Microsoft Copilot, GDPR and EU data residency · Updated: August 2026

Microsoft 365 Copilot, GDPR,
and where your data
actually goes.

Every European organization I work with asks the same question before it signs off on a Copilot budget: where does our data go, and does this survive GDPR. This page answers it using Microsoft's own wording, including the two things their marketing does not lead with.

I run Copilot rollouts. I am not a lawyer, and nothing here is legal advice. What it is: the specific commitments, the specific gaps, and the checklist I actually walk through with a customer before a single license gets assigned.

1 Mar 2024Copilot added as a covered workload in Microsoft's data residency commitments
EU Data BoundaryCopilot is an in-scope service for EU customers
Not used for trainingPrompts, responses and Graph data do not train the foundation models
1 exclusionAnthropic models are currently outside the EU Data Boundary

The short answer

For EU customers, Microsoft 365 Copilot is an EU Data Boundary service. In Microsoft's words: "EU traffic stays within the EU Data Boundary while worldwide traffic can be sent to the EU and other countries or regions for LLM processing."

Your prompts and Copilot's responses (Microsoft calls this the "content of interactions") are stored at rest in your region, under the same contractual commitments that already cover your Exchange mail and your SharePoint files. They are encrypted at rest. They are not used to train foundation models. Microsoft 365 Copilot has also opted out of the abuse monitoring with human review that exists in Azure OpenAI.

Bottom line: on the infrastructure question, Copilot clears the bar for most EU organizations. The real risk sits somewhere else, and almost nobody raises it in the first meeting. Keep reading.

Where your Copilot data actually lives

Two different things happen and it is worth keeping them apart.

Processing. Copilot routes LLM calls to the closest data centers in the region, and can call into other regions during high utilization. For EU users there are additional safeguards so that EU traffic stays inside the EU Data Boundary.

Storage. The content of interactions is stored at rest in your local region geography, alongside your other Microsoft 365 content. Advanced Data Residency and Multi-Geo have both covered Copilot since 1 March 2024.

Which region, exactly, is decided by the Preferred Data Location (PDL) of the user who typed the prompt. If the PDL is not set or is invalid, the data lands in the tenant's primary provisioned geography.

The Multi-Geo trap, in Microsoft's own example

User A writes a document and stores it in OneDrive in France. User B sits in Canada and asks Copilot to rewrite a paragraph. The document stays in France. The prompt and the rewrite options are stored in Canada, because storage follows the person who asked, not the file.

If you have EU staff and non-EU staff working on the same documents, this is the detail that decides whether your answer to the DPO is "yes" or "it depends". Check PDL per user, not per tenant.

The exclusion nobody mentions in the sales meeting

Microsoft now offers third-party models inside Copilot experiences, from Anthropic and from OpenAI. On the same documentation page that confirms the EU Data Boundary coverage, Microsoft adds this:

"Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary."

That is not a scandal and it is not hidden. It is one line in a long document, and it is the line your compliance team will care about most. The good news is that it is a decision you control: admins choose whether these models are enabled for the organization, and additional terms may apply when they are.

What to do: if "everything stays in the EU Data Boundary" is a hard requirement rather than a preference, put this on the agenda before rollout, not after someone finds it in an audit. Decide it as a policy, write the decision down, and move on.

What Copilot does not protect you from

Here is the sentence that matters more than every data residency clause combined:

"Microsoft 365 Copilot only surfaces organizational data to which individual users have at least view permissions."

Read it twice. Copilot does not create a new leak. It reads what the user could already open. The salary spreadsheet that has been sitting in a SharePoint site with "everyone in the organization" access for 4 years was always exposed. Nobody found it because nobody searched for it. Copilot searches for it in half a second, in plain language, for anyone who asks.

This is the number one reason a Copilot rollout goes wrong, and it is not a Copilot problem. It is a permissions problem that Copilot makes visible.

The tooling is there. Copilot honors sensitivity labels and content encrypted by Microsoft Purview Information Protection, and it respects the usage rights granted to the user. But the labels only help if someone applied them.

The checklist I walk through before rollout

Not exhaustive, and your DPO gets the final word. This is what covers the questions that actually come up.

