Compliance How-To

Microsoft 365 & Google Workspace Compliance: Canadian Privacy Configuration Guide

PIPEDA compliance guide for Microsoft 365 and Google Workspace. Canadian data residency, privacy settings, and configuration for SMBs.

Canada Compliance AI•
January 21, 2026
Updated September 12, 2026
11 min read
Microsoft 365
Google Workspace
PIPEDA
Law 25
data residency
cloud compliance
configuration guide

Microsoft 365 and Google Workspace power most Canadian businesses. They're convenient, cost-effective, and feature-rich. They're also cloud services processing vast amounts of personal information that require careful privacy configuration.

Out-of-the-box settings often fall short of PIPEDA and Law 25 requirements. This guide shows Canadian businesses how to properly configure these platforms for privacy compliance.

Why Office Suite Privacy Matters

The Data These Platforms Hold

Email Communication:

  • Customer conversations
  • Employee personal information
  • Confidential business discussions
  • Attachments with sensitive data

Document Storage:

  • Contracts with personal information
  • Financial records
  • HR documents
  • Client files

Collaboration Data:

  • Meeting recordings (video/audio)
  • Chat conversations
  • Calendar appointments
  • Contact directories

Usage Analytics:

  • Who accessed what documents
  • Communication patterns
  • Location data
  • Device information

Privacy Risks

Default Configurations:

  • Data processed in US data centers
  • Diagnostic data collected
  • Third-party app access enabled
  • Insufficient audit logging

Common Mistakes:

  • Shared links without expiration
  • External sharing enabled broadly
  • No data loss prevention
  • Weak authentication
  • Unencrypted email

Canadian Data Residency Options

Microsoft 365 Data Residency

Canada Geo (Toronto & Quebec City):

  • Available for most business subscriptions
  • Core customer data stored in Canadian data centers
  • Some services still process in US

What's Stored in Canada:

  • Exchange Online mailbox content
  • SharePoint Online site content
  • OneDrive for Business files
  • Teams chat and channel messages (with advanced setup)

What May Still Process in US:

  • Diagnostic/support data
  • Some metadata
  • Temporary processing for certain features
  • Backup/disaster recovery (can be configured)

How to Configure:

  1. Sign up with Canadian billing address
  2. Select Canada as data residency location during setup
  3. Verify data location in Admin Center > Settings > Org Settings > Organization profile > Data location
  4. Consider Advanced Data Residency add-on for extended coverage

Advanced Data Residency:

  • Additional fee per user
  • Covers more workloads
  • Includes Teams content
  • Adds Defender and other services
  • More data stays in Canada

Google Workspace Data Residency

Data Regions:

  • Available on Business Plus, Enterprise plans
  • Configure which regions can store data
  • Canada option available

What Can Be Regionalized:

  • Gmail messages and attachments
  • Drive files
  • Calendar events
  • Some Google Chat/Meet content

What May Still Process Globally:

  • Search indexes
  • Some metadata
  • Temporary processing
  • Certain services

How to Configure:

  1. Admin Console > Account > Data regions
  2. Select Canada as primary region
  3. Configure covered services
  4. Save and apply

Limitations:

  • Only available on higher-tier plans
  • Some services can't be regionalized
  • Legacy free accounts don't support

Essential Privacy Configuration

Microsoft 365 Critical Settings

1. Tenant-Wide Privacy Settings

Admin Center > Settings > Org Settings > Privacy:

  • ✅ Disable "Connected experiences that analyze content"
  • ✅ Disable "Connected experiences that download online content"
  • ✅ Set diagnostic data to "Required only"
  • ✅ Disable "Optional connected experiences"

2. Audit Logging

Security & Compliance Center > Audit:

  • ✅ Enable unified audit log
  • ✅ Retain for 365 days minimum (or maximum available)
  • ✅ Enable mailbox auditing for all users
  • ✅ Configure alert policies

3. Data Loss Prevention (DLP)

Security & Compliance Center > Data loss prevention:

  • ✅ Create policies for sensitive data (SSN, credit cards, personal info)
  • ✅ Apply to Exchange, SharePoint, OneDrive, Teams
  • ✅ Configure user notifications
  • ✅ Set up incident reports

4. External Sharing Controls

SharePoint Admin Center > Policies > Sharing:

  • ✅ Restrict to "Only people in your organization" (or authenticated external users if needed)
  • ✅ Require sign-in for shared links
  • ✅ Set link expiration (30-90 days)
  • ✅ Disable anonymous links (if not required)

OneDrive Admin Center > Sharing:

  • Apply same restrictions as SharePoint

5. Email Encryption

Exchange Admin Center > Mail flow > Rules:

  • ✅ Create rules for sensitive subject lines or content
  • ✅ Enable Office 365 Message Encryption
  • ✅ Consider S/MIME for end-to-end encryption
  • ✅ Configure external email warnings

6. Multi-Factor Authentication (MFA)

Azure AD > Security > MFA:

