“Is Copilot GDPR compliant?” is the wrong question, and it is one we hear at the start of nearly every Copilot conversation. Microsoft Copilot is not a single product with a single answer. It is three distinct tools sharing one name, each with a different relationship to your data. The right question is what using it actually commits your organisation to, and that depends entirely on which Copilot a given member of staff is using, and when.
This article sets out where data actually goes, what your existing protections cover, and what they do not. We are not here to hand you a verdict. We are here to give you the detail to write your own, and to document it properly.
Copilot is three products wearing one name
Microsoft 365 Copilot Chat is the free, broadly available version, present in Edge and accessible to any signed-in user. It behaves much like any other consumer AI tool: no Data Protection Agreement applies in the same way, and submitted content can be used differently from the licensed product. Staff often assume this version carries the same protections as their corporate 365 licence. It does not.
Microsoft 365 Copilot, the licensed product embedded in Word, Excel, PowerPoint, and Outlook, keeps your organisational data within your tenant boundary for the data it draws on. Prompts and responses are processed under Enterprise Data Protection, the same contractual footing as email in Exchange. That coverage sounds complete. It is not, and the gaps sit in two specific places: web search and third-party model routing, covered below.
Copilot Studio, the platform for building agents on top of Copilot, is a different proposition again, with its own permission model, plugin risk, and autonomy questions. It deserves a dedicated article rather than a paragraph here, and a follow-up piece in this series will cover it directly.
Where the licensed product still leaves the boundary
Two routes inside licensed Copilot sit outside the protections most organisations assume apply everywhere. Web search queries sent to Bing are not covered by the EU Data Boundary, a point Microsoft’s own documentation confirms, and Bing traffic is excluded from the Microsoft 365 Data Protection Addendum. A query containing more than it should can leave the boundary entirely.
Microsoft has also onboarded Anthropic as a subprocessor for some Copilot experiences, as set out in Microsoft’s subprocessor documentation. Anthropic-routed prompts are excluded from the EU Data Boundary, and from January 2026 this routing became enabled by default for most commercial tenants worldwide, with EU, EFTA, and UK tenants set to off by default. Many tenants never reviewed this setting, because it changed silently.
Flex Routing adds a third wrinkle. Under high load, Microsoft can route processing to other regions for capacity reasons, even on paths an organisation assumed were fixed in place. None of this makes Copilot unsafe. It does mean the boundary is more porous than the marketing suggests, and worth naming explicitly in your own documentation.
The bigger exposure is what Copilot is allowed to see
The genuinely hard problem is not which model processes a prompt. It is data access. Copilot’s intelligence comes from Graph-based search across emails, documents, and chats, building a more complete picture than any single source reveals on its own. That is the product working as designed, not a flaw.
Every Copilot rollout we have looked at eventually turns into an access control review, whether the client planned for one or not. Copilot can surface anything a user already has permission to view, and weak or misconfigured access controls turn that permission into exposure. A pen test report or HR file shared loosely two years ago becomes instantly discoverable the moment Copilot starts indexing it properly. It is rarely the model that catches people out. It is the share permission nobody revisited.
There is also a longer tail to this risk. Anything ever briefly made public, even a SharePoint site secured within hours, can remain retrievable through Copilot search long after the access was withdrawn. Roll out Copilot without reviewing access controls first, and you have given a very good search engine the run of an unaudited filing cabinet.
What this means for your paperwork
None of this argues against using Copilot. It argues for naming the actual sub-paths in your governance documents instead of treating Copilot as one line item. Update your data protection policy and supplier register to name Bing web search and Anthropic routing separately, and check whether either triggers a DPIA.
Before rollout, check Graph and SharePoint permission hygiene, not after. Confirm the Anthropic and web search toggles in your tenant reflect a decision someone made, not a default nobody noticed. Our free
AI Supplier Review Checklist is a reasonable starting point for capturing this properly, and our AI Risk Register template gives you somewhere to log Copilot’s specific sub-paths as distinct entries rather than one generic risk. Our AI risk assessment guide covers what a proper assessment needs to include beyond a vendor’s marketing claims.
Oversharing through Copilot is one of the most common AI data leakage scenarios we see, and worth reading alongside the access-control point above. If a misconfiguration does surface sensitive data, our AI Incident Review service covers what happens next.
Black Chili’s AI Governance and Guardrails Design service builds the documented policy and access controls a Copilot rollout actually needs, before deployment rather than after an incident.