
SharePoint Retention + Purview Label Mapping: Enterprise Reference (2026)
Complete reference mapping between SharePoint content types and Microsoft Purview retention labels. Per content category, jurisdiction, regulatory framework. Includes autolabeling rules and Copilot-impact analysis.
Complete reference mapping between SharePoint content types and Microsoft Purview retention labels. Per content category, jurisdiction, regulatory framework. Includes autolabeling rules and Copilot-impact analysis.

A practical reference mapping SharePoint content types to Microsoft Purview retention labels by content category, jurisdiction, and regulatory framework. Adapt to your environment.
Map every SharePoint content type to ONE retention label (Purview Retention Policy) and ONE sensitivity label (Purview Information Protection). The retention label answers "how long do we keep this?" The sensitivity label answers "who can access this?" Both feed Microsoft 365 Copilot behavior.
EPC Group's reference taxonomy. Each category maps to a retention label (R-#) and sensitivity label (S-#).
1. Executive + Board Materials
2. Legal + Contracts
3. Financial Records
4. HR + Personnel Records
5. Patient / Customer Health Information (PHI/ePHI)
6. Customer + Sales Records
7. Engineering + Product Designs
8. Marketing + Public Content
9. Project + Engagement Documents
10. Training + Knowledge Base
11. Operational + Day-to-Day Communications
12. Regulated Records (SOX, FINRA, FDA, FERPA)
| Region | Retention Driver | Sensitivity Override |
|---|---|---|
| US Federal | HIPAA (6yr), SOX (7yr), IRS (7yr) | Standard |
| EU (GDPR) | Article 17 right to erasure | + Data Subject category |
| California (CCPA) | 12 months min, deletion right | + Personal Information classifier |
| Canada (PIPEDA) | Personal info disposal after purpose | + PII classifier |
| Healthcare State Extensions | State-specific (e.g., FL 7yr adult, age-of-majority + 7 minor) | Override federal floor |
| Financial (FINRA Rule 4511) | 6 years from creation | + FINRA classifier |
| Public Sector | NARA (federal) or state retention schedule | + Public Records classifier |
| Sensitivity Label | Copilot Grounding | Copilot Output |
|---|---|---|
| S-1 Public | Searchable | No label inheritance |
| S-2 Internal | Searchable within tenant | Internal label inherits |
| S-3 Internal-Restricted | Filtered by Information Barrier | Internal-Restricted label inherits |
| S-4 Confidential | Restricted Search applies | Confidential label inherits + DLP scrub |
| S-5 Confidential-Encrypted | Excluded from Copilot | N/A |
Step 1: Inventory. Run SharePoint Site Inventory PowerShell + Purview content explorer. Identify which content categories live where.
Step 2: Build Label Taxonomy. Use the 5 sensitivity labels + 12 retention labels above as starting baseline. Refine for jurisdiction.
Step 3: Container Labels First. Apply container labels to SharePoint sites + Teams + Groups BEFORE deploying file labels.
Step 4: Default Label Policies. Each container gets a default label. Files inherit.
Step 5: Autolabeling for Regulated Content. Trainable classifiers + sensitive info types. Run in simulation mode first.
Step 6: Retention Label Application. Auto-apply via policy. Manual override allowed by content owner.
Step 7: Copilot Behavior Validation. Test prompts as each persona. Validate Restricted Search + DLP for Copilot output.
Step 8: Quarterly Audit. Content explorer + activity explorer + DLP policy match report.
Map every SharePoint content type to ONE retention + ONE sensitivity label. Apply container labels first. Add autolabeling for regulated content. Validate Copilot behavior per persona. Audit quarterly. The taxonomy above is a starting baseline; refine for your jurisdiction + regulatory scope.
Q: Can a document have multiple sensitivity labels?
A: No. One sensitivity label per document. Multiple retention labels are technically possible via Adaptive Scope but operationally complex.
Q: How do I migrate legacy SharePoint content into this taxonomy?
A: Bulk-apply container labels to sites; autolabeling backfills file labels over 30-60 days; manual remediation for edge cases.
Q: Does this work for Microsoft Teams + OneDrive + Loop?
A: Yes. Sensitivity labels apply to all M365 workloads. Retention labels apply to email + Teams chat + SharePoint + OneDrive + Loop components.
Q: How do I prove compliance to auditors?
A: Microsoft Purview Content Explorer + Activity Explorer + Audit (Premium) provide the evidence trail.
Q: What if my retention label policy conflicts with regulatory requirements?
A: Regulatory wins. Adjust the retention label or build a jurisdiction-specific variant. Document the rationale.
Q: Why EPC Group?
A: 29 years Microsoft + SharePoint consulting. Errin O'Connor authored Microsoft Press books including SharePoint inside-out volumes. EPC Group is a Microsoft Solutions Partner with all six designations. See /reviews.
CEO & Chief AI Architect
Microsoft Press bestselling author with 29 years of enterprise consulting experience.
View Full ProfileMicrosoft 365 Copilot HIPAA blueprint: 47-control governance framework, BAA scope, ePHI sensitivity labels, Communication Compliance for Copilot, audit trail, breach response. Built from Fortune 500 healthcare Copilot rollouts.
AI GovernanceThe 38-control buyer's checklist for FINRA-regulated broker-dealers + SEC-registered RIAs deploying Microsoft 365 Copilot. SEC 17a-4, FINRA Rule 4511, Reg BI, NIST CSF mapping. Built from financial services Copilot rollouts.
AI GovernanceThe EU AI Act high-risk system requirements enforce August 2, 2026. Article 6 + Annex III high-risk classification, AI literacy obligations (Article 4), data governance, technical documentation. 12-week enterprise compliance checklist.
Our team of experts can help you implement enterprise-grade ai governance solutions tailored to your organization's needs.