01 Confirm the tenant's sign-up region

Data residency commitments in the Product Terms depend on it. The EU is covered, and so are Germany, France, Sweden, Norway, Switzerland and the UK as local region geographies in their own right.

02 Decide on Advanced Data Residency or Multi-Geo

ADR needs a subscription covering every user in the tenant. If the tenant currently stores data in a macro region geography, a global admin has to opt in to move it. That is a project, not a checkbox.

03 Check Preferred Data Location per user

Especially for anyone outside the EU who works on EU documents. See the France and Canada example above.

04 Make an explicit decision on third-party models

Anthropic models sit outside the EU Data Boundary today. Admins control whether they are on. Decide deliberately and record the decision.

05 Review SharePoint and OneDrive permissions before, not after

This is the one that takes real time and the one people skip. Start with the sites everyone can reach.

06 Set retention and eDiscovery for Copilot interactions

Microsoft Purview handles retention policies for Copilot data, and Content Search lets admins find it. Users can delete their own Copilot activity history from the My Account portal.

07 Know what your privacy controls will switch off

If your organization turns off connected experiences that analyze your content, Copilot features stop being available in Word, Excel, Outlook, PowerPoint and OneNote. Worth knowing before you buy licenses.

Bottom line: steps 4 and 5 are where the real work is. Everything else is reading and a decision.

Certifications and commitments, briefly

Copilot carries GDPR, ISO 27001, ISO 42001 (the standard for AI management systems) and HIPAA among its compliance offerings, and Microsoft has stated its commitment to comply with the EU AI Act. There is also the Copilot Copyright Commitment: if a third party sues a commercial customer for copyright infringement over Copilot output, Microsoft defends the customer and pays adverse judgments or settlements, provided the customer kept the built-in guardrails and content filters in place.

Microsoft also publishes a Risk Assessment Quickstart for Copilot on its Service Trust Portal, which is a reasonable starting document to hand your compliance team.

Questions that come up in every EU rollout

Is Microsoft 365 Copilot GDPR compliant?

Microsoft states that Microsoft 365 Copilot is compliant with its existing privacy, security and compliance commitments to Microsoft 365 commercial customers, including GDPR and the EU Data Boundary. Compliance of the service is not the same as compliance of your deployment, which depends on your permissions, your labels and your retention policy.

Where are our prompts stored if we are an EU tenant?

At rest in your local region geography, under the same commitments as your other Microsoft 365 content. The exact location follows the Preferred Data Location of the user who wrote the prompt, and falls back to the tenant's primary provisioned geography.

Does Microsoft train its models on our documents?

No. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation LLMs, including those used by Microsoft 365 Copilot. Optional customer feedback is also not used for that training.

What about the Anthropic and OpenAI models inside Copilot?

Anthropic models, provided as a subprocessor, are currently excluded from the EU Data Boundary. Admins decide whether third-party models power their experiences, and additional terms may apply.

Does Copilot increase our risk of a data leak?

It does not grant new access. It surfaces what users could already open, much faster and in plain language. If your permissions are loose, Copilot will find that out for you. Fix permissions first.

Do we need Advanced Data Residency?

Not always. The Product Terms already carry data residency commitments for covered regions. ADR is for organizations that need the guarantee tied to a specific local region geography, and it requires a subscription for every user in the tenant.

Can we delete and retain Copilot conversations?

Yes to both. Purview handles retention policies and Content Search for admins. Users can delete their own Copilot activity history from the My Account portal.

Sources

Everything above is drawn from Microsoft's own documentation, current as of August 2026. Microsoft updates these pages, so check them before you put anything in a policy document.

Data, Privacy, and Security for Microsoft 365 Copilot
Data Residency for Microsoft 365 Copilot and Copilot Chat
Enterprise data protection in Microsoft 365 Copilot

Copilot rollout in a European organization

Planning a rollout and want the awkward questions asked early?

An intro call takes 30 to 45 minutes. We go through where you actually stand: licensing, permissions, what your compliance team will ask, and whether training makes sense yet. I deliver workshops and rollout advisory live in English over Zoom, for teams across Europe.

Updated: August 2026 · by Eyal Marcus · Not legal advice. Verify against Microsoft's current documentation and your own DPO.