A CRM holds some of the most sensitive personal data a firm possesses — customer identities, contact histories, sometimes financial and behavioural detail — which makes where that data lives and how it is governed a compliance question, not just a configuration one. Dynamics 365 is a strong platform for a regulated firm, particularly a Microsoft-centric one, but “it runs on Microsoft’s cloud” is not the same as “it satisfies our data-residency and GDPR obligations.” The gap between those two statements is where firms get caught, usually because no one asked the residency question before the data was already in the system.
Why “Microsoft, therefore compliant” is a trap
Microsoft provides the tools to run Dynamics 365 compliantly; it does not make your specific configuration compliant automatically. Data residency depends on where you provision the environment and how the service’s supporting flows behave — backups, replicas, and the telemetry and support access that may reach beyond your chosen region. GDPR compliance depends on your lawful basis, your handling of data-subject rights within the CRM, your retention, and your control of who can access what. These are your responsibilities under the shared-responsibility model, and a default deployment that no one examined for residency and governance can be storing or moving regulated data in ways your obligations do not permit.
The questions that matter
- Where is the data provisioned, and where does it actually go? Not just the primary region, but backups, replicas, and any support or telemetry flows that could take data elsewhere. For a GCC firm with in-country requirements, or an EU firm with transfer constraints, this is decisive.
- Is access least-privilege and evidenced? Who can see and export the customer data, is that justified, and can you show a supervisor the controls? CRM data is a common over-exposure.
- Are data-subject rights operable in the CRM? Access, erasure and rectification have to be executable against the data as it actually sits in Dynamics, including in integrated systems.
- What is the retention, and is it enforced? CRM data accumulates indefinitely by default; a compliant posture requires a retention policy the system actually applies.
Getting it right
- Decide residency before deployment. Provision the environment against your residency obligations, and confirm contractually where all copies and flows of data reside — retrofitting this after the data is in is far harder.
- Govern access as regulated data. Apply least privilege, review it, and be able to evidence it, because CRM access sprawl is a predictable audit finding.
- Make rights and retention operational. Build the data-subject-rights and retention capabilities into how the CRM runs, not as an afterthought when a request or a regulator arrives.
- Map the integrations. CRM data flows out to marketing, analytics and support tools; the residency and governance questions follow the data wherever it goes.
Dynamics 365 can absolutely serve a regulated firm well, but only if the residency and GDPR questions are answered deliberately rather than assumed away because the platform carries a trusted name. The firms that stay clear of trouble treat their CRM as the regulated-data system it is — deciding where the data lives, governing who reaches it, and proving both — rather than discovering, in an audit or a data-subject request, that “it’s Microsoft” was never the answer to the question the regulator was asking.
Free · 4 minutes
Do you actually know what you are running — and what it is about to cost you?
Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.
Who this is for
This reading is for:
- CTOs and DPOs running or considering Dynamics 365 for regulated data
- Compliance leads mapping where CRM data actually lives
- Firms in the EU or GCC with residency obligations on customer data
- Boards who assume “it’s Microsoft, so it’s compliant”
Sixteen Pillars helps firms run Dynamics 365 as the regulated-data system it is – deciding where data lives, governing who reaches it, and proving both. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming