Data Governance News: Updates for Small Businesses
Latest data governance news and updates. Microsoft 365 governance changes, SharePoint storage overages, AI readiness requirements, and data management developments that affect how your business handles its data.
Last updated: 2026-03-02
Data governance is moving fast. Microsoft is tightening SharePoint storage policies, AI tools like Copilot are exposing data oversharing risks, and regulators worldwide are introducing new frameworks for AI governance and data management.
This page tracks the developments that matter for businesses managing their data. Updated regularly with Microsoft 365 policy changes, AI governance requirements, storage management updates, and regulatory shifts that affect how your organisation handles its information.
Bookmark this page. When Microsoft changes a policy or a new AI regulation takes effect, check here first.
Every item below links to its primary source so you can verify the detail and read further.
September 2026
US: Delaware cuts its privacy threshold to 10,000 consumers from 2027
On 2 September 2026, Delaware's Governor signed HB 380, which amends the Delaware Personal Data Privacy Act from 1 January 2027. The applicability threshold drops from 35,000 to 10,000 Delaware consumers, and to 5,000 for businesses that earn more than 20% of revenue from selling personal data. The Governor's office calls it the lowest threshold in the country. The law also pulls in third parties that acquire personal data from controllers, gives consumers a right to learn what inferences a business has drawn about them, expands sensitive data to cover citizenship and immigration status, pregnancy status, neural data, government ID numbers, and financial account credentials, and narrows the financial-services exemption to actual banks, credit unions, insurers, and their affiliates. A companion bill, HB 381, requires breach notification to the Delaware Department of Justice within 60 days and took effect on signing.
Delaware is small, but 10,000 consumers is a number that a modest online shop, a SaaS product, or a regional service business can reach without noticing. Connecticut follows with its own next round on 1 October 2026, adding a ban on selling precise location data, government ID numbers as sensitive data, and a data broker registry.
What to do: Count your Delaware customers, subscribers, and users. If you are anywhere near 10,000, you have until January to put a consumer-rights process, a privacy notice, and vendor contracts in place. A current data inventory is the starting point. See our Delaware guide and the multi-jurisdiction compliance guide.
Sources: State of Delaware: Governor Meyer signs historic data privacy legislation; Delaware General Assembly: HB 380; Hunton: Connecticut privacy law updates
Ireland: DPC fines the health service €645,000 over records nobody could find
On 2 September 2026, Ireland's Data Protection Commission fined the Health Service Executive €645,000 after a two-year inquiry into how it stored paper records. Investigators found patient files in disused bathrooms, a shipping container in a turf shed, and derelict buildings, damaged by mould, water, and animal droppings. The fine splits into €300,000 for security failures, €300,000 for keeping records with no retention justification, and smaller amounts for notifying the breach late and failing to tell the people affected. The HSE has been ordered to audit every paper storage site, remove records from unfit locations, destroy what it no longer needs, and put tracking in place.
The retention half of the fine is the part worth noting. Half the penalty was for holding records that should have been destroyed, not for the state they were found in. Paper is not a special case either. A box of old client files in a storeroom, a departed employee's HR folder, or a hard drive in a drawer are all records under the GDPR, and if you cannot find them you cannot secure them, answer an access request about them, or say what was in them after a breach.
What to do: Extend your retention policy to paper and offline storage, and schedule the first physical clear-out. If you have never written a retention schedule, our data lifecycle management guide explains what a workable one looks like for a small business.
Source: Data Protection Commission: Final decision following inquiry into the Health Service Executive
Google: audit logs for Gemini Notebook and admin controls for new Studio actions
Google shipped two governance updates in the first days of September. From 3 September, actions taken in Gemini Notebook appear in the Admin console's audit and investigation tools, with the user, IP address, and resource involved, so AI-assisted work on your documents is no longer invisible to whoever handles security. From 1 September, Workspace Studio automations gained new steps that move or copy Drive files, reply in Chat, and reply to email (the Gmail steps follow on 8 September), each with an admin toggle to disable it and an option to require approval before any step that shares data outside the organisation.
This continues August's theme (below) of Google putting brakes on AI agents before staff build too many of them. The controls are available on Business Starter, Standard, and Plus, so small businesses are not excluded.
What to do: Before anyone in your domain automates email replies or file moves, decide which steps stay disabled and turn on approval for external sharing. Then check that the Gemini Notebook logs are included in whatever you review after an incident. See our Google Workspace governance guide.
