[nonimo]
EN
Download

Is Microsoft Copilot safe for confidential information?

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Is Copilot safe for confidential client work? The first answer is a question back: which Copilot? Microsoft has attached the name to at least four different products with four different sets of promises, and what separates two of them is neither a setting nor a price but the account someone signed into, which nobody can see from across the room.

Signed in with a work account, Microsoft states that prompts, responses and data reached through Microsoft Graph are not used to train foundation models, and that the contractual protections it calls enterprise data protection apply. Signed in with a personal account, neither statement is true: conversations are used for training unless the person opted out, and there is no opt-out of human review at all.

This guide separates the four, from Microsoft’s own documentation as it stood on 19 September 2026, and then deals with the three things that apply whichever one you are on: the web search that leaves the boundary by design, where the data is processed if you are British, and what none of it fixes.

Four products, one name

Microsoft renamed things in 2026, and the note at the top of its own documentation says so: Microsoft 365 Copilot is now named Microsoft Copilot, and Microsoft 365 Copilot Chat is now named Microsoft Copilot Chat. Older pages still use the long names.

What someone is usingThe accountTraining on your content
Microsoft Copilot, consumerA personal Microsoft accountYes, unless that person opted out
Microsoft Copilot, licensedA Microsoft Entra work accountNo, and enterprise data protection applies
Microsoft Copilot ChatA Microsoft Entra work accountNo, and enterprise data protection applies
GitHub CopilotA GitHub account, separate termsA different product with a different answer

A fifth case is worth naming because it catches people: Copilot inside Microsoft 365 apps on a Personal or Family subscription. Microsoft lists them among the users it does not train on, and says they will not even see the training setting.

If your firm has never written down which of these your staff use, that is the gap, and the AI policy template is the cheapest way to close it this week.

The consumer Copilot trains by default, and the UK is not excluded

Microsoft’s privacy FAQ for Copilot is unusually direct about this. Except for certain categories of user and those who have opted out, Microsoft uses data from Bing, MSN, Copilot and interactions with ads for AI training.

The exclusion list, and who is on it

Read the FAQ’s list as a British reader and only one line matters.

Excluded from consumer Copilot training
Signed in with an organisational Entra ID accountEnterprise data protection applies instead
Using Copilot in Microsoft 365 apps on Personal or FamilyThey do not see the setting
Not signed in at allNo account to attach it to
Under the age of 18 and signed in
Users who have opted outThe setting is in Copilot’s privacy settings
Brazil, China excluding Hong Kong, Israel, Nigeria, South Korea, VietnamNo user data used for training in those markets

The United Kingdom is not in that last row. Nor is any European country. So on the consumer Copilot, a British user’s conversations are used for generative AI model training unless that person went into settings and turned it off, and nothing about being in Britain changes that.

To be fair to the drafting, Microsoft also limits what it trains on: it says it does not train on personal account data such as your Microsoft account profile or email contents, and that it takes steps to strip identifying details from uploaded images and files, removing metadata and blurring faces. That is a genuine mitigation for photographs. It is not much help with a letter, where the identifying information is the prose.

Eighteen months, and no opt-out of human review

Two more lines from the same FAQ belong in any decision about this product.

18 months
the default storage period for consumer Copilot conversation activity, and the maximum for a file you upload. Microsoft privacy FAQ for Copilot

The first is retention: by default Microsoft stores conversation activity for 18 months, and a file you share with Copilot is stored securely for no longer than 18 months before automatic deletion. You can delete individual conversations or the whole history at any time.

The second is the one with no setting attached. Microsoft states that some Copilot conversations are subject to both automated and human review for product improvement and digital safety, and then answers the obvious next question directly: an opt-out of human review is not available.

Personalisation, and the adverts that use your history

Personalisation is on by default where it is available to you, and it is separate from the training setting. You can opt out of training and leave personalisation on, in which case Copilot still remembers recent conversations.

Advertising has a third switch of its own. Microsoft states that if your settings allow personalised ads in Copilot and the personalisation setting is on, it will use your Copilot conversation history to help further personalise the ads you already receive. Three separate controls, three separate answers, and turning one off tells you nothing about the other two. Among Copilot’s main rivals, only ChatGPT now advertises against chat context, as the ChatGPT guide sets out.

