GDPR check

Is Microsoft Teams GDPR compliant? What universities should check

Microsoft Teams is the default place for lectures, supervision and staff meetings at universities that run Microsoft 365 Education. This page sets out what Microsoft publicly documents about the EU Data Boundary, its data protection addendum, recording and transcript storage and Copilot in Teams, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

For universities, Teams is part of a Microsoft 365 Education tenant, so the contract is Microsoft's Product Terms and its Products and Services Data Protection Addendum, under which Microsoft acts as processor. Tenants signed up in the EU or EFTA fall within Microsoft's EU Data Boundary, with limited documented exceptions, and Microsoft states it is certified under the EU-US Data Privacy Framework and uses the 2021 SCCs. Recordings and transcripts land in OneDrive or SharePoint and expire after 120 days by default. Copilot in Teams needs an add-on licence; Microsoft says prompts and meeting data are not used to train foundation models, while Anthropic models sit outside the EU Data Boundary and are off by default in Europe. Dutch public DPIAs by SURF are the most detailed independent reviews available.

What Microsoft documents publicly

The table below summarises Microsoft's privacy statement, Data Protection Addendum (May 2026 version), EU Data Boundary documentation and Teams and Copilot admin documentation, read on 7 October 2026. It covers Teams in a commercial or education Microsoft 365 tenant, not personal Teams accounts.

TopicWhat the vendor statesSource
Company and establishmentDocumented Microsoft Ireland Operations Limited in Dublin is the EU contact point for data protection, and Microsoft Corporation is the US parent. The privacy statement (September 2026) says that for enterprise products, the customer's agreements with Microsoft take precedence over the statement where they conflict.Privacy Statement [1]
Where data is stored and processedDocumented Microsoft 365 customers with a sign-up location in an EU or EFTA country are in scope for the EU Data Boundary: customer data and pseudonymised personal data are stored and processed in the EU and EFTA, subject to limited circumstances Microsoft documents. Tenants that purchased Multi-Geo are not in scope. Datacentres used include Ireland, the Netherlands, Germany, Sweden, Finland, Norway and others.EU Data Boundary [2], DPA [3]
Data processing agreementDocumented The Products and Services DPA (May 2026) applies through the Product Terms. Microsoft commits not to use customer data or personal data for user profiling, advertising or similar commercial purposes, or market research, unless the customer instructs it.[3]
SubprocessorsDocumented Microsoft publishes its subprocessor list through the Service Trust Portal. The DPA promises at least six months' notice before a new subprocessor gets access to customer data, or 30 days for subprocessors supporting AI functionality, with the ability to disable that subprocessor until at least six months after notice.[3], Anthropic models [7]
International transfers (DPF, SCCs)Documented The DPA says transfers out of the EU, EEA, UK and Switzerland are subject to the 2021 SCCs between Microsoft Ireland Operations Limited and Microsoft Corporation, and that Microsoft is certified to the EU-US DPF (DPF status read from Microsoft's DPA and privacy statement; the official list API returned no results for any query on the check date).[3], [1]
Recordings and transcriptionDocumented Meeting recordings and transcripts save to the organiser's OneDrive; channel meeting recordings go to the team's SharePoint site. They expire after 120 days by default, which admins can change; the maximum default for A1 users is 30 days. Admins can require explicit participant consent before recording or transcription and set a custom privacy link.Recording storage [4], Expiration policy [5], Recording policies [6]
AI features and training on customer contentDocumented Microsoft says prompts, responses and data accessed through Microsoft Graph "aren't used to train foundation LLMs". For EU users, Copilot traffic stays within the EU Data Boundary, but Anthropic models are excluded from it and disabled by default for EU, EFTA and UK tenants. Microsoft 365 Copilot has been renamed Microsoft Copilot.Copilot privacy [8], [7]
Copilot in Teams meetingsDocumented Requires an add-on Copilot licence. The default admin policy is "On with saved transcript required". An "Only during the meeting" option uses speech-to-text data that is not saved after the meeting, though Purview retention policies may still keep prompts and responses. Turning Copilot off for a meeting also turns off recording and transcription.Copilot in Teams [9]
Retention and deletionDocumented After a subscription ends, Microsoft keeps customer data in a limited-function account for 90 days so it can be extracted, then deletes it within a further 90 days. During the subscription, retention inside the tenant is set by the customer through Teams and Purview policies.[3], [5]
Security certificationsDocumented Microsoft Teams is listed among the in-scope Office 365 services for ISO/IEC 27001, with a statement of applicability covering ISO 27017, 27018 and 27701 on the Service Trust Portal.ISO 27001 offering [10]