Source: Google Workspace Updates, September 2026
August 2026
EU: AI Act transparency rules take effect as the high-risk deadline moves to 2027
The provisional agreement we covered in May became law just in time. Regulation (EU) 2026/1744, the "Digital Omnibus on AI," was published on 24 July and entered into force on 27 July 2026, six days before the original high-risk deadline. Annex III high-risk obligations (AI used in hiring, credit, education, and similar decisions) now apply from 2 December 2027, and product-embedded high-risk AI from 2 August 2028. The omnibus also softened the AI literacy duty from "ensure" to "support," added SME definitions with simplified documentation, and added a prohibition on AI that generates non-consensual intimate imagery.
What did apply on 2 August 2026 is Article 50, the transparency layer. Chatbots must tell users they are talking to an AI unless it is obvious. Systems that generate synthetic audio, images, video, or text must mark their output as AI-generated (systems already on the market get until 2 December 2026 for the marking requirement). Anyone deploying deepfakes, emotion recognition, or biometric categorisation must disclose it. Penalties for Article 50 breaches run to €15 million or 3% of worldwide turnover, and the Commission has published guidelines and a voluntary code of practice on AI-generated content.
What to do: If you run a customer-facing chatbot or publish AI-generated images, audio, or text to EU customers, put the disclosure and marking in place now. The high-risk paperwork is not due until December 2027, but the groundwork of knowing what your AI tools can access has not moved. See data governance before AI.
Sources: European Commission: Regulatory framework on AI; Cooley: EU AI Act transparency obligations take effect 2 August 2026
Australia: tranche 2 draft keeps the small business exemption but adds a 72-hour breach clock
On 31 August 2026, the Attorney-General's Department released the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026, with submissions due by 18 September. The government says it will introduce the bill before the end of the year. For small businesses the headline is what the draft does not do. The $3 million small business exemption survives, and so does the employee records exemption. The only tightening is to the existing carve-out for small businesses that trade in personal information.
For businesses already inside the Act, including the professions brought in on 1 July, the changes are substantial. Collection, use, and disclosure would have to pass a "fair and reasonable" test weighing reasonable expectations, data minimisation, and genuine choice. Consent would need to be voluntary, informed, current, specific, and unambiguous. Eligible data breaches would have to be notified to the OAIC within 72 hours instead of the current 30-day assessment window. Precise geolocation becomes sensitive information, direct marketing gets new opt-out rules, and a right to erasure arrives, but only against large digital platforms.
What to do: If you are covered, name the person who decides whether an incident is notifiable and make sure they can be reached within hours, not days. Our Notifiable Data Breaches scheme guide covers the current process. If you are under $3 million, check the exemption explainer to confirm you are actually exempt.
Sources: Attorney-General's Department: Privacy reform consultation; Allens: What the proposed Privacy Act reforms mean in practice
Microsoft: Copilot in OneDrive arrives as an opt-out preview
Message center post MC1459130 (21 August) announced that Copilot in OneDrive starts rolling out as a public preview from late August, reaching general availability by late December. Anyone with a Microsoft 365 Copilot licence can find, summarise, compare, and act on files from the OneDrive web interface without opening them, drawing on content across OneDrive, SharePoint, Teams, and Outlook they already have access to. It is on by default. Copilot in OneDrive and Copilot in SharePoint share a single tenant-level control, and opting out through PowerShell disables both.
Microsoft repeats that Copilot "does not grant new access to files." That is true, and it is the problem. Every folder that is shared more widely than it should be becomes easier to find. A related change in MC1449182 (6 August) moves newly created Copilot Pages and Notebooks into the user's OneDrive, which brings them under retention labels, eDiscovery, and DLP for the first time. Existing pages stay where they are.
What to do: If you have Copilot licences and have not yet cleaned up broadly shared folders, either opt out of the preview until you have, or run the oversharing reports first (see the next item). Then check that your OneDrive retention and departed-user policies are the ones you want applied to AI-drafted documents, because that is where they now live. Our Copilot security best practices guide has the checklist.
Sources: Microsoft 365 message center: MC1459130 (via Merill); Microsoft 365 message center: MC1449182 (via msmessagecenter.com); HANDS ON SharePoint: What's new in SharePoint, August 2026
Microsoft: SharePoint sharing gets a single editable link and an oversharing report
Two changes in August go straight at permission sprawl. First, MC1454378 (13 August) introduces the "hero link": one link per file or folder that controls access and can be changed after the fact, instead of a new link every time the audience changes. The default audience is "Only people added to the file," so the link itself grants nothing. Admins can set a default of "Only people added" or "Organization" per site or OneDrive using PowerShell, but there is no tenant-wide setting yet. Legacy links keep working. Rollout runs from mid-September to late October.
