Is Microsoft Copilot GDPR compliant? What universities should check
Most European universities already run Microsoft 365, so Copilot Chat often arrives without a procurement decision. This page sets out what Microsoft publicly documents for Copilot used with a work or school (Entra ID) account, where the EU Data Boundary stops, and the questions a DPO should settle before switching features on.
Short answer
Microsoft Copilot (formerly Microsoft 365 Copilot) and Microsoft Copilot Chat (formerly Microsoft 365 Copilot Chat) are Microsoft products; for the EEA, Microsoft Ireland Operations Limited in Dublin is Microsoft's data protection representative and the EU exporter under its transfer clauses. Copilot Chat is included with Microsoft 365 subscriptions, while Microsoft Copilot is a paid licence that also reasons over the user's mail, files and chats. Used with a work or school account, both fall under Microsoft's Data Protection Addendum with Microsoft as processor, are not used to train foundation models, and are documented as EU Data Boundary services, with exceptions for Bing web search and Anthropic models. Whether a university can use them depends on its Microsoft 365 agreement, its tenant configuration (web search, third-party models, agents, retention), its permission hygiene in SharePoint and Teams, and what personal data users will put in.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers an AI assistant for research work with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Microsoft Copilot documents publicly
Everything below comes from Microsoft Learn, Microsoft's Data Protection Addendum (May 2026 edition), the Microsoft Privacy Statement and the official Data Privacy Framework List, all read on 7 October 2026. It covers Copilot and Copilot Chat used with a Microsoft Entra (work or school) account, not consumer Copilot on a personal Microsoft account.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Microsoft Ireland Operations Limited (Leopardstown, Dublin) is Microsoft's data protection representative for the EEA and Switzerland under the DPA, and the EU party to the 2021 Standard Contractual Clauses with Microsoft Corporation. Where Microsoft acts as controller, the Privacy Statement names Microsoft Ireland Operations Limited as controller for people in the EEA. | [4], [6] |
| Where data is stored and processed | Documented For EU customers, Copilot is an EU Data Boundary service and EU traffic stays within the boundary for model processing. The boundary covers EU and EFTA countries; Microsoft 365 tenants with a sign-up location in the EU or EFTA are in scope, but tenants with Multi-Geo Capabilities are not. Copilot was added to the data residency commitments in the Product Terms on 1 March 2024. Exceptions: Bing web search queries are not covered by the boundary, and Anthropic models are excluded from it. | [1], [2], [3], [5] |
| Data processing agreement | Documented Use of Copilot and Copilot Chat by organisations is covered by the Microsoft Products and Services Data Protection Addendum and the Product Terms, with Microsoft acting as processor. Copilot Chat offers this "enterprise data protection" to users signed in with an Entra account, without admin action. Web search queries are handled by Bing under the Microsoft Services Agreement and Privacy Statement, with Microsoft as an independent controller. | [2], [7] |
| Subprocessors | Documented Microsoft publishes its subprocessor list on the Service Trust Portal. OpenAI and Anthropic are named as subprocessors for models in Copilot experiences. The DPA promises at least 6 months' notice of new subprocessors, or 30 days' notice for subprocessors supporting AI functionality, with the ability to disable them until at least 6 months after notice. | [1], [4], [5] |
| International transfers | Documented Transfers out of the EU, EEA, UK and Switzerland are subject to the 2021 SCCs. Microsoft also states that it is certified to the EU-U.S. Data Privacy Framework. On the official DPF List, Microsoft Corporation's EU-U.S. status read "Active - Re-certification under Review" when we searched. | [4], [8] |
| AI model training on customer content | Documented Prompts, responses and data accessed through Microsoft Graph are not used to train foundation LLMs, including those used by Copilot. Optional customer feedback may be used to improve Copilot but not to train those models, and admins can manage feedback. Microsoft says Copilot services have opted out of the human abuse-monitoring review that is available in Azure OpenAI. | [1], [2] |
| Retention and deletion | Documented Prompts and responses are stored as Copilot activity history alongside the organisation's other Microsoft 365 content. Admins can search it and set retention through Microsoft Purview; users can delete their own history. Under the DPA, data is kept for 90 days after a subscription ends so the customer can extract it, and then deleted. | [1], [4] |
| Security certifications | Documented Microsoft lists compliance offerings for Copilot including ISO 27001, ISO/IEC 27018, HIPAA support and ISO 42001 for AI management systems. | [1], [2] |
| Institution and enterprise controls | Documented Copilot only surfaces content the user already has permission to see, honours sensitivity labels and Purview encryption, applies retention policies and supports audit. Admins choose which agents are allowed and whether third-party model subprocessors may be used. Students under 13 are not eligible for Copilot Chat, and admins must take extra steps for students aged 13 and over. | [1], [2], [5], [7] |
What this means for a university
Validemic's analysisThe contract is probably already in place. Unlike most AI tools, Copilot and Copilot Chat sit inside the Microsoft 365 agreement a university has usually assessed already. Microsoft states that the same DPA and Product Terms that cover Exchange and SharePoint cover Copilot prompts and responses [2]. That is a real strength: Article 28 GDPR requires processing on a controller's behalf to be governed by a binding contract [9], and here the contract, the EU Data Boundary, the 6-month subprocessor notice and the training restriction are all documented in one place.
The gaps are in the switches, not the contract. Two documented exceptions decide how much of a Copilot session stays inside the DPA and the boundary. First, web search: Copilot turns parts of a prompt into a Bing query, which Microsoft handles as an independent controller outside the DPA and outside the EU Data Boundary, with user and tenant identifiers removed [2]. Second, Anthropic models: they are excluded from the EU Data Boundary, and for EU, EFTA and UK tenants they are off by default but can be turned on by an admin, including a setting introduced on 3 April 2026 to make Anthropic the default model for Copilot in Microsoft 365 apps [5]. Some newer models are offered only under Anthropic's own terms with data retention [5]. A DPO should know who in IT can change these settings and record the decision.
Permissions become the main risk. Microsoft Copilot (the licensed version) answers from everything a user can access in Microsoft Graph [1]. In a university, old Teams sites, shared drives with student records and HR folders with broad "everyone" access are common. Copilot does not widen access, but it makes overshared content much easier to find. A permissions review in SharePoint and Teams is a practical precondition.
A DPIA is likely for a broad rollout. Article 35 GDPR requires a DPIA where processing using new technologies is likely to result in a high risk [9]. Licensed Copilot processes staff mail, chats and meeting content, which can include student data, health information and HR matters. Many DPOs will treat a tenant-wide rollout as needing a DPIA, and national DPA lists may require one. Copilot Chat without Graph access is narrower, since it only sees what the user types or uploads [7].
Transfers are covered, with a review flag. Microsoft relies on the 2021 SCCs and on its DPF certification [4]. On the date we checked, the DPF List showed Microsoft's certification as active with re-certification under review [8], which is worth noting in the transfer record and re-checking. The European Commission lists the United States as adequate for organisations participating in the EU-US Data Privacy Framework [10].
Students and staff. Microsoft makes Copilot Chat available to students aged 13 and over after admin configuration [7]. Staff with a paid licence get Graph-grounded answers; most students will have Copilot Chat only. Consumer Copilot on a personal Microsoft account is a different product for personal use [7], so guidance should tell staff and students to sign in with their university account.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Microsoft before approving it
- Is our tenant in scope for the EU Data Boundary, or does Multi-Geo or our sign-up location take it out of scope?
- Which Copilot features in our tenant send data outside the EU Data Boundary today (web search, Anthropic models, agents, previews), and how do we turn each one off?
- Who in our organisation holds the AI Administrator or Global Administrator role that can enable Anthropic or other third-party models, and is that change logged?
- How will we be notified of new AI subprocessors under the 30-day notice in the DPA, and how do we disable one?
- Which retention policy applies to Copilot activity history by default, and can we set a shorter period for students than for staff?
- Can we see audit records of Copilot interactions for access requests and incident investigations?
- Which agents from the store are available to Copilot Chat users by default, and which of them process data under their own terms?
- What is the current status of Microsoft Corporation's DPF re-certification, and does anything change in our transfer assessment if it lapses?
- Does Microsoft provide a DPIA template or risk assessment pack for Copilot that covers education use?
