FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Microsoft SharePoint

Microsoft SharePoint

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Microsoft SharePoint do?

Microsoft SharePoint is a web based collaboration and content management platform from Microsoft, available as SharePoint Online inside Microsoft 365 and as the self hosted SharePoint Server. It powers intranets, document libraries and public sites, relying on first party authentication cookies to manage sign in and sessions. Because it routinely processes employee and customer data, its cookie behaviour and EU data residency are firmly within GDPR scope.

What Microsoft SharePoint is

Microsoft SharePoint is a web based collaboration and content management platform from Microsoft, available both as the cloud service SharePoint Online inside Microsoft 365 and as the self hosted SharePoint Server. Organisations use it to build intranets, document libraries, team sites and public facing websites. When SharePoint pages are served to end users, the platform relies on authentication and session cookies to manage sign in state, security and the rendering of personalised content. Because SharePoint is frequently the backbone of corporate portals that process employee and customer data, its cookie behaviour and data residency are squarely in scope for the GDPR.

Cookies and storage set by SharePoint

SharePoint Online authenticates users through Azure Active Directory and sets several first party cookies on the sharepoint.com domain. The main ones are rtFa, used for cross site federated authentication across Microsoft 365, and FedAuth, the federated authentication session cookie. The platform also writes operational cookies such as WSS_FullScreenMode to remember interface state. Microsoft 365 properties may additionally drop MUID and the analytics cookie MSFPC tied to Microsoft telemetry. The authentication cookies are strictly necessary to keep the user signed in, while telemetry cookies are not.

GDPR and ePrivacy implications

Under article 5(3) of the ePrivacy Directive, storing cookies that are strictly necessary to deliver a service explicitly requested by the user is exempt from prior consent. The SharePoint sign in and session cookies fall inside that exemption because no authenticated session can exist without them. The GDPR still applies to the personal data processed: account identifiers, IP addresses, document metadata and audit logs. The controller, normally the organisation running the tenant, must define a lawful basis, usually contract for employees and legitimate interest or contract for external collaborators, and document Microsoft as a processor.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

For a private intranet behind a login, consent for the authentication cookies is not required because they are strictly necessary and the user actively requests the authenticated session. If SharePoint is used to power a public website, or if Microsoft 365 analytics, Clarity or third party embeds are added, then any non essential cookie used for analytics or personalisation requires prior informed consent collected through a consent banner before the script runs. The strictly necessary set can always load first.

International data transfers

Microsoft Corporation is established in the United States and is certified under the EU US Data Privacy Framework since 2023. SharePoint Online data is hosted in the Microsoft 365 data centre region chosen for the tenant, and customers in the European Union can rely on the Microsoft EU Data Boundary to keep core customer data and processing within Europe. Some support, telemetry and troubleshooting operations may still involve Microsoft staff outside the EU under the Standard Contractual Clauses included in the Microsoft Products and Services Data Protection Addendum.

Practical compliance steps

Record Microsoft as a processor in your article 30 register and sign the Microsoft Data Protection Addendum. Configure the tenant region and enable the EU Data Boundary if European residency is required. List the SharePoint authentication cookies in your cookie policy as strictly necessary and explain their purpose and duration. If you expose SharePoint content publicly, place any analytics or embedded media behind a consent banner. Review audit log retention, restrict external sharing, and apply Microsoft Purview retention and sensitivity labels to govern personal data stored in document libraries.

GDPR consent category

Other

Websites using Microsoft SharePoint must obtain user consent under GDPR regulations.

Legal basisStrictly necessary authentication and session cookies are exempt from consent under article 5(3) ePrivacy. The underlying processing relies on performance of a contract (GDPR art. 6(1)(b)) for users of the service and on the legitimate interest of the organisation (art. 6(1)(f)) for security and audit logging. Optional analytics and personalisation cookies require consent under art. 6(1)(a).
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, EU Standard Contractual Clauses, TTDSG (Germany), LOPDGDD (Spain), LIL (France)

DPIA considerations

A DPIA is not automatic for a standard intranet but becomes necessary when SharePoint stores special category data, supports large scale employee monitoring, holds extensive audit logs or powers a public site with tracking. Document data flows to Microsoft and the EU Data Boundary configuration.

