Policy-based review, with HR and DPO overlay

Communication Compliance

Configure it so it has a purpose, a reviewer, and a fairness path — not a licence to watch everyone.

Microsoft Purview Communication Compliance for UK organisations

A purpose, a reviewer, and a limit

Microsoft Purview Communication Compliance can detect communications that may breach a written policy — for example harassment, threats, or sharing of regulated information. It is not “we spy on staff”. Enabling every template for the whole tenant is how these programmes lose trust and, in a UK organisation, how they become hard to defend.

Ghani Governance configures the product and the overlay around it: which scenarios justify a policy, who may see a match, how HR is involved, and how the DPO can explain the purpose. Product reference: Microsoft’s Communication Compliance documentation.

What we set up

Written scenarios

Each policy has a purpose a non-specialist can repeat. No “monitor everything in case”.

Policy configuration

Scope, conditions and reviewers aimed at usable cases, not volume.

Reviewer access

A small named set. Matches are not a spectator sport for IT.

HR and DPO overlay

Fairness, retention of investigative material, and a path that can be explained if challenged. The DPO is in the design, not a slide at the end.

Testing and tuning

False positives reviewed before the population grows.

All Purview services · Insider Risk Management · UK and Greater Manchester service area

Process

Define scenarios

Behaviours that justify a policy, agreed with HR and the DPO.

Prerequisites

Licensing, permissions, related DLP or Insider Risk controls.

Pilot

One scenario or a limited population first.

Review quality

Matches, false positives, and whether reviewers can actually act.

Govern

Ownership, access reviews, change control.

Communication Compliance questions

Is this staff surveillance?

It must not be. Communication Compliance is for defined policy scenarios — for example harassment, threat, or unauthorised sharing of sensitive information — with named reviewers, a purpose, and HR/DPO overlay. Broad “read everyone’s mail” configurations are how these programmes lose legitimacy.

How is this different from DLP or Insider Risk?

DLP looks at sensitive content leaving a channel. Insider Risk looks at patterns of user activity. Communication Compliance reviews the content of communications against policy. They can share signals; they are not substitutes, and they should not all be pointed at the same population without a reason.

Who should be allowed to review matches?

A small, named set — typically a combination of HR, employee relations, legal or compliance, not the whole security team. We design that access with the DPO in the conversation.

Book a discovery workshop

A scoping conversation about what you need to protect, what is already configured, and what must not break.

Request a workshop Call 0161 568 3030