Microsoft 365 Copilot and data protection: what German companies must know
What Microsoft commits to for 365 Copilot, what stays your responsibility (DPA, configuration, permissions), and how to minimise sensitive input.
Microsoft 365 Copilot can be used in a GDPR-compliant way, but not automatically. According to Microsoft documentation, its commercial data protection commitments apply: your company data does not train the underlying language models, and certain data stays inside the EU Data Boundary. Responsibility is shared, though. The contract, the configuration, the permissions, and the question of which sensitive data you enter at all remain with you.
What Microsoft commits to for 365 Copilot
Microsoft makes several clear commitments in its documentation. These apply to Microsoft 365 Copilot in the commercial context, meaning business and public-sector customers. The statements below are drawn from Microsoft Learn documentation and attributed there.
- Commercial data protection: According to Microsoft, 365 Copilot carries the same data protection and security commitments as the other Microsoft 365 enterprise services.
- No model training on your data: According to Microsoft, your prompts, the responses, and the data retrieved through Microsoft Graph are not used to train the underlying foundation models.
- EU Data Boundary: According to Microsoft, the EU Data Boundary processes and stores certain customer data of EU customers within the EU and EFTA.
- Existing permissions still apply: Microsoft states that Copilot only accesses content the individual user is already authorised to see.
- Encryption and tenant boundary: According to Microsoft, your data stays within your Microsoft 365 tenant boundary and is encrypted in transit and at rest.
These commitments matter. But they do not replace your own GDPR obligations, because here Microsoft is your data processor, not the controller.
What stays your responsibility
As a company, you are the controller under the GDPR. That means you must create the legal and technical conditions yourself. Microsoft supplies the tool, but compliance sits with you.
- Data processing agreement (DPA): You need a valid DPA under Art. 28 GDPR. Microsoft provides its Data Protection Addendum, but you must accept and document it.
- Configuration and labelling: You set up sensitivity labels and access rules yourself, for example through Microsoft Purview. Without configuration, Copilot reaches more than it should.
- Permissions and oversharing: Copilot inherits your existing access rights. If they are too broad, Copilot surfaces content users would otherwise never have found.
- Data protection impact assessment (DPIA): Depending on the use case, a DPIA under Art. 35 GDPR may be required. Check this before rollout.
- Co-determination: In Germany, the works council may have a say if Copilot could monitor employee behaviour or performance (Section 87 BetrVG).
- Professional secrecy: For doctors, lawyers, or tax advisers, Section 203 of the Criminal Code applies. Using Copilot with client or patient data needs special care.
- Data minimisation: You remain obliged to process only the data you truly need (Art. 5 GDPR). This also covers what employees type into prompts.
Responsibility at a glance: Microsoft and you
The table below shows who handles what. The Microsoft column reflects the official documentation. The right column stays your job as the responsible company.
| Area | What Microsoft handles per its documentation | What stays your responsibility |
|---|---|---|
| Model training | Your tenant data does not train the foundation models | Internal rules on what data employees may enter |
| Storage location | EU Data Boundary for certain customer data | Check whether your use case is covered |
| Contract | Provision of the Data Protection Addendum | Sign and document a DPA under Art. 28 GDPR |
| Access | Copilot respects existing permissions | Clean up permissions, prevent oversharing |
| Labelling | Support for sensitivity labels (Purview) | Define, apply, and maintain the labels |
| Inputs | Encryption and tenant boundary | Minimise sensitive input, train staff |
Oversharing: the underrated risk
The biggest risk with Copilot is rarely the model itself. It is the permission structure in your tenant. Copilot searches all content a user is allowed to access. If folders, Teams channels, or SharePoint sites are shared too openly, Copilot suddenly makes that content easy to find.
- 1Inventory: Check which SharePoint sites and Teams are open to too many people.
- 2Clean-up: Remove broad shares like "Everyone in the organisation" where they are not needed.
- 3Labelling: Apply sensitivity labels to confidential documents before you roll out Copilot.
- 4Pilot phase: Start with a small group and watch what Copilot surfaces.
- 5Training: Explain to the team that Copilot mirrors existing rights — no more, but no less.
Minimise sensitive data before Copilot
Even with the best commitments, one rule holds: the less sensitive data you enter, the smaller the risk. This applies to Copilot, but equally to ChatGPT, Gemini, Claude, or Le Chat when employees use them outside your tenant. This is exactly where ONYRI Sanitize fits in.
- The tokenizer runs 100% in the browser. It detects names, customer data, credentials, or API keys in the text.
- Detected values are replaced with reversible tokens before sending. The token-to-value mapping never leaves your browser.
- When you use the built-in chat, the AI model only receives the already-anonymised text. Afterwards, the original values are restored in the answer.
- Important and honest: this is pseudonymisation, not anonymisation. Pseudonymised data remains personal data (GDPR Recital 26). ONYRI reduces exposure and supports data minimisation — it does not remove your obligations.
This way you combine the benefit of AI with less disclosure. Copilot stays Copilot, but sensitive details do not have to land in every prompt.
Data protection with Copilot is not a single switch. It is shared responsibility: Microsoft supplies the commitments, you supply the contract, the configuration, and discipline in what you enter.
Frequently asked questions
- Does Microsoft train its AI on our Copilot data?
- According to Microsoft, your prompts, responses, and the tenant data retrieved through Microsoft Graph are not used to train the foundation models. For binding detail, check the current Microsoft Learn documentation, since policies can change.
- Do we need a DPA for Microsoft 365 Copilot?
- Yes. As the controller, you need a data processing agreement under Art. 28 GDPR. Microsoft provides its Data Protection Addendum, which you must accept and document.
- Does our data stay in the EU with Copilot?
- According to Microsoft, the EU Data Boundary processes and stores certain customer data within the EU and EFTA. Whether your specific use case is fully covered should be checked against the official documentation.
- Is Copilot therefore automatically GDPR-compliant?
- No. Microsoft's commitments are a foundation, but compliance depends on your configuration, permissions, the DPA, and your internal rules. Your responsibility as the controller remains with you.
Sources & references
- Data, privacy, and security for Microsoft 365 Copilot — Microsoft Learn
- EU Data Boundary for the Microsoft Cloud — Microsoft Learn
- Regulation (EU) 2016/679 (GDPR) — EUR-Lex
- DSK Guidance: Artificial Intelligence and Data Protection — Datenschutzkonferenz (DSK)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.