[nonimo]
EN
Download

Which Copilot has your data? An Irish guide to Microsoft

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Before anything else, the question in the title is the whole guide. Copilot is really four products: a consumer assistant, a work assistant on an Entra account, a chat experience inside Microsoft 365, and a coding tool that shares the brand and almost nothing else. The answer to “what does it do with my data” changes with each, and most of the confusion in Irish offices comes from people comparing two of them without noticing.

There is good news in the detail. On the versions a firm is likely to use, Microsoft gives the strongest training answer of the four large assistants. There are also two named exceptions to its European boundary, and they are worth reading twice.

Which Copilot are you actually using?

The account you sign in with decides the product, the contract and the regulator’s view of who is responsible. Nothing else on this page matters until that is settled.

What you sign in withWhat you getMicrosoft’s role
Personal Microsoft accountThe Copilot app for individualsController, under the Privacy Statement
Work or school Entra accountMicrosoft Copilot, with enterprise data protectionProcessor, under the Data Protection Addendum
Entra account, no Copilot licenceMicrosoft Copilot ChatProcessor, same boundary for prompts and responses
A developer tool subscriptionGitHub CopilotA separate product with its own terms

Sources: Microsoft Privacy Statement, September 2026; Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot, consulted 19 September 2026.

One naming change catches people out. Microsoft Learn now records that Microsoft 365 Copilot has been renamed Microsoft Copilot, and Microsoft 365 Copilot Chat renamed Microsoft Copilot Chat, with the older names still appearing during the transition.

Microsoft states there are no changes to security, compliance and privacy for organisations. The label moved and the commitments did not, so a firm reading an older policy document is not reading a different product. Our AI policy template names the account rather than the brand for exactly this reason.

Copilot on a personal account: what changed in August 2026

The consumer story moved in 2026, and it moved in the direction firms want.

The new app does not train on your prompts

For the Copilot app released on 18 August 2026, Microsoft states that prompts, responses and your file contents are not used to train foundation models. Optional customer feedback may be used to improve the product, and Microsoft says that feedback is not used to train the foundation models either.

Not used to train
"Prompts, responses, and your file contents when using the Microsoft Copilot app aren't used to train foundation models." Microsoft Support, Copilot for individuals, app of 18 August 2026

That is a stronger default than ChatGPT, Claude or Gemini offer on a personal plan, and it is worth saying plainly because the market assumes otherwise. It is also version specific. The older app, which Microsoft still documents separately, carries training controls you can switch off, which means it was training by default.

Ads, memory and shared experiences still apply

Training is one use of text. The consumer product has three others, and a professional should know all three.

Conversation activity is stored for 18 months by default. Memory keeps details from your conversations until you delete them, and turning the setting off does not delete what is already saved. Shared experiences let Copilot chats personalise Bing, Edge and MSN, and let those services personalise Copilot. If you have no Microsoft 365 subscription you may see advertising, and personalised ads may use your chat history and saved memories.

None of that is model training. All of it is your text being used, which is the distinction this guide is built on and our ChatGPT guide covers from the other direction.

Copilot on a work account: enterprise data protection

This is the product Microsoft documents most thoroughly, and the documentation is genuinely good. It is also the version most Irish firms already own without realising, because it rides on licences they hold. Local authorities piloting the same product hold residents’ housing and planning files, which is why a Copilot licence is not a control for an Irish council on its own.

The commitment, in Microsoft’s own words

Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, including those used by Copilot. It adds that Copilot is compliant with its existing privacy, security and compliance commitments to Microsoft 365 commercial customers, including the GDPR and the EU Data Boundary.

Copilot also only surfaces organisational data the individual user already has permission to see, honouring the same access controls as the rest of Microsoft 365. That is a real architectural property rather than a policy promise, and it is the reason the main Copilot risk in practice is oversharing inside the tenant rather than leakage outside it.

What “stored in alignment with your other content” means

Prompts and responses are stored as part of the user’s Copilot activity history, encrypted at rest, and processed and stored in alignment with your organisation’s other Microsoft 365 content. Administrators can view and manage that data with Content search or Microsoft Purview, and set retention policies for it.

Read that as an employee and it says something the marketing does not. Your Copilot conversations are discoverable corporate records held by your employer, and our guide on whether a paste is a breach explains why that is usually a good thing and occasionally an awkward one.

Training and passing through your data are not the same question

Copilot illustrates this better than any of the other three, because the training answer is excellent and the interesting questions are all somewhere else.

Take an Irish solicitor drafting an attendance note in Word with Copilot on a work account. The text is not used to train a foundation model. It is still processed by Microsoft, still stored in the tenant, still readable by an administrator, still discoverable, and if web search is enabled, a few words derived from it may still leave the service boundary.

Two separate promises
"Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs." A promise about training, not about storage, access or the search boundary. Microsoft Learn

Every one of those is compatible with the training promise being kept in full. The professional question is whether this document should be in this system at all, whatever the vendor does about training, and that question is answered by your own duties rather than by a vendor page. The same question for ChatGPT, Claude and Gemini is worked through in our other guides.

The web search exception, and the query that leaves

This is the detail that deserves to be better known in Ireland, and Microsoft publishes it in full rather than burying it.

A colleague’s name, sent to Bing

When web search is on, Copilot parses your prompt and generates a short search query, a few words informed by what you asked, and sends it to the Bing search service. Microsoft’s own worked example is the one to remember: ask “who is my manager and what public information is available about them”, and the generated query is the manager’s name.

What is not sent is your entire prompt unless it is very short, whole Microsoft 365 files or uploaded files, whole web pages summarised in Edge, and any identifying information from your Entra ID such as username, domain or tenant ID.

What the Product Terms commit to, and what they exclude

The commitments Microsoft makes about those queries are specific and good. They are not used to improve Bing, not used to create advertising profiles or track behaviour, not shared with advertisers, not used to train generative AI foundation models, and are treated as customer confidential information.

Then comes the exclusion, in the same document. The Data Protection Addendum does not apply to generated web search queries, and neither HIPAA compliance nor the EU Data Boundary applies to them. For those queries Microsoft acts as a controller under the Product Terms, and Bing operates separately from Microsoft 365.

24 hourshow long web query citations stay in the chat thread
18 monthsdefault retention of consumer conversation activity
2named exceptions to the EU Data Boundary for Copilot
Microsoft Learn, web search in Microsoft Copilot, and Microsoft Support, Copilot for individuals, consulted 19 September 2026

Copilot Chat shows users the exact queries it sent, in the citation section of the response, and those citations stay in the chat thread for 24 hours. Admins can audit the same queries through Purview.

An admin can also turn web search off for the whole tenant with the Allow web search in Copilot policy, and users have their own toggle. If your practice handles matters where a name alone is sensitive, that decision takes two minutes, has a real effect, and is the sort of setting an external IT provider should be asked about by name.

The EU Data Boundary, and the two exceptions Microsoft names

For an Irish firm this is the section that matters most, because the boundary is the thing everybody has heard of and the exceptions are the thing nobody has.

Microsoft states that Copilot calls to the model are routed to the closest data centres in the region, that EU traffic stays within the EU Data Boundary, and that for EU customers Copilot is an EU Data Boundary service. Copilot was added as a covered workload in the data residency commitments in the Product Terms on 1 March 2024.

What Microsoft saysInside the EU Data Boundary
Copilot prompts and responses for EU customersYes
Generated web search queries sent to BingNo, explicitly excluded
Models provided by Anthropic as a subprocessorNo, currently excluded
Customers outside the EUMay be processed in the US, EU or elsewhere

Source: Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot, and web search in Microsoft Copilot, consulted 19 September 2026.

The exception that an admin toggle creates

The Anthropic line is the one to take to your administrator. Microsoft offers models from other companies inside Copilot, an admin decides whether to enable them, and the documentation says models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary.

If those models are on in your tenant, the boundary answer you gave a client last year has an exception in it. Our Claude guide covers Anthropic’s own residency position, which is that traffic can be routed to Europe while data is stored in the United States.

Who is the controller here, and who regulates it

All four of these companies answer for European data through an Irish entity. That is a fact about the Irish economy that turns out to be a fact about your file.

ProductThe controller for the EEAWhere it is registered
Microsoft Copilot, consumerMicrosoft Ireland Operations LimitedLeopardstown, Dublin 18
ChatGPTOpenAI Ireland LimitedSheriff Street Upper, Dublin 1
ClaudeAnthropic Ireland, LimitedBarrow Street, Dublin 4
Gemini AppsGoogle Ireland LimitedProvider for the EEA and Switzerland

Sources: each company’s own privacy documentation, consulted 19 September 2026 and cited in full below.

For work accounts the picture changes shape rather than address. Microsoft acts as a data processor under the Data Protection Addendum, and your organisation is the controller.

That is the right answer and it is also the uncomfortable one, because the decisions that matter are yours and the regulator that reviews them is the Data Protection Commission. The AI Act adds a second set of regulators on top, and who does what in Ireland was decided by an Act of its own.

The DPC’s own AI guidance of 18 July 2024 puts it in one line for a firm rather than for a vendor. As a user of an AI product relying on personal data, your organisation could be a data controller, and if so a formal risk assessment should be considered. Our guide to whether a paste is a breach picks up from there.

What the DPC did to LinkedIn, and why it belongs on this page

LinkedIn is Microsoft, and in November 2025 it produced the clearest statement any Irish regulator has made about AI training by a large technology company.

