[nonimo]
EN
Download

Is Microsoft Copilot safe for confidential information?

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Is Copilot safe? It depends which Copilot, and which account. That sounds like a dodge, but it is the real answer: Microsoft sells several things under one name, and the answer to “what happens to my client’s details” changes completely between them.

An Australian practice that gets this right pays nothing extra and moves from consumer terms to a commercial contract. One that gets it wrong has staff pasting files into a consumer product while believing they are covered by the firm’s Microsoft 365 agreement, which is the most common version of this mistake we see.

Below, we separate the products, read the commitments Microsoft publishes for each, and then ask the question the Privacy Act 1988 asks, which none of those documents mentions. Our guides to ChatGPT, Claude and Gemini do the same for those assistants.

Copilot is not one product, and the names changed in 2026

Microsoft’s own documentation carries the notice at the top of the page.

Microsoft 365 Copilot is now named Microsoft Copilot, and Microsoft 365 Copilot Chat is now named Microsoft Copilot Chat. Some experiences, licenses, and capabilities might continue to reference Microsoft 365 Copilot and Microsoft 365 Copilot Chat during the transition period.

So an article about Microsoft 365 Copilot and one about Microsoft Copilot may be about the same product, or may not, depending on when it was written. That alone explains why “is Copilot safe?” draws so much contradictory advice.

What it isSign in withEnterprise data protection
Microsoft Copilot, consumerA personal Microsoft accountNo
Microsoft Copilot ChatA work or school accountYes, at no extra cost
Microsoft Copilot, licensedA work account with a licenceYes
GitHub CopilotA GitHub accountSeparate product and terms

Read from Microsoft’s own documentation on 19 September 2026.

GitHub Copilot is a developer tool with its own agreements and it is out of scope here. The distinction that matters for a professional practice is the first three rows, and it is settled by which account the browser is signed into when somebody pastes something. Whoever runs your systems can tell you which one your people are actually in.

The consumer Copilot: training, advertising and 18 months

With a personal Microsoft account, the governing documents are the Microsoft Services Agreement and the Microsoft Privacy Statement, last updated September 2026. Copilot conversation history is retained for 18 months, and there are controls for model training on conversations and on voice.

18 months
How long the consumer Copilot keeps conversation history. Microsoft, Copilot privacy controls

The limit of the control is written down, and it is worth reading before relying on it.

Opting out will exclude your future conversation activities from being used for training these AI models. This setting will not exclude your conversations from being used for other general product or system improvements nor from use for advertising, digital safety, security, and compliance purposes.

The word that separates this one from the other three

Advertising is in that sentence, and it is not in the equivalent sentence at OpenAI, Anthropic or Google. Microsoft’s own support page notes that “Copilot does not serve personalized advertising to authenticated users under the age of 18”, which tells you what happens for everyone else.

To be fair to Microsoft, its privacy statement draws a line elsewhere that is genuinely protective, and it applies to the productivity files most practices worry about.

Microsoft does not use what you say in emails, human-to-human chat, video calls or voice mail, or your documents, photos, or other personal files stored on your device or cloud storage to target ads to you.

Both statements can be true at once, and you need to read them side by side to get a fair picture. The consumer chat surface is treated differently from the mailbox and the file store, and a practice deciding what staff may use needs that distinction in its written AI policy.

A work account, and what enterprise data protection actually is

Sign in with a Microsoft Entra work or school account and the contract changes. Microsoft’s term for what you get is enterprise data protection, and it defines the term precisely.

Enterprise data protection refers to controls and commitments, under the Data Protection Addendum (DPA) and the Product Terms, that apply to customer data for users of Microsoft Copilot and Copilot Chat, with Microsoft acting as a data processor.

Two things in that sentence matter. The first is that it points at named contractual documents rather than at a marketing promise. The second is the processor role, which is the same distinction that separates a consumer account from a commercial one at every other provider.

The green shield, and what it certifies

Microsoft made this visible rather than buried, which is unusually practical: Copilot Chat “makes it clear that enterprise data protection is applied by featuring a green shield along the top of the user interface next to the New Chat button”.

Telling staff to look for the shield before they type is a control that costs nothing, takes one sentence in a written policy, and is checkable by anyone walking past a screen. It is the only indicator of this kind that users can see on any of the four products covered on this site.

Training, and one line about human review

For the work products the training answer is short and Microsoft repeats it in both documents.

Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs, including those used by Microsoft Copilot.

There is a second line that most summaries leave out: “While abuse monitoring, which includes human review of content, is available in Azure OpenAI, Microsoft Copilot services have opted out of it.”

Compare that with Google’s position on Gemini, where Google states that a subset of consumer chats is read by reviewers. These are different commitments about different products, each published by the company that makes it, and this is exactly the kind of difference that gets flattened into “they are all the same” when they are not.