Second, MC1450131 (7 August) adds an item-level report in the SharePoint admin center showing every file and folder exposed through the "Everyone" and "Everyone except external users" groups, across SharePoint and OneDrive. Until now you could see which sites contained such content, not which files. The report changes no permissions and requires SharePoint Advanced Management, which is already bundled for tenants with at least one Copilot licence. Alongside it, Purview auto-labelling capacity rose from 100,000 to 500,000 files per tenant per day.
What to do: Run the "Everyone except external users" report once, fix anything sensitive that is open to the whole company (HR, finance, client folders), and repeat it quarterly. Before mid-September, decide whether your key sites should default to "Organization" or "Only people added" and set it. Then update your one-page sharing guidance for staff. Our SharePoint permissions audit and external sharing guides cover the rest.
Sources: Microsoft 365 message center: MC1454378 (via Merill); Microsoft 365 message center: MC1450131 (via Merill); Microsoft Security blog: What's new in Microsoft Security, August 2026
Google: admins get kill switches and DLP for Workspace Studio agents
On 17 August 2026, Google added a set of enterprise controls for Workspace Studio, the no-code tool staff use to build automations and agents across Gmail, Drive, and Chat. Each flow now runs under its own auditable agent identity rather than the owner's account. A new agent access management dashboard lets admins suspend flows or revoke specific OAuth scopes such as Drive access. Configuration and execution events are logged. Admin settings can disable step types, restrict Gemini's data access, turn off webhooks, and force end-user confirmation before any step that sends data outside the domain. The core controls are available on Business Starter, Standard, and Plus. The runtime DLP pieces, which can block a flow based on the sensitivity of the data it touches, need Enterprise or Frontline editions.
The same month, the Allowlisted Domains API went generally available, so the list of external domains staff can share with can be managed programmatically, and Gemini-based data classification in Drive entered open beta for Enterprise Plus and Frontline Plus tenants.
What to do: If anyone in your Workspace domain has built Studio flows, open the agent access dashboard, check which flows can read Drive or send data outside the organisation, and turn on end-user confirmation for external sharing steps. See our Google Workspace governance guide.
Sources: Google Workspace Updates: New enterprise security controls for Workspace Studio; Google Workspace Updates: Allowlisted Domains API now generally available
UK: ICO reprimands ACRO for patching nobody owned, and launches free SME training
On 12 August 2026, the ICO reprimanded the ACRO Criminal Records Office over a breach in which an attacker had access to its website and Kentico content management system for seven months between August 2022 and March 2023, putting up to 10,920 people's data at risk, including passport and driving licence details, bank details, and criminal offence data. The ICO's findings were not about exotic attacks. Nobody had clear responsibility for identifying and applying critical CMS updates, patch management was ineffective despite outsourced security providers, and security alerts went uninvestigated. The regulator's stated lessons: make accountability clear across systems and suppliers, act on warning signs, and get the basics right. Network segmentation limited the damage, which is partly why this ended in a reprimand rather than a fine.
The same day, the ICO launched Data Protection Essentials, a free, self-paced online course for SMEs and sole traders with no data protection specialist. It uses sector-specific examples (professional services, retail, health and social care, education, and property) and ends with a shareable certificate.
What to do: Write down who is responsible for patching your website, CMS, and cloud apps, and who reads the alerts. A contract that says "managed" is not the same as a named person owning it. Then put whoever handles client or staff data through the ICO course. The certificate is a cheap way to evidence "appropriate measures" if you are ever asked. See our data protection audit guide.
Sources: ICO: ACRO Criminal Records Office reprimand; ICO: Boost your business fitness with free data protection training for SMEs; Local Government Lawyer: ACRO reprimanded over cyber security failings
July 2026
US: Connecticut, Utah, and Arkansas privacy laws take effect
On 1 July 2026, Arkansas's comprehensive privacy law became enforceable and significant amendments took effect in Connecticut and Utah. The most consequential change is in Connecticut, which cut its applicability threshold from 100,000 to 35,000 consumers, pulling many smaller businesses into scope for the first time, and removed the consumer minimum entirely for businesses that sell personal data or process sensitive data. Utah added a new right to correct inaccurate data (with a 45-day response window), and Arkansas's Personal Data Privacy Act is now live.
Connecticut's cure period has also lapsed, so its Attorney General can act on violations without a grace period. As with other US state laws, enforcement is by the state AG, and there is no private right of action.
What to do: If you have customers in these states, recheck your numbers against the new, lower thresholds, Connecticut especially. A single data inventory and a current privacy notice cover most of what these laws require. For the full map, see our jurisdiction guides.
Sources: Ice Miller: State privacy law updates July 2026 (Connecticut, Arkansas, Utah); MultiState: Comprehensive privacy laws taking effect in 2026
Australia: AML "tranche 2" brings 100,000+ small businesses under the Privacy Act
The change we flagged in March has arrived. From 1 July 2026, the AML/CTF "tranche 2" reforms took effect, bringing lawyers, conveyancers, accountants, real estate professionals, and dealers in precious metals and stones into Privacy Act coverage for the personal information they handle for anti-money-laundering purposes, regardless of the $3 million small business exemption.
