No Graph, no oversharing
SpeechToWork only sees the text you select or dictate. It does not search drives, mailboxes or Teams channels.
Is Copilot GDPR compliant? It depends first on which Copilot you mean: the version for organisations, which can read your email and files, or the app signed in with a personal Microsoft account. This guide explains what happens to your prompts under UK GDPR, what regulators and security researchers have found, which settings to check and when a local assistant is the simpler choice.

In short: With a work account and the right licence, Copilot can be used in line with UK GDPR, but not simply by switching it on. You need tidy permissions, a data protection impact assessment (DPIA) and settings you have checked. Client, patient or customer data does not belong in Copilot signed in with a personal Microsoft account.
Microsoft commits that prompts, responses and organisational data are not used to train the underlying models, and that its Data Protection Addendum covers Copilot for business customers. Those commitments have exceptions that many firms are not aware of. And the biggest practical risk is often not Microsoft at all, but your own sharing settings.
A note on names: according to Microsoft, Microsoft 365 Copilot is now called “Microsoft Copilot” and Microsoft 365 Copilot Chat is now “Microsoft Copilot Chat”. The consumer app is also called Copilot. What matters is not the name but the account you are signed in with.
They look alike, but legally they are different services. The table follows Microsoft’s own documentation.
| Question | Copilot with a work account | Copilot with a personal Microsoft account |
|---|---|---|
| Sign-in | Your organisation’s account (Microsoft Entra ID) | Personal Microsoft account |
| Contract | Microsoft Product Terms and Data Protection Addendum (DPA), acting as your processor contract | Consumer terms and privacy statement, no processor contract |
| Training | According to Microsoft, prompts, responses and organisational data are not used to train foundation models | According to Microsoft’s help pages, possible by default and can be switched off |
| Access to company data | Yes, through Microsoft Graph: email, files, chats and calendars the person can access | No, only what you type or upload |
| Storage | Activity history in your tenant, retention controlled with Microsoft Purview | History kept for 18 months according to Microsoft (older app version), deletable |
| Suitable for client data? | Only after checks: permissions, DPIA, settings | No |
On the personal app: the details on training and the 18-month history come from Microsoft’s help pages for the app version before 18 August 2026; for the new version Microsoft refers to updated privacy controls. According to Microsoft, some conversations can also be reviewed automatically and by people, for example when a breach of the Code of Conduct is suspected, and there is no opt-out from that review.
Copilot for organisations connects a language model to your Microsoft 365 data. Through Microsoft Graph it reads email, documents, chats, calendars and meetings, and combines them with what the person is working on.
Microsoft puts it plainly: Copilot only surfaces organisational data to which the person has at least view permission. That sounds reassuring, but it is exactly the risk. Over the years most organisations collect sharing they no longer track: SharePoint sites open to everyone in the company, old sharing links, folders with inherited permissions.
That mess used to do little harm because nobody stumbled across the folder with the salary review. With Copilot one everyday question is enough, and it summarises whatever it finds. Under UK GDPR that touches data minimisation and security (Article 5).
Before you roll it out:
Protective features can fail too: in early 2026 a bug let Copilot Chat summarise emails labelled confidential despite the policy meant to block it (see below).
The points below are documented and dated. Some concern Microsoft 365 as a whole, some Copilot itself. Regulators’ views have changed over time, and an honest picture includes that.
The European Data Protection Supervisor found infringements of Regulation (EU) 2018/1725 on purpose limitation, international transfers and unauthorised disclosures, and ordered data flows to certain third countries to be suspended. On 11 July 2025 it concluded that the infringements had been remedied and closed the case.
SLM Rijk, which negotiates software contracts for the Dutch government, and SURF, the Dutch education IT cooperative, published a data protection impact assessment. Their advice: do not use Copilot for now, mainly because of a lack of transparency.
Researchers at Aim Security showed how a crafted email could make Copilot leak data from the user’s access scope without any click (CVE-2025-32711, CVSS 9.3). Microsoft had fixed it on the server side; customers did not need to act, and reports found no evidence of exploitation.
After changes by Microsoft, the four high risks were downgraded to medium. Use is possible with care and conditions: an AI policy, defined use cases, careful permissions and your own DPIA.
Because of a code issue, Copilot Chat processed emails in Sent Items and Drafts even though sensitivity labels should have blocked it (Microsoft reference CW1226324). Reports started on 21 January; Microsoft began rolling out a fix in early February.
