Three months into enforcement, the organisations working hardest on GDPR collaboration data are the ones that have already had a subject access request land on a messaging platform. Everyone else is still treating chat as exhaust. It is not exhaust. Chat is personal data, it has been personal data since the day the platform was switched on, and almost nobody made a deliberate decision about how long to keep it. That omission is not a documentation gap. It is a retention surface that grows every day, contains the least considered writing anybody in the company does, and is now searchable by people whose interests are not aligned with the employer's.
What is actually in a collaboration platform
Start with the obvious layer. Messages name people, describe their performance, record their absences, speculate about their intentions and occasionally discuss their health. Direct messages between two colleagues about a third are personal data concerning all three, and the third one has rights over it. Then the layer nobody inventories. Presence and status history. Who is in which channel. Message timestamps that describe working patterns, including patterns an employee has not disclosed. Reactions, which are small structured opinions attached to a named person. Read receipts where they exist. Call and meeting logs with durations and participants. Files shared into channels, which are frequently the same HR and finance attachments that are carefully controlled in their system of record and entirely uncontrolled here. Then the layer that is genuinely new. The analytics products that sit on top of collaboration platforms and describe how individuals spend their time, who they interact with, how much of their week is meetings, how quickly they respond after hours. Microsoft has been shipping this capability for two years and most tenants that own it have never examined what it computes. A dashboard describing an individual's working patterns is profiling, whatever the product marketing calls it, and the fact that it was included in a licence bundle is not a lawful basis. A reasonable working assumption is that a collaboration platform holds the widest range of personal data categories of any system in the business, held in the least structured form, with the weakest retention discipline and the highest proportion of content the organisation would not choose to defend.
Three obligations that bite immediately
Access. A subject access request covers personal data concerning the requester, wherever it sits, subject to the usual limits. Nobody asking for their data is required to know your systems map. The question is not whether chat is in scope but whether you can search it, filter it for other people's personal data, and produce it inside one month. The first organisation in any market to be asked will discover that the platform search built for finding last week's decision is not an extraction tool, and that reviewing six years of channel history for third-party content is a manual exercise with an unpleasant hourly rate. Retention. Personal data must not be kept longer than necessary for the purpose. The default configuration of most collaboration platforms is to keep everything indefinitely, because indefinite retention is a product feature and deletion is a support cost. That default was chosen by a vendor, not by the controller, and the controller is the one who has to justify it. "It is useful sometimes" is a poor answer when the content in question is four years of informal commentary about named employees. Transparency and basis. Employees are entitled to know what is collected about them and why. Where that extends to analytics on individual working patterns, the standard analysis is that consent from an employee is not freely given, because the power imbalance makes refusal costly. That pushes most employers onto legitimate interests, which requires a balancing exercise that has actually been done, written down, and honestly reached. In several European jurisdictions there is a further step, because employee monitoring is subject to national employment provisions and, in practice, to works council agreement. Organisations rolling out analytics across a European footprint this year have found that the negotiation, not the deployment, is the project.
Deletion is harder than it looks
The platform will let you delete a message. What it does with copies is a separate question, and the honest answer for most deployments is that nobody has tested it. Exports taken by users. Compliance archives configured by legal three years ago and forgotten. Third-party backup products bolted on because the platform's own retention felt risky. Integrations that copy messages into ticketing systems, project tools and notification logs. Mobile devices holding local caches. Email notifications containing the full message body sitting in inboxes that have their own retention policy. Deleting the original in these conditions produces a true statement about one system and a false statement about the organisation. The related trap is the difference between deleting content and deleting an account. Removing a leaver's licence commonly leaves their messages in place, attributed to a name, while removing their data can strip context from conversations other people still rely on. Both outcomes are defensible. Neither is defensible if it happened by accident.
| Copy surface | Review question |
|---|---|
| Exports and archives | Who keeps exported or compliance copies and for what purpose? |
| Third-party backups | Does the backup retention and deletion routine match the policy? |
| Integrations | Which ticketing, project or notification systems receive message content? |
| Mobile caches | What remains on managed or personal devices after an account leaves? |
| Email notifications | Does an inbox retain message bodies under a different policy? |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for a Collaboration Compliance Review
- Make retention a decision, not a default. Pick a period, apply it to messages and to files separately, and write down the reasoning. A short default with explicit exceptions is easier to defend than an indefinite default with good intentions.
- Test a subject access extraction before you receive one. Pick a volunteer, run the export, time it, and look at how much third-party content has to be redacted. The result reprices your retention decision immediately.
- Inventory the copies. Archives, backups, integrations, exports, notification emails. Deletion claims are only as true as the least controlled copy.
- Decide what you are doing with analytics, deliberately. If individual-level insights are switched on, complete the balancing assessment, restrict who can see them, and tell people. If nobody will defend it, turn it off; an unused capability is a liability with no offsetting benefit.
