Copilot is moving into Word, Outlook, Teams and Windows, right next to the organisation’s documents. Hence a legitimate question: what happens to the data it accesses and the data entrusted to it? Microsoft publishes specific commitments for work accounts. They are solid, but they rely on two conditions: using the right account, and having properly configured access rights.
Which Copilot are we talking about?
The name covers several services. Microsoft has renamed Microsoft 365 Copilot “Microsoft Copilot” and Microsoft 365 Copilot Chat “Microsoft Copilot Chat”, stating that this change does not alter security, compliance or privacy for organisations.1 Alongside these, there is a Copilot app for individuals, used with a personal Microsoft account, whose privacy pages explicitly exclude work accounts.5
This distinction is the first thing to check: the safeguards described below only apply when signing in with a work account (Microsoft Entra ID).
Copilot’s enterprise data protection
Microsoft uses the term “enterprise data protection” for the set of commitments that apply to Copilot and Copilot Chat with a work account. According to Microsoft:
- interactions are covered by the Data Protection Addendum (DPA) and the Product Terms, with Microsoft acting as processor1;
- prompts, responses and data accessed through Microsoft Graph are not used to train foundation models1,2;
- Copilot respects the organisation’s identity model and permissions, inherits sensitivity labels and applies retention policies1;
- the privacy commitments include the GDPR and the EU Data Boundary.1,2
Microsoft also states that stored interactions (prompts and responses) are encrypted, handled under the same contractual commitments as other Microsoft 365 content, and that administrators can apply retention policies to them.2 In Copilot Chat, a green shield displayed next to the “New chat” button shows that the protection applies.3
- Use to train the models
- Depends on settingsConsumer terms apply. Microsoft’s former privacy FAQ stated that users can choose whether their activity is used for training.
- Contractual framework
- Consumer termsCopilot privacy pages for individuals, which do not apply to work accounts.
- Visual indicator
- No shieldNo indication of enterprise data protection.
- Management by the organisation
- NoneAccount tied to the individual: the organisation has neither visibility nor administration.
Access rights: what the tool does not fix for you
This is the most frequently underestimated point. Microsoft states that Copilot only surfaces organisational data that the user has at least view permission for, and stresses the importance of using Microsoft 365 permission models, such as those in SharePoint, so that the right people have access to the right content.2
In other words, Copilot does not create new access: it makes existing access much easier to exploit. A salary folder mistakenly shared “with the whole organisation” used to be hard to find. With an assistant that can search and summarise, it can turn up in an answer.
The assistant only draws on what the user can already open: here, their team’s documents.
The same principle applies to other vendors: Google states, for example, that Gemini in Workspace follows existing permissions.8 Before a rollout, auditing sharing is therefore a security project in its own right, independent of the tool chosen. It ties in with the GDPR obligation to implement security measures appropriate to the risk (Article 32).6
Copilot and the GDPR: processing and data location
Under the GDPR, Microsoft positions itself as the organisation’s processor for Copilot, under its Data Protection Addendum.1 It is this contract that meets the requirement of Article 28, under which a controller may only entrust data to a processor providing sufficient guarantees, with a contract governing the processing.6
On data location, Microsoft states that, for customers in the European Union, Copilot is an EU Data Boundary service: EU traffic stays within the boundary, although during periods of high demand, calls to the models may be routed to other regions for other customers.2 Copilot has also been included in the data residency commitments of the Product Terms since 1 March 2024.2
Two further details complete the picture. Microsoft states that Copilot does not use Azure OpenAI abuse monitoring, which includes human review of content.2 And optional user feedback may be used to improve Copilot, but not to train foundation models; administrators can manage it.2
Personal accounts: a different framework
An employee who signs in to Copilot with a personal Microsoft account leaves the framework described above. Microsoft’s page on Copilot for individuals states that it does not apply to work or school accounts.5 The former privacy FAQ, which concerns the previous app, stated that users signed in with a Microsoft account can control whether their activity is used for training, and that Microsoft does not train Copilot on the data of users signed in with an Entra ID work account.4
For the organisation, the issue is the same as with ChatGPT: a personal account falls outside its contract, its settings and its visibility, while the organisation remains responsible for the personal data entered into it.6,7
Points to be aware of
- Web search. When web search is used, Copilot generates a query sent to the Bing service; Microsoft states that the EU Data Boundary does not apply to these queries.1,2
- Agents and extensions. For a third-party agent, Microsoft advises checking its own privacy statement and terms of use.2
- Third-party models. Administrators can enable models from other providers; Microsoft states that models provided by Anthropic are currently excluded from the EU Data Boundary.1,2
- Other assistants. Copilot’s protection only covers Copilot. Text pasted into other online services is subject to the terms of those services.
Before rolling out Copilot: the checklist
- Check the account typeSign-in with the Entra ID work account, green shield visible.
- Audit sharingSites and folders open “to the whole organisation”, anonymous links.
- Apply labelsSensitivity labels on sensitive documents.
- Set retentionRetention policies for the history of interactions with Copilot.
- Decide on optionsWeb search, agents, third-party models: enable them knowingly.
- Govern other toolsPolicy and controls for assistants used outside Microsoft 365.
More broadly, the French CNIL recommends governing the use of generative AI through a policy that defines permitted and prohibited uses.7 For assistants used in the browser or in development tools, an on-device check can complete the setup: that is what Tacite-IA offers in Chrome and Edge and in coding assistants. It does not cover desktop apps, including Copilot in Windows.
Frequently asked questions
Is Copilot GDPR compliant?
Microsoft states that Copilot complies with its existing commitments to Microsoft 365 business customers, including the GDPR and the EU Data Boundary, and acts as a processor under its Data Protection Addendum. The organisation remains the controller: access rights, informing employees and usage rules are still its responsibility.
Does Copilot use my company’s data to train its models?
According to Microsoft, with a work account, prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, including those used by Copilot.
What is Copilot’s enterprise data protection (EDP)?
It is the set of commitments Microsoft applies to Copilot and Copilot Chat with a work account: coverage by the Data Protection Addendum, with Microsoft acting as processor, no training of foundation models, and respect for the organisation’s permissions, labels and retention policies.
Can Copilot see files I do not have access to?
No: Microsoft states that Copilot only surfaces data that the user has at least view permission for. However, a file shared too widely becomes accessible to Copilot for everyone who has access to it.
How can I tell whether the protection applies in Copilot Chat?
Microsoft states that a green shield appears at the top of the interface, next to the new chat button, when enterprise data protection applies.
Sources
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat. Microsoft Learn. Accessed on 5 October 2026.
- Data, Privacy, and Security for Microsoft Copilot. Microsoft Learn, page dated 9 July 2026. Accessed on 5 October 2026.
- Microsoft Copilot Chat Privacy and Protections. Microsoft Learn. Accessed on 5 October 2026.
- Privacy FAQ for Microsoft Copilot. Microsoft Support. Accessed on 5 October 2026.
- Microsoft Copilot for individuals: your data, privacy, and responsible AI. Microsoft Support. Accessed on 5 October 2026.
- Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). EUR-Lex. Accessed on 5 October 2026.
- Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative. CNIL (French data protection authority), 18 July 2024. In French. Accessed on 5 October 2026.
- Generative AI in Google Workspace Privacy Hub. Google Workspace. Accessed on 5 October 2026.
ChatGPT is a trademark of OpenAI, Copilot of Microsoft, Claude of Anthropic, Gemini of Google. Tacite-IA is not affiliated with any of these vendors. This article is for information only and does not constitute legal advice.