The questionConsumer CopilotCopilot ChatLicensed Copilot
TrainingControls let you opt outNot used to train foundation modelsNot used to train foundation models
AdvertisingStill possible after opting out of trainingBing queries not shared with advertisersBing queries not shared with advertisers
Human reviewNot covered in this guideOpted out of Azure OpenAI abuse monitoringOpted out of Azure OpenAI abuse monitoring
RetentionConversation history kept 18 monthsLogged in Exchange for auditing and eDiscoveryActivity history in your tenant, under your retention policies
Microsoft’s roleConsumer terms: Services Agreement and Privacy StatementProcessor, under the DPA and Product TermsProcessor, under the DPA and Product Terms

From the Microsoft documents listed under Sources, read on 19 September 2026.

What Copilot can see in your tenant, and what it cannot

A specific fear comes up in every conversation about this product: that turning Copilot on lets everyone read everything. Microsoft’s answer is narrower and testable, and whoever runs your systems can verify it in a morning.

Microsoft Copilot only surfaces organizational data to which individual users have at least view permissions.

When Copilot looks up material to answer, it stays within what each user’s identity and permissions allow, and where a file is encrypted by Purview Information Protection, Copilot honours the usage rights granted to that user. Sensitivity labels and information rights management continue to apply.

In practice, Copilot does not create access. It surfaces existing access very quickly, which is a different problem and often a worse one. A SharePoint site that has been open to the whole tenant since 2019 was always a risk, and Copilot is what finds it.

Copilot Chat is grounded in the web, not your files

Copilot Chat behaves differently from the licensed product, and the difference is worth knowing before you assume either is safer.

Unlike Microsoft Copilot, Copilot Chat is not grounded in organizational content like files, emails, or chats as part of the chat experience, it is grounded in data from the web only.

Microsoft then lists the ways organisational content does get in: pasted or uploaded by the user, used through Copilot Chat in Outlook, reached through an open document in Word, Excel or PowerPoint, or supplied by an agent with access to tenant data. Uploaded files are stored in the user’s OneDrive for Business under enterprise data protection.

Agents bring their own privacy statements

Agents are where a clean boundary can quietly spring a leak. Microsoft says that when an agent is needed, Copilot generates a query and sends it to that agent on the user’s behalf, and it tells administrators plainly what to do about it.

When you’re using agents to help Microsoft Copilot to provide more relevant information, check the privacy statement and terms of use of the agent to determine how it will handle your organization’s data.

An administrator controls which agents are allowed in the tenant. That control is worth exercising deliberately, because an agent built by another company is another recipient, and under Australian law who receives the data is the whole question.

Training and transit are two different questions

Everything above is a promise about what Microsoft does with the text once it has it. That is not the question Australian law asks first, and it is why our approach for organisations treats control and residency as two separate lines.

A promise not to train says your words will not end up in the weights of a future model. It does not say the text stayed in your office, that it was not stored, that it was not logged for eDiscovery, or that the machine it ran on was in this country. Those are separate facts, and Microsoft publishes them separately.

When the Privacy Act says the disclosure happens

The Office of the Australian Information Commissioner sets out the moment that matters in its Guidance on privacy and the use of commercially available AI products, published 21 October 2024 and updated 17 January 2025. The worked example is an insurance company putting claim details into a public chatbot.

By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.

The test a work account can actually pass

Then the guidance gives the other half, and this is the half a properly configured tenant can satisfy.

If your organisation is using a proprietary AI system rather than a publicly available chatbot, for example, and has protections in place to ensure that information entered into the system will not be disclosed outside the organisation (such as to the system developer), this will constitute a use rather than a disclosure of personal information.

That is a test about effective control, evidenced by contract and configuration. A tenant with enterprise data protection, a data protection addendum and Microsoft acting as processor is on much firmer ground than a personal account. Litigators in New South Wales meet a test of the same shape in the Supreme Court’s rule on subpoenaed material.

It is still an argument you have to be able to make, with documents, on the day somebody asks. And it has a limit, which the next section covers.

The exception nobody reads: the queries that go to Bing

There is one place where the boundary customers think they have paid for does not hold, and Microsoft documents it openly. When web search is enabled, Copilot parses the prompt, generates a short search query from it, and sends that query to the Bing search service. Bing is not inside the Microsoft 365 boundary.

The Bing search service operates separately from Microsoft 365 and has different data-handling practices from those used for prompts and responses.

For those queries Microsoft says it “acts as an independent data controller responsible for complying with all applicable laws and controller obligations”, under the Microsoft Services Agreement and the Microsoft Privacy Statement rather than the data protection addendum.

