Microsoft Copilot and Data Privacy: What to Know

Photo: Christina Morillo / Pexels
Key takeaways
- Copilot data privacy depends entirely on which product you mean, business tenant or personal account.
- Microsoft 365 Copilot doesn't train foundation models on your content and stays inside your tenant boundary.
- Personal and consumer Copilot products run on terms that can use conversations for service improvement.
- The GDPR DPA is included in M365 licensing, log the confirmation rather than assume it.
- Copilot inherits existing file permissions, so it can surface oversharing problems that predate it.
Microsoft Copilot is now built into Word, Excel, Teams, Outlook and dozens of other Microsoft 365 apps, which means understanding Copilot data privacy has quietly become a basic IT and compliance task rather than an advanced one. The trouble is that 'Copilot' isn't one product. Microsoft 365 Copilot on a business tenant behaves very differently from Copilot in Windows or Bing Copilot on a personal account, and the gap between them is where most policy mistakes happen. This guide sets out what each version actually does with your data and what to write into your AI usage policy.
Which Copilot are you actually talking about?
Microsoft ships several products under the Copilot name, and the data-handling terms differ significantly between them. Microsoft 365 Copilot, available on an E3 or E5 licence or as an add-on, is the enterprise product with the strongest protections. Copilot in Windows, Bing Copilot and the free consumer Copilot app are separate products running on consumer terms. When you write your AI policy, name the specific product that's approved, 'Copilot' on its own isn't specific enough to be useful.
What Microsoft 365 Copilot does with your data
Microsoft states that M365 Copilot doesn't train its foundation models on your organisation's content, and that prompts and responses stay within your Microsoft 365 tenant boundary rather than being used to improve third-party or foundational models. Your existing Microsoft data-processing terms and GDPR Data Processing Agreement extend to cover it, and EU-based organisations get the added European Data Boundary commitment, meaning EU customer data processed by in-scope services stays within the EU/EFTA, which matters if your own GDPR documentation specifies residency requirements for a client or regulator. In practice, that makes Copilot on the business tier closer to 'using your own tenant's data with an AI feature switched on' than 'sending your data to a third party'.
The consumer Copilot gap
If someone on your team uses Copilot through a personal Microsoft account or Bing.com, they're on consumer terms, and those terms allow Microsoft to use conversational data to improve its services unless the person opts out, which almost nobody does. It's the same free-tier-versus-business-tier gap that trips people up with ChatGPT and Gemini. The fix is the same too: name the approved product and account type explicitly, and treat personal-account AI use the way you'd treat a personal email account for work correspondence, not approved. If you want to check whether this is already happening, look at sign-in logs for Microsoft consumer domains on company devices, most organisations that check find at least a handful, rarely out of malice, usually just habit from before the business tool existed.
Does Copilot train on your organisation's data?
On Microsoft 365 Copilot, no. On personal-account Copilot, potentially yes, unless the individual has opted out in their own account settings, which your organisation has no visibility into or control over. That opt-out setting lives inside the individual's personal Microsoft privacy dashboard, not anywhere your IT team can see or manage, which is exactly why relying on personal-account use for work is a bad bet regardless of any one person's settings. That's the entire reason the product distinction matters more than the brand name.
Do you need a separate DPA for Copilot?
For M365 Copilot, no separate agreement is required: Microsoft includes it within your existing licensing terms, and it's worth logging that confirmation in your data processing register rather than assuming it's covered. See the ICO's guidance on AI and data protection and our GDPR compliance hub for what that register should actually contain, and check the underlying GDPR text if you need the legal basis spelled out for an auditor.
The oversharing risk Copilot exposes
Copilot doesn't invent new access, it works with whatever the signed-in user can already reach across Teams, SharePoint and OneDrive, which means it can surface an old permissions mistake nobody noticed. An operations manager at a 25-person accountancy practice found this out during a Copilot pilot: a search turned up a folder from a client acquisition three years earlier that had been left open tenant-wide, filed away and forgotten, but never actually locked down. Nothing had gone wrong until Copilot made it trivially easy to find. Before rolling Copilot out widely, a permissions review is worth doing, not because Copilot is unsafe, but because it's very good at finding what was already exposed.
Admin controls worth switching on before rollout
A handful of tenant settings are worth checking before Copilot goes wide, not after. Restrict web-grounded answers if you don't want Copilot pulling from the open internet inside a work document. Review default SharePoint sharing settings so Copilot search doesn't inherit years of loose permissions along with everything else. Confirm the audit log is switched on so you can actually see which prompts touched which content if a question ever comes up. None of these take long individually, but skipping them is how a rollout that looked fine in a five-person pilot turns messy at five hundred people. Treat the admin-centre review as a required step before rollout, the same way you'd treat file-permission hygiene before opening any new collaboration tool to the whole company.
What to put in your AI policy
Name Microsoft 365 Copilot on your business tenant as the approved product for anything involving company, client or personal data. State plainly that personal Microsoft accounts and consumer Copilot products are not approved for the same. If you allow Copilot Chat, the standalone web assistant on the business tenant, alongside Copilot embedded in Word or Excel, name both explicitly; teams often assume approving one automatically covers the other. Log the GDPR DPA confirmation in your data processing register, and note the data residency commitments that apply if you operate in the EU. That distinction, written down, closes the most common Copilot-related gap we see in Microsoft-heavy organisations.
Get the policy written before the rollout
Copilot's business tier is genuinely well protected, but that protection only helps if your team knows which version they're meant to be using. Write it into your policy before a wider rollout, not after someone's already pasted client data into the wrong one. ModelCharter's free AI usage policy generator builds that distinction into your policy automatically, tailored to the Microsoft tools you actually run.
| Product | Access route | Trains on your content? | Business protections |
|---|---|---|---|
| Microsoft 365 Copilot | Business tenant, E3/E5 licence or add-on | No, not used to train foundation models | Tenant boundary, GDPR DPA, European Data Boundary |
| Copilot in Windows / Bing Copilot | Personal Microsoft account | May be used for service improvement unless opted out | Consumer terms, no DPA |
| Consumer Copilot app | Personal Microsoft account | Same consumer terms as above | Consumer terms, no DPA |
“The Copilot in someone's Word document and the Copilot on their phone at lunchtime are not the same product, and your policy has to say so.”