Which Copilot has your data? An Irish guide to Microsoft
· Updated · Written and maintained by Joaquín Trapero, Nonimo
Before anything else, the question in the title is the whole guide. Copilot is really four products: a consumer assistant, a work assistant on an Entra account, a chat experience inside Microsoft 365, and a coding tool that shares the brand and almost nothing else. The answer to “what does it do with my data” changes with each, and most of the confusion in Irish offices comes from people comparing two of them without noticing.
There is good news in the detail. On the versions a firm is likely to use, Microsoft gives the strongest training answer of the four large assistants. There are also two named exceptions to its European boundary, and they are worth reading twice.
Which Copilot are you actually using?
The account you sign in with decides the product, the contract and the regulator’s view of who is responsible. Nothing else on this page matters until that is settled.
| What you sign in with | What you get | Microsoft’s role |
|---|---|---|
| Personal Microsoft account | The Copilot app for individuals | Controller, under the Privacy Statement |
| Work or school Entra account | Microsoft Copilot, with enterprise data protection | Processor, under the Data Protection Addendum |
| Entra account, no Copilot licence | Microsoft Copilot Chat | Processor, same boundary for prompts and responses |
| A developer tool subscription | GitHub Copilot | A separate product with its own terms |
Sources: Microsoft Privacy Statement, September 2026; Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot, consulted 19 September 2026.
One naming change catches people out. Microsoft Learn now records that Microsoft 365 Copilot has been renamed Microsoft Copilot, and Microsoft 365 Copilot Chat renamed Microsoft Copilot Chat, with the older names still appearing during the transition.
Microsoft states there are no changes to security, compliance and privacy for organisations. The label moved and the commitments did not, so a firm reading an older policy document is not reading a different product. Our AI policy template names the account rather than the brand for exactly this reason.
Copilot on a personal account: what changed in August 2026
The consumer story moved in 2026, and it moved in the direction firms want.
The new app does not train on your prompts
For the Copilot app released on 18 August 2026, Microsoft states that prompts, responses and your file contents are not used to train foundation models. Optional customer feedback may be used to improve the product, and Microsoft says that feedback is not used to train the foundation models either.
That is a stronger default than ChatGPT, Claude or Gemini offer on a personal plan, and it is worth saying plainly because the market assumes otherwise. It is also version specific. The older app, which Microsoft still documents separately, carries training controls you can switch off, which means it was training by default.
Ads, memory and shared experiences still apply
Training is one use of text. The consumer product has three others, and a professional should know all three.
Conversation activity is stored for 18 months by default. Memory keeps details from your conversations until you delete them, and turning the setting off does not delete what is already saved. Shared experiences let Copilot chats personalise Bing, Edge and MSN, and let those services personalise Copilot. If you have no Microsoft 365 subscription you may see advertising, and personalised ads may use your chat history and saved memories.
None of that is model training. All of it is your text being used, which is the distinction this guide is built on and our ChatGPT guide covers from the other direction.
Copilot on a work account: enterprise data protection
This is the product Microsoft documents most thoroughly, and the documentation is genuinely good. It is also the version most Irish firms already own without realising, because it rides on licences they hold. Local authorities piloting the same product hold residents’ housing and planning files, which is why a Copilot licence is not a control for an Irish council on its own.
The commitment, in Microsoft’s own words
Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, including those used by Copilot. It adds that Copilot is compliant with its existing privacy, security and compliance commitments to Microsoft 365 commercial customers, including the GDPR and the EU Data Boundary.
Copilot also only surfaces organisational data the individual user already has permission to see, honouring the same access controls as the rest of Microsoft 365. That is a real architectural property rather than a policy promise, and it is the reason the main Copilot risk in practice is oversharing inside the tenant rather than leakage outside it.
What “stored in alignment with your other content” means
Prompts and responses are stored as part of the user’s Copilot activity history, encrypted at rest, and processed and stored in alignment with your organisation’s other Microsoft 365 content. Administrators can view and manage that data with Content search or Microsoft Purview, and set retention policies for it.
Read that as an employee and it says something the marketing does not. Your Copilot conversations are discoverable corporate records held by your employer, and our guide on whether a paste is a breach explains why that is usually a good thing and occasionally an awkward one.
