

Not sure on the policy for this (and too lazy to read through the TOS) but the usual standard is:
You have read only access to your data in some form for N months. Sometimes individual, sometimes grabbing the whole dump. If you haven’t renewed your license within N months, that data is deleted (but not really).
If data has handling requirements it 500% should not be something people are storing on their “personal” devices.
I personally hate the idea of storing corporate data in “cloud” storage, but MS et al have gotten approval from many governments to do exactly that. So if that is your corporate data store? Then that is where it goes. And if someone is making a new document with additional restrictions then they better damned well have training on how to pick which folder in onedrive it goes into.