The OAIC's guidance for these newly covered "reporting entities" stresses data minimisation: collect only what is reasonably necessary for customer due diligence, keep it secure, and destroy or de-identify it when no longer needed. Notably, it advises that businesses should not retain copies of full identity documents solely for AML record-keeping.
What to do: If you are in one of these professions, you now need a Privacy Act–compliant approach to customer-verification data. Start with our Australian Privacy Act guide and the $3M exemption explainer.
Source: OAIC: Know your privacy obligations under the AML/CTF Act
Microsoft: sensitivity labels now block Copilot from analysing protected files
Microsoft is completing the rollout (through July 2026) of a Purview control that stops Microsoft 365 Copilot from analysing Word, Excel, PowerPoint, and Outlook content carrying a protective sensitivity label, so files labelled confidential can't be summarised or used as grounding by Copilot. In parallel, Copilot in SharePoint is now on by default for licensed users, and site owners get a per-site setting to disable the Copilot button for visitors, a useful control for sensitive sites.
This continues 2026's steady theme: the governance controls that make Copilot safe to switch on are increasingly built into the admin surface rather than bolted on afterwards.
What to do: Make sure your sensitivity labels are actually applied to confidential content. The Copilot block is only as good as your labelling. Review the per-site Copilot setting for sites that hold sensitive material, and pair it with a periodic SharePoint permissions audit.
Sources: Microsoft: What's new in Copilot in SharePoint, July 2026; Level Up M365: July 2026 roadmap updates
June 2026
UK: Every business must have a data complaints process from 19 June
The complaints-handling provisions of the Data (Use and Access) Act 2025 come into force on 19 June 2026. From this date, every UK organisation that handles personal data must have a formal process for dealing with data protection complaints from individuals, and the ICO has confirmed there is no exemption for small businesses.
In practice, the duty has four parts: provide a clear, accessible way for someone to raise a data protection complaint; acknowledge the complaint within 30 days; investigate it without undue delay while keeping the complainant informed; and communicate the outcome without undue delay. The procedure has to exist on paper before complaints arrive. It can't be improvised after the first one lands.
What to do: Publish a short complaints procedure (a paragraph on your privacy page plus an email address is enough for most small businesses), assign one named person or team to own it, and start a simple log that records when each complaint was received, acknowledged, investigated, and closed. This sits alongside your existing subject access request process. See boringdsar.com/guides/dsar-compliance for the related access-request obligations the same Act amends.
Source: ICO: How to deal with data protection complaints
Microsoft Purview tightens Copilot data protections
Microsoft shipped a round of Purview controls aimed squarely at the Copilot oversharing problem. Data Loss Prevention can now inspect Copilot prompts and web searches in real time, blocking Copilot from responding, or from using sensitive content as grounding, when a prompt itself contains regulated data. A new condition also lets administrators stop Copilot from using external email as grounding data, reducing the risk of prompt injection from untrusted senders. Alongside these, Purview added bulk remediation of overshared content and expanded Copilot dashboard analytics so admins can see usage and risk in one place. (The external-email control is in preview at launch.)
This is the continuation of a clear pattern through 2026: the governance gaps Copilot exposes are increasingly fixable from the admin centre rather than requiring third-party tooling. The bulk remediation feature in particular addresses the practical problem of finding thousands of overshared files but having no efficient way to fix them.
What to do: If you run Microsoft 365 Copilot, review the new DLP conditions for the Copilot location and enable prompt and external-email protections for your sensitivity labels. Run a bulk remediation pass on overshared content. If Copilot isn't deployed yet, treat these controls as part of the pre-rollout checklist. See data governance before AI and Microsoft 365 governance.
Source: Microsoft Learn: Learn about DLP for Microsoft 365 Copilot; Microsoft Learn: What's new in Microsoft Purview
SharePoint adds a Governance Reviews Dashboard
Microsoft began rolling out a Governance Reviews Dashboard (in private preview) that gives site owners a single place to see all pending governance tasks across the sites they own (inactivity checks, ownership validation, and site attestations) with due dates and enforcement status. It replaces the scatter of individual notification emails with one actionable surface, and where owners don't respond, sites can be automatically made read-only or archived.
For small businesses this matters because site attestation is the practical answer to permission sprawl: instead of an admin auditing every site, owners periodically confirm their site is still needed and its sharing settings are correct. The dashboard makes that recurring review something an owner can actually keep up with.
