoft Priva legal disclaimer](/privacy/priva/priva-disclaimer?azure-portal=true)
Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
Managing subject rights requests for data beyond Microsoft 365 enables organizations to address privacy-related requests for personal data stored across diverse platforms, including multicloud environments and on-premises systems. This feature streamlines compliance efforts by automating request workflows and providing visibility into request progress.
2+
3+
## Types of requests
4+
5+
Subject rights requests for data beyond Microsoft 365 support two request types:
6+
7+
- **Export**: Provides an export of a data subject's personal data located in your organization's data landscape.
8+
- **Delete**: Removes all personal data belonging to a data subject from your organization's systems.
9+
10+
These requests can be initiated in two ways:
11+
12+
1. **By the data subject**: An external individual, such as a customer or former employee, submits a request via an online form created by your organization.
13+
2. **Manually by your organization**: A user in your organization creates a request on behalf of the data subject.
14+
15+
## Create a request manually
16+
17+
When a data subject contacts your organization to request an export or deletion of their personal data, you can create a request manually. This process involves selecting a template to define how the request will be fulfilled and entering basic details about the data subject.
18+
19+
### Steps to create a request
20+
21+
1. In the Microsoft Priva portal (preview), navigate to the **Request management** page.
22+
1. Select **New request** to open the request builder.
23+
1. On the **Basic details** page, choose the template that aligns with the request type (export or delete), then select **Next**.
24+
1. On the **Request form** page, provide required details such as the data subject's name and email address.
25+
1. Review the details and select **Submit**. The request is now active and moves into the first stage: **Validating identity**.
26+
27+
## Stages of request progress
28+
29+
Each request progresses through the following stages, shown on the request's details page:
30+
31+
1. **Not started**: The system begins validating the data subject's identity.
32+
1. **Identity validation**: If the request uses a manual validation template, a task is created for the data engineer to verify the identity. Otherwise, validation is assumed to be complete.
33+
1. **Analyzing data**: The system searches the Data Map for matches to classifications or sensitive information types specified in the template.
34+
1. **Working on tasks**: Tasks are assigned to asset owners, who locate, extract, or delete data as required.
35+
1. **Approving tasks**: Tasks are reviewed and approved by the request owner or designated approver.
36+
1. **Ready to respond**: All tasks are complete, and the request is ready for the organization's response to the data subject.
37+
38+
## Tasks and responsibilities
39+
40+
When assets containing relevant data are identified, tasks are created and assigned to asset owners. Asset owners are notified via email and must complete the following steps:
41+
42+
1. On the **Task management** page, select the task and choose **Claim task**. The task status updates to **In progress**.
43+
1. On the task's flyout pane, go to the **Scope** tab to view assets and data subject values in scope.
44+
- **Export requests**: Locate the data, extract it to a CSV file, and upload the file to the task.
45+
- **Delete requests**: Locate the data and delete it from the identified assets.
46+
1. Once the required actions are finished, select **Mark as complete**. The task status updates to **Awaiting approval**.
47+
48+
If no relevant data is found, mark the task as **Not applicable**.
49+
50+
## Approving tasks
51+
52+
The request owner or designated approver reviews completed tasks to ensure accuracy and compliance:
53+
54+
1. On the **Tasks** tab of the request's details page, review the uploaded data or task completion details.
55+
1. Approve tasks that meet requirements by selecting **Approve**. Tasks requiring revisions can be marked as **Rejected**, returning them to the task owner for updates.
56+
57+
## Respond to the data subject
58+
59+
After all tasks are approved, the request progresses to the **Ready to respond** stage. The organization must respond to the data subject outside of Priva:
60+
61+
- **Export requests**: Download the export package from the **Packages** tab on the request's details page. Share the .zip file with the data subject.
62+
- **Delete requests**: Notify the data subject that their personal data has been deleted.
63+
64+
## Complete the request
65+
66+
Once the data subject has been notified, mark the request as complete:
67+
68+
1. On the request's details page, select **Mark as complete**.
69+
1. The request status updates to **Complete**. Requests remain in the system for 180 days for record-keeping.
70+
71+
## Legal disclaimer
72+
73+
[Microsoft Priva legal disclaimer](/privacy/priva/priva-disclaimer?azure-portal=true)
Lines changed: 102 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,102 @@
1+
Creating a subject rights request is the first step in managing privacy requests effectively. This process allows organizations to locate and retrieve personal data efficiently, ensuring compliance with privacy regulations while streamlining workflows for data discovery and review.
2+
3+
To create a Subject Rights Request, users need to belong to the **Subject Rights Request Administrators** role group. Requests can be created in two ways:
4+
5+
- **Using a template**: A quick, preconfigured option with tailored default settings.
6+
- **Custom setup**: A guided process that allows full customization of request settings.
7+
8+
## Types of requests
9+
10+
Priva Subject Rights Requests support four request types:
11+
12+
1. **Access**: Summarizes the data subject's personal information held by your organization in Microsoft 365.
13+
1. **Export**: Provides a summary and an exported file of the content marked for inclusion during the review process.
14+
1. **Tagged list for follow-up**: Generates a summary of files tagged during data review. Priva provides predefined tags, and you can create custom tags in settings.
15+
1. **Delete**: Removes content items containing a data subject's personal information, pending approval and compliance with retention policies.
16+
17+
## Create a request using a template
18+
19+
Templates simplify the process with default settings for three request types: **Data access**, **Data export**, and **Data tagged for further action**. You can review and modify these settings during the request creation process.
20+
21+
### Steps to create a request
22+
23+
1. Sign in to the [Microsoft Priva portal (preview)](https://purview.microsoft.com/priva) and select **Subject Rights Requests**.