What LinkedIn proposed, and what it ended up doing

In March 2025 LinkedIn told the DPC it intended to train its own generative AI models using the personal data of EU and EEA members, starting in early November 2025. After a detailed review and extensive engagement, the DPC identified a series of risks and made recommendations.

LinkedIn changed its plan in five ways: better transparency notices, a reduced scope of data and time period, stronger measures for users under 18, filters to avoid sensitive content from certain pages and groups including trade union material, and fuller risk assessments including a legitimate interest assessment and a DPIA.

The sentence to remember
"The DPC has not approved, or found compliant, LinkedIn's use of users' personal data for generative AI model training." DPC statement on LinkedIn AI training, 7 November 2025

That line sums up how the DPC approaches AI. Engagement is not approval, changes are not a clean bill of health, and the DPC required a report within five months of the processing starting. The same statement describes the DPC as lead supervisory authority for many large global technology companies with their main establishment in Ireland.

7 Nov 2025the DPC statement on LinkedIn AI training
5 monthsthe reporting deadline the DPC imposed on LinkedIn
208cross-border complaints the DPC concluded in 2025
DPC statement on LinkedIn AI Training, 7 November 2025; DPC Annual Report 2025, 30 June 2026

That standard is also worth borrowing. If a regulator will not say that a company’s own carefully documented plan is compliant, a firm should be slow to say that a tool it bought makes it compliant. The same caution runs through our other guides, and it is why none of them ends with a recommendation to buy something.

The inquiry, and the opinion Dublin asked for

Two other public facts complete the picture. On 12 September 2024 the DPC opened a cross-border statutory inquiry into Google Ireland Limited under section 110 of the Data Protection Act 2018, about a Data Protection Impact Assessment for an AI model. And in September 2024 the DPC asked the European Data Protection Board, under Article 64(2) of the GDPR, for an opinion on personal data in AI model development, delivered on 17 December 2024.

New cases from individuals16,160
Cases concluded11,734
Valid breach notifications6,521
The Data Protection Commission's workload in 2025. Annual Report 2025, published 30 June 2026

None of that is enforcement against Copilot, and nobody should present it as such. What it shows is that the regulator reading Microsoft’s documents is in Dublin, has already read LinkedIn’s, and wrote down that reading them is not the same as approving them.

In 2025 the DPC received 16,160 new cases from individuals, concluded 11,734 and took in 6,521 valid breach notifications, alongside the 208 cross-border complaints it closed as lead authority. Those figures are the caseload of the office that would read your file if a client complained, and the reason a firm that can produce its reasoning in writing is treated differently from one that cannot.

How the four assistants compare on the questions that matter

Putting the four side by side is the fastest way to see that there is no single winner, and that the differences are not where the marketing says they are.

ProductConsumer defaultWork accountChats and advertising
ChatGPTTrains until you turn it offNo trainingFree and Go, with consent
ClaudeTrains until you opt outNo trainingNo sale, no use of chats for ads
GeminiTrains until Keep Activity is offNot outside your domainNo, stated flatly
CopilotNo, in the app of 18 August 2026No trainingPersonalised ads may use chat history

Sources: each provider’s own documentation, consulted 19 September 2026 and cited in each guide.

The row that is not in the table, and why

Human review does not fit a grid, so it is written out instead. OpenAI names outside contractors who review Business conversations for abuse and misuse. Anthropic uses flagged conversations for safety work even after you opt out. Google says plainly that trained reviewers read a subset of personal account chats and keep them for three years.

Microsoft says something narrower and not directly comparable: abuse monitoring including human review of content is available in Azure OpenAI, and Copilot services have opted out of it. Putting a tidy “no” in a cell would have been easier and less true, and the same reasoning is why our Gemini guide quotes Google’s warning in full rather than summarising it.

4Copilot products with different answers
4assistants with an Irish controller for EEA data
1regulator that supervises all four
Each company's own privacy documentation, and the Data Protection Commission, as at 19 September 2026

For an Irish firm that last row is the useful one. Four companies, four Irish entities, one authority on Pembroke Row, and one set of questions that you answer rather than they do.

It also means a comparison exercise has a natural stopping point. Once you know which account each member of staff signs in with, the vendor differences above shrink to something a page can hold, and the remaining work is internal: permissions, retention, transcription and the rule everybody signs. Our template covers the last of those, and the first three are configuration in a system you already pay for.

What Irish professional rules ask, whichever Copilot you use

On 12 November 2025 the Law Society of Ireland published guidance on generative AI for the profession, written against the Solicitors’ Guide to Professional Conduct. Copilot is the first system it names, ahead of ChatGPT, Claude and Gemini. Holding a Microsoft licence does not end that guidance’s questions, and covering the client’s numbers before an Irish solicitor pastes works the same whichever Copilot is open.

Its central line is about versions rather than vendors: free and paid consumer versions are not suitable for securely handling personal data or client confidential data by default. The consumer Copilot app sits squarely in that description, however good its training answer has become, because ads, memory and shared experiences are consumer features and an Entra account has none of them.

Doctors answer to the Medical Council rather than the Law Society, and its test of disclosing only the minimum governs how much of a clinical letter can go into Copilot.

Embedded AI, and the recording nobody agreed to

The guidance makes one point that is more about Microsoft than about any other vendor, and it is worth quoting in substance. Generative AI has been built into everyday tools such as PDF readers, text editors and transcription features in Teams and Zoom, and users may not realise how much is embedded. It adds that a solicitor should not record a conversation on a video platform without the express consent of the other party.

For an Irish practice on Microsoft 365, that is the most likely first incident, and it has nothing to do with anyone typing a prompt. Our Irish cyber cover guide sets out how these things surface at renewal, and the questionnaire guide covers how to answer the AI questions without overclaiming.

What to check in your own tenant, in order

  1. Confirm the account. Ask three people which login they use for Copilot. If any of them says a personal Microsoft account, start there rather than with policy.
  2. Check whether web search is on. The Allow web search in Copilot policy is in the Cloud Policy service, and it applies to Copilot and Copilot Chat.
  3. Ask whether models from other companies are enabled. If Anthropic models are on, the EU Data Boundary answer has a named exception in it.
  4. Set retention deliberately. Purview holds the retention policy for Copilot interactions, and the default is whatever your tenant already does with other content.
  5. Review the permissions, not just the tool. Copilot surfaces what a user can already open, so an oversharing problem in SharePoint becomes a Copilot problem overnight.
  6. Decide about meeting transcription separately. In most firms it captures more of what clients say than anything else, and it is a consent question before it is a data protection one.
  7. Write the rule down and diary the review. The consumer app changed on 18 August 2026, and the product names changed with it. Our template ends with the signature block that turns a rule into evidence.

What a tool can do here, and what no tool can do, including ours

Software of this category masks identifiers before the text is sent, and it does not make an organisation compliant. What ours does is pseudonymisation: the mapping back to the person is kept, encrypted, on your own machine, so it is reversible by design and the result is still personal data under the GDPR.

Copilot shows the limit of the category particularly clearly. A masking layer sits between a person and the box they type into; it does not sit between Copilot and Bing, decide which models your administrator enabled, or see what Purview retains. Those three are configuration questions inside your tenant.

In practice ours is a Mac and Windows app: select the text, press one key, and the identifiers it recognises become labels before anything is pasted, with the originals restored in the reply. What it keeps is on our security page: the map stays encrypted on your computer.

For a firm already on Microsoft 365, the sensible first step costs nothing: move people onto the work account, turn off what you do not need and write one page of rules. Our organisations page is for the firms that get there and want the control as well, and our Gemini guide answers the same questions for Google.

Sources

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does Microsoft Copilot train on your data?

Not in the versions most firms use. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, and that in the Copilot app released on 18 August 2026 prompts, responses and file contents are not used either.

Which Copilot am I actually using?

It depends on the account you signed in with. A personal Microsoft account gives you consumer Copilot. A work or school Entra account gives you Microsoft Copilot or Copilot Chat with enterprise data protection. They are different products with different commitments.

Does Copilot send my data to Bing?

It can send a generated search query, not your document. Microsoft says the query is a few words informed by your prompt, with user and tenant identifiers removed, and it can include a colleague's name if that is what you asked about.

Is Copilot covered by the EU Data Boundary?

Mostly. Microsoft states that EU traffic stays within the EU Data Boundary, and names two exceptions: generated web search queries are outside it, and models provided by Anthropic as a subprocessor are currently excluded from it.

Who is the data controller for Copilot in Ireland?

For consumer use, Microsoft Ireland Operations Limited, at One Microsoft Place, South County Business Park, Leopardstown, Dublin 18. For work accounts Microsoft acts as a processor and your organisation is the controller.

How long does Copilot keep my conversations?

On a personal account, conversation activity is stored for 18 months by default and you can delete individual chats or the lot. On a work account, retention is set by your administrator through Microsoft Purview.

Can my employer read my Copilot chats?

On a work account, yes. Admins can use Content search or Microsoft Purview to view and manage stored interactions, set retention policies, and search the exact web queries Copilot derived from prompts.

What did the Irish regulator say about Microsoft and AI training?

On 7 November 2025 the DPC said LinkedIn had changed its AI training plans after the DPC identified risks, and added that it has not approved or found compliant LinkedIn's use of personal data for generative AI model training.

Is Copilot suitable for client files in an Irish firm?

The Law Society of Ireland names Copilot and says free and paid consumer versions are not suitable for client confidential data by default. A work account with enterprise data protection is the enterprise option, and it still needs due diligence.