Turn privacy obligations into concrete Microsoft 365 controls. This guide maps APP 1–13 to practical configurations across Microsoft Purview (data classification, DLP, retention and records), SharePoint, Exchange and Entra ID — so you can demonstrate compliance while keeping day‑to‑day work simple.
Small and mid-sized Australian organisations running Microsoft 365 that need a clear, actionable way to align with the Australian Privacy Principles (APPs) without adding busywork or buying point tools you don’t need.
– We summarise each APP in plain English.
– We recommend specific Microsoft 365 controls to meet, evidence or operationalise that principle.
– We focus on Microsoft Purview (Information Protection, DLP, Records Management, eDiscovery), SharePoint, Exchange and Entra ID, with a light touch on Defender where it directly reduces risk.
This is practical implementation guidance, not legal advice. Pair it with your privacy policy and risk register.
– APP 1 — Open and transparent management
– Publish your privacy policy on SharePoint with version history and approvals enabled.
– Use Microsoft Purview Compliance Manager to track APP controls and evidence owners.
– Build a privacy register (processing activities, data types, systems) in a SharePoint list with retention labels.
– Enable Purview Data Map, Content Explorer and Data Classification to identify where personal information lives.
– APP 2 — Anonymity and pseudonymity
– Configure Microsoft Forms to allow anonymous submissions where feasible; route responses to a restricted SharePoint site.
– Use data minimisation defaults: mandatory fields only, with guidance on forms and templates (stored in SharePoint).
– Create a documented pathway (SharePoint page) for customers to interact without identifying themselves where practical.
– APP 3 — Collection of solicited personal information
– Standardise intake with approved Forms and SharePoint lists; restrict who can create forms.
– Use Purview auto-labelling to detect and label personal/sensitive info at the point of collection.
– Train teams via Outlook and SharePoint tips; reinforce with DLP policies that flag excessive or unnecessary data capture.
– APP 4 — Dealing with unsolicited personal information
– Create a triage folder in Exchange and a SharePoint quarantine library with short retention (e.g., 7–30 days) to assess and delete unsolicited personal data.
– Use Purview search/classification to find and remove or de-identify data not required for your functions.
– APP 5 — Notification of collection
– Add a privacy notice to standard Forms, SharePoint intake pages and booking pages.
– Use Exchange mail flow rules to append a collection notice to specific inbound acknowledgement emails.
– Store templates (approved wording) in SharePoint; apply records labels to manage changes over time.
– APP 6 — Use or disclosure
– Apply Purview Sensitivity Labels with encryption and usage rights (e.g., block external forwarding, watermarking).
– Set SharePoint and OneDrive external sharing to “Specific people” by default; enable domain allow/block lists.
– Configure DLP across Exchange, SharePoint, OneDrive and Teams to prevent unauthorised sharing of personal data.
– Use Entra ID Conditional Access to enforce MFA, device compliance and session restrictions for sensitive content.
– APP 7 — Direct marketing
– Maintain a consent register in SharePoint with retention and audit; limit edit access to marketing/privacy owners.
– Use Exchange rules to ensure unsubscribe links are present in outbound marketing from shared mailboxes.
– DLP policy to prevent sending marketing lists that include special category data or government identifiers.
– APP 8 — Cross‑border disclosure
– Confirm Microsoft 365 data residency in the Australia geo; preference AU data locations for core workloads.
– Block auto-forwarding to external domains in Exchange; enforce TLS for known partners.
– Sensitivity labels to restrict opening outside your tenant; SharePoint external sharing limited to approved domains.
– DLP policy that blocks sharing of personal data to non‑AU domains unless approved.
– APP 9 — Government related identifiers
– Use Purview sensitive info types for Australia (e.g., Tax File Number, Medicare, driver’s licence) and enable DLP to prevent storage in unapproved locations or unauthorised sharing.
– Auto-label documents containing government identifiers and apply “Confidential – Personal” restrictions.
– APP 10 — Quality of personal information
– Use SharePoint as the single source of truth with mandatory metadata, versioning and content approval.
– Implement periodic review workflows (Power Automate) to verify key records’ accuracy.
– Ensure user attributes in Entra ID/Exchange (addresses, phone) are owned and reviewed with change control.
– APP 11 — Security of personal information
– Enforce MFA, block legacy protocols and require compliant devices via Entra ID Conditional Access.
– Encrypt and restrict personal data with Sensitivity Labels; enable Purview Audit (Standard/Premium) for traceability.
– Use Defender for Office 365 (Safe Links, Safe Attachments) and Intune device encryption/patch compliance.
