Is Microsoft Copilot safe for confidential information?
· Updated · Written and maintained by Joaquín Trapero, Nonimo
Is Copilot safe for confidential client work? The first answer is a question back: which Copilot? Microsoft has attached the name to at least four different products with four different sets of promises, and what separates two of them is neither a setting nor a price but the account someone signed into, which nobody can see from across the room.
Signed in with a work account, Microsoft states that prompts, responses and data reached through Microsoft Graph are not used to train foundation models, and that the contractual protections it calls enterprise data protection apply. Signed in with a personal account, neither statement is true: conversations are used for training unless the person opted out, and there is no opt-out of human review at all.
This guide separates the four, from Microsoft’s own documentation as it stood on 19 September 2026, and then deals with the three things that apply whichever one you are on: the web search that leaves the boundary by design, where the data is processed if you are British, and what none of it fixes.
Four products, one name
Microsoft renamed things in 2026, and the note at the top of its own documentation says so: Microsoft 365 Copilot is now named Microsoft Copilot, and Microsoft 365 Copilot Chat is now named Microsoft Copilot Chat. Older pages still use the long names.
| What someone is using | The account | Training on your content |
|---|---|---|
| Microsoft Copilot, consumer | A personal Microsoft account | Yes, unless that person opted out |
| Microsoft Copilot, licensed | A Microsoft Entra work account | No, and enterprise data protection applies |
| Microsoft Copilot Chat | A Microsoft Entra work account | No, and enterprise data protection applies |
| GitHub Copilot | A GitHub account, separate terms | A different product with a different answer |
A fifth case is worth naming because it catches people: Copilot inside Microsoft 365 apps on a Personal or Family subscription. Microsoft lists them among the users it does not train on, and says they will not even see the training setting.
If your firm has never written down which of these your staff use, that is the gap, and the AI policy template is the cheapest way to close it this week.
The consumer Copilot trains by default, and the UK is not excluded
Microsoft’s privacy FAQ for Copilot is unusually direct about this. Except for certain categories of user and those who have opted out, Microsoft uses data from Bing, MSN, Copilot and interactions with ads for AI training.
The exclusion list, and who is on it
Read the FAQ’s list as a British reader and only one line matters.
| Excluded from consumer Copilot training | |
|---|---|
| Signed in with an organisational Entra ID account | Enterprise data protection applies instead |
| Using Copilot in Microsoft 365 apps on Personal or Family | They do not see the setting |
| Not signed in at all | No account to attach it to |
| Under the age of 18 and signed in | |
| Users who have opted out | The setting is in Copilot’s privacy settings |
| Brazil, China excluding Hong Kong, Israel, Nigeria, South Korea, Vietnam | No user data used for training in those markets |
The United Kingdom is not in that last row. Nor is any European country. So on the consumer Copilot, a British user’s conversations are used for generative AI model training unless that person went into settings and turned it off, and nothing about being in Britain changes that.
To be fair to the drafting, Microsoft also limits what it trains on: it says it does not train on personal account data such as your Microsoft account profile or email contents, and that it takes steps to strip identifying details from uploaded images and files, removing metadata and blurring faces. That is a genuine mitigation for photographs. It is not much help with a letter, where the identifying information is the prose.
Eighteen months, and no opt-out of human review
Two more lines from the same FAQ belong in any decision about this product.
The first is retention: by default Microsoft stores conversation activity for 18 months, and a file you share with Copilot is stored securely for no longer than 18 months before automatic deletion. You can delete individual conversations or the whole history at any time.
The second is the one with no setting attached. Microsoft states that some Copilot conversations are subject to both automated and human review for product improvement and digital safety, and then answers the obvious next question directly: an opt-out of human review is not available.
Personalisation, and the adverts that use your history
Personalisation is on by default where it is available to you, and it is separate from the training setting. You can opt out of training and leave personalisation on, in which case Copilot still remembers recent conversations.
Advertising has a third switch of its own. Microsoft states that if your settings allow personalised ads in Copilot and the personalisation setting is on, it will use your Copilot conversation history to help further personalise the ads you already receive. Three separate controls, three separate answers, and turning one off tells you nothing about the other two. Among Copilot’s main rivals, only ChatGPT now advertises against chat context, as the ChatGPT guide sets out.
With a work account, the answer changes
This is the product most British firms are actually entitled to use, often without realising it, because Copilot Chat comes with work accounts they already pay for. In a GP surgery or a hospital trust the work account settles the contract but not the prior question, which is whether a patient letter may go into it at all.
