Microsoft Purview Information Protection: A Practical Data Classification Guide for Canadian SMBs
Most personal information stored in Microsoft 365 tenants is invisible to the organization that holds it. Email attachments containing client financial data, SharePoint sites with employee Social Insurance Numbers, Teams chats with medical details — the content is there, it is searchable, and in a breach scenario it is subject to mandatory notification under PIPEDA. The problem is that most Canadian SMBs have no programmatic way to know what sensitive information they hold, where it lives, or who can access it.
Microsoft Purview Information Protection changes that. It is the data classification and data loss prevention (DLP) layer built into Microsoft 365, and it is available — at least in its most useful form for SMBs — under licences that most Canadian organizations already hold. This guide explains what it does, what PIPEDA requires you to demonstrate, what licensing actually unlocks for an organization under 300 employees, and how to implement it in four practical stages.
Why Unclassified Data Is a Breach Liability
The Office of the Privacy Commissioner of Canada 2025–2026 Annual Report recorded almost 700 breach reports from businesses, affecting more than 20 million Canadians — and that figure counts only organizations that actually reported. PIPEDA complaints to the OPC rose 109 percent year-over-year, driven in part by AI-enhanced awareness of privacy rights among Canadians. The report, titled "Championing Privacy in the Age of AI," was presented to Parliament in June 2026.
The financial exposure is substantial. The IBM 2025 Cost of a Data Breach Report for Canada puts the average Canadian breach at CA$6.98 million — a 10.4 percent increase from 2024. Phishing-initiated breaches averaged CA$7.91 million. The CIRA 2025 Cybersecurity Survey found that 42 percent of Canadian organizations experienced a breach of customer or employee data in the past 12 months.
When a breach occurs, one of the first questions from the OPC and from legal counsel is: what information was in the compromised system, and who does it belong to? An organization without data classification cannot answer that question quickly or accurately — which drives up breach response costs, delays the mandatory notification decision, and creates regulatory exposure. Organizations deploying security AI and automation reduced Canadian breach costs to CA$5.19 million compared to CA$8.53 million for those without — a CA$3.34 million gap. Data classification is the baseline on which that automation is calibrated.
PIPEDA Principle 7: The Safeguards Obligation
PIPEDA Principle 7 — Safeguards requires organizations to protect personal information by security safeguards appropriate to the sensitivity of the information. The OPC expects those safeguards to include:
- Physical measures — secured physical access to systems storing personal information
- Technological controls — encryption, access controls, firewalls, and current security patches
- Organizational controls — limiting access to need-to-know, staff training, and written agreements with processors
The critical word is *appropriate to the sensitivity*. You cannot apply the right level of protection without knowing what you have. Data classification is therefore not optional infrastructure — it is the prerequisite for a defensible Principle 7 posture.
The OPC's guidance on mandatory breach notification also requires organizations to assess whether a breach creates a "real risk of significant harm" to individuals — a determination that turns entirely on the sensitivity category of the information involved. PIPEDA further requires a record of every breach to be retained for two years and provided to the OPC on request. Classification infrastructure and compliance documentation are the same system.
What Microsoft Purview Information Protection Actually Does
Microsoft Purview Information Protection operates on three integrated capabilities:
Know your data. Content Explorer and Activity Explorer scan your Microsoft 365 environment and surface where sensitive content exists — across Exchange, SharePoint, OneDrive, and Teams. This provides a baseline map of your data landscape before any policies are enforced. Running Content Explorer before designing labels prevents the common mistake of building a taxonomy against an imaginary data footprint.
Protect your data. Sensitivity labels are metadata tags applied to documents, emails, Teams meetings, and calendar items. A label such as *Confidential — Personal Information* can enforce encryption, restrict external forwarding, add a visual watermark, and prevent sharing outside the organization — all automatically, based on the label applied. Labels are persistent: they travel with the file wherever it goes, including outside Microsoft 365.
Prevent data loss. DLP policies match content against sensitive information types (SITs) — pattern-based detectors for Canadian Social Insurance Numbers, credit card numbers, bank account details, passport numbers, and more than 300 other categories. When a match is found, the policy can block the action, prompt the user with a visible policy tip, or generate an alert for administrator review. Policies apply across Exchange, SharePoint, OneDrive, and Teams — and with the right licence, on Windows endpoints as well.
Licensing Reality for Canadian SMBs
Most Canadian organizations under 300 employees are on Microsoft 365 Business Premium. Here is what each tier unlocks for Purview:
| Feature | Business Premium | M365 E3 | M365 E5 / E5 Compliance |
|---|---|---|---|
| Manual sensitivity labels | Yes | Yes | Yes |
| Default label policies | Yes | Yes | Yes |
| Basic DLP (Exchange, SharePoint, OneDrive) | Yes | Yes | Yes |
| DLP for Teams | Limited | Yes | Yes |
| Service-side auto-labeling | No | No | Yes |
| Trainable classifiers | No | No | Yes |
| Endpoint DLP | No | No | Yes |
| Audit Premium (1-year log retention) | No | No | Yes |
Business Premium covers everything required for Stages 1 and 2 of the implementation below. Most Canadian SMBs can build a meaningful classification and DLP program entirely within their existing licences without additional spend. Service-side auto-labeling — where content is classified automatically without any user interaction — requires E5 or the E5 Compliance add-on and is worth evaluating once manual labeling is mature and the label taxonomy is stable.