- Write the rule about direct messages down. Whether they are searched, under what circumstances, and by whom. Employees behave differently when they know, which is the point.
- Govern external participants explicitly. Guests and shared channels mean your platform holds personal data belonging to other companies' staff, sometimes under contracts that specify how it is handled.
- Give the platform an owner who is not just an administrator. Channel creation, guest approval, retention, data requests and integrations need one accountable name. Most deployments have three part-time owners and no decision-maker.
- Fix the leaver process for collaboration specifically. The identity is deprovisioned quickly; the messages, the files, the caches on a personal phone and the third-party integrations authorised under that account are a separate list that usually does not exist.
The Regional Angle
The largest collaboration archive in most organisations here is not the collaboration platform. It is WhatsApp, on personal phones, containing supplier negotiations, approvals, staff matters and customer commitments, owned by nobody and retained forever. That is a governance problem rather than a platform one, and it has a specific shape in this market: when an employee leaves, the record leaves with them, and when a dispute reaches a labour authority or a court, both sides produce screenshots. Any collaboration compliance review that stops at the sanctioned tool is reviewing the smaller half of the estate. The language mix compounds the extraction problem. Content moves between English, Arabic, Hindi, Urdu, Malayalam and Tagalog across a single operational channel, sometimes within a message, often transliterated. Search that performs adequately in English can miss most of a conversation, and any commitment to find all personal data concerning an individual has to survive that reality. It is a reason to keep less, not a reason to search harder. The basis question is also sharper here than the imported templates suggest. Where residency status is tied to employment, the argument that an employee's consent to monitoring is freely given is weaker than it is in Europe, not stronger. That does not make monitoring unlawful; it makes consent the wrong instrument and a documented, proportionate legitimate interest the only workable one. On location, the position this year is that collaboration workloads sit outside the region for most tenants. Microsoft has announced data centres in the UAE but they are not open yet, so organisations with residency commitments in customer contracts or sector rules are relying on contractual mechanisms rather than geography, and should know which. Add the usual multi-entity complication: one tenant covering mainland, free zone and DIFC or ADGM entities means one retention configuration spanning several different legal baselines, so the honest question is which entity's obligation is the strictest and whether the shared setting meets it.
The objection worth taking seriously
The objection is that chat is noise and treating it as a record is a category error. Most messages are logistics, jokes and links. Subjecting them to formal retention, indexing and review turns ephemeral conversation into a discoverable corpus, which is worse for everyone including the employees the regulation is meant to protect. The compliance-maximalist answer of retaining and indexing everything actively creates the liability it claims to manage. The harder version is practical. Subject access requests landing on chat are rare today. The volume is dominated by ex-employees in disputes, and those are usually visible in advance. Spending a quarter building extraction capability for an event that occurs twice a year is poor allocation compared with almost anything else on the security backlog. Both points are right, and they lead to the same conclusion rather than to inaction. The correct response to "this is noise" is not better search, it is less retention. Keeping ninety days or twelve months by default eliminates most of the access burden, most of the discovery exposure and most of the argument, at a cost that is genuinely contested only because teams use chat as a knowledge base it was never designed to be. That is the real trade, and it belongs to the business rather than to legal: decide what you are prepared to lose, and then stop keeping the rest.
Common Questions
Are private direct messages in scope of a subject access request?
Personal data concerning the requester is in scope regardless of which channel it sits in, including messages between two other people that discuss them. The practical constraints are the rights of those other individuals, which require redaction rather than refusal, and the requirement that the request be reasonably searchable. Short retention narrows the problem far more effectively than any exemption argument.
Can we monitor collaboration activity for productivity?
Aggregate, anonymised measurement of how teams work is relatively straightforward. Individual-level profiling is not, and it requires a lawful basis, a completed balancing assessment, transparency to the people measured and, in parts of Europe, worker representative agreement. The question worth asking first is what decision the data will inform, because most answers to that question do not require individual attribution at all.
How long should we keep messages?
There is no prescribed period, and the reasoning matters more than the number. A defensible pattern is a short default for general channels, a longer period where a specific obligation applies such as regulated communications or project records, and an explicit hold process for disputes. What is not defensible is indefinite retention chosen by nobody.
What should we expect over the next twelve months?
Expect retention controls and compliance features to move up the vendor roadmaps quickly, since every enterprise buyer in Europe is now asking the same questions at renewal. Expect the first uncomfortable cases to come from employment disputes rather than regulators, because that is where chat archives are already being read line by line. Expect workplace analytics to attract more scrutiny than messaging itself, and expect at least one high-profile argument about it involving worker representatives. And expect the gap between sanctioned platforms and consumer messaging to become the harder problem, because the compliance work will be done where the controls exist and the risk will remain where they do not.
Collaboration Compliance Review — we look at what your messaging estate actually holds, what you could produce if asked, and what you should stop keeping, including the channels that never appeared on anybody's system inventory.