What enterprise data protection promises
Microsoft’s enterprise data protection page describes a set of contractual commitments under the Data Protection Addendum and the Product Terms, with Microsoft acting as a data processor. Four of its promises matter here.
| The commitment | What it means for a firm |
|---|---|
| Not used to train foundation models | Prompts, responses and Microsoft Graph data are excluded |
| Your access controls apply | Copilot respects permissions, sensitivity labels and retention policies |
| Same terms as Exchange and SharePoint | The protections you already rely on for email and files |
| Microsoft is the processor | You remain the controller, with the duties that carries |
The third row is the useful one for a partner making a decision. Copilot with a work account is governed by the same contract as the email system your firm has trusted for a decade. That is a meaningful answer to give a client, and it is a far better answer than any consumer product can offer. For a chartered accountant it is one of the three things ICAEW asks for before client data goes in.
The place Microsoft says it opted out of human review
One sentence in the privacy documentation is worth quoting, because it is the mirror image of the consumer answer. While abuse monitoring, which includes human review of content, is available in Azure OpenAI, Microsoft states that Copilot services have opted out of it.
Set that against the consumer FAQ, where an opt-out of human review is not available. Same brand, opposite answer, and the only variable is the account. That single contrast is the most useful thing in this guide, and it is worth saying to staff in exactly those terms, then writing it into your AI policy. For comparison, Google states the opposite for its consumer product, as the Gemini guide sets out.
Training is not the same as passing through Microsoft’s servers
Everything above is about training, and training is the least important of the five things that happen to a document.
When someone sends a file, it is transmitted to a company outside your firm, it is retained for some period, an automated system reads it, it becomes reachable by legal process directed at whoever holds it, and it may or may not be used to adjust model weights. A training promise answers the last one. The other four are still open, and they are what a client is asking about.
Microsoft’s own documentation is honest about this in a way that helps. It states that when you enter prompts, the information in them, the data they retrieve and the generated responses are processed and stored in alignment with the contractual commitments covering your other Microsoft 365 content. Stored is the operative word. The interaction is kept, encrypted, and an administrator can find it.
Whether a particular interaction is also a reportable breach is a separate test, worked through in the breach guide.
Who can read a Copilot conversation inside your own firm
This one surprises staff more than anything to do with Microsoft, and it should be said out loud before someone finds out the hard way.
Microsoft stores the user’s prompt and Copilot’s response, with citations, as the user’s Copilot activity history. Administrators can view and manage that stored data using Content search or Microsoft Purview, and can set retention policies for it. For Teams chats with Copilot, admins can also use the Teams Export APIs.
| Who can reach a conversation on a work account | How |
|---|---|
| The person who typed it | Their own Copilot activity history |
| Your administrators | Content search, Microsoft Purview, retention policies |
| Your eDiscovery process | Search and delete AI application data in eDiscovery |
| Microsoft, as processor | Under the Data Protection Addendum, on your instructions |
There is a control on the user’s side: people can delete their Copilot activity history from the My Account portal. But a retention policy set by your firm is a decision for the firm, and eDiscovery reaches what retention keeps.
Far from a flaw, that is exactly why a work account is the safer place for client material, and exactly why someone should be told before they type something they would not put in an email. Neither ChatGPT nor Claude gives a small firm the same admin reach without a business plan.
The web search that leaves the boundary by design
Here is the carve-out, and it is the single most misunderstood thing about Copilot. The general case is set out in client data and a data breach; what follows is the British detail.
When web search is on, Copilot reads the prompt, picks out terms where the web would improve the answer, and generates a short search query that it sends to the Bing search service. That query is a few words, not your prompt and not your document.
What Microsoft commits to, and what falls outside it
The commitments on those queries are real and specific. Microsoft states they are sent with user and tenant identifiers removed, that it has no rights to them beyond providing the service, that they are not used to improve Bing, not used to build advertising profiles or track behaviour, not shared with advertisers, not used to train generative AI foundation models, and are treated as customer confidential information.
Then come the exclusions, and they are what a compliance officer needs.
| What does not apply to a generated web query | Microsoft’s wording |
|---|---|
| The Data Protection Addendum | It “doesn’t apply to the use of generated web search queries” |
| HIPAA compliance | Does not apply to generated search queries |
| The EU Data Boundary | Does not apply to generated search queries |
| Microsoft as your processor | For web query data Microsoft acts as a data controller |
That last row is the structural point. For the prompt, Microsoft is your processor and you are the controller. For the query it derives from your prompt and sends to Bing, Microsoft is an independent controller in its own right, under the Microsoft Services Agreement and the Microsoft Privacy Statement rather than your addendum.