Two medium risks remain: a filter that cannot be switched off and whose thresholds Microsoft does not disclose, and pseudonymised usage data kept for up to 18 months. SURF still advises caution and a risk check for each use case.
We are not aware of a fine against a UK organisation for using Copilot as of September 2026. The ICO itself uses Microsoft 365 Copilot and says in its privacy notice that the data stays in its UK tenants, is not used to train foundation models, that prompts and responses are deleted after 7 days and that a person always checks the output. That is a useful benchmark for the controls a careful organisation puts in place.
How the same questions play out with another provider is covered in Is ChatGPT GDPR compliant?.
In Microsoft Purview, create a retention policy for Copilot interactions that matches your purpose, rather than keeping everything indefinitely.
You can delete your own Copilot activity history with prompts and responses in the My Account portal (myaccount.microsoft.com). Your organisation’s retention policies may take precedence.
In the older app version: profile icon › Settings › Privacy › Training on conversation activity. Menus vary by version. For business data this only limits the damage; it is not a solution.
Copilot is strong at searching and connecting information across Microsoft 365. Much of everyday writing does not need that access: replying to an email, tidying up a dictation, taking meeting minutes, reading an invoice. A language model that sees only the text you are working on is enough.
SpeechToWork does exactly that on your own Windows PC. Speech recognition and the language model run locally, and nothing goes to a cloud. For this work the questions in this guide simply do not arise: no processor for your content, no international transfer, no training, no activity history on someone else’s server, no sharing settings for a tool to trawl, and no terms that change overnight.
To be fair about the limits: the local model is smaller than the big cloud models, it does not search your whole mailbox, it runs on Windows only and needs a reasonably recent computer. Many offices combine both: Copilot where it fits after a proper assessment, and local AI for anything confidential. More on GDPR-compliant AI and local AI.
Last reviewed: September 2026. This guide is not legal advice. Providers change plans, settings and terms often; check the linked original sources before you decide.
SpeechToWork only sees the text you select or dictate. It does not search drives, mailboxes or Teams channels.
No routing to other regions and no subprocessors: the language model runs on your processor or graphics card.
Client and patient information stays in your office because it never leaves the computer.
Speech recognition and the language model are installed on your PC and run there. What you dictate ends up in your program and nowhere else. How the data flow works.
Audio and text stay on your computer. There is no server listening in and no AI provider in the background.
No third party processes your dictations. So there is no data processing agreement to sign and no international transfer to assess.
Once installed, SpeechToWork works offline. Only the licence check needs a connection.
With a work account it can be used in line with UK GDPR: Microsoft offers a processor contract, says it does not train on your organisation’s data and documents where data is processed. Compliance still depends on you: clean permissions, checked settings, a DPIA and clear rules for staff.
For Copilot with a work account, Microsoft says no: prompts, responses and data from Microsoft Graph are not used to train foundation models. For the personal Copilot app, Microsoft’s help pages say training is possible by default and can be switched off under Privacy settings.
In most cases, yes. The ICO says that in the vast majority of cases the use of AI involves processing likely to result in a high risk, which requires a DPIA. Copilot with access to email and files clearly falls into that area. If you conclude no DPIA is needed, document your reasoning.
Copilot follows the data residency commitments in Microsoft’s Product Terms, so interactions are stored with your other Microsoft 365 content. Microsoft announced in-country processing for the UK by the end of 2025. Anthropic models are an exception and are off by default for UK tenants.
Oversharing means people can access more data than they need, often through old company-wide sharing links. Copilot surfaces everything a person has permission to view and makes forgotten sharing visible with a simple question. That is why permissions should be cleaned up before rollout.
No, not for work. With a personal Microsoft account consumer terms apply, there is no processor contract and your organisation has no control over settings or history. For writing tasks involving client data, a local assistant such as SpeechToWork keeps everything on your computer.
Training, retention and data location by plan, fines and proceedings, and the right settings.
ViewWhat the EU AI Act asks of businesses that use AI: timeline, AI literacy, bans, fines and whether it applies in the UK.
ViewUse AI in the office without handing data to a provider.
ViewSpeechToWork is about to launch. As soon as the first version is ready, you can download it here: one click, one file, no form.
Coming soonFor Windows 10/11 (64-bit). The download will be available here as soon as it is ready.
One installer for Windows, straight from our server.
A double click is all it takes. No administrator rights needed.
On first start: enter your name and business email, no payment method.
On first start, SpeechToWork downloads the language models once (4 to 6 GB). Already have a licence key? Enter it on first start. What is transferred in the process is explained in our privacy policy.