What to do: Once the dashboard reaches your tenant, set up recurring site attestation policies in the SharePoint admin center and decide your enforcement action for unattested sites (read-only is a safer default than auto-archive while owners get used to the process). Pair this with a periodic SharePoint permissions audit for the sites that hold sensitive content.
Source: Microsoft: What's new in content governance in SharePoint, OneDrive, and Teams for the AI era
Kentucky's privacy-assessment duty takes effect
The data protection assessment requirements of the Kentucky Consumer Data Protection Act apply to processing activities carried out on or after 1 June 2026. Businesses covered by the Act must document an assessment before high-risk processing: targeted advertising, selling personal data, certain profiling, and processing sensitive data.
Most genuinely small businesses fall below Kentucky's thresholds (controlling or processing data on 100,000+ residents, or 25,000+ with more than half of revenue from selling data), so this is context rather than an action item for the typical reader. It's worth noting as part of a wider 2026 trend: documented risk assessments are becoming standard across US state privacy laws. Connecticut, Utah, and Arkansas privacy provisions follow on 1 July 2026.
What to do: If you operate across multiple US states, check whether you meet any state's threshold rather than assuming small size exempts you. A single data inventory covering what you collect, why, and who you share it with is the document most of these assessments build on.
Sources: Akin Gump: Kentucky Data Protection Act, what businesses need to know; MultiState: Comprehensive privacy laws taking effect in 2026
Canada introduces Bill C-36 to overhaul federal privacy law
After years of false starts, the Canadian government introduced Bill C-36, the Protecting Privacy and Consumer Data Act, which received first reading on 15 June 2026. It is the successor to Bill C-27, which died when Parliament was prorogued in January 2025. C-36 is reported to carry forward the headline changes from the earlier Consumer Privacy Protection Act: substantially higher penalties (administrative penalties up to the greater of $10 million or 3% of global revenue, and fines up to the greater of $25 million or 5% for the most serious offences), treating children's data as sensitive by default, and a new right to delete personal data. It does not revive AIDA, the AI law bundled into C-27, so Canada still has no comprehensive AI statute.
For now, PIPEDA remains the federal law in force (maximum fine $100,000, for narrow offences), and Quebec's Law 25 continues to apply in full. Bill C-36 is at an early stage and could change substantially or stall.
What to do: Nothing urgent, since C-36 is not law yet. If you do business in Canada, keep building to current PIPEDA requirements; most of C-36 extends principles PIPEDA already contains. See our PIPEDA compliance guide.
Source: Parliament of Canada: Bill C-36 (LEGISinfo)
May 2026
EU provisionally agrees to delay high-risk AI Act deadlines
On 7 May 2026, negotiators from the Council, Parliament, and Commission reached a provisional agreement on the "Digital Omnibus", the first set of amendments to the EU AI Act since it was adopted in 2024. The headline change is timing relief: the compliance deadline for high-risk AI systems under Annex III is deferred from 2 August 2026 to 2 December 2027, and the obligation to machine-mark AI-generated synthetic content moves from August to 2 December 2026. The package also adds new prohibitions, including AI systems that generate non-consensual intimate imagery, from December 2026.
For businesses that deploy AI tools, this removes the near-term August 2026 pressure point, but "provisional" is the operative word. The agreement still needs formal adoption, and the underlying obligations have been postponed, not cancelled.
What to do: If you were preparing for an August 2026 high-risk deadline, you have more runway, but don't shelve the work. Most small businesses using off-the-shelf AI tools are deployers rather than providers; the governance foundations (knowing what your AI can access and what data it surfaces) matter regardless of the regulatory timeline. See the August 2025 entry below for the original timeline this amends.
Update (August 2026): The omnibus was formally adopted and entered into force on 27 July 2026. See the August 2026 entry above for the final dates.
Google Workspace adds an AI Control Center and AI-aware DLP
Google rolled out an AI control center for Workspace, a central place for admins to govern what generative AI and agents are allowed to access across Docs, Gmail, Drive, and other services. Organisations can now enable or disable specific data sources for AI features at the org level, and Data Loss Prevention rules can gate which data feeds AI. Google Vault retention and legal holds were also extended to cover the Gemini app, bringing AI interactions into the same eDiscovery and retention controls as the rest of Workspace.
This is the Google Workspace counterpart to the Purview controls Microsoft has been shipping for Copilot: the same recognition that AI features make existing access and sharing problems visible, and that governing them belongs in the admin console. For the substantial share of small businesses on Workspace rather than Microsoft 365, this is the first real set of native controls for AI data access.
What to do: If you run Google Workspace, review the AI control center, decide which services should feed AI features, and set DLP rules to keep sensitive content out of AI grounding. Extend Vault retention to the Gemini app so AI interactions fall under your existing retention policy.
