Tools & AI7 min read

Microsoft 365 Copilot and data protection: what German companies must know

What Microsoft commits to for 365 Copilot, what stays your responsibility (DPA, configuration, permissions), and how to minimise sensitive input.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

Microsoft 365 Copilot can be used in a GDPR-compliant way, but not automatically. According to Microsoft documentation, its commercial data protection commitments apply: your company data does not train the underlying language models, and certain data stays inside the EU Data Boundary. Responsibility is shared, though. The contract, the configuration, the permissions, and the question of which sensitive data you enter at all remain with you.

What Microsoft commits to for 365 Copilot

Microsoft makes several clear commitments in its documentation. These apply to Microsoft 365 Copilot in the commercial context, meaning business and public-sector customers. The statements below are drawn from Microsoft Learn documentation and attributed there.

  • Commercial data protection: According to Microsoft, 365 Copilot carries the same data protection and security commitments as the other Microsoft 365 enterprise services.
  • No model training on your data: According to Microsoft, your prompts, the responses, and the data retrieved through Microsoft Graph are not used to train the underlying foundation models.
  • EU Data Boundary: According to Microsoft, the EU Data Boundary processes and stores certain customer data of EU customers within the EU and EFTA.
  • Existing permissions still apply: Microsoft states that Copilot only accesses content the individual user is already authorised to see.
  • Encryption and tenant boundary: According to Microsoft, your data stays within your Microsoft 365 tenant boundary and is encrypted in transit and at rest.

These commitments matter. But they do not replace your own GDPR obligations, because here Microsoft is your data processor, not the controller.

What stays your responsibility

As a company, you are the controller under the GDPR. That means you must create the legal and technical conditions yourself. Microsoft supplies the tool, but compliance sits with you.

  • Data processing agreement (DPA): You need a valid DPA under Art. 28 GDPR. Microsoft provides its Data Protection Addendum, but you must accept and document it.
  • Configuration and labelling: You set up sensitivity labels and access rules yourself, for example through Microsoft Purview. Without configuration, Copilot reaches more than it should.
  • Permissions and oversharing: Copilot inherits your existing access rights. If they are too broad, Copilot surfaces content users would otherwise never have found.
  • Data protection impact assessment (DPIA): Depending on the use case, a DPIA under Art. 35 GDPR may be required. Check this before rollout.
  • Co-determination: In Germany, the works council may have a say if Copilot could monitor employee behaviour or performance (Section 87 BetrVG).
  • Professional secrecy: For doctors, lawyers, or tax advisers, Section 203 of the Criminal Code applies. Using Copilot with client or patient data needs special care.
  • Data minimisation: You remain obliged to process only the data you truly need (Art. 5 GDPR). This also covers what employees type into prompts.

Responsibility at a glance: Microsoft and you

The table below shows who handles what. The Microsoft column reflects the official documentation. The right column stays your job as the responsible company.

AreaWhat Microsoft handles per its documentationWhat stays your responsibility
Model trainingYour tenant data does not train the foundation modelsInternal rules on what data employees may enter
Storage locationEU Data Boundary for certain customer dataCheck whether your use case is covered
ContractProvision of the Data Protection AddendumSign and document a DPA under Art. 28 GDPR
AccessCopilot respects existing permissionsClean up permissions, prevent oversharing
LabellingSupport for sensitivity labels (Purview)Define, apply, and maintain the labels
InputsEncryption and tenant boundaryMinimise sensitive input, train staff

Oversharing: the underrated risk

The biggest risk with Copilot is rarely the model itself. It is the permission structure in your tenant. Copilot searches all content a user is allowed to access. If folders, Teams channels, or SharePoint sites are shared too openly, Copilot suddenly makes that content easy to find.

  1. 1Inventory: Check which SharePoint sites and Teams are open to too many people.
  2. 2Clean-up: Remove broad shares like "Everyone in the organisation" where they are not needed.
  3. 3Labelling: Apply sensitivity labels to confidential documents before you roll out Copilot.
  4. 4Pilot phase: Start with a small group and watch what Copilot surfaces.
  5. 5Training: Explain to the team that Copilot mirrors existing rights — no more, but no less.

Minimise sensitive data before Copilot

Even with the best commitments, one rule holds: the less sensitive data you enter, the smaller the risk. This applies to Copilot, but equally to ChatGPT, Gemini, Claude, or Le Chat when employees use them outside your tenant. This is exactly where ONYRI Sanitize fits in.

  • The tokenizer runs 100% in the browser. It detects names, customer data, credentials, or API keys in the text.
  • Detected values are replaced with reversible tokens before sending. The token-to-value mapping never leaves your browser.
  • When you use the built-in chat, the AI model only receives the already-anonymised text. Afterwards, the original values are restored in the answer.
  • Important and honest: this is pseudonymisation, not anonymisation. Pseudonymised data remains personal data (GDPR Recital 26). ONYRI reduces exposure and supports data minimisation — it does not remove your obligations.

This way you combine the benefit of AI with less disclosure. Copilot stays Copilot, but sensitive details do not have to land in every prompt.

Data protection with Copilot is not a single switch. It is shared responsibility: Microsoft supplies the commitments, you supply the contract, the configuration, and discipline in what you enter.

Frequently asked questions

Does Microsoft train its AI on our Copilot data?
According to Microsoft, your prompts, responses, and the tenant data retrieved through Microsoft Graph are not used to train the foundation models. For binding detail, check the current Microsoft Learn documentation, since policies can change.
Do we need a DPA for Microsoft 365 Copilot?
Yes. As the controller, you need a data processing agreement under Art. 28 GDPR. Microsoft provides its Data Protection Addendum, which you must accept and document.
Does our data stay in the EU with Copilot?
According to Microsoft, the EU Data Boundary processes and stores certain customer data within the EU and EFTA. Whether your specific use case is fully covered should be checked against the official documentation.
Is Copilot therefore automatically GDPR-compliant?
No. Microsoft's commitments are a foundation, but compliance depends on your configuration, permissions, the DPA, and your internal rules. Your responsibility as the controller remains with you.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next