What does not go, which is most of it

Microsoft is careful about the limits, and the list is genuinely narrow.

No user or tenant identifiers

Including username, domain or tenant ID.

Not the whole prompt

Unless the prompt is very short.

Not entire uploaded files

They stay in the user's OneDrive for Business under enterprise data protection.

Not shared with advertisers

And not used to affect search ranking or autosuggest.

What stays out of the query Copilot sends to Bing. Microsoft Learn, Copilot Chat privacy and protections, 24 August 2026

Microsoft also shows the generated queries back to the user as citations in the response, available in the chat thread for 24 hours, which is more transparency than any comparable product offers.

The sentence that shows how Microsoft rates it

One line in the same document tells you how seriously Microsoft itself takes that crossing: “Web search queries sent from Copilot Chat to Bing are not EUDB-compliant.”

If those queries fall outside Microsoft’s own European data boundary commitment, it is worth deciding deliberately whether web grounding should be on for the people in your practice who handle client matters. Administrators can turn it off. What leaving it on means for breach reporting is covered in our guide to client data and AI breach reporting.

Where an Australian tenant’s Copilot data actually sits

Microsoft publishes two different statements about location, and you only get the right answer by reading both.

The questionMicrosoft’s published position
Where is customer data stored at restIn the Tenant’s geography, and Australia is a Local Region
Where does the model runClosest data centres in the region, and other regions at high use
Is there an Australian equivalent of the EU Data BoundaryNone published

Microsoft Learn, Copilot privacy documentation, updated 18 August 2026, and Advanced Data Residency, updated 3 September 2026.

The sentence that decides it for a practice in Melbourne or Perth is this one, and it is in Microsoft’s own privacy documentation: “Customers outside the EU may have their queries processed in the US, EU, or other regions.”

Advanced Data Residency, and the 100 per cent rule

You can pay to keep data stored in a chosen country, and Australia is on the list. Advanced Data Residency, sold as an extra licence, names Australia among its Local Region Geographies, and Microsoft Copilot and Microsoft Copilot Chat are included in the services it covers.

100 per cent
The share of eligible paid licences in a tenant that must carry an Advanced Data Residency licence for the residency commitment to apply. Microsoft Learn, updated 3 September 2026

The coverage rule is not a formality. Microsoft says coverage is calculated on purchased seats rather than assigned ones, that there is no minimum that qualifies on its own, and that a tenant holding fewer Advanced Data Residency licences than eligible seats does not have the commitment at all.

A firm that buys the extra licence for its partners and not its support staff has bought nothing. The eligible licence list does include Microsoft 365 Business Basic, Standard and Premium, so it is not only for large enterprises, which is worth knowing before anyone assumes it is out of reach.

Storage is not processing, and APP 8 asks a third question

Even with the extra licence, storage at rest in Australia is not a commitment that the model runs here. Microsoft says the residency commitment concerns data stored at rest within the Local Region Geography, and it describes model routing separately.

Australian Privacy Principle 8 asks neither question. It turns on whether the recipient is a person who is not in Australia, and section 16C treats an act by that overseas recipient that would have breached the principles as your breach. The assessment clock that starts on suspicion is set out in the breach guide.

Third party models inside Copilot

One more location detail belongs here because it is easy to miss. Microsoft offers models made by Anthropic and OpenAI inside Copilot experiences, as subprocessors, and administrators decide whether to enable them.

Microsoft states that models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary. There is no Australian boundary for that exclusion to affect, but the wider point still holds: which model answers your prompt is an administrative choice with contractual consequences, and it should be made deliberately.

Where prompts are stored, and how to delete them

On a work tenant the storage answer is more useful than at any of the other three providers, because the data ends up in places an administrator already knows how to search.

Microsoft stores the prompt and the response as the user’s Copilot activity history, processed and stored alongside the organisation’s other Microsoft 365 content and encrypted at rest. Administrators can find it with Content search or Microsoft Purview, and set retention policies for it.

Copilot Chat interactions are logged and stored in Exchange for auditing and eDiscovery. Users can delete their own activity history from the My Account portal, and for Teams chats with Copilot there are export APIs. At a council that log is also a record under state law, and an access request from a resident can reach it.

The consequence nobody plans for

Those prompts are discoverable. If somebody pasted a client’s file into Copilot, the record of it sits inside your own tenant, under your own retention policy, and it is producible on request. For solicitors that is a privilege question as much as a privacy one, and the Law Society of NSW has already set out why paying for a business licence does not move the line for a law firm.

Whether that is good or bad depends entirely on whether you knew. It is also the strongest practical argument for writing the rule down first: a policy plus an audit trail is a defensible position, and an audit trail on its own is just evidence. The wording an insurer expects to see is in our guide to the AI questions on a cyber questionnaire.

