Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Microsoft SharePoint is a web based collaboration and content management platform from Microsoft, available as SharePoint Online inside Microsoft 365 and as the self hosted SharePoint Server. It powers intranets, document libraries and public sites, relying on first party authentication cookies to manage sign in and sessions. Because it routinely processes employee and customer data, its cookie behaviour and EU data residency are firmly within GDPR scope.
Microsoft SharePoint is a web based collaboration and content management platform from Microsoft, available both as the cloud service SharePoint Online inside Microsoft 365 and as the self hosted SharePoint Server. Organisations use it to build intranets, document libraries, team sites and public facing websites. When SharePoint pages are served to end users, the platform relies on authentication and session cookies to manage sign in state, security and the rendering of personalised content. Because SharePoint is frequently the backbone of corporate portals that process employee and customer data, its cookie behaviour and data residency are squarely in scope for the GDPR.
SharePoint Online authenticates users through Azure Active Directory and sets several first party cookies on the sharepoint.com domain. The main ones are rtFa, used for cross site federated authentication across Microsoft 365, and FedAuth, the federated authentication session cookie. The platform also writes operational cookies such as WSS_FullScreenMode to remember interface state. Microsoft 365 properties may additionally drop MUID and the analytics cookie MSFPC tied to Microsoft telemetry. The authentication cookies are strictly necessary to keep the user signed in, while telemetry cookies are not.
Under article 5(3) of the ePrivacy Directive, storing cookies that are strictly necessary to deliver a service explicitly requested by the user is exempt from prior consent. The SharePoint sign in and session cookies fall inside that exemption because no authenticated session can exist without them. The GDPR still applies to the personal data processed: account identifiers, IP addresses, document metadata and audit logs. The controller, normally the organisation running the tenant, must define a lawful basis, usually contract for employees and legitimate interest or contract for external collaborators, and document Microsoft as a processor.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For a private intranet behind a login, consent for the authentication cookies is not required because they are strictly necessary and the user actively requests the authenticated session. If SharePoint is used to power a public website, or if Microsoft 365 analytics, Clarity or third party embeds are added, then any non essential cookie used for analytics or personalisation requires prior informed consent collected through a consent banner before the script runs. The strictly necessary set can always load first.
Microsoft Corporation is established in the United States and is certified under the EU US Data Privacy Framework since 2023. SharePoint Online data is hosted in the Microsoft 365 data centre region chosen for the tenant, and customers in the European Union can rely on the Microsoft EU Data Boundary to keep core customer data and processing within Europe. Some support, telemetry and troubleshooting operations may still involve Microsoft staff outside the EU under the Standard Contractual Clauses included in the Microsoft Products and Services Data Protection Addendum.
Record Microsoft as a processor in your article 30 register and sign the Microsoft Data Protection Addendum. Configure the tenant region and enable the EU Data Boundary if European residency is required. List the SharePoint authentication cookies in your cookie policy as strictly necessary and explain their purpose and duration. If you expose SharePoint content publicly, place any analytics or embedded media behind a consent banner. Review audit log retention, restrict external sharing, and apply Microsoft Purview retention and sensitivity labels to govern personal data stored in document libraries.
Websites using Microsoft SharePoint must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is not automatic for a standard intranet but becomes necessary when SharePoint stores special category data, supports large scale employee monitoring, holds extensive audit logs or powers a public site with tracking. Document data flows to Microsoft and the EU Data Boundary configuration.
Sample consent text
This site uses Microsoft SharePoint to host content and manage your session. Strictly necessary cookies such as rtFa and FedAuth keep you signed in and secure your session; they load without consent because the service cannot work without them. Any analytics or embedded media from Microsoft 365 loads only after you accept optional cookies. Your data is processed by Microsoft Corporation under the EU US Data Privacy Framework and the Standard Contractual Clauses, with EU Data Boundary residency where configured.
Third-party domains contacted
sharepoint.commicrosoftonline.comoffice.commicrosoft.comoffice365.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| rtFa | strictly necessary | Persistent until sign out | Cross site federated authentication across Microsoft 365 and SharePoint Online. |
| FedAuth | strictly necessary | Session to persistent | Federated authentication session cookie that keeps the user signed in to a SharePoint site. |
| WSS_FullScreenMode | strictly necessary | Session | Remembers whether the SharePoint interface is displayed in full screen mode. |
| MSFPC | analytics | 1 year | Microsoft first party client identifier used for telemetry and usage analytics across Microsoft properties. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
SharePoint Online sets first party authentication cookies on the sharepoint.com domain, mainly rtFa for cross site federated sign in and FedAuth for the authenticated session, plus operational cookies such as WSS_FullScreenMode. Microsoft 365 may add the telemetry cookie MSFPC. The authentication cookies are strictly necessary; the telemetry cookie is not and requires consent.
For a private intranet behind a login you do not need consent for the SharePoint authentication cookies because they are strictly necessary to deliver the session the user requested. You do need prior consent for any optional analytics, personalisation or embedded media cookies added to a public SharePoint site, and these must load only after the user accepts them.
The strictly necessary cookies rely on the ePrivacy article 5(3) exemption. The personal data processed in SharePoint, such as account identifiers and audit logs, is usually justified by performance of a contract under GDPR article 6(1)(b) for service users and by the legitimate interest of the organisation under article 6(1)(f) for security. Optional analytics need consent under article 6(1)(a).
Microsoft Corporation is based in the United States and is certified under the EU US Data Privacy Framework. With the EU Data Boundary enabled, core SharePoint Online customer data stays within Europe, but some telemetry, support and troubleshooting can reach Microsoft staff in the United States under the Standard Contractual Clauses in the Microsoft Data Protection Addendum.
A DPIA is not automatically required for a standard intranet, but it becomes necessary when SharePoint stores special category data, supports large scale employee monitoring, hosts extensive audit logging or powers a public site with tracking. The assessment should document data flows to Microsoft and the EU Data Boundary configuration.
Sign the Microsoft Data Protection Addendum, record Microsoft as a processor in your article 30 register, and set the tenant region or EU Data Boundary for European residency. List the authentication cookies in your cookie policy as strictly necessary, gate any analytics behind a consent banner, restrict external sharing, and apply Microsoft Purview retention and sensitivity labels to personal data.
Collaboration and content alternatives include Nextcloud, which can be self hosted in the EU, Atlassian Confluence, Google Workspace sites and open source platforms such as TYPO3 or Plone. European or self hosted options can simplify data residency, but each still requires its own cookie and processor analysis.
Add the SharePoint authentication cookies rtFa, FedAuth and WSS_FullScreenMode to the strictly necessary section of your cookie policy with their purpose and duration, and list any Microsoft 365 telemetry cookie such as MSFPC under analytics requiring consent. State that Microsoft acts as a processor, mention the EU US Data Privacy Framework, and re scan the site after each Microsoft 365 update.