Skip to content
SpeechToWork
100% local · GDPR-compliant without the cloud

Is Copilot GDPR compliant? What happens to your firm’s data in Microsoft Copilot

Is Copilot GDPR compliant? It depends first on which Copilot you mean: the version for organisations, which can read your email and files, or the app signed in with a personal Microsoft account. This guide explains what happens to your prompts under UK GDPR, what regulators and security researchers have found, which settings to check and when a local assistant is the simpler choice.

Golden sound wave under a glass dome, symbolising protected company data
  • View accessis all Copilot needs to find and summarise content, including forgotten sharing.
  • 7 daysis how long the ICO keeps its own Copilot prompts and responses, per its privacy notice.
  • 100%local: SpeechToWork processes your text on your computer.

Is Microsoft Copilot GDPR compliant? The short answer

In short: With a work account and the right licence, Copilot can be used in line with UK GDPR, but not simply by switching it on. You need tidy permissions, a data protection impact assessment (DPIA) and settings you have checked. Client, patient or customer data does not belong in Copilot signed in with a personal Microsoft account.

Microsoft commits that prompts, responses and organisational data are not used to train the underlying models, and that its Data Protection Addendum covers Copilot for business customers. Those commitments have exceptions that many firms are not aware of. And the biggest practical risk is often not Microsoft at all, but your own sharing settings.

A note on names: according to Microsoft, Microsoft 365 Copilot is now called “Microsoft Copilot” and Microsoft 365 Copilot Chat is now “Microsoft Copilot Chat”. The consumer app is also called Copilot. What matters is not the name but the account you are signed in with.

Microsoft 365 Copilot or Copilot with a personal account: the difference

They look alike, but legally they are different services. The table follows Microsoft’s own documentation.

QuestionCopilot with a work accountCopilot with a personal Microsoft account
Sign-inYour organisation’s account (Microsoft Entra ID)Personal Microsoft account
ContractMicrosoft Product Terms and Data Protection Addendum (DPA), acting as your processor contractConsumer terms and privacy statement, no processor contract
TrainingAccording to Microsoft, prompts, responses and organisational data are not used to train foundation modelsAccording to Microsoft’s help pages, possible by default and can be switched off
Access to company dataYes, through Microsoft Graph: email, files, chats and calendars the person can accessNo, only what you type or upload
StorageActivity history in your tenant, retention controlled with Microsoft PurviewHistory kept for 18 months according to Microsoft (older app version), deletable
Suitable for client data?Only after checks: permissions, DPIA, settingsNo

On the personal app: the details on training and the 18-month history come from Microsoft’s help pages for the app version before 18 August 2026; for the new version Microsoft refers to updated privacy controls. According to Microsoft, some conversations can also be reviewed automatically and by people, for example when a breach of the Code of Conduct is suspected, and there is no opt-out from that review.

What happens to your prompts in Microsoft 365 Copilot

Copilot for organisations connects a language model to your Microsoft 365 data. Through Microsoft Graph it reads email, documents, chats, calendars and meetings, and combines them with what the person is working on.

  • Stored: every prompt and response, including citations, as the Copilot activity history. Admins can search it with Content search and Microsoft Purview and set retention policies.
  • Not used for training: according to Microsoft, no foundation model is trained on prompts, responses or Graph data. Optional feedback may be used to improve Copilot.
  • Where it is processed: Copilot follows the data residency commitments in Microsoft’s Product Terms and DPA. The EU Data Boundary covers EU and EFTA customers, not the UK. In November 2025 Microsoft announced in-country processing of Copilot interactions for the UK by the end of 2025; check with Microsoft whether it applies to your tenant.
  • Anthropic models: Microsoft offers Claude models inside Copilot. They are excluded from the EU Data Boundary and, for UK customers, switched off by default. Whoever turns them on should know where that data goes.
  • Web search: if allowed, Copilot turns your prompt into a search query and sends it to Bing, under separate rules described by Microsoft.

The oversharing problem: Copilot finds everything you are allowed to see

Microsoft puts it plainly: Copilot only surfaces organisational data to which the person has at least view permission. That sounds reassuring, but it is exactly the risk. Over the years most organisations collect sharing they no longer track: SharePoint sites open to everyone in the company, old sharing links, folders with inherited permissions.

That mess used to do little harm because nobody stumbled across the folder with the salary review. With Copilot one everyday question is enough, and it summarises whatever it finds. Under UK GDPR that touches data minimisation and security (Article 5).