  • ✅ Require MFA for all users (no exceptions)
  • ✅ Configure trusted IPs if needed
  • ✅ Use authenticator app (not SMS when possible)
  • ✅ Set up Conditional Access policies

7. Mobile Device Management

Endpoint Manager > Devices:

  • ✅ Require device encryption
  • ✅ Enforce PIN/password
  • ✅ Enable remote wipe
  • ✅ Restrict data sharing between apps
  • ✅ Configure compliance policies

Google Workspace Critical Settings

1. Data Protection Settings

Admin Console > Security > Data protection:

  • ✅ Enable Drive for Desktop encryption
  • ✅ Configure data loss prevention rules
  • ✅ Set external sharing restrictions
  • ✅ Enable Drive file audit logging

2. Access and Data Control

Admin Console > Security > Access and data control:

  • ✅ Disable "Allow users to install apps"
  • ✅ Restrict third-party app access
  • ✅ Enable context-aware access
  • ✅ Configure session length

3. Audit and Investigation

Admin Console > Security > Investigation tool:

  • ✅ Enable audit logging (maximum retention)
  • ✅ Configure log events for all services
  • ✅ Set up security alerts
  • ✅ Enable security center dashboards

4. Email Security

Admin Console > Apps > Google Workspace > Gmail:

  • ✅ Enable S/MIME encryption (Enterprise plans)
  • ✅ Configure content compliance rules
  • ✅ Enable attachment protection
  • ✅ Set up email allowlists/blocklists
  • ✅ Enable spoofing warnings

5. Drive Sharing Controls

Admin Console > Apps > Google Workspace > Drive:

  • ✅ Restrict external sharing (if appropriate)
  • ✅ Disable public links (if not needed)
  • ✅ Set link sharing defaults to "Restricted"
  • ✅ Enable warning for external shares
  • ✅ Configure expiration for shared links

6. Two-Factor Authentication

Admin Console > Security > 2-Step Verification:

  • ✅ Enable enforced 2FA for all users
  • ✅ Allow security keys
  • ✅ Consider disabling SMS (use authenticator apps)
  • ✅ Set grace period for enrollment (7-14 days max)

7. Mobile Management

Admin Console > Devices > Mobile devices:

  • ✅ Require device encryption
  • ✅ Enforce screen lock
  • ✅ Enable remote wipe
  • ✅ Configure password requirements
  • ✅ Set up device approval

Third-Party App Management

Microsoft 365 App Governance

Marketplace Apps:

SharePoint Admin Center > More features > Apps:

  • ✅ Review and restrict app permissions
  • ✅ Disable app catalog if not needed
  • ✅ Require admin approval for new apps
  • ✅ Audit installed apps quarterly

OAuth App Security:

  • Review connected apps per user
  • Revoke unused or suspicious apps
  • Limit app permissions
  • Monitor for over-permissioned apps

Google Workspace App Controls

Marketplace Management:

Admin Console > Apps > Marketplace apps:

  • ✅ Restrict to allowlisted apps only (or individual review)
  • ✅ Review app permissions before approval
  • ✅ Monitor installed apps
  • ✅ Remove unused apps

Third-Party Access:

  • Limit API access
  • Review OAuth tokens
  • Monitor unusual access patterns
  • Revoke suspicious applications

Email Encryption Deep Dive

Microsoft 365 Email Encryption

Office 365 Message Encryption (OME):

  • Encrypts email content
  • Recipients can read without special software
  • Requires Azure Information Protection

S/MIME (Secure/Multipurpose Internet Mail Extensions):

  • End-to-end encryption
  • Digital signatures for authentication
  • Requires certificate management
  • Recipient must also have S/MIME

When to Use Which:

  • OME: Sending to external parties without S/MIME
  • S/MIME: Organization-to-organization with mutual S/MIME support
  • Both: Maximum security for highly sensitive communications

Google Workspace Encryption

Hosted S/MIME:

  • Available on Enterprise plans
  • Managed certificates
  • Automatic encryption when available
  • Falls back to TLS if recipient doesn't support

Client-Side Encryption (CSE):

  • Enterprise Plus and Education Plus
  • Encryption before data leaves client
  • Google cannot decrypt
  • Maximum privacy
  • More complex setup

TLS Encryption:

  • Default for all Gmail
  • Encrypts in transit
  • Not end-to-end (Google can access)

Data Loss Prevention (DLP)

Microsoft 365 DLP Policies

Common Canadian-Specific DLP Rules:

Protect Social Insurance Numbers:

  • Detect Canadian SIN patterns
  • Block external sharing
  • Alert security team
  • Encrypt automatically

Credit Card Protection:

  • Detect card number patterns
  • Restrict external email
  • Alert on bulk transfers
  • Require justification

Personal Information Bundles:

  • Combine name + address + DOB
  • Higher sensitivity when combined
  • Restrict accordingly