With a work account, the answer changes

This is the product most British firms are actually entitled to use, often without realising it, because Copilot Chat comes with work accounts they already pay for. In a GP surgery or a hospital trust the work account settles the contract but not the prior question, which is whether a patient letter may go into it at all.

What enterprise data protection promises

Microsoft’s enterprise data protection page describes a set of contractual commitments under the Data Protection Addendum and the Product Terms, with Microsoft acting as a data processor. Four of its promises matter here.

The commitmentWhat it means for a firm
Not used to train foundation modelsPrompts, responses and Microsoft Graph data are excluded
Your access controls applyCopilot respects permissions, sensitivity labels and retention policies
Same terms as Exchange and SharePointThe protections you already rely on for email and files
Microsoft is the processorYou remain the controller, with the duties that carries

The third row is the useful one for a partner making a decision. Copilot with a work account is governed by the same contract as the email system your firm has trusted for a decade. That is a meaningful answer to give a client, and it is a far better answer than any consumer product can offer. For a chartered accountant it is one of the three things ICAEW asks for before client data goes in.

The place Microsoft says it opted out of human review

One sentence in the privacy documentation is worth quoting, because it is the mirror image of the consumer answer. While abuse monitoring, which includes human review of content, is available in Azure OpenAI, Microsoft states that Copilot services have opted out of it.

Set that against the consumer FAQ, where an opt-out of human review is not available. Same brand, opposite answer, and the only variable is the account. That single contrast is the most useful thing in this guide, and it is worth saying to staff in exactly those terms, then writing it into your AI policy. For comparison, Google states the opposite for its consumer product, as the Gemini guide sets out.

Training is not the same as passing through Microsoft’s servers

Everything above is about training, and training is the least important of the five things that happen to a document.

When someone sends a file, it is transmitted to a company outside your firm, it is retained for some period, an automated system reads it, it becomes reachable by legal process directed at whoever holds it, and it may or may not be used to adjust model weights. A training promise answers the last one. The other four are still open, and they are what a client is asking about.

Microsoft’s own documentation is honest about this in a way that helps. It states that when you enter prompts, the information in them, the data they retrieve and the generated responses are processed and stored in alignment with the contractual commitments covering your other Microsoft 365 content. Stored is the operative word. The interaction is kept, encrypted, and an administrator can find it.

Whether a particular interaction is also a reportable breach is a separate test, worked through in the breach guide.

Who can read a Copilot conversation inside your own firm

This one surprises staff more than anything to do with Microsoft, and it should be said out loud before someone finds out the hard way.

Microsoft stores the user’s prompt and Copilot’s response, with citations, as the user’s Copilot activity history. Administrators can view and manage that stored data using Content search or Microsoft Purview, and can set retention policies for it. For Teams chats with Copilot, admins can also use the Teams Export APIs.

Who can reach a conversation on a work accountHow
The person who typed itTheir own Copilot activity history
Your administratorsContent search, Microsoft Purview, retention policies
Your eDiscovery processSearch and delete AI application data in eDiscovery
Microsoft, as processorUnder the Data Protection Addendum, on your instructions

There is a control on the user’s side: people can delete their Copilot activity history from the My Account portal. But a retention policy set by your firm is a decision for the firm, and eDiscovery reaches what retention keeps.

Far from a flaw, that is exactly why a work account is the safer place for client material, and exactly why someone should be told before they type something they would not put in an email. Neither ChatGPT nor Claude gives a small firm the same admin reach without a business plan.

The web search that leaves the boundary by design

Here is the carve-out, and it is the single most misunderstood thing about Copilot. The general case is set out in client data and a data breach; what follows is the British detail.

When web search is on, Copilot reads the prompt, picks out terms where the web would improve the answer, and generates a short search query that it sends to the Bing search service. That query is a few words, not your prompt and not your document.

What Microsoft commits to, and what falls outside it

The commitments on those queries are real and specific. Microsoft states they are sent with user and tenant identifiers removed, that it has no rights to them beyond providing the service, that they are not used to improve Bing, not used to build advertising profiles or track behaviour, not shared with advertisers, not used to train generative AI foundation models, and are treated as customer confidential information.

Then come the exclusions, and they are what a compliance officer needs.

What does not apply to a generated web queryMicrosoft’s wording
The Data Protection AddendumIt “doesn’t apply to the use of generated web search queries”
HIPAA complianceDoes not apply to generated search queries
The EU Data BoundaryDoes not apply to generated search queries
Microsoft as your processorFor web query data Microsoft acts as a data controller

That last row is the structural point. For the prompt, Microsoft is your processor and you are the controller. For the query it derives from your prompt and sends to Bing, Microsoft is an independent controller in its own right, under the Microsoft Services Agreement and the Microsoft Privacy Statement rather than your addendum.

The example from Microsoft’s own table

Microsoft publishes worked examples, and one of them makes the risk concrete without anybody having to speculate. The user prompt is “Who is my manager and what public information is available about them?” The generated search query is the manager’s name.

So the identifiers stripped from the query are yours, not theirs. Copilot removes the user and tenant identifiers, which protects the person typing. The words it sends can still be a named individual, because that is what the prompt was about.

Two practical notes. The web content toggle is on by default when an administrator enables web search, so this is the state most tenants are in. And administrators can audit the exact queries: they appear in Purview audit logs and in activity explorer in Data Security Posture Management for AI, while web search query citations show users the exact queries in Copilot Chat for 24 hours.

Where the data is processed, if your firm is British

Microsoft names a boundary, and the boundary is not ours.

The privacy documentation states that Copilot calls to the language model are routed to the closest data centres in the region, and can call into other regions when capacity is short. Then: “For European Union (EU) users, we have additional safeguards to comply with the EU Data Boundary. EU traffic stays within the EU Data Boundary while worldwide traffic can be sent to the EU and other countries or regions for LLM processing.”

And on residency, in so many words: “For EU customers, Microsoft Copilot is an EU Data Boundary service. Customers outside the EU may have their queries processed in the US, EU, or other regions.”

The United Kingdom is outside the EU. A British tenant is therefore in the second sentence, not the first, and on the face of the document its Copilot queries may be processed in the United States, the EU or elsewhere.

Advanced Data Residency does cover the UK

This is where a British firm gets something back, and it is worth knowing before anyone concludes the worst.

Microsoft’s Advanced Data Residency add-on commits to keeping customer data at rest in a local region, the United Kingdom is one of the eligible Local Region Geographies, and Copilot and Copilot Chat are among the covered services. Eligible licences include Microsoft 365 Business Basic, Standard and Premium, which is what a firm of this size actually owns.

There are two conditions and both bite. It is a paid add-on, and the tenant must hold ADR licences covering 100 per cent of eligible purchased seats, not just the seats in use. Fall below that and Microsoft states the data may be relocated outside the local region.

100%of eligible seats must hold an ADR licence
18 monthsdefault consumer retention
24 hoursthat a web query citation stays in the thread
Microsoft Advanced Data Residency, 18 May 2026; privacy FAQ for Copilot; web search documentation, 18 August 2026

So the position for a British firm is precise, and it is the whole argument in one paragraph. You can buy a commitment about where the data sleeps. The boundary Microsoft names for where the processing happens is the European Union’s, and you are not in it.

The subprocessor that sits outside the boundary

One more line, and it is recent enough that most advisers have not read it. Microsoft offers models from other companies inside Copilot, and its documentation states that models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary and, where applicable, from commitments to process data within a country.

Administrators choose whether to enable those models. That says nothing against any one provider. What it shows is that a residency commitment has a supply chain behind it, and the answer to “where is our data processed” can change when somebody ticks a box in an admin centre. That belongs in the questions you answer for an insurer about your AI use at renewal.

Who your data controller is, if your firm is in the UK

Read the same clause across four providers and the British answer splits two against two. Microsoft is on the better side of it for a UK reader.

The Microsoft Privacy Statement says that where Microsoft is a controller, Microsoft Corporation and, for those in the European Economic Area, the United Kingdom and Switzerland, Microsoft Ireland Operations Limited are the data controllers, at One Microsoft Place, Dublin 18.

ProviderController named for a UK userWhere
Microsoft CopilotMicrosoft Ireland Operations LimitedDublin
ClaudeAnthropic Ireland, LimitedDublin
ChatGPTOpenAI OpCo, LLCSan Francisco
GeminiGoogle LLCMountain View

Note what this table covers and what it does not. Microsoft names the Irish entity where it is a controller, which covers the consumer product. For Copilot with a work account, Microsoft is your processor and your firm is the controller, so the row above describes the consumer case and the Bing query case rather than your tenant. The other three rows are read from their own pages in the guides on ChatGPT, Claude and Gemini.

GitHub Copilot is a different product

Worth one paragraph so nobody is caught out by the name. GitHub Copilot is a coding assistant with its own terms, its own account and its own settings, and none of the Microsoft 365 commitments above transfer to it.

For a firm, the exposure there lies less in the source code than in the fixtures: a database dump used for testing, a support ticket pasted into a comment, a client name in a branch. If a contractor is building something for you, the account they use is the one that decides the terms, and it is not yours. The equivalent question for Anthropic’s coding tool is answered in the Claude guide.

What to check this week

Five things, none of which needs a purchase.

  1. Look at which account each person is signed into. Open Copilot on the device they actually use and read the account at the top. Then check their phone. This single check answers most of the questions above.
  2. Decide on web search. The Allow web search in Copilot policy is in Cloud Policy service for Microsoft 365, and it can be off for work mode while on elsewhere.
  3. Check whether you hold ADR. Your Data Location Card in the Microsoft 365 admin centre shows the committed geography and the ADR licence count.
  4. Ask about Anthropic models. Whether they are enabled in your tenant changes your answer on processing location.
  5. Tell people about the consumer version. They have a personal Microsoft account, it trains by default, and there is no opt-out of human review on it.

Four of those five are questions for whoever runs your systems, and the fifth is a conversation with your staff. Neither costs anything, and together they decide most of your answer.

Is Copilot safe under UK law?

No regulator has ruled on a named product, and any page claiming the ICO has approved or banned Copilot is wrong. What applies is the UK GDPR with the Data Protection Act 2018, supervised by the ICO, plus your professional regulator and your indemnity insurer. A council adds freedom of information, which can reach what a supplier holds on its behalf, as the guide for council officers explains.

Your firm is the controller for the client data it holds. You need a lawful basis, and you owe data minimisation and the security duties in Article 5(1)(f) and Article 32. The ICO’s practical advice is a sequence: identify a lawful basis before any sharing begins, then minimise, because “if an organisation is able to anonymise the information, or remove identifiable information from the documents shared, then they should do so”.

Processor for the prompt, controller for the query

The Copilot architecture produces a split that is unusual enough to be worth writing into your record of processing. For the prompt and the response, Microsoft is your processor under the Data Protection Addendum. For the web query derived from that prompt, Microsoft is an independent controller and the addendum does not apply. Where those roles sit is one of the things a UK buyer has to establish tool by tool.

The prompt and the response · Microsoft as processor

Covered by the Data Protection Addendum and the Product Terms. Not used to train foundation models. Stored under the same commitments as your other Microsoft 365 content, where your administrators and eDiscovery can reach it. Your firm is the controller.

The web query sent to Bing · Microsoft as controller

A few words Copilot derives from the prompt, sent with user and tenant identifiers removed. The Data Protection Addendum, HIPAA and the EU Data Boundary do not apply. Microsoft is an independent controller under the Microsoft Services Agreement and the Microsoft Privacy Statement.

One prompt, two relationships: who Microsoft is for each part of a Copilot request with web search on, from Microsoft's enterprise data protection and web search documentation

The ICO’s own position makes that split harder to wave away, because it said that controllership turns on practical reality rather than labels and that “a contract does not necessarily determine whether an organisation is a controller”. A document that describes your Copilot deployment as a single processing relationship is describing something simpler than what is happening.

One duty is newer than most guidance acknowledges. The ICO states that all data protection provisions of the Data (Use and Access) Act 2025 came into force on 19 June 2026, and you must acknowledge a complaint about your handling of personal information within 30 days and respond without undue delay. What is arriving through your customers rather than your regulator is in our note on the EU AI Act timetable.

What none of this fixes

Everything above is about a service. The problem in a small office is a person, on a deadline, with a bundle that will not summarise itself. In litigation, that bundle reaches Copilot long before anything you sign for the court about AI.

Configure a tenant perfectly and one thing remains true: the document went to a company outside your firm, and the words in it are still the words in it. Delete every name from a page of correspondence and a specific street address, a child in the household and a file reference at a named previous adviser will still identify the matter to anyone who has seen the file. Identifiability belongs to the whole document, not to the words you removed.

What a masking tool does here, and what it does not

The facts first, so you can check them. Nonimo is a Mac and Windows app that finds identifiers in text before it is sent and hides them, working on the machine rather than in a cloud, with a policy set by IT rather than by each user.

For the United Kingdom it covers NHS numbers, UTRs and driving licence numbers written after their label, National Insurance numbers with or without one, and postcodes, plus a vehicle registration, masked as a number plate when a word such as “Registration:” comes before it, and a mobile number that follows a label such as “Mobile:”.

Each of them is masked in front of you, where you can undo it, so the person who knows the matter has the last word on every change.

What the tool puts in place of an identifier is a reversible label, and the key linking each label to the real detail is kept encrypted on your own computer. That is pseudonymisation in the sense Article 4 gives the word, so the data remains personal data for whoever holds the key, and the key is yours. It lowers risk without moving a document outside data protection law, and the longer treatment is in the breach guide.

What it keeps on your computer is set out on Nonimo’s security page.

The work account

Move people onto it.

The consumer app

Leave it for weekend recipes.

The short list

Five lines at most: the documents that never go into either.

Three moves with the Copilot a firm already pays for, if it buys nothing else

So is Copilot safe for a small British firm? If you buy nothing at all, the Microsoft answer is better than most firms realise, and it is already paid for. Move people onto the work account, leave the consumer app for weekend recipes, and write a short list, five lines at most, of the documents that never go into either.

Whether your insurance would pay out if it went wrong is a separate question, set out in the UK cyber insurance comparison, and our other guides cover what to look for when it is time to judge a tool.

Put the same tests to ChatGPT, Claude and Gemini and the answers differ, but none of them is that the document stayed in your office.

Sources

Checked 19 September 2026.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Is Microsoft Copilot safe for confidential information?

It depends which Copilot. Signed in with a work account, Microsoft states prompts and responses are not used to train foundation models and enterprise data protection applies. Signed in with a personal account, neither is true.

Does the consumer Copilot train on my conversations?

Yes, unless you opt out. Microsoft's privacy FAQ lists the users excluded from training, including six named countries, and the United Kingdom is not among them. The opt-out is in Copilot's privacy settings.

Can I stop humans reading my Copilot conversations?

Not on the consumer product. Microsoft states that some conversations are subject to automated and human review, and that an opt-out of human review is not available because of Code of Conduct investigations.

Does Microsoft 365 Copilot train on our company documents?

No. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation LLMs, and that Copilot services have opted out of the human abuse monitoring available in Azure OpenAI.

Do Copilot web searches leave the Microsoft 365 boundary?

Yes, by design. Copilot generates a short query and sends it to Bing with user and tenant identifiers removed. Microsoft acts as controller there, and says the Data Protection Addendum and the EU Data Boundary do not apply.

Is the UK inside the EU Data Boundary for Copilot?

No. Microsoft states that for EU customers Copilot is an EU Data Boundary service, and that customers outside the EU may have their queries processed in the US, EU or other regions. The UK is outside the EU.

Can a UK firm get UK data residency for Copilot?

For data at rest, yes. Advanced Data Residency is a paid add-on, the United Kingdom is in its Local Region Geography, and Copilot is covered. It requires ADR licences covering 100 per cent of eligible seats.

Who is my data controller for Copilot if I am in the UK?

Microsoft Ireland Operations Limited, in Dublin. The Microsoft Privacy Statement names it as controller for those in the European Economic Area, the United Kingdom and Switzerland together. For Copilot on a work account Microsoft is your processor, so your firm is the controller.