Before you roll it out:

  1. find and remove broad sharing on SharePoint, OneDrive and Teams,
  2. protect sensitive areas such as HR, the board, health or client matters, for example with sensitivity labels,
  3. give Copilot to a small pilot group first and check what they can find,
  4. record the result in your DPIA.

Protective features can fail too: in early 2026 a bug let Copilot Chat summarise emails labelled confidential despite the policy meant to block it (see below).

Known problems, investigations and incidents

The points below are documented and dated. Some concern Microsoft 365 as a whole, some Copilot itself. Regulators’ views have changed over time, and an honest picture includes that.

  1. 8 March 2024
    EDPS: the European Commission’s use of Microsoft 365 infringed data protection law

    The European Data Protection Supervisor found infringements of Regulation (EU) 2018/1725 on purpose limitation, international transfers and unauthorised disclosures, and ordered data flows to certain third countries to be suspended. On 11 July 2025 it concluded that the infringements had been remedied and closed the case.

  2. December 2024
    Netherlands: DPIA on Microsoft 365 Copilot finds four high risks

    SLM Rijk, which negotiates software contracts for the Dutch government, and SURF, the Dutch education IT cooperative, published a data protection impact assessment. Their advice: do not use Copilot for now, mainly because of a lack of transparency.

  3. June 2025
    EchoLeak: a zero-click flaw in Microsoft 365 Copilot

    Researchers at Aim Security showed how a crafted email could make Copilot leak data from the user’s access scope without any click (CVE-2025-32711, CVSS 9.3). Microsoft had fixed it on the server side; customers did not need to act, and reports found no evidence of exploitation.

  4. 17 September 2025
    Netherlands: Copilot moves from red to amber

    After changes by Microsoft, the four high risks were downgraded to medium. Use is possible with care and conditions: an AI policy, defined use cases, careful permissions and your own DPIA.

  5. January to February 2026
    Copilot summarised emails labelled confidential

    Because of a code issue, Copilot Chat processed emails in Sent Items and Drafts even though sensitivity labels should have blocked it (Microsoft reference CW1226324). Reports started on 21 January; Microsoft began rolling out a fix in early February.

  6. 27 May 2026
    SURF: Copilot remains amber ongoing

    Two medium risks remain: a filter that cannot be switched off and whose thresholds Microsoft does not disclose, and pseudonymised usage data kept for up to 18 months. SURF still advises caution and a risk check for each use case.

We are not aware of a fine against a UK organisation for using Copilot as of September 2026. The ICO itself uses Microsoft 365 Copilot and says in its privacy notice that the data stays in its UK tenants, is not used to train foundation models, that prompts and responses are deleted after 7 days and that a person always checks the output. That is a useful benchmark for the controls a careful organisation puts in place.

What UK organisations need to sort out before using Copilot

  • Contract: Microsoft’s Product Terms and DPA are your processor contract under Article 28 UK GDPR. They only cover work accounts.
  • DPIA: the ICO says that in the vast majority of cases the use of AI involves processing likely to result in a high risk, which triggers the legal requirement for a DPIA. If you decide one is not needed, document why.
  • Admin settings: decide on Anthropic models, web search and agents deliberately rather than leaving the defaults.
  • Permissions: clean up sharing before Copilot indexes it.
  • Staff: the activity history can be seen by admins. Tell staff what is logged and why.
  • Confidentiality: solicitors, accountants and medical practices have professional duties of confidentiality on top of UK GDPR.
  • EU clients: if you serve customers in the EU, the EU AI Act’s AI literacy duty may matter too. See our guide to the EU AI Act.

How the same questions play out with another provider is covered in Is ChatGPT GDPR compliant?.

Copilot privacy settings step by step

Check Anthropic models (admins)

  1. In the Microsoft 365 admin center, go to Copilot › Settings and open AI providers operating as Microsoft subprocessors.
  2. Check whether Anthropic is enabled and for whom. For UK tenants it is off by default, according to Microsoft.

Set retention (admins)

In Microsoft Purview, create a retention policy for Copilot interactions that matches your purpose, rather than keeping everything indefinitely.

Delete your history (staff)

You can delete your own Copilot activity history with prompts and responses in the My Account portal (myaccount.microsoft.com). Your organisation’s retention policies may take precedence.

Switch off training (personal Copilot app)

In the older app version: profile icon › Settings › Privacy › Training on conversation activity. Menus vary by version. For business data this only limits the damage; it is not a solution.