Sources: Google Workspace Updates: Securely manage AI and agent access with the AI control center; Google Workspace Updates: Vault retention and holds for the Gemini app
New Zealand: new indirect-collection notification rule (IPP 3A) in force
On 1 May 2026, New Zealand's new Information Privacy Principle 3A came into force under the Privacy Amendment Act 2025. It requires any business that collects personal information about someone from a third party, rather than from the person directly, to take reasonable steps to make that person aware of the collection: what was collected, why, who holds it, and their access and correction rights. A generic "we may collect information from third parties" line in a privacy policy is no longer enough.
New Zealand's Privacy Act 2020 applies to businesses of all sizes (there is no small business exemption) and reaches overseas businesses operating in NZ. The change matters for anyone buying contact lists, using data brokers, or enriching customer records from outside sources.
What to do: If you collect personal information indirectly, add a notification step, such as an email or a clear notice covering the IPP 3A points. It applies to information collected on or after 1 May 2026. See our New Zealand Privacy Act guide.
Source: NZ Office of the Privacy Commissioner: IPP3A
April 2026
SharePoint external sharing moves to Entra B2B guest accounts
Microsoft is retiring the legacy SharePoint "one-time passcode" experience for external sharing and moving all SharePoint and OneDrive external sharing to Microsoft Entra B2B, where each external person is added as a guest account in your directory. Tenants could manually enable the integration through the end of April 2026; from May 2026 Microsoft began switching remaining tenants automatically, and the change can't be opted out of. External users without a B2B guest account will start seeing "access denied" on previously shared links from July 2026.
The upside is genuine governance: guest accounts give you a single, auditable list of every external person with access, conditional-access enforcement, and clean revocation, which is far better than anonymous passcode links that linger forever. The risk is disruption: a supplier, accountant, or client could lose access to shared files mid-2026 if they were never converted to a guest.
What to do: Run the external sharing report in the SharePoint admin center to see who has access through the old experience, and make sure those people have B2B guest accounts before July 2026 so nothing breaks. Review the guest list while you're there. It doubles as a permissions audit.
Source: Microsoft Learn: SharePoint and OneDrive integration with Microsoft Entra B2B (FAQ)
Purview DLP can now target files by created or modified date
Microsoft Purview Data Loss Prevention for SharePoint and OneDrive added "file created" and "last modified" date conditions, letting administrators scope DLP and auto-labelling policies by a document's age. You can apply stricter protection to recently edited files, or sweep up stale content that hasn't been touched in years.
It's a small change with a practical payoff for small teams: core SharePoint and OneDrive DLP is included in Microsoft 365 Business Premium and E3 (not just E5), so date-aware policies are within reach without an enterprise licence.
What to do: If you already run a DLP policy on SharePoint or OneDrive, check whether a "last modified" condition would help you focus protection on active sensitive files, or flag stale ones for review and archival.
Source: Microsoft Learn: What's new in Microsoft Purview
March 2026
Australia: 100,000+ small businesses lose privacy exemption from July
Australia's privacy reforms will strip the small business exemption from businesses in newly regulated industries starting 1 July 2026. Lawyers, accountants, real estate agents, conveyancers, and dealers in high-value goods (the "tranche 2" entities brought under anti-money-laundering rules) will be required to comply with the Privacy Act for the first time, regardless of revenue. Previously, businesses with annual turnover under $3 million were exempt.
This is a significant expansion of privacy obligations for affected small businesses. They will need to meet the same data handling, breach notification, and individual rights requirements as larger organisations, including responding to access requests and maintaining records of personal information handling.
What to do: If your business falls into one of the newly regulated categories, start preparing now. At minimum: conduct a data inventory, draft a privacy policy, establish a process for handling access requests, and train staff on the basics. The OAIC has begun publishing guidance for newly covered businesses ahead of the July deadline.
Source: OAIC: Know your privacy obligations under the AML/CTF Act
SharePoint sharing links now support automatic expiration
Microsoft rolled out the ability to set organisation-wide expiration policies for "People in your organisation" sharing links in SharePoint and OneDrive. Administrators can now configure a maximum lifespan for internal sharing links, after which access is automatically revoked.
Previously, internal sharing links lived forever, and anyone with the link retained access indefinitely. This was one of the biggest sources of permission sprawl and a core reason permissions audits consistently find over-shared content.
What to do: Set an expiration policy in the SharePoint admin center. A 90-day default is a reasonable starting point for most businesses: long enough for active collaboration, short enough to limit lingering access.
