As we are looking for Business Central for ERP. Found concern about data protection. For that how we can secure. And who can be responsible for data breach ?
Business Central SaaS is generally secured through a shared responsibility model: Microsoft secures the cloud platform, datacenter, encryption, monitoring, updates, and service availability, while your company is responsible for who can access the system and what they can do inside it. Practically, you secure financial and operational data by enforcing Microsoft Entra ID + MFA, using least-privilege permission sets/security groups, limiting SUPER users, enabling approval workflows for sensitive transactions, using Change Log / Field Monitoring for critical fields like vendor bank accounts, reviewing permissions regularly, and monitoring compliance/security reports through Microsoft Trust Center and Service Trust Portal. For data breach responsibility, it depends on the source of the breach: if it is a Microsoft cloud/service incident, Microsoft has breach notification obligations; if it is caused by weak customer controls, wrong permissions, compromised user accounts, or poor internal process, then the customer is usually responsible as the data controller, so this should also be reviewed legally and contractually.
Regards,
Oussama Sabbouh
Was this reply helpful?YesNo
Under review
Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.