The most detailed independent review comes from the Netherlands. In February 2022 Privacy Company published a DPIA on Teams, OneDrive and SharePoint for the Dutch government and SURF. It found six low risks and one high risk: storing or exchanging sensitive and special category data without encryption keys under the organisation's own control [11]. For Microsoft 365 Copilot, SURF's second update DPIA of 27 May 2026 kept two medium risks, one on the opaque "workplace harms" filter and one on the 18-month retention of pseudonymised diagnostic data. SURF advises institutions to remain cautious and assess each use case, and says no follow-up assessment is planned [12].

What this means for a university

Validemic's analysis

The contract is strong; the configuration is where risk lives. Microsoft's processor terms, EU Data Boundary and published subprocessor regime are more mature than most vendors'. Credit where it is due. The day-to-day risk sits in tenant settings that the university controls: who may record, whether transcription is on, how long recordings live, who can see them and whether Copilot keeps transcripts.

Recordings and transcripts. A recorded supervision session or oral exam stored in a teacher's OneDrive is personal data with no natural end date unless expiry is set. The 120-day default [5] is a reasonable start, but universities should decide per use case: lectures may be kept for a term, exams under assessment rules, supervision rarely at all. Explicit recording consent [6] is a transparency tool, not automatically a lawful basis.

Sensitive conversations. The 2022 Dutch DPIA's main finding [11] still deserves attention: counselling, disability support and HR cases discussed in Teams are special category or highly sensitive data. Microsoft offers end-to-end encryption for one-to-one calls, but Copilot does not work in end-to-end encrypted meetings [9], so the two choices pull in different directions.

Copilot. Copilot changes Teams from a channel into a source: transcripts become searchable, summarised and reusable across Microsoft 365. Under Article 35 GDPR [13], introducing it across teaching and student services is a strong candidate for a DPIA, and SURF's Copilot assessments [12] are the obvious starting point. Keeping Anthropic models off unless deliberately enabled preserves the EU Data Boundary position [7].

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to settle before approving Teams features

  1. Is our tenant's sign-up location in the EU or EFTA, and have we bought Multi-Geo, which takes the tenant out of the EU Data Boundary?
  2. Which of Microsoft's documented EU Data Boundary exceptions apply to Teams in our set-up, for example support access or security operations?
  3. Who in our institution may record and transcribe, and what recording expiry applies to lectures, exams, supervision and staff meetings?
  4. Do we require explicit recording consent, and does our custom privacy link explain recordings, transcripts and Copilot?
  5. Which Copilot policy value do we use for meetings, and do Purview retention policies keep Copilot prompts and responses longer than intended?
  6. Have we kept Anthropic models and "Anthropic models with Data Retention" switched off, and who can change that setting?
  7. How are new AI subprocessor notices received, and who decides within the 30-day window whether to disable a new provider?
  8. Which of SURF's recommended measures for Teams and Copilot apply to our tenant outside the Dutch agreements?

The EU AI Act angle

Teams transcription, captions and Copilot meeting recaps are general productivity functions, not the education uses listed as high-risk in Annex III, such as evaluating learning outcomes or monitoring students during tests [14]. That could change if a university used Copilot summaries of oral exams or seminar participation to support grading. The obligation that applies now is Article 4: deployers must take measures to support the AI literacy of staff using AI systems on their behalf [15]. Article 5(1)(f) prohibits emotion recognition in education institutions except for medical or safety reasons [16]. Microsoft documents that Copilot restricts inferences about a person's internal or emotional state in workplace scenarios [8], but third-party Teams apps offering engagement or sentiment scoring would need a separate check. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [17].