Training and passing through your data are not the same question
Copilot illustrates this better than any of the other three, because the training answer is excellent and the interesting questions are all somewhere else.
Take an Irish solicitor drafting an attendance note in Word with Copilot on a work account. The text is not used to train a foundation model. It is still processed by Microsoft, still stored in the tenant, still readable by an administrator, still discoverable, and if web search is enabled, a few words derived from it may still leave the service boundary.
Every one of those is compatible with the training promise being kept in full. The professional question is whether this document should be in this system at all, whatever the vendor does about training, and that question is answered by your own duties rather than by a vendor page. The same question for ChatGPT, Claude and Gemini is worked through in our other guides.
The web search exception, and the query that leaves
This is the detail that deserves to be better known in Ireland, and Microsoft publishes it in full rather than burying it.
A colleague’s name, sent to Bing
When web search is on, Copilot parses your prompt and generates a short search query, a few words informed by what you asked, and sends it to the Bing search service. Microsoft’s own worked example is the one to remember: ask “who is my manager and what public information is available about them”, and the generated query is the manager’s name.
What is not sent is your entire prompt unless it is very short, whole Microsoft 365 files or uploaded files, whole web pages summarised in Edge, and any identifying information from your Entra ID such as username, domain or tenant ID.
What the Product Terms commit to, and what they exclude
The commitments Microsoft makes about those queries are specific and good. They are not used to improve Bing, not used to create advertising profiles or track behaviour, not shared with advertisers, not used to train generative AI foundation models, and are treated as customer confidential information.
Then comes the exclusion, in the same document. The Data Protection Addendum does not apply to generated web search queries, and neither HIPAA compliance nor the EU Data Boundary applies to them. For those queries Microsoft acts as a controller under the Product Terms, and Bing operates separately from Microsoft 365.
Copilot Chat shows users the exact queries it sent, in the citation section of the response, and those citations stay in the chat thread for 24 hours. Admins can audit the same queries through Purview.
An admin can also turn web search off for the whole tenant with the Allow web search in Copilot policy, and users have their own toggle. If your practice handles matters where a name alone is sensitive, that decision takes two minutes, has a real effect, and is the sort of setting an external IT provider should be asked about by name.
The EU Data Boundary, and the two exceptions Microsoft names
For an Irish firm this is the section that matters most, because the boundary is the thing everybody has heard of and the exceptions are the thing nobody has.
Microsoft states that Copilot calls to the model are routed to the closest data centres in the region, that EU traffic stays within the EU Data Boundary, and that for EU customers Copilot is an EU Data Boundary service. Copilot was added as a covered workload in the data residency commitments in the Product Terms on 1 March 2024.
| What Microsoft says | Inside the EU Data Boundary |
|---|---|
| Copilot prompts and responses for EU customers | Yes |
| Generated web search queries sent to Bing | No, explicitly excluded |
| Models provided by Anthropic as a subprocessor | No, currently excluded |
| Customers outside the EU | May be processed in the US, EU or elsewhere |
Source: Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot, and web search in Microsoft Copilot, consulted 19 September 2026.
The exception that an admin toggle creates
The Anthropic line is the one to take to your administrator. Microsoft offers models from other companies inside Copilot, an admin decides whether to enable them, and the documentation says models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary.
If those models are on in your tenant, the boundary answer you gave a client last year has an exception in it. Our Claude guide covers Anthropic’s own residency position, which is that traffic can be routed to Europe while data is stored in the United States.
Who is the controller here, and who regulates it
All four of these companies answer for European data through an Irish entity. That is a fact about the Irish economy that turns out to be a fact about your file.
| Product | The controller for the EEA | Where it is registered |
|---|---|---|
| Microsoft Copilot, consumer | Microsoft Ireland Operations Limited | Leopardstown, Dublin 18 |
| ChatGPT | OpenAI Ireland Limited | Sheriff Street Upper, Dublin 1 |
| Claude | Anthropic Ireland, Limited | Barrow Street, Dublin 4 |
| Gemini Apps | Google Ireland Limited | Provider for the EEA and Switzerland |
Sources: each company’s own privacy documentation, consulted 19 September 2026 and cited in full below.
