Microsoft Teams Data Protection, Swiss Configuration Guide

5 min readLast updated By Oliver Stutz

Introduction

Microsoft Teams is the default collaboration platform in Swiss organisations. Chats, calls, meetings, files, tasks, wikis, co-authoring, whiteboards and, since 2024, Copilot integrations all run through Teams. That very breadth makes data-protection governance demanding: Teams spreads personal data across Exchange (chats, calendars), SharePoint (team files), OneDrive (1:1 chat files), Stream/SharePoint (recordings), Loop (components) and Microsoft Purview (compliance backend).

This article shows:

  • which data flows arise in a standard Teams setup;
  • which retention settings for chats and meetings are legally appropriate;
  • how recording, transcription and live captioning are classified under data-protection law;
  • how eDiscovery, Communication Compliance and Insider Risk Management can collide with the right of access under Art. 25 DSG;
  • how sensitivity labels operate in Teams;
  • and which configuration baseline we recommend for Swiss clients.

Legal anchors: Federal Act on Data Protection (DSG, Art. 6, 8, 9, 12, 19, 22, 24, 25, 32), GDPR (Art. 6, 13, 15, 17, 28, 32, 44 et seq.), Art. 26 Swiss Labour Act (employee monitoring), Art. 328b Swiss Code of Obligations (personal data in employment), FINMA Circular 2018/3 for regulated institutions, CJEU C-311/18 (Schrems II), EU-US DPF / Swiss-US DPF.

Data flows in a standard Teams setup

Teams is not a monolithic service but a front-end that orchestrates several M365 backends:

  • 1:1 and group chats: stored in a hidden Chat folder in each participant's Exchange Online mailbox.
  • Team channel messages: stored in the group mailbox of the underlying Microsoft 365 Groups object.
  • Channel-shared files: SharePoint document library of the team site.
  • Files shared in 1:1 chats: sender's OneDrive, shared with recipients.
  • Meeting recordings: organiser's OneDrive (1:1 meetings) or channel's SharePoint (channel meetings).
  • Transcripts and live captions: as a linked Stream file.
  • Call logs and voicemail: Exchange mailbox, with their own retention settings.
  • Compliance metadata: Microsoft Purview (audit log, DLP events, sensitivity-label events).

Two consequences follow. First, retention and erasure duties hit several backends simultaneously. Second, a data-subject access request (Art. 25 DSG / Art. 15 GDPR) must cover all these storage locations, hence eDiscovery.

Getting chat retention right

A sensible retention strategy is the most important data-protection lever in Teams. By default, Microsoft stores chat messages indefinitely, which is problematic under Art. 6(4) DSG (retention only as long as necessary) and Art. 5(1)(e) GDPR (storage limitation).

We recommend the following retention heuristic for Swiss organisations:

  • 1:1 and group chats: retention 12-24 months, then auto-deletion. Rationale: chats are primarily ephemeral communication.
  • Channel messages: 3-5 years, because project-relevant decisions are often documented here.
  • Recordings: 30-90 days standard deletion; exceptions via sensitivity label for rare long-term recordings.
  • Shared files: governed via separate SharePoint retention policy, typically longer.
  • Call logs / voicemail: 6-12 months.

Configure this in Microsoft Purview under Data Lifecycle Management → Retention Policies. Important: a retention policy in "delete only" mode deletes without user consent, this requires prior employee information (Art. 19 DSG).

Recording, transcription and captioning

Recording and transcription of Teams meetings are highly sensitive processings. They generate three data categories:

  1. Audio/video: content of the discussion, voice, facial expression (when cameras are on), background noise, visible screen content.
  2. Transcript: a text version of the discussion, searchable and AI-analysable.
  3. Live captions: real-time subtitles, these streams are usually deleted shortly after the meeting, but with active speech-to-text learning they may be used to improve recognition.

Legally: recording is only lawful with notice to all participants (Art. 19 DSG, Art. 13 GDPR). Teams automatically shows a banner once recording starts, but this does not replace prior, documented consent when the recording has consequences (internal training, external distribution).

