Data Subject Access Requests
To help your organization comply with the General Data Protection Regulation (GDPR), IBM® Storage Protect for Cloud Microsoft 365 provides a tool that discovers all copies of the Exchange Online Mailbox, SharePoint Online Site Collections and OneDrive backups of a given data subject that are stored by IBM Storage Protect for Cloud Microsoft 365 solution and deletes the user-generated backups of Mailbox, SharePoint Online Site Collections, and OneDrive. After the deletion, the entire object, along with all associated data, is permanently deleted.
About this task
The IBM Storage Protect for Cloud Microsoft 365 data stored on the backend is immutable to users. Administrators can enable data availability for data subject access requests in accordance with their organization’s GDPR policy.
- If you currently have no GDPR requests and want to avoid any accidental deletion of backup data, you can contact IBM Software Support to disable this feature. Note that the Data Subject Access Requests feature and the Manually Delete Backup Data feature will both be disabled.
- You can enable the approval process for data deletion in Settings > Security to
avoid accidental data loss. With this feature enabled, data deletion requests and email
notifications will be sent to the administrators when you delete data in Manually delete backup
data and Data subject access requests. Then administrators can access the IBM Storage Protect for Cloud Microsoft 365 interface and click My Tasks (
) on the upper-right of the interface to approve or
reject your requests. The deletion jobs will start when the requests are approved. Note that the
requests will be automatically invalidated if not approved within 7 days. Complete the steps
below: