Is GitHub Copilot GDPR compliant? What universities should check
GitHub Copilot is free for verified students and teachers through GitHub Education, so it is often in use at a university long before anyone has assessed it. This page sets out what GitHub publicly documents about plans, AI training, contracts, subprocessors, transfers and EU data residency, and what that means for a university.
Short answer
GitHub, a Microsoft subsidiary, offers Copilot on individual plans (Free, Student, Pro, Pro+ and Max) and organisation plans (Business and Enterprise). The difference matters a great deal. Since 24 April 2026, interaction data from Copilot Free, Pro and Pro+ (and Max, according to GitHub's settings page) is used to train AI models unless the user opts out, while Business and Enterprise data is covered by the GitHub Data Protection Agreement and not used for training. GitHub states that it is certified under the EU-U.S. Data Privacy Framework, uses the Standard Contractual Clauses and offers EU data residency for Copilot on GitHub Enterprise Cloud. Free student and teacher access comes through GitHub Education to individuals, not through an institutional contract.
What GitHub documents publicly
Everything in this table comes from GitHub's own documentation, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented GitHub, Inc. (San Francisco) and GitHub B.V. (Amsterdam) are named in the privacy statement, effective 27 April 2026. GitHub is owned by Microsoft. A Data Protection Officer can be contacted at GitHub. | [1] |
| Plans | Plan-dependent Individual: Copilot Free, Copilot Student (free for verified students), Pro, Pro+ and Max. Organisation: Copilot Business and Copilot Enterprise. Verified teachers may get Copilot Pro free. GitHub re-checks education eligibility every month. | [2] [3] |
| Education programme | GitHub Education offers schools free GitHub Enterprise Cloud or Server, but the offer "does not include" Copilot Business, among other features. Free Copilot for students and educators is "not accessed through our educational institutional benefits". | [4] |
| AI training on user data | Plan-dependent From 24 April 2026, inputs, outputs, code snippets and context from Copilot Free, Pro and Pro+ are used to train AI models unless the user turns off "Allow GitHub to use my data for AI model training". The settings page names Free, Pro, Pro+ and Max and does not mention Copilot Student. Business and Enterprise are not affected. GitHub says it does not train on private repository content at rest, and does not let third-party model providers train on inputs or outputs. | [5] [6] [7] |
| Data processing agreement | Documented The GitHub DPA (October 2025) applies to GitHub Enterprise Cloud, Teams and GitHub Copilot. Section J.3 of the Terms of Service on AI training does not apply where use is governed by a GitHub Customer Agreement or volume licensing agreement. Copilot bought directly since 5 March 2026 falls under the GitHub Generative AI Services Terms. | [7] [8] [9] |
| Subprocessors | Documented Public list. For AI services it includes Microsoft Azure (US, Canada, Chile, Mexico), OpenAI and Anthropic (United States) and Google Cloud Platform (US, Belgium, Singapore). GitHub gives 30 days' notice of new subprocessors. | [8] [10] |
| International transfers | Documented The privacy statement says GitHub has certified under the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF. The DPA also includes SCC Modules One, Two and Three. The official DPF list showed GitHub (San Francisco) as active under all three frameworks on 7 October 2026. | [1] [8] [11] |
| Data residency | Enterprise Cloud only Copilot data residency is documented for GitHub Enterprise Cloud with data residency, in US and EU regions. When enforced, inference, prompts, responses, logs and telemetry stay in the region. GitHub's April 2026 announcement says the EU region covers EU and EFTA countries and is off by default, and that data-resident requests carry a 10% increase in the premium request model multiplier. | [12] [13] |
| Retention | The archived Copilot product terms for Business and Enterprise say prompts in the code editor are deleted once suggestions are generated, while tools outside the editor, such as the CLI, retain prompts to provide the service. The privacy statement keeps personal data while the account is active and as needed for legal and contractual reasons. | [1] [14] |
| Security certifications | GitHub reports SOC 2 Type II coverage for Copilot Business and Enterprise, available through the GitHub Enterprise Trust Center. | [15] |
GitHub deserves credit for publishing a detailed subprocessor list, a single DPA that covers Copilot, a clear opt-out setting and an explicit statement that third-party model providers may not train on user inputs or outputs. EU data residency for Copilot, aligned with Microsoft's EU Data Boundary, is a meaningful option for institutions that need it.
What this means for a university
Validemic's analysis
Most university use is individual use. Students get Copilot Student and teachers get Copilot Pro as individuals, under GitHub's standard Terms of Service and privacy statement. No contract between the university and GitHub covers that use, and the university cannot set retention, training or residency policies for it. That is not unusual for a free education benefit, but it means the university's role is guidance rather than control.
The training default is the main point to communicate. Since 24 April 2026, interaction data from Copilot Free, Pro and Pro+ is used for training by default [5]. Students working on assessed code, thesis projects or research software that touches personal data should know where the opt-out is. Because GitHub's settings documentation does not mention Copilot Student by name [6], students should check the setting in their own account rather than assume it is off.
Code can contain personal data. Research code often sits next to data: test fixtures, configuration files, sample records or comments that name participants. Copilot reads the context around the cursor [5], so personal data in open files can be sent to the service. Course and lab guidance should keep real participant data out of repositories and editors where Copilot is active.