For work accounts the picture changes shape rather than address. Microsoft acts as a data processor under the Data Protection Addendum, and your organisation is the controller.
That is the right answer and it is also the uncomfortable one, because the decisions that matter are yours and the regulator that reviews them is the Data Protection Commission. The AI Act adds a second set of regulators on top, and who does what in Ireland was decided by an Act of its own.
The DPC’s own AI guidance of 18 July 2024 puts it in one line for a firm rather than for a vendor. As a user of an AI product relying on personal data, your organisation could be a data controller, and if so a formal risk assessment should be considered. Our guide to whether a paste is a breach picks up from there.
What the DPC did to LinkedIn, and why it belongs on this page
LinkedIn is Microsoft, and in November 2025 it produced the clearest statement any Irish regulator has made about AI training by a large technology company.
What LinkedIn proposed, and what it ended up doing
In March 2025 LinkedIn told the DPC it intended to train its own generative AI models using the personal data of EU and EEA members, starting in early November 2025. After a detailed review and extensive engagement, the DPC identified a series of risks and made recommendations.
LinkedIn changed its plan in five ways: better transparency notices, a reduced scope of data and time period, stronger measures for users under 18, filters to avoid sensitive content from certain pages and groups including trade union material, and fuller risk assessments including a legitimate interest assessment and a DPIA.
That line sums up how the DPC approaches AI. Engagement is not approval, changes are not a clean bill of health, and the DPC required a report within five months of the processing starting. The same statement describes the DPC as lead supervisory authority for many large global technology companies with their main establishment in Ireland.
That standard is also worth borrowing. If a regulator will not say that a company’s own carefully documented plan is compliant, a firm should be slow to say that a tool it bought makes it compliant. The same caution runs through our other guides, and it is why none of them ends with a recommendation to buy something.
The inquiry, and the opinion Dublin asked for
Two other public facts complete the picture. On 12 September 2024 the DPC opened a cross-border statutory inquiry into Google Ireland Limited under section 110 of the Data Protection Act 2018, about a Data Protection Impact Assessment for an AI model. And in September 2024 the DPC asked the European Data Protection Board, under Article 64(2) of the GDPR, for an opinion on personal data in AI model development, delivered on 17 December 2024.
None of that is enforcement against Copilot, and nobody should present it as such. What it shows is that the regulator reading Microsoft’s documents is in Dublin, has already read LinkedIn’s, and wrote down that reading them is not the same as approving them.
In 2025 the DPC received 16,160 new cases from individuals, concluded 11,734 and took in 6,521 valid breach notifications, alongside the 208 cross-border complaints it closed as lead authority. Those figures are the caseload of the office that would read your file if a client complained, and the reason a firm that can produce its reasoning in writing is treated differently from one that cannot.
How the four assistants compare on the questions that matter
Putting the four side by side is the fastest way to see that there is no single winner, and that the differences are not where the marketing says they are.
| Product | Consumer default | Work account | Chats and advertising |
|---|---|---|---|
| ChatGPT | Trains until you turn it off | No training | Free and Go, with consent |
| Claude | Trains until you opt out | No training | No sale, no use of chats for ads |
| Gemini | Trains until Keep Activity is off | Not outside your domain | No, stated flatly |
| Copilot | No, in the app of 18 August 2026 | No training | Personalised ads may use chat history |
Sources: each provider’s own documentation, consulted 19 September 2026 and cited in each guide.
The row that is not in the table, and why
Human review does not fit a grid, so it is written out instead. OpenAI names outside contractors who review Business conversations for abuse and misuse. Anthropic uses flagged conversations for safety work even after you opt out. Google says plainly that trained reviewers read a subset of personal account chats and keep them for three years.
Microsoft says something narrower and not directly comparable: abuse monitoring including human review of content is available in Azure OpenAI, and Copilot services have opted out of it. Putting a tidy “no” in a cell would have been easier and less true, and the same reasoning is why our Gemini guide quotes Google’s warning in full rather than summarising it.
For an Irish firm that last row is the useful one. Four companies, four Irish entities, one authority on Pembroke Row, and one set of questions that you answer rather than they do.