A Four-Stage Implementation
Stage 1 — Discover What You Hold (Weeks 1–2)
Before publishing any labels, run a Content Explorer baseline. How much content contains Canadian SINs, financial account details, or health information? Which SharePoint sites and mailboxes hold the most sensitive material? This baseline prevents the most common implementation failure: designing a label taxonomy before understanding the actual data landscape.
If Content Explorer surfaces sensitive information types in unexpected locations — HR records in a project SharePoint site, client SINs in a shared mailbox — that finding requires immediate access control remediation, independent of any label policy.
Stage 2 — Define a Minimal Label Taxonomy (Weeks 2–4)
Start with four to six labels. Complexity is the enemy of adoption: every additional label reduces the likelihood that users apply them consistently.
| Label | Typical content | Default protection |
|---|---|---|
| Public | Marketing materials, published content | None |
| Internal | General business communications | None (watermark only) |
| Confidential | Business strategy, vendor contracts | Encryption optional |
| Confidential — Personal Information | Employee SINs, client PII, health data | Encryption required; external sharing blocked |
| Restricted | Financial statements, legal privilege | Encryption required; organization-only access |
Align *Confidential — Personal Information* directly to PIPEDA's definition of personal information. This label is the classification that drives mandatory breach notification decisions: a compromised account with access only to *Internal* content triggers a different risk assessment than one with access to *Confidential — Personal Information*.
Stage 3 — Publish Labels and Run Simulation (Weeks 4–8)
Publish labels in simulation mode — audit-only, no enforcement — first. Review Activity Explorer daily to see what labels users are applying and where DLP would have triggered. A two-to-four week simulation period catches misconfigured policies and gives administrators data to refine rules before enforcement begins.
In-app policy tips — the orange bar that appears in Outlook or Word when a DLP rule detects a match — are the most effective just-in-time training mechanism in Microsoft 365. Configure policy tips to explain what triggered the warning and what the user should do next. A policy tip that blocks an email and provides context converts the enforcement event into a training moment; one that blocks without explanation generates a help desk ticket.
Stage 4 — Activate DLP Enforcement (Months 2–4)
With labels deployed and simulation data analyzed, move DLP policies to enforce mode in priority order:
Block SIN numbers in outbound email. Canadian Social Insurance Numbers in email attachments or message bodies are the single highest-risk exfiltration vector for identity theft. This policy covers the most sensitive PIPEDA-defined personal information with minimal false positives.
Block SharePoint anonymous sharing links for Confidential and Restricted content. Misconfigured SharePoint permissions — anyone with the link — are responsible for a disproportionate share of accidental disclosures. This policy prevents sensitive-labelled content from being exposed via publicly accessible URLs regardless of SharePoint site permissions.
Alert on high-volume data movement. When more than 50 files labeled Confidential or higher are downloaded from SharePoint within a short window, an alert fires for administrator review. This pattern catches compromised accounts performing data staging before exfiltration — a precursor that appears consistently in ransomware and business email compromise investigations.
Teams DLP for guest users. Prevent SINs and health information from being shared in Teams chats with external guest users. With hybrid and contractor workforces, Teams has become a primary sensitive data sharing channel that many DLP programs leave uncovered.
The Breach Notification Connection
PIPEDA mandatory notification turns on two factors: the sensitivity of the personal information involved, and the probability of misuse. An organization with a working classification system can answer those questions in hours — and can demonstrate to the OPC, during investigation, that appropriate safeguards matching the sensitivity of the data were in place.
The audit logs generated by Purview Activity Explorer and DLP incident reports are also the breach records that PIPEDA requires you to retain for two years. Classification infrastructure and regulatory compliance documentation are not separate workstreams: Purview builds both simultaneously.
Organizations without data classification face a harder post-breach path. Forensic investigators must reconstruct what was in a mailbox or SharePoint site from backup snapshots and application logs — a process that is expensive, time-consuming, and produces results with lower confidence than a labeling system that tagged content at creation.
Sources
- Office of the Privacy Commissioner of Canada. *Championing Privacy in the Age of AI — 2025–2026 Annual Report.* priv.gc.ca
- Office of the Privacy Commissioner of Canada. *PIPEDA Principle 7 — Safeguards.* priv.gc.ca
- Office of the Privacy Commissioner of Canada. *Mandatory reporting of breaches of security safeguards.* priv.gc.ca
- IBM. *Cost of a Data Breach Report 2025 — Canada.* canada.newsroom.ibm.com
- CIRA. *2025 Cybersecurity Survey.* cira.ca
- Microsoft. *Learn about sensitivity labels.* learn.microsoft.com
- Microsoft. *Learn about sensitive information types.* learn.microsoft.com
- Microsoft. *Microsoft Purview service description — licensing guidance.* learn.microsoft.com
Cloud Forces configures Microsoft Purview Information Protection for Canadian SMBs — from Content Explorer baseline assessments through sensitivity label taxonomies, DLP policy deployment, and breach response audit logging. Explore our Cybersecurity services or contact us to book a Purview readiness review.
Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.
Ready to bring AI to your business?
Book a free AI Readiness Consultation — no commitment required.
Book Free Consultation