Sources

  1. Microsoft Privacy Statement (September 2026), retrieved 7 October 2026
  2. What is the EU Data Boundary?, Microsoft Learn, retrieved 7 October 2026
  3. Microsoft Products and Services Data Protection Addendum (May 2026 version), retrieved 7 October 2026
  4. Teams meeting recording and transcript storage and permissions in OneDrive and SharePoint, Microsoft Learn, retrieved 7 October 2026
  5. Manage Teams recording expiration policy, Microsoft Learn, retrieved 7 October 2026
  6. Manage Teams recording policies for meetings and events, Microsoft Learn, retrieved 7 October 2026
  7. Anthropic models in Microsoft Online Services, Microsoft Learn, retrieved 7 October 2026
  8. Data, Privacy, and Security for Microsoft Copilot, Microsoft Learn, retrieved 7 October 2026
  9. Manage Microsoft Copilot in Teams meetings and events, Microsoft Learn, retrieved 7 October 2026
  10. ISO/IEC 27001 offering, Microsoft Learn, retrieved 7 October 2026
  11. New DPIA for the Dutch government and universities on Microsoft Teams, OneDrive and SharePoint Online, Privacy Company, 21 February 2022, retrieved 7 October 2026
  12. Privacy risks Microsoft 365 Copilot remain 'orange' despite improvements, SURF, 27 May 2026, retrieved 7 October 2026
  13. Regulation (EU) 2016/679 (GDPR), Article 35, text read from the Publications Office copy, retrieved 7 October 2026
  14. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
  15. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  16. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  17. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Microsoft's privacy statement, the May 2026 Products and Services DPA, the EU Data Boundary documentation, Teams admin documentation on recording, expiry and Copilot, Microsoft's Copilot privacy and Anthropic subprocessor pages, its ISO 27001 offering page, the SURF and Privacy Company DPIA publications and the relevant EU legal texts on 7 October 2026. Statements about Microsoft come from those pages; our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Teams complies with the GDPR. If you spot an error or Microsoft has updated a document, please contact us and we will correct it.

Frequently asked questions

Is Microsoft Teams GDPR compliant?

No tool is GDPR compliant on its own. For Microsoft 365 Education, Microsoft acts as processor under its Products and Services Data Protection Addendum, commits to the EU Data Boundary for EU and EFTA tenants and states that it is certified under the EU-US Data Privacy Framework. Whether a university's use complies depends on its tenant settings, recording and retention rules, lawful basis and transparency.

Does Microsoft Teams store data in the EU?

Microsoft says Microsoft 365 customers whose tenant sign-up location is in the EU or EFTA are in scope for the EU Data Boundary, so customer data and pseudonymised personal data are stored and processed there, subject to limited documented exceptions. Tenants that bought Multi-Geo are not in scope.

Where are Teams meeting recordings stored and for how long?

Recordings and transcripts of ordinary meetings go to the organiser's OneDrive, and channel meeting recordings go to the team's SharePoint site. By default they expire after 120 days, which administrators can change. Microsoft notes that the maximum default expiration for A1 users is 30 days.

Does Copilot in Teams use meetings to train AI?

Microsoft says prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, including those used by Copilot. Copilot in Teams meetings needs an add-on licence. Anthropic models, which Microsoft offers as a subprocessor, are excluded from the EU Data Boundary and off by default for EU, EFTA and UK tenants.

Is there a DPIA for Microsoft Teams in education?

Yes. SURF and the Dutch government commissioned a public DPIA on Teams, OneDrive and SharePoint, published in 2022, and SURF has published DPIAs on Microsoft 365 Copilot for education, most recently a second update on 27 May 2026 that kept two medium risks. They reflect Dutch contracts and settings, so a university should still assess its own tenant.