The example from Microsoft’s own table
Microsoft publishes worked examples, and one of them makes the risk concrete without anybody having to speculate. The user prompt is “Who is my manager and what public information is available about them?” The generated search query is the manager’s name.
So the identifiers stripped from the query are yours, not theirs. Copilot removes the user and tenant identifiers, which protects the person typing. The words it sends can still be a named individual, because that is what the prompt was about.
Two practical notes. The web content toggle is on by default when an administrator enables web search, so this is the state most tenants are in. And administrators can audit the exact queries: they appear in Purview audit logs and in activity explorer in Data Security Posture Management for AI, while web search query citations show users the exact queries in Copilot Chat for 24 hours.
Where the data is processed, if your firm is British
Microsoft names a boundary, and the boundary is not ours.
The privacy documentation states that Copilot calls to the language model are routed to the closest data centres in the region, and can call into other regions when capacity is short. Then: “For European Union (EU) users, we have additional safeguards to comply with the EU Data Boundary. EU traffic stays within the EU Data Boundary while worldwide traffic can be sent to the EU and other countries or regions for LLM processing.”
And on residency, in so many words: “For EU customers, Microsoft Copilot is an EU Data Boundary service. Customers outside the EU may have their queries processed in the US, EU, or other regions.”
The United Kingdom is outside the EU. A British tenant is therefore in the second sentence, not the first, and on the face of the document its Copilot queries may be processed in the United States, the EU or elsewhere.
Advanced Data Residency does cover the UK
This is where a British firm gets something back, and it is worth knowing before anyone concludes the worst.
Microsoft’s Advanced Data Residency add-on commits to keeping customer data at rest in a local region, the United Kingdom is one of the eligible Local Region Geographies, and Copilot and Copilot Chat are among the covered services. Eligible licences include Microsoft 365 Business Basic, Standard and Premium, which is what a firm of this size actually owns.
There are two conditions and both bite. It is a paid add-on, and the tenant must hold ADR licences covering 100 per cent of eligible purchased seats, not just the seats in use. Fall below that and Microsoft states the data may be relocated outside the local region.
So the position for a British firm is precise, and it is the whole argument in one paragraph. You can buy a commitment about where the data sleeps. The boundary Microsoft names for where the processing happens is the European Union’s, and you are not in it.
The subprocessor that sits outside the boundary
One more line, and it is recent enough that most advisers have not read it. Microsoft offers models from other companies inside Copilot, and its documentation states that models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary and, where applicable, from commitments to process data within a country.
Administrators choose whether to enable those models. That says nothing against any one provider. What it shows is that a residency commitment has a supply chain behind it, and the answer to “where is our data processed” can change when somebody ticks a box in an admin centre. That belongs in the questions you answer for an insurer about your AI use at renewal.
Who your data controller is, if your firm is in the UK
Read the same clause across four providers and the British answer splits two against two. Microsoft is on the better side of it for a UK reader.
The Microsoft Privacy Statement says that where Microsoft is a controller, Microsoft Corporation and, for those in the European Economic Area, the United Kingdom and Switzerland, Microsoft Ireland Operations Limited are the data controllers, at One Microsoft Place, Dublin 18.
| Provider | Controller named for a UK user | Where |
|---|---|---|
| Microsoft Copilot | Microsoft Ireland Operations Limited | Dublin |
| Claude | Anthropic Ireland, Limited | Dublin |
| ChatGPT | OpenAI OpCo, LLC | San Francisco |
| Gemini | Google LLC | Mountain View |
Note what this table covers and what it does not. Microsoft names the Irish entity where it is a controller, which covers the consumer product. For Copilot with a work account, Microsoft is your processor and your firm is the controller, so the row above describes the consumer case and the Bing query case rather than your tenant. The other three rows are read from their own pages in the guides on ChatGPT, Claude and Gemini.
GitHub Copilot is a different product
Worth one paragraph so nobody is caught out by the name. GitHub Copilot is a coding assistant with its own terms, its own account and its own settings, and none of the Microsoft 365 commitments above transfer to it.
For a firm, the exposure there lies less in the source code than in the fixtures: a database dump used for testing, a support ticket pasted into a comment, a client name in a branch. If a contractor is building something for you, the account they use is the one that decides the terms, and it is not yours. The equivalent question for Anthropic’s coding tool is answered in the Claude guide.
What to check this week
Five things, none of which needs a purchase.
- Look at which account each person is signed into. Open Copilot on the device they actually use and read the account at the top. Then check their phone. This single check answers most of the questions above.