Source: Microsoft 365 Roadmap: Feature ID 553220 (expiration for "People in your organization" links)
EDPB launches 2026 coordinated enforcement on transparency
The European Data Protection Board announced its 2026 Coordinated Enforcement Framework (CEF) action, with 25 Data Protection Authorities across Europe jointly assessing compliance with GDPR transparency obligations under Articles 12 to 14. This follows previous coordinated actions on the right of access (2024) and the role of data protection officers (2023).
The focus on transparency means regulators will be scrutinising privacy notices, information provided at the point of data collection, and how clearly organisations communicate their data practices. For businesses serving EU customers, including those in the UK, Ireland, and other English-speaking jurisdictions, unclear or outdated privacy notices are now a higher enforcement priority.
What to do: Review privacy notices and data collection forms. Ensure they clearly state what data is collected, why, how long it is kept, and who to contact. If the privacy policy has not been updated since 2018, it is overdue.
Source: EDPB: CEF 2026 coordinated enforcement action on transparency and the right to information
February 2026
Microsoft retires standalone SharePoint and OneDrive plans
Microsoft announced it will retire standalone SharePoint Online Plan 1 and Plan 2, and OneDrive for Business Plan 1 and Plan 2 licenses. Sales cease on 31 May 2026, with no contract renewals after January 2027. Service continues until December 2029.
This pushes all customers toward Microsoft 365 suite licenses, which include more storage but at higher per-user costs. For small businesses currently on standalone SharePoint plans, this is a forced migration that requires planning.
What to do: Review your current SharePoint and OneDrive licensing. If you are on standalone plans, start evaluating Microsoft 365 Business Basic ($6/user/month) or Business Standard ($12.50/user/month) as replacements. Factor in total cost of ownership including the additional services bundled in suite licenses.
Source: Microsoft: Partner Center announcements, January 2026
NIST launches AI Agent Standards Initiative
In February 2026, NIST officially released the AI Agent Standards Initiative, marking the beginning of standardisation work for AI agents, meaning systems that can take autonomous actions on behalf of users. It is run through NIST's Center for AI Standards and Innovation and builds on NIST's broader AI standards work, including the AI Risk Management Framework (AI RMF 1.0).
For businesses deploying AI tools like Microsoft Copilot or third-party AI agents, these emerging standards will shape future compliance expectations. Data governance foundations (knowing where your data is, who can access it, and how it is classified) are prerequisites for any AI agent deployment.
What to do: Review the NIST AI RMF 1.0 and consider how your data governance practices align with its risk management principles. Organisations with strong data governance will be better positioned when formal AI agent standards arrive.
Source: NIST: Announcing the AI Agent Standards Initiative
January 2026
Three more US states' privacy laws take effect
On 1 January 2026, comprehensive consumer privacy laws took effect in Indiana, Kentucky, and Rhode Island, bringing the number of US states with comprehensive privacy laws to 20. Each gives residents rights to access, correct, delete, and opt out of the sale of their personal data, and requires covered businesses to post clear privacy notices and honour those requests.
Most carry the now-familiar thresholds (typically processing the data of 100,000+ state residents, or 25,000+ while earning significant revenue from selling data), so the smallest businesses often fall outside them. But the direction of travel is what matters: the patchwork keeps growing, and a business serving customers in several states can be caught by one law even when it's exempt under another.
What to do: If you sell to consumers across US states, don't assume your size exempts you everywhere. Check each state where you have meaningful customer numbers. A single data inventory and a clear, current privacy notice cover most of what these laws require.
Source: IAPP: New year, new rules (US state privacy requirements coming online as 2026 begins)
December 2025
Trump signs AI executive order targeting state AI laws
On 11 December 2025, President Trump signed an executive order titled "Ensuring a National Policy Framework for Artificial Intelligence." The order directs the Department of Justice to establish an AI Litigation Task Force to challenge state AI laws deemed inconsistent with federal policy, and threatens federal funding restrictions for states with "onerous" AI regulations.
This creates uncertainty for businesses navigating the growing patchwork of state-level AI laws. While the order aims to simplify compliance by establishing a uniform federal framework, the transition period may produce conflicting requirements as state and federal policies are reconciled.
What to do: Track which state AI laws may be affected by federal preemption. If your organisation operates across multiple US states, a unified approach to AI governance is increasingly important.
Source: The White House: Presidential action on national AI policy (11 December 2025)
November 2025
Microsoft Ignite 2025: Copilot governance and security updates
At Ignite 2025, Microsoft announced expanded security and governance tools for Microsoft 365 Copilot. Key updates include Microsoft Purview Data Loss Prevention (DLP) for Copilot reaching general availability, blocking Copilot from processing files and emails with specific sensitivity labels, and expanded data risk assessments with item-level investigation and bulk remediation of overshared links.