It also means a comparison exercise has a natural stopping point. Once you know which account each member of staff signs in with, the vendor differences above shrink to something a page can hold, and the remaining work is internal: permissions, retention, transcription and the rule everybody signs. Our template covers the last of those, and the first three are configuration in a system you already pay for.
What Irish professional rules ask, whichever Copilot you use
On 12 November 2025 the Law Society of Ireland published guidance on generative AI for the profession, written against the Solicitors’ Guide to Professional Conduct. Copilot is the first system it names, ahead of ChatGPT, Claude and Gemini. Holding a Microsoft licence does not end that guidance’s questions, and covering the client’s numbers before an Irish solicitor pastes works the same whichever Copilot is open.
Its central line is about versions rather than vendors: free and paid consumer versions are not suitable for securely handling personal data or client confidential data by default. The consumer Copilot app sits squarely in that description, however good its training answer has become, because ads, memory and shared experiences are consumer features and an Entra account has none of them.
Doctors answer to the Medical Council rather than the Law Society, and its test of disclosing only the minimum governs how much of a clinical letter can go into Copilot.
Embedded AI, and the recording nobody agreed to
The guidance makes one point that is more about Microsoft than about any other vendor, and it is worth quoting in substance. Generative AI has been built into everyday tools such as PDF readers, text editors and transcription features in Teams and Zoom, and users may not realise how much is embedded. It adds that a solicitor should not record a conversation on a video platform without the express consent of the other party.
For an Irish practice on Microsoft 365, that is the most likely first incident, and it has nothing to do with anyone typing a prompt. Our Irish cyber cover guide sets out how these things surface at renewal, and the questionnaire guide covers how to answer the AI questions without overclaiming.
What to check in your own tenant, in order
- Confirm the account. Ask three people which login they use for Copilot. If any of them says a personal Microsoft account, start there rather than with policy.
- Check whether web search is on. The Allow web search in Copilot policy is in the Cloud Policy service, and it applies to Copilot and Copilot Chat.
- Ask whether models from other companies are enabled. If Anthropic models are on, the EU Data Boundary answer has a named exception in it.
- Set retention deliberately. Purview holds the retention policy for Copilot interactions, and the default is whatever your tenant already does with other content.
- Review the permissions, not just the tool. Copilot surfaces what a user can already open, so an oversharing problem in SharePoint becomes a Copilot problem overnight.
- Decide about meeting transcription separately. In most firms it captures more of what clients say than anything else, and it is a consent question before it is a data protection one.
- Write the rule down and diary the review. The consumer app changed on 18 August 2026, and the product names changed with it. Our template ends with the signature block that turns a rule into evidence.
What a tool can do here, and what no tool can do, including ours
Software of this category masks identifiers before the text is sent, and it does not make an organisation compliant. What ours does is pseudonymisation: the mapping back to the person is kept, encrypted, on your own machine, so it is reversible by design and the result is still personal data under the GDPR.
Copilot shows the limit of the category particularly clearly. A masking layer sits between a person and the box they type into; it does not sit between Copilot and Bing, decide which models your administrator enabled, or see what Purview retains. Those three are configuration questions inside your tenant.
In practice ours is a Mac and Windows app: select the text, press one key, and the identifiers it recognises become labels before anything is pasted, with the originals restored in the reply. What it keeps is on our security page: the map stays encrypted on your computer.
For a firm already on Microsoft 365, the sensible first step costs nothing: move people onto the work account, turn off what you do not need and write one page of rules. Our organisations page is for the firms that get there and want the control as well, and our Gemini guide answers the same questions for Google.