– Limit Teams guest access; enable Information Barriers where needed.
– APP 12 — Access to personal information
– Use Microsoft Purview Subject Rights Requests to locate, review, redact and export an individual’s data.
– Build a repeatable DSR playbook in SharePoint: intake form, identity verification steps, search scope, approvals and fulfilment timeline.
– Apply disposition reviews to ensure DSR exports are retained or destroyed in line with policy.
– APP 13 — Correction of personal information
– Provide a SharePoint form for correction requests that routes to data owners.
– Maintain version history in SharePoint libraries; use retention labels that allow updates without premature record sealing.
– Log corrections and notify downstream systems; store evidence in the privacy register.

Prioritise these changes to lift your APP alignment fast:
1. Turn on Purview foundations
– Enable Data Classification, Content Explorer and sensitive information types for Australia.
– Define Sensitivity Labels: Public, Internal, Confidential – Personal, Secret – Personal.
– Publish labels to users; enable auto-labelling for documents and emails with personal information.
2. Set retention and records
– Create baseline retention labels: Working (modification allowed), Business record (immutable), Short-term quarantine (7–30 days).
– Publish retention policies to Exchange mailboxes, SharePoint sites and OneDrive with appropriate durations.
3. Lock down sharing and forwarding
– SharePoint/OneDrive: set “Specific people” as default link type; limit external sharing to approved domains.
– Exchange: block external auto-forward; enforce DKIM/DMARC and TLS for trusted partners.
4. Build DLP policies that matter
– Start with a single “Protect AU identifiers” DLP policy covering Exchange, SharePoint, OneDrive and Teams.
– Add a “Prevent external personal data sharing” policy that warns or blocks when sending to non‑AU domains.
5. Enforce secure access
– Conditional Access: require MFA, compliant or hybrid-joined devices for sensitive content; block legacy authentication.
– Defender for Office 365: enable Safe Links and Safe Attachments on all mailboxes.
6. Operationalise privacy workflows
– Publish privacy policy and collection notices on SharePoint with approvals.
– Stand up a Subject Rights Requests process using Microsoft Purview.
– Create a SharePoint privacy register and consent register with retention and audit.
Want help implementing the above in a way that suits your business? Visit https://azcloudsolutions.com.au for a no‑jargon walkthrough of options that fit your licences and risk profile.
– Purview Compliance Manager score with APP‑aligned control list and owners.
– Screenshots/exports: DLP policies, Sensitivity Labels, Conditional Access, external sharing settings.
– SharePoint privacy register, consent records and policy version history.
– Sample DSR package from Purview Subject Rights Requests (with redactions).
– Audit logs showing access, label application and sharing events.
– Over‑labelling everything as “Confidential” and slowing work. Start simple and iterate.
– Forgetting Teams and OneDrive in DLP and retention scope. Include all collaboration surfaces.
– Treating privacy as “set and forget”. Schedule quarterly reviews of policies, labels and exceptions.
– Relying only on policy. Train staff with short, contextual tips in Outlook/Teams and provide approved templates.
AZ Cloud Solutions runs Microsoft 365, Azure and cybersecurity for Australian organisations — monitored around the clock, secured by design, and backed by a local team on a fixed monthly cost.
Here’s what we do to make APP alignment practical:
– Map your data and risks: We use Microsoft Purview to discover where personal information actually lives across Exchange, SharePoint, OneDrive and Teams.
– Configure the right controls: Sensitivity Labels, DLP, retention and records management set up to match your privacy policy, not someone else’s.
– Harden access end‑to‑end: Entra ID Conditional Access, device compliance with Intune, and Defender protections aligned to the Essential Eight.
– Operationalise privacy: Build your Subject Rights Requests process, consent register and evidence pack so you can respond quickly and prove compliance.
– Report in plain English: Monthly summaries of incidents blocked, labelling coverage, DLP hits and outstanding actions — no black box.
Explore our services and see real‑world results at https://azcloudsolutions.com.au.
Call 0468 747 676 or email support@azcloudsolutions.com.au for practical guidance that fits your licences, your team and your timelines.
No obligation, no jargon. We’ll review your Microsoft 365 tenant against the Australian Privacy Principles, identify quick wins and map a clear plan for Purview labels, DLP and retention that doesn’t slow your business down.
Visit: https://azcloudsolutions.com.au
Call: 0468 747 676
Email: support@azcloudsolutions.com.au
#AzCloudSolutions #AZCloudSolutions #AustralianPrivacyPrinciples #Microsoft365 #MicrosoftPurview #EntraID #Compliance #Australia