For Firms Running Microsoft 365

Copilot is here.
Is your compliance ready?

Microsoft 365 Copilot changes how your team works. I handle the GDPR side: data protection impact assessment, sensitivity labels, permissions architecture. So Copilot runs compliant, not just functional.

CISSP M365 Endpoint Admin Security+ Data Stays in the EU

Copilot is powerful. The compliance gaps are real.

Copilot processes everything your employees can access. Without a DPIA, without sensitivity labels, without a permissions audit, the tool becomes a liability.

No DPIA

Your firm has Microsoft 365. Copilot licenses are ready or already active. But has anyone created a DPIA? GDPR Article 35 requires a data protection impact assessment for AI-driven processing. Microsoft is the processor. The obligation falls on the controller. That's you.

Open Permissions

Your SharePoint permissions were set up years ago. Team structures changed, but access rights didn't. Copilot shows your employees everything they have access to -- including files they shouldn't see.

DSK Criticism

Microsoft says Copilot is compliant. The DSK (Germany's data protection conference) says Microsoft's data processing agreement is insufficient. The responsibility falls on you as the controller, regardless of what Microsoft certifies.

Section 203 StGB

Tax advisors, lawyers, physicians: professionals under German secrecy obligations face criminal liability -- not just fines. If sensitive client data flows through Copilot without proper architecture, you risk a criminal violation. That's not a GDPR penalty. That's criminal law.

Three services for three situations

Copilot Compliance Audit

You have Copilot. I check whether it's compliant.

  • DPIA per GDPR Article 35 -- the document your regulator can request at any time.
  • SharePoint permissions, sensitivity labels, and DLP policies reviewed. Where oversharing happens, it becomes visible.
  • Section 203 StGB analysis for professional secrecy obligations (tax advisors, lawyers, physicians).
DPIA included 2 weeks

Compliant Copilot Deployment

You want Copilot. I make sure it's set up right from day one.

  • Sensitivity label taxonomy, auto-labeling rules, and DLP policies designed and configured before Copilot activation.
  • SharePoint permission structure that prevents oversharing from the start. Not patched after the fact.
  • Staff training and collaboration with your IT provider on implementation. I complement your team, not replace it.
Turnkey architecture 3-4 weeks

Managed Compliance Service

Compliance doesn't end after the audit. I stay on it.

  • Quarterly DPIA reviews. Microsoft changes subprocessors regularly -- most recently Anthropic in January 2026. Your DPIA needs to reflect that.
  • Sensitivity label monitoring and incident response. Labels had two documented vulnerabilities in the last 8 months.
  • Audit preparation for regulators. When the request comes, everything is documented.
Ongoing support Quarterly reviews

Copilot is one of the most capable AI tools on the market. The question isn't whether to use it. The question is whether your environment is ready for it.

1

Compliance Assessment

30 minutes, free. I ask about your M365 environment, Copilot status, data types, and existing DPO setup. After that, we both know which path fits.

2

Audit or Architecture

Depending on your starting point: either I audit an existing Copilot deployment (2 weeks) or I design the compliance architecture for a new one (3-4 weeks). You get a DPIA, sensitivity label design, permissions remediation plan, and staff training.

3

Ongoing Compliance

Copilot changes constantly. Microsoft adds subprocessors, updates features, labels fail. I monitor the changes and keep your firm compliant quarter by quarter.

Copilot & Compliance -- what you need to know

Do I need a DPIA for Copilot?
Yes. GDPR Article 35 requires a data protection impact assessment for high-risk processing. AI-driven document processing qualifies. Microsoft provides a template but explicitly states the controller must complete their own. Most firms haven't done it.
Is Microsoft 365 Copilot GDPR-compliant?
Partially. Microsoft holds compliance certifications. But the DSK (Germany's data protection conference) has flagged Microsoft's data processing agreement as insufficient. The firm remains responsible as the controller, regardless of what Microsoft certifies.
What about Section 203 StGB (professional secrecy)?
The criminal secrecy obligation applies to tax advisors, lawyers, and physicians in Germany. Copilot processes document content. If sensitive client data flows through Copilot without proper architecture (sensitivity labels, restricted access), the firm risks a violation. Architecture is required, not optional.
What are sensitivity labels and why do I need them?
Sensitivity labels are Microsoft's tool for classifying and protecting documents. They control what Copilot can access. Without properly configured labels, Copilot treats all content equally -- including confidential client files.
Can't my IT provider handle this?
Your IT provider handles infrastructure. Compliance architecture for AI requires both M365 administration and GDPR expertise. I bring both. And I work alongside your existing IT provider, not against them.
What does it cost?
Pricing depends on your starting point: whether Copilot is already deployed, being introduced, or needs ongoing management. In the free 30-minute call, I assess your situation and provide a specific quote. No long-term contracts, no hidden costs.
What happens if Microsoft closes these gaps?
Some gaps will close. Microsoft has announced in-country processing and more stable labels. Others are structural and permanent: the DPIA obligation is law, not a feature. SharePoint permissions are unique to every firm. Section 203 architecture is the firm's responsibility regardless of what Microsoft does.

Jose Lugo. CISSP certified.
12 years U.S. Army Intelligence.

  • CISSP certified -- one of the most recognized security certifications worldwide
  • Microsoft 365 Certified: Endpoint Administrator Associate
  • CompTIA Security+
  • 12 years protecting sensitive data in high-security environments
  • Specialized in Copilot compliance for regulated industries in Germany

I'm American, based in Germany, and I make AI deployments compliant. My background is in protecting sensitive data in environments where mistakes weren't an option. Twelve years in the U.S. Army taught me that. Today I bring that same discipline to Copilot compliance for firms handling client data: tax advisors, financial services, law firms.

I don't just write assessments. I configure your system myself. Sensitivity labels, DLP policies, SharePoint permissions: I log in and set it up. My work is open source and auditable on GitHub.

CISSP · Security+ · M365 Endpoint Administrator

Jose Lugo, CISSP-certified AI compliance consultant

DPIA created and documented

Sensitivity labels configured to industry standard

SharePoint permissions audited and remediated

Section 203 StGB architecture addressed

Ongoing monitoring via managed service

Is your M365 environment ready for Copilot?

7 questions, 2 minutes. Find out whether your firm can deploy Copilot within GDPR.

Take the Copilot Readiness Check

Ready to use Copilot with confidence?

Book a free 30-minute call. No sales pitch -- just an honest assessment of where your compliance stands.

Have a question first?

Contact me

LinkedIn · GitHub