Sample consent text

This site uses Microsoft SharePoint to host content and manage your session. Strictly necessary cookies such as rtFa and FedAuth keep you signed in and secure your session; they load without consent because the service cannot work without them. Any analytics or embedded media from Microsoft 365 loads only after you accept optional cookies. Your data is processed by Microsoft Corporation under the EU US Data Privacy Framework and the Standard Contractual Clauses, with EU Data Boundary residency where configured.

Technical details

Tracking methodfirst party authentication and session cookies
Server locationMicrosoft 365 cloud, hosted in the data centre region selected for the tenant. Customers in the European Union can enable the Microsoft EU Data Boundary so that core SharePoint Online customer data is stored and processed within the EU and EFTA. SharePoint Server is hosted wherever the organisation deploys it.
Data transferred outside the EUMicrosoft Corporation is based in Redmond, United States, and is certified under the EU US Data Privacy Framework. Primary SharePoint Online data stays in the chosen region and, with the EU Data Boundary, within Europe, but telemetry, support and troubleshooting can involve Microsoft personnel in the United States under the Standard Contractual Clauses in the Microsoft Data Protection Addendum.

Third-party domains contacted

sharepoint.commicrosoftonline.comoffice.commicrosoft.comoffice365.com

Cookies placed

NameTypeDurationPurpose
rtFastrictly necessaryPersistent until sign outCross site federated authentication across Microsoft 365 and SharePoint Online.
FedAuthstrictly necessarySession to persistentFederated authentication session cookie that keeps the user signed in to a SharePoint site.
WSS_FullScreenModestrictly necessarySessionRemembers whether the SharePoint interface is displayed in full screen mode.
MSFPCanalytics1 yearMicrosoft first party client identifier used for telemetry and usage analytics across Microsoft properties.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Microsoft SharePoint set?

SharePoint Online sets first party authentication cookies on the sharepoint.com domain, mainly rtFa for cross site federated sign in and FedAuth for the authenticated session, plus operational cookies such as WSS_FullScreenMode. Microsoft 365 may add the telemetry cookie MSFPC. The authentication cookies are strictly necessary; the telemetry cookie is not and requires consent.

Do I need consent to use Microsoft SharePoint?

For a private intranet behind a login you do not need consent for the SharePoint authentication cookies because they are strictly necessary to deliver the session the user requested. You do need prior consent for any optional analytics, personalisation or embedded media cookies added to a public SharePoint site, and these must load only after the user accepts them.

What is the legal basis for SharePoint processing?

The strictly necessary cookies rely on the ePrivacy article 5(3) exemption. The personal data processed in SharePoint, such as account identifiers and audit logs, is usually justified by performance of a contract under GDPR article 6(1)(b) for service users and by the legitimate interest of the organisation under article 6(1)(f) for security. Optional analytics need consent under article 6(1)(a).

Does SharePoint transfer data to the United States?

Microsoft Corporation is based in the United States and is certified under the EU US Data Privacy Framework. With the EU Data Boundary enabled, core SharePoint Online customer data stays within Europe, but some telemetry, support and troubleshooting can reach Microsoft staff in the United States under the Standard Contractual Clauses in the Microsoft Data Protection Addendum.

Is a DPIA required for Microsoft SharePoint?

A DPIA is not automatically required for a standard intranet, but it becomes necessary when SharePoint stores special category data, supports large scale employee monitoring, hosts extensive audit logging or powers a public site with tracking. The assessment should document data flows to Microsoft and the EU Data Boundary configuration.

How do I make a SharePoint site GDPR compliant?

Sign the Microsoft Data Protection Addendum, record Microsoft as a processor in your article 30 register, and set the tenant region or EU Data Boundary for European residency. List the authentication cookies in your cookie policy as strictly necessary, gate any analytics behind a consent banner, restrict external sharing, and apply Microsoft Purview retention and sensitivity labels to personal data.

What are the alternatives to Microsoft SharePoint?

Collaboration and content alternatives include Nextcloud, which can be self hosted in the EU, Atlassian Confluence, Google Workspace sites and open source platforms such as TYPO3 or Plone. European or self hosted options can simplify data residency, but each still requires its own cookie and processor analysis.

How do I update my cookie policy for SharePoint?

Add the SharePoint authentication cookies rtFa, FedAuth and WSS_FullScreenMode to the strictly necessary section of your cookie policy with their purpose and duration, and list any Microsoft 365 telemetry cookie such as MSFPC under analytics requiring consent. State that Microsoft acts as a processor, mention the EU US Data Privacy Framework, and re scan the site after each Microsoft 365 update.