- Decide on web search. The Allow web search in Copilot policy is in Cloud Policy service for Microsoft 365, and it can be off for work mode while on elsewhere.
- Check whether you hold ADR. Your Data Location Card in the Microsoft 365 admin centre shows the committed geography and the ADR licence count.
- Ask about Anthropic models. Whether they are enabled in your tenant changes your answer on processing location.
- Tell people about the consumer version. They have a personal Microsoft account, it trains by default, and there is no opt-out of human review on it.
Four of those five are questions for whoever runs your systems, and the fifth is a conversation with your staff. Neither costs anything, and together they decide most of your answer.
Is Copilot safe under UK law?
No regulator has ruled on a named product, and any page claiming the ICO has approved or banned Copilot is wrong. What applies is the UK GDPR with the Data Protection Act 2018, supervised by the ICO, plus your professional regulator and your indemnity insurer. A council adds freedom of information, which can reach what a supplier holds on its behalf, as the guide for council officers explains.
Your firm is the controller for the client data it holds. You need a lawful basis, and you owe data minimisation and the security duties in Article 5(1)(f) and Article 32. The ICO’s practical advice is a sequence: identify a lawful basis before any sharing begins, then minimise, because “if an organisation is able to anonymise the information, or remove identifiable information from the documents shared, then they should do so”.
Processor for the prompt, controller for the query
The Copilot architecture produces a split that is unusual enough to be worth writing into your record of processing. For the prompt and the response, Microsoft is your processor under the Data Protection Addendum. For the web query derived from that prompt, Microsoft is an independent controller and the addendum does not apply. Where those roles sit is one of the things a UK buyer has to establish tool by tool.
Covered by the Data Protection Addendum and the Product Terms. Not used to train foundation models. Stored under the same commitments as your other Microsoft 365 content, where your administrators and eDiscovery can reach it. Your firm is the controller.
A few words Copilot derives from the prompt, sent with user and tenant identifiers removed. The Data Protection Addendum, HIPAA and the EU Data Boundary do not apply. Microsoft is an independent controller under the Microsoft Services Agreement and the Microsoft Privacy Statement.
The ICO’s own position makes that split harder to wave away, because it said that controllership turns on practical reality rather than labels and that “a contract does not necessarily determine whether an organisation is a controller”. A document that describes your Copilot deployment as a single processing relationship is describing something simpler than what is happening.
One duty is newer than most guidance acknowledges. The ICO states that all data protection provisions of the Data (Use and Access) Act 2025 came into force on 19 June 2026, and you must acknowledge a complaint about your handling of personal information within 30 days and respond without undue delay. What is arriving through your customers rather than your regulator is in our note on the EU AI Act timetable.
What none of this fixes
Everything above is about a service. The problem in a small office is a person, on a deadline, with a bundle that will not summarise itself. In litigation, that bundle reaches Copilot long before anything you sign for the court about AI.
Configure a tenant perfectly and one thing remains true: the document went to a company outside your firm, and the words in it are still the words in it. Delete every name from a page of correspondence and a specific street address, a child in the household and a file reference at a named previous adviser will still identify the matter to anyone who has seen the file. Identifiability belongs to the whole document, not to the words you removed.
What a masking tool does here, and what it does not
The facts first, so you can check them. Nonimo is a Mac and Windows app that finds identifiers in text before it is sent and hides them, working on the machine rather than in a cloud, with a policy set by IT rather than by each user.
For the United Kingdom it covers NHS numbers, UTRs and driving licence numbers written after their label, National Insurance numbers with or without one, and postcodes, plus a vehicle registration, masked as a number plate when a word such as “Registration:” comes before it, and a mobile number that follows a label such as “Mobile:”.
Each of them is masked in front of you, where you can undo it, so the person who knows the matter has the last word on every change.
What the tool puts in place of an identifier is a reversible label, and the key linking each label to the real detail is kept encrypted on your own computer. That is pseudonymisation in the sense Article 4 gives the word, so the data remains personal data for whoever holds the key, and the key is yours. It lowers risk without moving a document outside data protection law, and the longer treatment is in the breach guide.
What it keeps on your computer is set out on Nonimo’s security page.
Move people onto it.
Leave it for weekend recipes.
Five lines at most: the documents that never go into either.
So is Copilot safe for a small British firm? If you buy nothing at all, the Microsoft answer is better than most firms realise, and it is already paid for. Move people onto the work account, leave the consumer app for weekend recipes, and write a short list, five lines at most, of the documents that never go into either.
Whether your insurance would pay out if it went wrong is a separate question, set out in the UK cyber insurance comparison, and our other guides cover what to look for when it is time to judge a tool.