Implementation: Security & Compliance Center > Data loss prevention > Policy:

  1. Create policy from template or custom
  2. Select locations (Exchange, SharePoint, OneDrive, Teams)
  3. Define sensitive info types
  4. Configure actions (block, alert, encrypt)
  5. Test with policy tips before enforcement
  6. Roll out gradually

Google Workspace DLP

DLP Rules Configuration:

Admin Console > Security > Data protection > Manage rules:

Example Rules:

  • Scan for Canadian SIN
  • Detect credit card numbers
  • Identify patterns indicating personal information
  • Alert on external shares of sensitive files
  • Prevent uploads to personal accounts

Predefined Content Detectors:

  • Canada Social Insurance Number
  • Credit card numbers
  • Medical information patterns
  • Custom regex patterns

Backup and Recovery

Why Third-Party Backup Matters

Microsoft 365 / Google Workspace Limitations:

  • Deleted items eventually permanently deleted
  • No guarantee of indefinite retention
  • Ransomware can encrypt cloud data
  • Accidental mass deletions
  • Compliance/eDiscovery requirements

Backup Solution Options

Commercial Backup Services:

  • Veeam Backup for Microsoft 365
  • Spanning Cloud Apps
  • Backupify (by Datto)
  • Afi.ai
  • Dropsuite

What to Back Up:

  • Email and attachments
  • SharePoint/Drive files
  • OneDrive content
  • Teams chats
  • Calendar and contacts

Backup Best Practices:

  • Daily automated backups
  • 30-90 day retention minimum
  • Canadian data center storage
  • Encrypted backups
  • Test restoration quarterly
  • Execute DPA with backup provider

PIPEDA Compliance Checklist

Microsoft 365 Compliance

  • Configure Canadian data residency
  • Execute Microsoft Customer Agreement and DPA
  • Disable non-essential diagnostic data
  • Enable comprehensive audit logging
  • Implement DLP policies
  • Configure external sharing restrictions
  • Enable email encryption
  • Enforce MFA for all users
  • Implement mobile device management
  • Configure third-party app restrictions
  • Set up third-party backup
  • Document configuration in privacy policy
  • Train users on security features

Google Workspace Compliance

  • Configure Canadian data regions
  • Execute Google Cloud Data Processing Amendment
  • Enable maximum audit logging
  • Implement DLP rules
  • Configure Drive sharing controls
  • Enable email encryption (S/MIME or CSE)
  • Enforce 2FA for all users
  • Implement mobile device management
  • Restrict marketplace apps
  • Review and limit third-party app access
  • Set up third-party backup
  • Update privacy policy
  • Conduct user security training

Cost Considerations

Plan tiers differ in their compliance, DLP, data residency and device management features. Check Microsoft and Google directly for current plan features and pricing.

Microsoft 365 Plans

Business Basic

  • Basic compliance features
  • Limited DLP
  • No Advanced Data Residency

Business Standard

  • Better compliance tools
  • Desktop apps included

Business Premium

  • Advanced security features
  • Better DLP
  • Device management

E3

  • Advanced compliance
  • Advanced DLP
  • eDiscovery

E5

  • All compliance features
  • Advanced Data Residency available
  • Most comprehensive security

Google Workspace Plans

Business Starter

  • Basic features only
  • Limited compliance

Business Standard

  • Better security
  • Vault for eDiscovery

Business Plus

  • Data regions available
  • Enhanced DLP
  • Advanced device management

Enterprise

  • Full compliance features
  • Client-side encryption
  • Maximum security

Additional Costs

Also budget for third-party backup, Microsoft's Advanced Data Residency add-on (if needed), and any compliance consulting support. Contact each vendor for current pricing.

Common Configuration Mistakes

  1. Default Settings: Accepting defaults without customization
  2. No MFA: Allowing password-only authentication
  3. Open Sharing: Enabling public links and external sharing broadly
  4. No DLP: Not implementing data loss prevention
  5. Weak Mobile Policy: Allowing unmanaged devices full access
  6. No Audit Logging: Leaving auditing disabled
  7. Too Many Apps: Not restricting third-party marketplace apps
  8. No Backup: Relying solely on platform retention
  9. Missing DPA: Not executing Data Processing Agreements
  10. Untrained Users: Not educating staff on security features

Conclusion

Microsoft 365 and Google Workspace can be PIPEDA and Law 25 compliant—but only with proper configuration. Out-of-the-box settings prioritize convenience over privacy compliance.

Follow this guide to:

  • Enable Canadian data residency
  • Configure appropriate privacy settings
  • Implement data loss prevention
  • Enforce strong authentication
  • Manage third-party app risks
  • Establish proper backup procedures

The investment in proper configuration—one-time setup plus ongoing monitoring—protects your business from data breaches, regulatory penalties, and customer trust violations.

Start today: Review your current configuration against this checklist, implement critical settings immediately, and schedule monthly reviews to maintain compliance as platforms evolve.

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.