Sensitive constellations:

  • Recording without external participants' consent: potentially criminal under Art. 179bis of the Swiss Criminal Code (illegal recording of conversations).
  • Recordings involving employees: qualifying as employee monitoring within the meaning of Art. 26 ArGV 3 if systematic and performance-related.
  • Transcription data flows: Teams sends audio snippets to Microsoft speech services; these run within the EU Data Boundary, but partly with telemetry to US Microsoft.

eDiscovery, Communication Compliance and the right of access

Microsoft Purview offers powerful compliance functions that must be carefully governed in Swiss organisations:

  • eDiscovery (Standard / Premium): allows searching all M365 data, mail, Teams chats, SharePoint, OneDrive, including already-deleted content (single-item recovery). Practically indispensable for handling access requests (Art. 25 DSG) and breach forensics (Art. 24 DSG), but at the same time a bulk-data access tool.
  • Communication Compliance: can automatically scan chats for specific keywords, sentiment patterns or behavioural rules. In Switzerland only lawful under strict conditions (Art. 26 ArGV 3, Art. 328b CO): clear purpose, proportionality, employee information.
  • Insider Risk Management: combines signals (file downloads, chat behaviour, external emails) into risk scores for individual employees. Highly sensitive, DPIA and employee participation rights are mandatory.

When you receive an access request, eDiscovery Premium is the practical toolkit. A four-eyes principle for searching, a documented authorisation, a clear separation between "access to data subject" and "internal investigation", without this governance, the tool itself creates a compliance risk.

Sensitivity labels in Teams

Microsoft Purview sensitivity labels can be applied directly to Teams, channels and meetings. Since 2022, this has been a central protection layer:

  • Team classification: when creating a team, you choose a label (e.g. Internal, Confidential, Strictly Confidential). The label governs guest access, external sharing, privacy (public/private) and the application of Conditional Access.
  • Meeting protection: meeting sensitivity labels can enforce end-to-end encryption, prohibit recording and transcription, display a watermark and restrict content sharing.
  • Files: labels on files (Word, Excel, PowerPoint) are visible and enforced within Teams, including when shared externally.

For Swiss organisations, a simple three- to four-label hierarchy (Public, Internal, Confidential, Strictly Confidential) is appropriate. More labels are not used in practice; fewer are often not enough to cleanly delimit sensitive personal data (Art. 5(c) DSG).

Auto-labeling for Teams content is available since 2024 (service-side auto-labeling). Purview can classify chats and files automatically based on content patterns, a major compliance gain, but requiring a DPIA.

Configuration baseline for Swiss clients

Our recommendation for Swiss Teams tenants:

  1. Identity: Entra ID with MFA for all, Conditional Access with device-compliance checks, Privileged Identity Management for Teams admins.
  2. External access: federation on an allow list rather than open ("allow all"), guest access on by default but with sensitivity-label control.
  3. Retention policies: chats 24 months, channels 5 years, recordings 90 days, with sensitivity-label overrides for regulated workloads.
  4. Recording policy: off by default for external meetings, permitted for internal training, documented consent where required.
  5. DLP: Microsoft Purview DLP for Teams Chat and Channel, rule sets for AHV numbers, IBAN, credit cards, diagnostic codes.
  6. Audit log: Unified Audit Log enabled, retained for at least 1 year.
  7. Copilot in Teams: DPIA before activation, sensitivity labels as a prerequisite, audit mode first.
  8. Apps & bots: App Governance via Entra ID; default app catalog set to "approved only".
  9. Employee information: annually refreshed privacy notice listing the compliance tools in use (eDiscovery, Communication Compliance, Insider Risk Management) and their purposes.

This baseline is achievable in a 4-6-week project and must be documented under Art. 22 DSG with a closing DPIA.

How SIDD supports you

SIDD runs Teams data-protection audits, DPIAs and tenant reviews. We combine legal assessment (DSG, GDPR, Labour Act, CO) with technical depth in Purview, Entra ID and Copilot. Our services:

  • Teams DPIA covering recording, transcription, Copilot and Communication Compliance;
  • tenant configuration review against our SIDD baseline;
  • training for admins (retention, eDiscovery, sensitivity labels) and end-users (chat privacy, handling recordings);
  • mandates as external data-protection advisor or external CISO/ISB;
  • ISO/IEC 27001 support, with Teams as the main platform in scope (ISO 27001 / ISMS);
  • penetration tests against Teams configurations and third-party apps (penetration testing);
  • awareness workshops for mixed teams (IT security workshop).

Write to us via the contact form or request a quote via the quote form. We deliver a Teams tenant diagnosis within 5 working days.

Need help putting this into practice? SIDD operates the matching service.
See service →

Microsoft Teams Data Protection, Swiss Configuration Guide

INSIGHT

Data Protection
24 May 2026
Oliver Stutz
Configuring Microsoft Teams for data protection: data flows, chat retention, recordings, eDiscovery and the right of access, sensitivity labels.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.