Microsoft 365 & Google Workspace Compliance: Canadian Privacy Configuration Guide
PIPEDA compliance guide for Microsoft 365 and Google Workspace. Canadian data residency, privacy settings, and configuration for SMBs.
Microsoft 365 and Google Workspace power most Canadian businesses. They're convenient, cost-effective, and feature-rich. They're also cloud services processing vast amounts of personal information that require careful privacy configuration.
Out-of-the-box settings often fall short of PIPEDA and Law 25 requirements. This guide shows Canadian businesses how to properly configure these platforms for privacy compliance.
Why Office Suite Privacy Matters
The Data These Platforms Hold
Email Communication:
- Customer conversations
- Employee personal information
- Confidential business discussions
- Attachments with sensitive data
Document Storage:
- Contracts with personal information
- Financial records
- HR documents
- Client files
Collaboration Data:
- Meeting recordings (video/audio)
- Chat conversations
- Calendar appointments
- Contact directories
Usage Analytics:
- Who accessed what documents
- Communication patterns
- Location data
- Device information
Privacy Risks
Default Configurations:
- Data processed in US data centers
- Diagnostic data collected
- Third-party app access enabled
- Insufficient audit logging
Common Mistakes:
- Shared links without expiration
- External sharing enabled broadly
- No data loss prevention
- Weak authentication
- Unencrypted email
Canadian Data Residency Options
Microsoft 365 Data Residency
Canada Geo (Toronto & Quebec City):
- Available for most business subscriptions
- Core customer data stored in Canadian data centers
- Some services still process in US
What's Stored in Canada:
- Exchange Online mailbox content
- SharePoint Online site content
- OneDrive for Business files
- Teams chat and channel messages (with advanced setup)
What May Still Process in US:
- Diagnostic/support data
- Some metadata
- Temporary processing for certain features
- Backup/disaster recovery (can be configured)
How to Configure:
- Sign up with Canadian billing address
- Select Canada as data residency location during setup
- Verify data location in Admin Center > Settings > Org Settings > Organization profile > Data location
- Consider Advanced Data Residency add-on for extended coverage
Advanced Data Residency:
- Additional fee per user
- Covers more workloads
- Includes Teams content
- Adds Defender and other services
- More data stays in Canada
Google Workspace Data Residency
Data Regions:
- Available on Business Plus, Enterprise plans
- Configure which regions can store data
- Canada option available
What Can Be Regionalized:
- Gmail messages and attachments
- Drive files
- Calendar events
- Some Google Chat/Meet content
What May Still Process Globally:
- Search indexes
- Some metadata
- Temporary processing
- Certain services
How to Configure:
- Admin Console > Account > Data regions
- Select Canada as primary region
- Configure covered services
- Save and apply
Limitations:
- Only available on higher-tier plans
- Some services can't be regionalized
- Legacy free accounts don't support
Essential Privacy Configuration
Microsoft 365 Critical Settings
1. Tenant-Wide Privacy Settings
Admin Center > Settings > Org Settings > Privacy:
- ✅ Disable "Connected experiences that analyze content"
- ✅ Disable "Connected experiences that download online content"
- ✅ Set diagnostic data to "Required only"
- ✅ Disable "Optional connected experiences"
2. Audit Logging
Security & Compliance Center > Audit:
- ✅ Enable unified audit log
- ✅ Retain for 365 days minimum (or maximum available)
- ✅ Enable mailbox auditing for all users
- ✅ Configure alert policies
3. Data Loss Prevention (DLP)
Security & Compliance Center > Data loss prevention:
- ✅ Create policies for sensitive data (SSN, credit cards, personal info)
- ✅ Apply to Exchange, SharePoint, OneDrive, Teams
- ✅ Configure user notifications
- ✅ Set up incident reports
4. External Sharing Controls
SharePoint Admin Center > Policies > Sharing:
- ✅ Restrict to "Only people in your organization" (or authenticated external users if needed)
- ✅ Require sign-in for shared links
- ✅ Set link expiration (30-90 days)
- ✅ Disable anonymous links (if not required)
OneDrive Admin Center > Sharing:
- Apply same restrictions as SharePoint
5. Email Encryption
Exchange Admin Center > Mail flow > Rules:
- ✅ Create rules for sensitive subject lines or content
- ✅ Enable Office 365 Message Encryption
- ✅ Consider S/MIME for end-to-end encryption
- ✅ Configure external email warnings
6. Multi-Factor Authentication (MFA)
Azure AD > Security > MFA:
- ✅ Require MFA for all users (no exceptions)
- ✅ Configure trusted IPs if needed
- ✅ Use authenticator app (not SMS when possible)
