Technical review date: 8 September 2026. Professional secrecy and data protection require controls appropriate to the risk. SharePoint can support those controls, but its structure alone does not make a repository legally compliant. Legal and technical assessment, clear ownership, and effective controls remain necessary.
What must be separated
Article 321 of the Swiss Criminal Code protects the professional secrecy of the professions it lists. Swiss data protection law requires appropriate technical and organisational measures. This does not literally mean that nobody internally may ever see data from different matters; access must be defined by role, confidentiality obligations, and need to know. Sources: Fedlex – Article 321 SCC and Fedlex – Article 8 FADP (accessed 8 September 2026).
SharePoint architectures
Separate sites with their own groups and restrictive external sharing reduce accidental overlap. They create a logical permission boundary, not complete technical isolation comparable to separate Microsoft 365 tenants. Tenant administrators, compliance functions, and misconfigured sharing still need to be considered.
Metadata and views are not security boundaries. A central library is appropriate only if every authorised person may see every matter stored there. Where access differs by matter, separate sites or libraries with well-managed groups are usually easier to review than large numbers of item-level permissions.
Microsoft recommends managing permissions for group-connected team sites through the Microsoft 365 group. External sharing is controlled at both organisation and site level, with the more restrictive setting taking effect. Source: Microsoft Learn – Sharing and permissions in SharePoint (accessed 8 September 2026).
Controls, not absolute promises
- Use role- and matter-based groups; avoid or document individual permissions.
- Manage guests with expiry, regular access reviews, and a tested offboarding process.
- Include sharing links, sync, downloads, and administrative roles in the protection design.
- Define retention and deletion by record type and legal basis rather than applying one period to every client document.
Purview Audit: 180 days is the standard default
The previous 90-day statement is outdated. Microsoft states that Audit (Standard) records generated since 17 October 2023 are retained for 180 days by default. Audit (Premium) retains Exchange, SharePoint, OneDrive, and Entra audit records for appropriately licensed users for one year by default; records for non-E5 and guest users remain at 180 days. Longer and ten-year retention have additional policy and licensing requirements. Audit records supported events, not indiscriminately “every file operation.” Source: Microsoft Learn – Audit log retention policies (accessed 8 September 2026).
Conclusion
SharePoint can enable reviewable client separation when information architecture, groups, external sharing, audit, and recertification are designed together. It cannot provide an automatic guarantee of compliance or complete isolation.