Sources
- Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot, consulted 19 September 2026. The rename of Microsoft 365 Copilot to Microsoft Copilot with no change to commitments; prompts, responses and Microsoft Graph data not used to train foundation models; compliance with the GDPR and the EU Data Boundary; permission based surfacing of organisational data; storage of interactions and admin management through Content search and Purview; EU traffic stays within the EU Data Boundary; “Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary”; Copilot added as a covered workload in data residency commitments on 1 March 2024; and Copilot services have opted out of the Azure OpenAI abuse monitoring that includes human review. Source
- Microsoft Learn, Data, privacy, and security for web search in Microsoft Copilot and Microsoft Copilot Chat, consulted 19 September 2026. How a generated query is built and what it excludes; the manager name worked example; the Product Terms commitments on generated queries; the Data Protection Addendum, HIPAA compliance and the EU Data Boundary do not apply to generated search queries; Microsoft acts as controller for them; query citations available for 24 hours; the Allow web search in Copilot policy. Source
- Microsoft Support, Microsoft Copilot for individuals, and its privacy controls and activity history articles, consulted 19 September 2026. The updated app of 18 August 2026; prompts, responses and file contents not used to train foundation models; memory, shared experiences, chat history, web search and personalised advertising controls; personalised ads may use chat history and saved memories. Source
- Microsoft Support, Privacy FAQ for Microsoft Copilot, consulted 19 September 2026. The 18 month default for consumer conversation activity, and deletion of individual conversations or the entire history. Source
- Microsoft Privacy Statement, last updated September 2026. Microsoft Ireland Operations Limited, at One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, as a data controller for people in the EEA, the UK and Switzerland. Source
- Data Protection Commission, DPC statement on LinkedIn AI Training, 7 November 2025. LinkedIn’s March 2025 notification and November 2025 start date; the risks identified and the five changes LinkedIn adopted; the report required within five months; “The DPC has not approved, or found compliant, LinkedIn’s use of users’ personal data for generative AI model training”; the DPC as lead supervisory authority for many large global technology companies established in Ireland. Source
- Data Protection Commission, inquiry into Google AI model, 12 September 2024. A cross-border statutory inquiry into Google Ireland Limited under section 110 of the Data Protection Act 2018, on whether a Data Protection Impact Assessment was required under Article 35. Source
- Data Protection Commission, welcome for the EDPB opinion, 18 December 2024. The opinion was sought by the DPC in September 2024 under Article 64(2) GDPR and delivered on 17 December 2024. Source
- Data Protection Commission, Annual Report 2025, published 30 June 2026. 208 valid cross-border complaints concluded as lead supervisory authority, a 43 per cent increase on 2024. Source
- Law Society of Ireland, guidance on generative artificial intelligence, December 2025. Names Copilot first among the systems covered; free and paid consumer versions not suitable for securely handling client confidential data by default; embedded AI in everyday tools including Teams and Zoom; no recording of a conversation on a video platform without the express consent of the other party. Source
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Does Microsoft Copilot train on your data?
Not in the versions most firms use. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, and that in the Copilot app released on 18 August 2026 prompts, responses and file contents are not used either.
Which Copilot am I actually using?
It depends on the account you signed in with. A personal Microsoft account gives you consumer Copilot. A work or school Entra account gives you Microsoft Copilot or Copilot Chat with enterprise data protection. They are different products with different commitments.
Does Copilot send my data to Bing?
It can send a generated search query, not your document. Microsoft says the query is a few words informed by your prompt, with user and tenant identifiers removed, and it can include a colleague's name if that is what you asked about.
Is Copilot covered by the EU Data Boundary?
Mostly. Microsoft states that EU traffic stays within the EU Data Boundary, and names two exceptions: generated web search queries are outside it, and models provided by Anthropic as a subprocessor are currently excluded from it.
Who is the data controller for Copilot in Ireland?
For consumer use, Microsoft Ireland Operations Limited, at One Microsoft Place, South County Business Park, Leopardstown, Dublin 18. For work accounts Microsoft acts as a processor and your organisation is the controller.
How long does Copilot keep my conversations?
On a personal account, conversation activity is stored for 18 months by default and you can delete individual chats or the lot. On a work account, retention is set by your administrator through Microsoft Purview.
Can my employer read my Copilot chats?
On a work account, yes. Admins can use Content search or Microsoft Purview to view and manage stored interactions, set retention policies, and search the exact web queries Copilot derived from prompts.
What did the Irish regulator say about Microsoft and AI training?
On 7 November 2025 the DPC said LinkedIn had changed its AI training plans after the DPC identified risks, and added that it has not approved or found compliant LinkedIn's use of personal data for generative AI model training.
Is Copilot suitable for client files in an Irish firm?
The Law Society of Ireland names Copilot and says free and paid consumer versions are not suitable for client confidential data by default. A work account with enterprise data protection is the enterprise option, and it still needs due diligence.