How to Respond to Data Subject Requests (DSR) Using Microsoft Purview eDiscovery
Your company is subject to GDPR and must be able to respond to data subject requests (DSRs) by finding all personal data of a specific user across Microsoft 365. Which Microsoft Purview solution should you use?
Quick Answer
The answer is Microsoft Purview eDiscovery (Standard or Premium). This is the correct choice because eDiscovery is specifically designed to respond to data subject requests (DSRs) in Microsoft 365 by searching for and exporting personal data across Exchange, SharePoint, OneDrive, and Teams, fulfilling GDPR obligations to locate all content related to a specific user. On the SC-900 exam, this question tests your ability to distinguish between Purview solutions: eDiscovery handles content search for DSRs, while Communication Compliance monitors policy violations, Audit logs track activities, and Privileged Access Management secures admin roles—common traps that confuse monitoring or logging with actual data retrieval. A helpful memory tip is to think of “eDiscovery” as “e-Discover the data” for DSRs, since it directly finds and exports personal information, unlike tools that only watch or record actions.
⚠ Common exam trap
Many exam-takers confuse Audit logs (which show who did what) with the actual content search needed for DSRs, mistakenly thinking Audit can retrieve personal data when it only provides metadata about actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
eDiscovery (Standard or Premium)
eDiscovery (Standard or Premium) is the correct solution because it is specifically designed to search for and export content across Microsoft 365 workloads (Exchange, SharePoint, OneDrive, Teams) to fulfill data subject requests (DSRs) under GDPR. It allows you to create a case, define a search query for a specific user's personal data, and export the results for review and action, directly supporting the right to access and erasure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance detects policy violations in messages and Teams conversations, scanning for risky or inappropriate content rather than compiling everything belonging to one person. It is tempting because it also searches Microsoft 365 communications, but would be correct for regulatory conduct monitoring, not GDPR data subject requests.
- ✓
eDiscovery (Standard or Premium)
Why this is correct
eDiscovery searches across Microsoft 365 workloads—Exchange, SharePoint, OneDrive, Teams—to locate and export content matching a data subject's identity. This supports GDPR DSR fulfilment by identifying all personal data for a specific user, which retention or DLP policies cannot do.
- ✗
Privileged Access Management
Why it's wrong here
Privileged Access Management governs just-in-time elevation and approval workflows for administrative roles, holding no index of user content to search. It is tempting because both sit within Microsoft Purview and address insider risk, but PAM would be correct for controlling standing admin access, not locating a data subject's personal data.
- ✗
Audit (Standard or Premium)
Why it's wrong here
Audit records activity events such as who accessed what and when, but does not locate and return the content items themselves for a subject. It is tempting because audit logs can show where a user's data was touched, yet Audit would be correct for investigations and forensic timelines, not DSR discovery.
Go deeper
Related to this question
Learn chapter
DLP Policies for Microsoft Teams
Key term
eDiscovery
eDiscovery is the process of identifying, collecting, and producing electronic information for legal cases or investigations.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has been fined for failing to respond to a data subject access request (DSAR) within the required timeframe. The compliance team needs to streamline the process of identifying and exporting personal data when a DSAR is received. Which Microsoft Purview solution should they use?
medium- A.Microsoft Purview Compliance Manager
- B.Microsoft Purview Communication Compliance
- ✓ C.Microsoft Purview eDiscovery (Premium)
- D.Microsoft Purview Data Lifecycle Management
Why C: Microsoft Purview eDiscovery (Premium) is the correct solution because it provides the case management, search, hold, and export capabilities specifically designed to identify and collect responsive content for legal and regulatory requests, including DSARs. Its ability to search across Microsoft 365 workloads, apply advanced conditions, and export data in a review-ready format directly addresses the need to streamline DSAR response. Compliance Manager, by contrast, is an assessment and improvement tool, not a data discovery engine.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.