24+
25+
1. In the navigation pane under **Data within Microsoft 365**, select **Microsoft 365 requests**, then select **New request**.
26+
27+
1. Choose the request type such as Data access, then select **Get started** to open a flyout pane.
28+
29+
1. At **Relationship to organization**, select the data subject's relationship with your organization, such as **Current employee**, **Former employee**, or **Other**. This choice adjusts default search settings:
30+
- **Current employee**: Excludes items authored by or communicated to the employee.
31+
- **Former employee**: Prioritizes the employee's mailbox and authored items.
32+
- **Other**: Focuses on the most recent versions of SharePoint items.
33+
34+
1. To review or modify settings, select **View settings** and then **Edit settings** to adjust advanced options.
35+
36+
1. Enter the data subject's details, including required fields, like name and email address. Extra fields like region or regulation type are optional.
37+
38+
1. Select **Create** to finalize the request. The request appears at the top of the request list.
39+
40+
By default, your request is named with the data subject's name and type of request. To edit the request name, select the request from the list to open its details page and select the **Edit** command at the top of the screen. You arrive at the request creation wizard. Select **Next** until you advance to the **Request name** page, where you can edit the name and add a description.
41+
42+
## Create a custom request
43+
44+
Custom requests allow users to tailor every aspect of the request process. You start by choosing a template, and then walk through each setting to customize your policy.
45+
46+
1. Sign in to the Microsoft Priva portal and select **Subject Rights Requests**.
47+
48+
1. Under **Microsoft 365 requests**, select **New request** and choose the **Custom** option.
49+
50+
1. Complete the following steps in the request creation wizard:
51+
- **Data subject information**: Enter first and family name, email address (required), and additional identifiers if available. Specify the data subject's relationship to your organization.
52+
- **Locations**: Enable search locations such as Exchange (mailboxes and Teams chats) or SharePoint (including OneDrive and Teams channels).
53+
- **Define search settings**: Adjust default settings such as including content authored by the data subject or retrieving all versions of SharePoint items. You can also request a data estimate before retrieval begins.
54+
- **Request type**: Select Access, Export, or Tagged list for follow-up. Specify privacy regulations and adjust deadlines as needed.
55+
- **Request details**: Review and edit the request's name and description.
56+
57+
1. On the final page, review all entries and select **Create request**. The request is added to your Subject Rights Requests list.
58+
59+
## Customize search settings
60+
61+
You can use advanced search settings to tailor your search and refine the data retrieved for subject rights requests. These options provide flexibility to meet specific organizational needs:
62+
63+
- **Refine your search**: Specify extra properties to narrow the scope, such as item name, sender/recipient, or personal data types. This option improves the accuracy of results by allowing you to focus on relevant data.
64+
- **Include content authored by the data subject**: Retrieve files, documents, or other content created by the data subject. Examples include files uploaded to SharePoint. Enabling this might increase the volume of retrieved data.
65+
- **Include all versions of items**: Expand SharePoint search results to include all previous versions of items in addition to the most recent one. This option is useful when historical versions are required for review.
66+
- **Get an estimate first**: Preview the expected amount of data before starting retrieval. Once the estimate appears on the request details page, you can view sample results to ensure they meet expectations. Select **Retrieve data** to proceed with full content retrieval.
67+
68+
## Manage delete requests
69+
70+
Delete requests include unique steps beyond those required for other request types. They enable the removal of personal data while maintaining compliance with retention and regulatory policies.
71+
72+
### Key steps for delete requests
73+
74+
- **Assign approvers**: When creating a delete request, assign at least one approver to review and approve items marked for deletion. Approvers can recommend changes if necessary.
75+
- **Data review**: Collaborators tag items for deletion by marking them as **Include**. Approvers verify these items and either approve or request adjustments.
76+
- **Delete workflow**: Approved requests trigger the **PrivaDelete** retention label, which is applied to items eligible for deletion. The deletion process evaluates:
77+
78+
- Conflicts with existing retention labels.
79+
- Unsupported storage locations.
80+
- Manually moved or deleted items.
81+
82+
### Interaction with Microsoft Purview Data Lifecycle Management
83+
84+
Microsoft Purview Data Lifecycle Management's features, such as retention labels and policies, are respected during the delete workflow. Key points include:
85+
86+
- **Conflict resolution**: The **PrivaDelete** retention label won't override existing retention labels applied for regulatory or organizational purposes. If an item is already subject to a retention policy, the delete request won't proceed for that item.
87+
- **Visibility into conflicts**: Items with conflicting retention labels are flagged as priority items for review. Administrators can access the Action execution log to understand why specific items couldn't be deleted.
88+
- **Principles of retention**: The workflow adheres to Purview's retention principles, ensuring that compliance obligations aren't inadvertently compromised.
89+
90+
Tip: Collaborate with your organization's records management or compliance teams to resolve retention conflicts and communicate with data subjects about items that can't be deleted.
91+
92+
### Monitor progress and resolve conflicts
93+
94+
The **Action summary** card on the request details page tracks the deletion progress, including unresolved conflicts. Use the Action execution log to view detailed reports and address any flagged items.
95+
96+
### Timeline for deletion
97+
98+
Once approved, the delete workflow begins automatically. Eligible items are deleted within 30 days, but conflicts might delay specific deletions. Regularly monitor reports to ensure items are processed as expected.
99+
100+
## Legal disclaimer
101+
102+
[Microsoft Priva legal disclaimer](/privacy/priva/priva-disclaimer?azure-portal=true)

0 commit comments

Comments
 (0)