Quick answer

Activate SSPA in OptiTech and the Data Protection Requirements load scoped to your data processing profile, cross-mapped against your existing program: GDPR artifacts cover most privacy sections, ISO 27001 controls cover most security ones, and the genuine deltas (Microsoft-specific notification duties, retention specifics) arrive as a short task list. The annual attestation becomes a review of recorded state instead of a yearly rediscovery project.

Profile-scoped requirements

Your data processing profile (personal data, confidential data, or both; where and how processed) determines which DPR sections apply, and the framework activation mirrors that: Microsoft-data-bearing systems tag in the asset inventory, the applicable requirements attach to controls, and out-of-scope sections are documented as such, so the attestation's boundaries are explicit and defensible.

The privacy and security substance, reused

  • Privacy: purpose limitation, retention and deletion schedules, data subject cooperation, and subprocessor management run from your GDPR machinery and supplier register; Microsoft-approved subprocessor tracking is one more attribute on vendors you already manage.
  • Security: access control, MFA, encryption, and secure development verify continuously through integrations, with Microsoft-data systems under the stricter check set.
  • Incident notification to Microsoft: the contractual clock lives in the incident flow alongside regulatory ones, so the commitment survives personnel changes.

The annual cycle without the scramble

SSPA's rhythm (profile review, attestation, possible independent verification) runs as a managed calendar: tasks with owners ahead of the attestation window, the attestation basis exported from the evidence log, and if your profile requires independent assurance, the assessor works from scoped read-only access. Where an ISO 27001 certificate reduces your verification burden, the certificate and its scope are already on file, one program answering one more program.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.