- ✅ Set up Conditional Access policies
7. Mobile Device Management
Endpoint Manager > Devices:
- ✅ Require device encryption
- ✅ Enforce PIN/password
- ✅ Enable remote wipe
- ✅ Restrict data sharing between apps
- ✅ Configure compliance policies
Google Workspace Critical Settings
1. Data Protection Settings
Admin Console > Security > Data protection:
- ✅ Enable Drive for Desktop encryption
- ✅ Configure data loss prevention rules
- ✅ Set external sharing restrictions
- ✅ Enable Drive file audit logging
2. Access and Data Control
Admin Console > Security > Access and data control:
- ✅ Disable "Allow users to install apps"
- ✅ Restrict third-party app access
- ✅ Enable context-aware access
- ✅ Configure session length
3. Audit and Investigation
Admin Console > Security > Investigation tool:
- ✅ Enable audit logging (maximum retention)
- ✅ Configure log events for all services
- ✅ Set up security alerts
- ✅ Enable security center dashboards
4. Email Security
Admin Console > Apps > Google Workspace > Gmail:
- ✅ Enable S/MIME encryption (Enterprise plans)
- ✅ Configure content compliance rules
- ✅ Enable attachment protection
- ✅ Set up email allowlists/blocklists
- ✅ Enable spoofing warnings
5. Drive Sharing Controls
Admin Console > Apps > Google Workspace > Drive:
- ✅ Restrict external sharing (if appropriate)
- ✅ Disable public links (if not needed)
- ✅ Set link sharing defaults to "Restricted"
- ✅ Enable warning for external shares
- ✅ Configure expiration for shared links
6. Two-Factor Authentication
Admin Console > Security > 2-Step Verification:
- ✅ Enable enforced 2FA for all users
- ✅ Allow security keys
- ✅ Consider disabling SMS (use authenticator apps)
- ✅ Set grace period for enrollment (7-14 days max)
7. Mobile Management
Admin Console > Devices > Mobile devices:
- ✅ Require device encryption
- ✅ Enforce screen lock
- ✅ Enable remote wipe
- ✅ Configure password requirements
- ✅ Set up device approval
Third-Party App Management
Microsoft 365 App Governance
Marketplace Apps:
SharePoint Admin Center > More features > Apps:
- ✅ Review and restrict app permissions
- ✅ Disable app catalog if not needed
- ✅ Require admin approval for new apps
- ✅ Audit installed apps quarterly
OAuth App Security:
- Review connected apps per user
- Revoke unused or suspicious apps
- Limit app permissions
- Monitor for over-permissioned apps
Google Workspace App Controls
Marketplace Management:
Admin Console > Apps > Marketplace apps:
- ✅ Restrict to allowlisted apps only (or individual review)
- ✅ Review app permissions before approval
- ✅ Monitor installed apps
- ✅ Remove unused apps
Third-Party Access:
- Limit API access
- Review OAuth tokens
- Monitor unusual access patterns
- Revoke suspicious applications
Email Encryption Deep Dive
Microsoft 365 Email Encryption
Office 365 Message Encryption (OME):
- Encrypts email content
- Recipients can read without special software
- Requires Azure Information Protection
S/MIME (Secure/Multipurpose Internet Mail Extensions):
- End-to-end encryption
- Digital signatures for authentication
- Requires certificate management
- Recipient must also have S/MIME
When to Use Which:
- OME: Sending to external parties without S/MIME
- S/MIME: Organization-to-organization with mutual S/MIME support
- Both: Maximum security for highly sensitive communications
Google Workspace Encryption
Hosted S/MIME:
- Available on Enterprise plans
- Managed certificates
- Automatic encryption when available
- Falls back to TLS if recipient doesn't support
Client-Side Encryption (CSE):
- Enterprise Plus and Education Plus
- Encryption before data leaves client
- Google cannot decrypt
- Maximum privacy
- More complex setup
TLS Encryption:
- Default for all Gmail
- Encrypts in transit
- Not end-to-end (Google can access)
Data Loss Prevention (DLP)
Microsoft 365 DLP Policies
Common Canadian-Specific DLP Rules:
Protect Social Insurance Numbers:
- Detect Canadian SIN patterns
- Block external sharing
- Alert security team
- Encrypt automatically
Credit Card Protection:
- Detect card number patterns
- Restrict external email
- Alert on bulk transfers
- Require justification
Personal Information Bundles:
- Combine name + address + DOB
- Higher sensitivity when combined
- Restrict accordingly
Implementation: Security & Compliance Center > Data loss prevention > Policy:
- Create policy from template or custom
- Select locations (Exchange, SharePoint, OneDrive, Teams)
- Define sensitive info types
- Configure actions (block, alert, encrypt)
- Test with policy tips before enforcement
- Roll out gradually
Google Workspace DLP
DLP Rules Configuration:
Admin Console > Security > Data protection > Manage rules:
Example Rules:
- Scan for Canadian SIN
- Detect credit card numbers
- Identify patterns indicating personal information