Institutional option. For staff developing research software or university systems, Copilot Business or Enterprise under the GitHub DPA puts GitHub in the processor role, excludes training [6] [8] and allows administrators to set policies. Where data must stay in Europe, the Enterprise Cloud data residency option is the documented route [12]. Under Article 28 GDPR [16], that institutional contract is what lets the university meet its own obligations.
Transfers. GitHub relies on the DPF and the SCCs [1] [8]. The European Commission's adequacy decision of 10 July 2023 allows transfers to certified US organisations [17]. Without data residency, AI processing runs through subprocessors largely in the United States [10].
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask GitHub before approving Copilot
- Does the AI training setting apply to Copilot Student accounts, and what is its default for students who signed up before 24 April 2026?
- Can a university manage or restrict Copilot for students who receive it through GitHub Education, or is that only possible through Copilot Business?
- What discount is available for Copilot Business for an accredited university, and does the Educational Institution Amendment apply?
- Is Copilot data residency in the EU available to us on GitHub Enterprise Cloud, and which features or models are excluded?
- Which subprocessors process our prompts and code when data residency is not enforced, and in which countries?
- What retention applies to prompts in agent mode, the CLI and code review under the Generative AI Services Terms?
- Can we obtain the current SOC 2 Type II report and ISO certificates under NDA?
The EU AI Act angle
The EU AI Act, Regulation (EU) 2024/1689, applies alongside the GDPR [18]. A coding assistant is a general productivity tool, not one of the education uses listed as high-risk in Annex III (such as admission decisions, evaluating learning outcomes or monitoring students during tests). Those obligations now apply from 2 December 2027 under Regulation (EU) 2026/1744 [19]. If a course uses Copilot output as part of how student work is assessed, check that use against Annex III with our AI Act education checker. The duty that applies today is AI literacy: Article 4, as amended, requires deployers to take measures to support the AI literacy of staff and others using AI systems on their behalf [20]. For programming courses, that includes teaching students how to review generated code and what data the assistant sees.
Sources
- GitHub General Privacy Statement, effective 27 April 2026, retrieved 7 October 2026
- Plans for GitHub Copilot, GitHub Docs, retrieved 7 October 2026
- About free GitHub Copilot access, GitHub Docs, retrieved 7 October 2026
- GitHub Education for schools, retrieved 7 October 2026
- Updates to our Privacy Statement and Terms of Service: How we use your data, GitHub Changelog, 25 March 2026, retrieved 7 October 2026
- Managing Copilot policies as an individual subscriber, GitHub Docs, retrieved 7 October 2026
- GitHub Terms of Service, Section J, effective 27 April 2026, retrieved 7 October 2026
- GitHub Data Protection Agreement, October 2025, retrieved 7 October 2026
- GitHub Customer Terms, retrieved 7 October 2026
- GitHub Subprocessors, retrieved 7 October 2026
- Data Privacy Framework List, entry for GitHub, retrieved 7 October 2026
- GitHub Copilot with data residency, GitHub Enterprise Cloud Docs, retrieved 7 October 2026
- Copilot data residency in US and EU and FedRAMP compliance now available, GitHub Changelog, 13 April 2026, retrieved 7 October 2026
- GitHub Copilot Product Specific Terms (archived), retrieved 7 October 2026
- The latest GitHub and GitHub Copilot SOC reports are now available, GitHub Changelog, retrieved 7 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), Article 28, retrieved 7 October 2026
- EU-US data transfers, European Commission, retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Annex III, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
About this page
We read GitHub's privacy statement, Terms of Service, Data Protection Agreement, customer terms, subprocessor list, Copilot documentation and changelog posts, and the GitHub Education pages on 7 October 2026. We also searched the official Data Privacy Framework list on the same day. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it. Copilot plans and terms change often, so confirm the current position with GitHub before relying on it.
This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for GitHub and see an error, please contact us and we will correct it.
Frequently asked questions
Is GitHub Copilot GDPR compliant?
No tool is GDPR compliant on its own. GitHub offers a Data Protection Agreement for Copilot, uses the EU Standard Contractual Clauses, states that it is certified under the EU-U.S. Data Privacy Framework and offers EU data residency for Copilot on GitHub Enterprise Cloud. Whether a university's use complies depends heavily on the plan: individual and student plans work very differently from Copilot Business and Enterprise.
Does GitHub Copilot use student code to train AI?
Since 24 April 2026, GitHub uses interaction data (inputs, outputs, code snippets and context) from Copilot Free, Pro and Pro+ to train AI models unless the user opts out in their settings. Copilot Student is also an individual plan; GitHub's settings documentation does not name it explicitly, so students should check the setting in their own account. Copilot Business and Enterprise data is not used this way.
Is GitHub Copilot free for universities?
Copilot is free for verified students, and verified teachers can get Copilot Pro, through GitHub Education. GitHub states that these benefits are not accessed through its institutional programme, and that the free GitHub Enterprise offer for schools does not include Copilot Business.
Can GitHub Copilot keep data in the EU?
GitHub documents Copilot data residency for GitHub Enterprise Cloud with data residency, with US and EU regions. When enforced, inference processing, prompts, responses, logs and telemetry stay in the selected region. Individual and student plans do not offer this.
Is GitHub certified under the EU-U.S. Data Privacy Framework?
GitHub's privacy statement says it has certified to the U.S. Department of Commerce under the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF. The official DPF list showed GitHub as an active participant under all three when we checked on 7 October 2026.