Three things people believe that Microsoft’s documents do not say

All three come up in practice and are answered above, and each has a close relative among the beliefs about ChatGPT, Claude and Gemini.

"Copilot is safe because it is Microsoft."

Enterprise data protection attaches to a work account. The consumer product is governed by consumer terms, including advertising.

"Nothing leaves the tenant."

Generated web search queries go to Bing, where Microsoft acts as an independent controller.

"Advanced Data Residency means processing stays in Australia."

It is a commitment about data at rest, and it requires 100 per cent licence coverage.

Three beliefs, against Microsoft's own documents quoted on this page

None of those is a criticism of Microsoft, whose documentation states all three limits plainly in pages anyone can read. They are places where a summary written by somebody else has quietly widened a commitment.

Is Copilot safe for a practice bound by the APPs?

The OAIC has not banned any of these tools. It recommends, as best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. The binding obligation is APP 6, which asks whether the individual would reasonably expect this use or disclosure. For sensitive information the test is stricter, and health details or union fees in a prompt bring the question of express consent in as well.

A work account with enterprise data protection gives you a real argument that the text stayed under your effective control, which the consumer product does not. It does not answer the APP 6 question about expectation, which is about your client and your engagement letter, not about Microsoft. The same argument has to be built separately for every assistant, and the questions that decide it do not land the same way on each.

The regulator has already written your scenario

In December 2025 the regulator wrote on generative AI in the workplace and named the products by brand, Copilot among them.

Its case study is an employee uploading a customer’s hardship application, with health and family details, against the employer’s own written policy. That is the scenario we build for, described by a regulator rather than a vendor.

In a clinic the same upload would be a patient’s record, and Ahpra expects informed consent before a patient’s data goes into a tool.

Whichever tool you use, your cyber insurer will ask about it, so it pays to know what a cyber policy covers in Australia.

What none of this fixes

Enterprise data protection is a real improvement and it is already paid for on licences most practices hold. It governs what Microsoft does with the text. It does not govern what your employee decides to put in the box at five o’clock on a Friday.

That gap is where our own software sits, and it is worth being exact about what it does. Nonimo runs on the computer, replaces identifiers before the text is sent, and shows what it changed so a person can overrule it.

It pseudonymises rather than anonymises: the mapping can be reversed and is stored encrypted on the user’s own machine. What it keeps is set out on Nonimo’s security page, and the licence terms on the licence page.

If you buy nothing at all, the three cheapest steps still work: decide which account people sign in with, teach them to look for the green shield, and write one page naming what may never be pasted. Comparing tools comes afterwards, which is the right order.

Sources

Every page below was open in front of us on 19 September 2026.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Is Copilot safe for confidential information?

It depends which Copilot and which account. With a work or school account, Microsoft applies enterprise data protection and says prompts and responses are not used to train foundation models. With a personal Microsoft account the commitments are consumer commitments, and they are different.

Does Microsoft train on Copilot prompts at work?

Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation large language models, including those used by Copilot. It says the same for Copilot Chat, which carries enterprise data protection at no extra cost.

What is enterprise data protection?

Microsoft's term for the controls and commitments under its Data Protection Addendum and Product Terms that apply to customer data in Copilot and Copilot Chat, with Microsoft acting as a data processor. The interface shows a green shield when it applies.

What leaves the Microsoft 365 boundary?

Web search. Copilot generates a short query and sends it to the Bing search service, which Microsoft says operates separately from Microsoft 365 and where Microsoft acts as an independent data controller. The query carries no user or tenant identifiers.

Can an Australian tenant keep Copilot data in Australia?

Storage, yes. Australia is one of the Local Region Geographies for Advanced Data Residency, an extra licence that covers Copilot and Copilot Chat. It has to be bought for 100 per cent of eligible paid licences in the tenant.

Where are Copilot prompts processed?

Microsoft says calls to the model are routed to the closest data centres in the region and can go to other regions at times of high use, and that customers outside the European Union may have their queries processed in the United States, the EU or other regions.

Can Copilot see files a user is not allowed to open?

Microsoft says Copilot only surfaces organisational data to which the individual user has at least view permissions, and that it honours usage rights applied by Purview sensitivity labels. Copilot exposes badly set SharePoint permissions sooner; it does not create them.

Does consumer Copilot use my chats for advertising?

Microsoft says opting out of model training will not exclude conversations from other product improvements or from advertising, safety, security and compliance purposes. It also states that Copilot does not serve personalised advertising to users under 18 who are signed in.

Does using Copilot at work avoid the Privacy Act question?

It changes it rather than removing it. Where information stays under your effective control the regulator treats it as a use rather than a disclosure, but that turns on your contract and configuration, and Australian Privacy Principle 6 still governs the use.