These tools address the oversharing problem that Copilot has made impossible to ignore. Concentric AI's Data Risk Report found that 16% of business-critical data is overshared on average, totalling roughly 802,000 files per organisation at risk. When Copilot can surface any content a user has access to, broadly shared files become a liability.
What to do: If you use Microsoft 365 Copilot, enable Purview DLP policies to restrict Copilot's access to sensitive content. Run a data risk assessment from the Microsoft 365 admin centre to identify overshared files and sites.
Sources: Microsoft: Security and governance innovations for Microsoft 365 Copilot from Ignite; Concentric AI: Data Risk Report (oversharing statistics)
Microsoft 365 Archive eliminates reactivation fees
Microsoft eliminated reactivation fees for Microsoft 365 Archive content effective 31 March 2025, making it cheaper to move inactive SharePoint content to cold storage and bring it back when needed. Archive storage costs up to 75% less than standard SharePoint storage ($0.05/GB/month versus the $0.20/GB/month overage rate).
For organisations hitting SharePoint storage limits, Archive provides a way to reduce costs without deleting data. File-level archiving, which allows individual documents to be archived without taking entire sites offline, reached public preview at the end of March 2026, with GA targeted for July 2026.
What to do: Identify inactive SharePoint sites consuming storage. Move them to Microsoft 365 Archive to free up pooled storage and avoid the $0.20/GB/month overage charges. Each Microsoft 365 tenant gets 1 TB plus 10 GB per licensed user of pooled SharePoint storage, and anything above that costs real money.
Source: Microsoft: Microsoft 365 Archive eliminates reactivation fees by March 31, 2025
August 2025
EU AI Act: General-purpose AI obligations take effect
The EU AI Act's obligations for general-purpose AI (GPAI) models took effect on 2 August 2025. Providers of GPAI models must now comply with transparency requirements including maintaining technical documentation, publishing content usage policies, and implementing copyright compliance measures.
The next major milestone was originally 2 August 2026, when obligations for high-risk AI systems in Annex III and transparency rules under Article 50 were due to come into force. Penalties for non-compliance are significant: up to €35 million or 7% of worldwide turnover for prohibited practices.
Update (May 2026): EU negotiators have provisionally agreed to defer the high-risk (Annex III) deadline to December 2027. See the May 2026 entry above.
What to do: If your organisation develops or deploys AI systems that serve EU users, review the EU AI Act risk classification. Most businesses using off-the-shelf AI tools like Copilot are deployers rather than providers, but deployers of high-risk AI systems will have their own obligations once the deadline arrives.
Source: European Commission: Regulatory framework on AI
Late 2024 to Early 2025
Trump rescinds Biden AI executive order
On 20 January 2025, President Trump rescinded Executive Order 14110, Biden's "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence" order from October 2023. Three days later, he signed Executive Order 14179, "Removing Barriers to American Leadership in Artificial Intelligence," signalling a shift from oversight and risk mitigation toward deregulation and innovation promotion.
For businesses, this means less federal guidance on AI risk management but potentially fewer compliance obligations at the federal level. State-level AI laws continue to develop independently, and the EU AI Act applies regardless of US federal policy.
Source: The White House: Removing Barriers to American Leadership in Artificial Intelligence (EO 14179)
SharePoint Advanced Management bundled with Copilot licenses
From January 2025, Microsoft began bundling SharePoint Advanced Management (SAM) features with Microsoft 365 Copilot licenses. SAM provides data access governance reports, site access reviews, and oversharing detection, tools that help organisations identify and remediate the data governance gaps that Copilot makes visible.
Previously a separate add-on, SAM's inclusion with Copilot licenses reflects Microsoft's acknowledgement that AI readiness requires better data governance. Site access reviews allow administrators to delegate the review of overshared sites to site owners directly.
What to do: If you have Copilot licenses, enable SharePoint Advanced Management and run data access governance reports. These reports identify sites with broadly shared content, the same content Copilot can surface to any user with access.
Source: Microsoft Learn: SharePoint Advanced Management licensing
EU AI Act: Prohibited AI practices take effect
The first binding obligations under the EU AI Act took effect on 2 February 2025, prohibiting AI systems that pose unacceptable risks. These include AI systems that use subliminal manipulation techniques, exploit vulnerabilities of specific groups, enable social scoring by public authorities, and deploy real-time biometric identification in public spaces (with limited exceptions).
While most small businesses are unlikely to deploy prohibited AI systems, the broader message is clear: AI governance is becoming a regulatory requirement, not a best practice.
Source: European Commission: Guidelines on prohibited AI practices
Last updated: 6 September 2026. This page is updated regularly as data governance developments occur. Bookmark it and check back for the latest changes.