Why a local assistant is often the better choice for office work

Copilot is strong at searching and connecting information across Microsoft 365. Much of everyday writing does not need that access: replying to an email, tidying up a dictation, taking meeting minutes, reading an invoice. A language model that sees only the text you are working on is enough.

SpeechToWork does exactly that on your own Windows PC. Speech recognition and the language model run locally, and nothing goes to a cloud. For this work the questions in this guide simply do not arise: no processor for your content, no international transfer, no training, no activity history on someone else’s server, no sharing settings for a tool to trawl, and no terms that change overnight.

To be fair about the limits: the local model is smaller than the big cloud models, it does not search your whole mailbox, it runs on Windows only and needs a reasonably recent computer. Many offices combine both: Copilot where it fits after a proper assessment, and local AI for anything confidential. More on GDPR-compliant AI and local AI.

An example

What you say. What appears.

You sayQuick note to the team, um, please don’t put any client data into Copilot until it’s approved, not even, no, especially not the personal Copilot, questions to Sarah Collins.
In your programQuick note to the team: please don’t put any client data into Copilot until it’s approved, especially not the personal Copilot. Questions to Sarah Collins.
Your advantage

Why SpeechToWork fits this job.

No Graph, no oversharing

SpeechToWork only sees the text you select or dictate. It does not search drives, mailboxes or Teams channels.

No data centres abroad

No routing to other regions and no subprocessors: the language model runs on your processor or graphics card.

Fit for confidential work

Client and patient information stays in your office because it never leaves the computer.

Privacy

Local means local. No compromises.

Speech recognition and the language model are installed on your PC and run there. What you dictate ends up in your program and nowhere else. How the data flow works.

No upload

Audio and text stay on your computer. There is no server listening in and no AI provider in the background.

GDPR made simple

No third party processes your dictations. So there is no data processing agreement to sign and no international transfer to assess.

Works without internet

Once installed, SpeechToWork works offline. Only the licence check needs a connection.

Good to know

Frequently asked questions

Is Microsoft Copilot GDPR compliant?

With a work account it can be used in line with UK GDPR: Microsoft offers a processor contract, says it does not train on your organisation’s data and documents where data is processed. Compliance still depends on you: clean permissions, checked settings, a DPIA and clear rules for staff.

Does Microsoft Copilot use my data for training?

For Copilot with a work account, Microsoft says no: prompts, responses and data from Microsoft Graph are not used to train foundation models. For the personal Copilot app, Microsoft’s help pages say training is possible by default and can be switched off under Privacy settings.

Do I need a DPIA for Microsoft Copilot?

In most cases, yes. The ICO says that in the vast majority of cases the use of AI involves processing likely to result in a high risk, which requires a DPIA. Copilot with access to email and files clearly falls into that area. If you conclude no DPIA is needed, document your reasoning.

Where is Copilot data stored for UK organisations?

Copilot follows the data residency commitments in Microsoft’s Product Terms, so interactions are stored with your other Microsoft 365 content. Microsoft announced in-country processing for the UK by the end of 2025. Anthropic models are an exception and are off by default for UK tenants.

What is oversharing in Microsoft Copilot?

Oversharing means people can access more data than they need, often through old company-wide sharing links. Copilot surfaces everything a person has permission to view and makes forgotten sharing visible with a simple question. That is why permissions should be cleaned up before rollout.

Can I put client data into the personal Copilot app?

No, not for work. With a personal Microsoft account consumer terms apply, there is no processor contract and your organisation has no control over settings or history. For writing tasks involving client data, a local assistant such as SpeechToWork keeps everything on your computer.

Coming soon

Coming soon. Then try it for 14 days.

SpeechToWork is about to launch. As soon as the first version is ready, you can download it here: one click, one file, no form.

Coming soon

For Windows 10/11 (64-bit). The download will be available here as soon as it is ready.

  • All features, no payment details
  • Ends automatically, nothing to cancel
  • Your dictations never leave your computer, not even in the trial
  1. Download

    One installer for Windows, straight from our server.

  2. Install

    A double click is all it takes. No administrator rights needed.

  3. Choose “Try for 14 days”

    On first start: enter your name and business email, no payment method.

On first start, SpeechToWork downloads the language models once (4 to 6 GB). Already have a licence key? Enter it on first start. What is transferred in the process is explained in our privacy policy.

Coming soon