Separating client data properly in SharePoint

    Back to Blog
    Strategy

    Separating client data properly in SharePoint

    How law firms can structure SharePoint access, restrict external sharing, and license Microsoft Purview Audit with the correct retention periods.

    July 10, 20269 min read
    Marcel Haas

    Marcel Haas

    Solution Architect, CEO

    marcel.haas@cnext.ch

    Quick Answer

    How law firms can structure SharePoint access, restrict external sharing, and license Microsoft Purview Audit with the correct retention periods.

    Technical review date: 8 September 2026. Professional secrecy and data protection require controls appropriate to the risk. SharePoint can support those controls, but its structure alone does not make a repository legally compliant. Legal and technical assessment, clear ownership, and effective controls remain necessary.

    What must be separated

    Article 321 of the Swiss Criminal Code protects the professional secrecy of the professions it lists. Swiss data protection law requires appropriate technical and organisational measures. This does not literally mean that nobody internally may ever see data from different matters; access must be defined by role, confidentiality obligations, and need to know. Sources: Fedlex – Article 321 SCC and Fedlex – Article 8 FADP (accessed 8 September 2026).

    SharePoint architectures

    Separate sites with their own groups and restrictive external sharing reduce accidental overlap. They create a logical permission boundary, not complete technical isolation comparable to separate Microsoft 365 tenants. Tenant administrators, compliance functions, and misconfigured sharing still need to be considered.

    Metadata and views are not security boundaries. A central library is appropriate only if every authorised person may see every matter stored there. Where access differs by matter, separate sites or libraries with well-managed groups are usually easier to review than large numbers of item-level permissions.

    Microsoft recommends managing permissions for group-connected team sites through the Microsoft 365 group. External sharing is controlled at both organisation and site level, with the more restrictive setting taking effect. Source: Microsoft Learn – Sharing and permissions in SharePoint (accessed 8 September 2026).

    Controls, not absolute promises

    • Use role- and matter-based groups; avoid or document individual permissions.
    • Manage guests with expiry, regular access reviews, and a tested offboarding process.
    • Include sharing links, sync, downloads, and administrative roles in the protection design.
    • Define retention and deletion by record type and legal basis rather than applying one period to every client document.

    Purview Audit: 180 days is the standard default

    The previous 90-day statement is outdated. Microsoft states that Audit (Standard) records generated since 17 October 2023 are retained for 180 days by default. Audit (Premium) retains Exchange, SharePoint, OneDrive, and Entra audit records for appropriately licensed users for one year by default; records for non-E5 and guest users remain at 180 days. Longer and ten-year retention have additional policy and licensing requirements. Audit records supported events, not indiscriminately “every file operation.” Source: Microsoft Learn – Audit log retention policies (accessed 8 September 2026).

    Conclusion

    SharePoint can enable reviewable client separation when information architecture, groups, external sharing, audit, and recertification are designed together. It cannot provide an automatic guarantee of compliance or complete isolation.

    Review your protection needs and permission model

    SharePointComplianceSecurity
    Teilen:

    This article was created with the support of AI and reviewed by our team. We use AI tools to produce high-quality content efficiently — the editorial responsibility always lies with our experts.

    Marcel Haas

    Marcel Haas

    Solution Architect, CEO

    6x Microsoft Applied Skills

    Have questions about this topic?

    Our experts are happy to advise you – free and without obligation.