- Alert on external shares of sensitive files
- Prevent uploads to personal accounts
Predefined Content Detectors:
- Canada Social Insurance Number
- Credit card numbers
- Medical information patterns
- Custom regex patterns
Backup and Recovery
Why Third-Party Backup Matters
Microsoft 365 / Google Workspace Limitations:
- Deleted items eventually permanently deleted
- No guarantee of indefinite retention
- Ransomware can encrypt cloud data
- Accidental mass deletions
- Compliance/eDiscovery requirements
Backup Solution Options
Commercial Backup Services:
- Veeam Backup for Microsoft 365
- Spanning Cloud Apps
- Backupify (by Datto)
- Afi.ai
- Dropsuite
What to Back Up:
- Email and attachments
- SharePoint/Drive files
- OneDrive content
- Teams chats
- Calendar and contacts
Backup Best Practices:
- Daily automated backups
- 30-90 day retention minimum
- Canadian data center storage
- Encrypted backups
- Test restoration quarterly
- Execute DPA with backup provider
PIPEDA Compliance Checklist
Microsoft 365 Compliance
- Configure Canadian data residency
- Execute Microsoft Customer Agreement and DPA
- Disable non-essential diagnostic data
- Enable comprehensive audit logging
- Implement DLP policies
- Configure external sharing restrictions
- Enable email encryption
- Enforce MFA for all users
- Implement mobile device management
- Configure third-party app restrictions
- Set up third-party backup
- Document configuration in privacy policy
- Train users on security features
Google Workspace Compliance
- Configure Canadian data regions
- Execute Google Cloud Data Processing Amendment
- Enable maximum audit logging
- Implement DLP rules
- Configure Drive sharing controls
- Enable email encryption (S/MIME or CSE)
- Enforce 2FA for all users
- Implement mobile device management
- Restrict marketplace apps
- Review and limit third-party app access
- Set up third-party backup
- Update privacy policy
- Conduct user security training
Cost Considerations
Plan tiers differ in their compliance, DLP, data residency and device management features. Check Microsoft and Google directly for current plan features and pricing.
Microsoft 365 Plans
Business Basic
- Basic compliance features
- Limited DLP
- No Advanced Data Residency
Business Standard
- Better compliance tools
- Desktop apps included
Business Premium
- Advanced security features
- Better DLP
- Device management
E3
- Advanced compliance
- Advanced DLP
- eDiscovery
E5
- All compliance features
- Advanced Data Residency available
- Most comprehensive security
Google Workspace Plans
Business Starter
- Basic features only
- Limited compliance
Business Standard
- Better security
- Vault for eDiscovery
Business Plus
- Data regions available
- Enhanced DLP
- Advanced device management
Enterprise
- Full compliance features
- Client-side encryption
- Maximum security
Additional Costs
Also budget for third-party backup, Microsoft's Advanced Data Residency add-on (if needed), and any compliance consulting support. Contact each vendor for current pricing.
Common Configuration Mistakes
- Default Settings: Accepting defaults without customization
- No MFA: Allowing password-only authentication
- Open Sharing: Enabling public links and external sharing broadly
- No DLP: Not implementing data loss prevention
- Weak Mobile Policy: Allowing unmanaged devices full access
- No Audit Logging: Leaving auditing disabled
- Too Many Apps: Not restricting third-party marketplace apps
- No Backup: Relying solely on platform retention
- Missing DPA: Not executing Data Processing Agreements
- Untrained Users: Not educating staff on security features
Conclusion
Microsoft 365 and Google Workspace can be PIPEDA and Law 25 compliant—but only with proper configuration. Out-of-the-box settings prioritize convenience over privacy compliance.
Follow this guide to:
- Enable Canadian data residency
- Configure appropriate privacy settings
- Implement data loss prevention
- Enforce strong authentication
- Manage third-party app risks
- Establish proper backup procedures
The investment in proper configuration—one-time setup plus ongoing monitoring—protects your business from data breaches, regulatory penalties, and customer trust violations.
Start today: Review your current configuration against this checklist, implement critical settings immediately, and schedule monthly reviews to maintain compliance as platforms evolve.
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
90-Day Privacy Program Launch: Implementation Roadmap for Canadian Small Businesses
Launch a complete PIPEDA and Law 25 privacy program in 90 days. Step-by-step roadmap for Canadian SM...
DIY vs. Automated Compliance: Cost Analysis for Canadian SMBs in 2026
DIY privacy compliance vs automation for Canadian SMBs: year-one and ongoing costs, the hidden costs...