Microsoft Viva: Viva Pulse - New Pulse customization options

🚨 The Signal: Viva Pulse surveys now offer anonymous or identified responses, link sharing, and no end dates. This increases data collection flexibility but introduces new privacy and data governance considerations for organisations.

The Impact

All users are affected by new survey options, increasing the risk of unmanaged data collection and privacy breaches if not governed.

  • End Users: Risk of inadvertently collecting sensitive identified data.
  • Admins: Risk of unmanaged data sprawl and privacy non-compliance.
  • Security Team: Risk of increased data exfiltration vectors and privacy incidents.
  • Legal/Privacy Team: Risk of non-compliance with data protection regulations.

The Action

  1. Review and update internal data governance policies for Viva Pulse, specifically addressing identified responses and link sharing.
  2. Communicate updated Viva Pulse usage guidelines to all employees, emphasising responsible data collection practices.
  3. Monitor Viva Pulse usage for compliance with new internal policies.
  4. Consider implementing Microsoft Purview Data Loss Prevention (DLP) policies to detect and prevent sensitive data sharing via Viva Pulse links.

Domain: Purview · Impact: high · Workload: Microsoft Purview