The EU AI Act angle
Regulation (EU) 2024/1689, the AI Act, has applied in stages [11]. Article 4 on AI literacy has applied to deployers since 2 February 2025. The Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026, replaced Article 4: providers and deployers must take measures to support the AI literacy of their staff, without guaranteeing a specific level for any individual [12], [13]. A university that enables Copilot is a deployer and should train and guide its users.
Using Copilot for drafting, summarising or search is normally not a high-risk use. It becomes one if the university uses it for the purposes in Annex III point 3: admission decisions, evaluating learning outcomes, assessing the appropriate level of education, or monitoring students during tests [11]. After the Omnibus, the Annex III high-risk rules apply from 2 December 2027 [12], [13]. Chapter V obligations for general-purpose AI models have applied since 2 August 2025 and sit with the providers of the underlying models, not with the university [11]. Microsoft, OpenAI and Anthropic all appear on the European Commission's list of signatories of the General-Purpose AI Code of Practice [14].
Sources
- Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot, retrieved 7 October 2026.
- Microsoft Learn, Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat, retrieved 7 October 2026.
- Microsoft Learn, What is the EU Data Boundary? (last updated 26 February 2025), retrieved 7 October 2026.
- Microsoft, Microsoft Products and Services Data Protection Addendum (DPA) (English, May 2026 edition, last updated 22 May 2026), retrieved 7 October 2026.
- Microsoft Learn, Anthropic models in Microsoft Online Services, retrieved 7 October 2026.
- Microsoft Privacy Statement (last updated September 2026), retrieved 7 October 2026.
- Microsoft Learn, Frequently asked questions about Microsoft Copilot Chat, retrieved 7 October 2026.
- U.S. Department of Commerce, Data Privacy Framework List (entry for Microsoft Corporation), retrieved 7 October 2026.
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28 and 35, retrieved 7 October 2026.
- European Commission, Data protection adequacy for non-EU countries, retrieved 7 October 2026.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal L, 12 July 2024, Articles 4 and 113 and Annex III, retrieved 7 October 2026.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal L, 24 July 2026, retrieved 7 October 2026.
- European Commission, AI Act (application timeline), retrieved 7 October 2026.
- European Commission, The General-Purpose AI Code of Practice (signatories), retrieved 7 October 2026.
About this page
We read Microsoft's public Learn documentation, the May 2026 English edition of the Data Protection Addendum, the Microsoft Privacy Statement, the official Data Privacy Framework List and the EU legal texts on 7 October 2026. The page covers Copilot and Copilot Chat for work and school accounts; we did not test a tenant or review any customer-specific agreement. Microsoft renamed these products during 2026 and updates its documentation often, so check the linked pages before relying on them. This page is not legal advice and is not a verdict on whether any organisation's use of Copilot complies with the GDPR. If you work at Microsoft or spot an error, please contact us and we will correct it.
Frequently asked questions
Does Microsoft Copilot train on my data?
For Microsoft Copilot and Copilot Chat used with a work or school (Entra ID) account, Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation large language models. Optional feedback may be used to improve the service but, Microsoft says, not to train those models (checked 7 October 2026).
Does Microsoft Copilot stay in the EU Data Boundary?
Microsoft says Copilot is an EU Data Boundary service for EU customers and that EU traffic stays within the boundary. Two documented exceptions matter: web search queries sent to Bing are not covered, and Anthropic models are excluded from the EU Data Boundary (they are off by default for EU, EFTA and UK tenants).
Is Copilot Chat covered by our Microsoft DPA?
Microsoft says Copilot and Copilot Chat used by organisations are covered by the Microsoft Products and Services Data Protection Addendum and the Product Terms, with Microsoft acting as processor, when users sign in with an Entra account. Web search queries are handled by Bing with Microsoft as an independent controller.
Can students use Microsoft Copilot Chat?
Microsoft says students under 13 are not eligible for Copilot Chat and that admins must take additional steps to enable it for students aged 13 and over. A university still needs to decide, as controller, whether and how students may use it and whether a DPIA is needed.
Is consumer Copilot the same as Copilot Chat?
No. Microsoft distinguishes Copilot Chat and Microsoft Copilot for work and education, accessed with an Entra account, from the consumer Microsoft Copilot used with a personal Microsoft account. Only the work and school versions come with the enterprise data protection commitments described on this page.