Put the same tests to ChatGPT, Claude and Gemini and the answers differ, but none of them is that the document stayed in your office.
Sources
Checked 19 September 2026.
- Microsoft, Data, Privacy, and Security for Microsoft Copilot, article date 9 July 2026, updated 18 August 2026. That prompts, responses and Microsoft Graph data are not used to train foundation LLMs; that Copilot services have opted out of the Azure OpenAI abuse monitoring that includes human review; the data stored about user interactions and the admin tools that reach it; the EU Data Boundary wording and the sentence about customers outside the EU; and the exclusion of Anthropic subprocessor models from that boundary.
- Microsoft, Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat, article date 29 May 2026. What EDP covers, Microsoft acting as processor under the Data Protection Addendum and Product Terms, and the footnotes stating that the EU Data Boundary and HIPAA do not apply to web search queries.
- Microsoft, Data, privacy, and security for web search in Microsoft Copilot and Microsoft Copilot Chat, 18 August 2026. How the generated query is built, the identifiers removed, the six Product Terms commitments, the exclusions from the DPA, HIPAA and the EU Data Boundary, Microsoft as independent controller, the worked example whose generated query is the manager’s name, the admin policy and the default state of the web content toggle.
- Microsoft, Advanced data residency in Microsoft 365, article date 18 May 2026. Copilot and Copilot Chat as covered services, the United Kingdom in the Local Region Geography list, the eligible licences including Microsoft 365 Business plans, and the requirement to cover 100 per cent of eligible seats.
- Microsoft, Privacy FAQ for Microsoft Copilot. Consumer training by default and the opt-out, the published list of users and countries excluded from training, the default retention of 18 months for conversation activity and uploaded files, the statement that an opt-out of human review is not available, personalisation on by default, and the use of conversation history to personalise advertising.
- Microsoft Privacy Statement. Microsoft Ireland Operations Limited as the data controller for those in the European Economic Area, the United Kingdom and Switzerland.
- ICO, Allocating controllership across the generative AI supply chain. That a contract does not necessarily determine controllership.
- ICO, Innovation advice: previously asked questions. The sequence of lawful basis then minimisation, and the quoted line on removing identifiable information before sharing.
- ICO, The Data (Use and Access) Act 2025: what does it mean for organisations. All data protection provisions in force from 19 June 2026, and the complaints duty with its acknowledgement within 30 days.
- UK GDPR, Article 4 and the Data Protection Act 2018. The definition of pseudonymisation and the domestic regime the ICO supervises.
- Anthropic, Privacy Policy, effective 10 September 2026; Google, Privacy Policy, effective 2 April 2026; OpenAI, Europe privacy policy, 24 August 2026. The other three rows of the controller table. OpenAI’s domain returns 403 when fetched from the command line and was read in a browser.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Is Microsoft Copilot safe for confidential information?
It depends which Copilot. Signed in with a work account, Microsoft states prompts and responses are not used to train foundation models and enterprise data protection applies. Signed in with a personal account, neither is true.
Does the consumer Copilot train on my conversations?
Yes, unless you opt out. Microsoft's privacy FAQ lists the users excluded from training, including six named countries, and the United Kingdom is not among them. The opt-out is in Copilot's privacy settings.
Can I stop humans reading my Copilot conversations?
Not on the consumer product. Microsoft states that some conversations are subject to automated and human review, and that an opt-out of human review is not available because of Code of Conduct investigations.
Does Microsoft 365 Copilot train on our company documents?
No. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation LLMs, and that Copilot services have opted out of the human abuse monitoring available in Azure OpenAI.
Do Copilot web searches leave the Microsoft 365 boundary?
Yes, by design. Copilot generates a short query and sends it to Bing with user and tenant identifiers removed. Microsoft acts as controller there, and says the Data Protection Addendum and the EU Data Boundary do not apply.
Is the UK inside the EU Data Boundary for Copilot?
No. Microsoft states that for EU customers Copilot is an EU Data Boundary service, and that customers outside the EU may have their queries processed in the US, EU or other regions. The UK is outside the EU.
Can a UK firm get UK data residency for Copilot?
For data at rest, yes. Advanced Data Residency is a paid add-on, the United Kingdom is in its Local Region Geography, and Copilot is covered. It requires ADR licences covering 100 per cent of eligible seats.
Who is my data controller for Copilot if I am in the UK?
Microsoft Ireland Operations Limited, in Dublin. The Microsoft Privacy Statement names it as controller for those in the European Economic Area, the United Kingdom and Switzerland together. For Copilot on a work account Microsoft is your processor, so your firm is the controller.