GDPR
Is Microsoft 365 Copilot GDPR Compliant? The Oversharing Problem, and the Two Toggles That Change the Answer
Yes. Microsoft 365 Copilot can be run in a GDPR compliant way, and on Microsoft's side most of the hard parts are already handled. The condition is one Microsoft states itself. Copilot surfaces whatever your users can already reach, so if your SharePoint permissions are looser than anyone realised, Copilot is a very good search engine pointed at the mistake.
Microsoft has renamed the product to Microsoft Copilot and says there are no changes to security, compliance, and privacy for organisations. Most people still search for it under the old name, so that is the name used here.
This is written the same way as the ChatGPT API guide and the Claude API guide: what Microsoft has already handled, what you have to configure, and what you have to write down. Every quotation below is from a Microsoft Learn page or a Microsoft Message Center notice, read on 5 September 2026, with the page's own date given.
Get articles like this. Compliance Engineering, practical AI compliance for founders and the people who run the tenant, written by a CIPP/E certified practitioner.
Need this checked for your tenant? A £500 scoping review covers your Copilot settings, the subprocessor toggles, sharing defaults, DPA position and DPIA. Written report in one week.
Two products, and only one of them reads your files
Copilot Chat is, in the words of Microsoft's licensing page (dated 19 May 2026), "automatically included with an eligible Microsoft 365 subscription at no extra cost". The paid Copilot licence is an add-on, and the difference is what each one can see.
Microsoft's enterprise data protection page (dated 29 May 2026) draws the line in one sentence: "Microsoft Copilot Chat uses the user's context to create relevant responses. Microsoft Copilot also uses Microsoft Graph data." Graph data is your files. The paid licence reasons over your SharePoint, OneDrive, Exchange and Teams content, and the free Chat does not.
Both are covered by the same terms. The same page again: "The use of Microsoft Copilot and Microsoft Copilot Chat, as used by organizations, is covered by the terms of the Microsoft Products and Services Data Protection Addendum (DPA) and Microsoft Product Terms, with Microsoft acting as a data processor."
So the Article 28 position is in place from day one, for both, without a separate signature. The rest of this piece is about the paid licence, because that is the one that reads the files.
"It sees everything in SharePoint": what is actually happening
The complaint always arrives the same way. Someone turned Copilot on, asked it a question about pay or a restructure or a client, and it answered from a document they were never meant to see.
Microsoft's privacy page (dated 9 July 2026) explains the mechanism, and it is worth reading the two sentences together:
"Microsoft Copilot only surfaces organizational data to which individual users have at least view permissions. It's important that you're using the permission models available in Microsoft 365 services, such as SharePoint, to help ensure the right users or groups have the right access to the right content within your organization."
The first sentence is a promise Microsoft keeps, and the second hands the work to you.
Copilot honours permissions exactly, and that is the problem, because in a tenant that has grown for a few years the permissions have usually drifted and nobody knew. A library shared with Everyone except external users in 2021. A finance site where somebody broke permission inheritance on one folder and then left the company. An HR site with no owner. All of that was open before Copilot arrived. It was also invisible, because organisation-wide search was mediocre and nobody went looking, and a file nobody can find is a file nobody complains about.
Microsoft's own worked example on the Restricted SharePoint Search page (dated 6 July 2026) says so directly. A marketing specialist asks Copilot for budgeting information. "Contoso Electronics has a budgeting site with important business information. Most people don't know about this site, so the site owner hasn't set up proper permissions and hasn't followed correct data governance process." The site is open to a user who was never meant to see it, and Copilot answers from it.
Under GDPR that is an Article 32 security failure and an Article 5(1)(f) confidentiality failure, and both existed before the licence was bought. What Copilot added was a way to find them.
The fix most firms used is being switched off
Microsoft's first answer was an interim control called Restricted SharePoint Search. It let an administrator keep an allow list of up to 100 sites, and Copilot would only draw on those plus whatever the user had already touched.
Microsoft has always been clear about what it was. From the same page: "it's important to note that Restricted SharePoint Search isn't a security boundary and doesn't change any permissions on SharePoint sites." And: "Neither Copilot nor Restricted SharePoint Search prevents users from accessing content they own or previously accessed."
It is now being retired. The page says so: "Restricted SharePoint Search is retiring. Starting July 31, 2026, new enablement is blocked." Message Center notice MC1395311, published 18 June 2026, gives the rest of the timetable. The feature is fully retired on 31 January 2027, with no extensions or exceptions, and the PowerShell cmdlets go on 28 February 2027.
The sentence from that notice that matters for anyone who turned it on and forgot about it: "If no action is taken, restricted content may become discoverable after RSS retirement."
If your tenant switched Restricted SharePoint Search on when it first appeared and has been treating the problem as solved, you have until 31 January to actually solve it.
What Microsoft says to do instead
The replacement is Restricted Content Discovery, and Microsoft's page for it (dated 27 July 2026) describes it as "a temporary governance control that gives organizations time to review and right-size access while continuing their Copilot deployment." It is applied site by site, in the SharePoint admin centre or by PowerShell, and it hides a site's content from organisation-wide search and from Copilot.
Three things to know before relying on it:
- It does not change permissions either. "Restricted Content Discovery doesn't change existing permissions. Users who already have access to content can continue to access that content directly."
- It needs a Copilot licence and SharePoint Advanced Management, which Microsoft says is included with Copilot licences.
- It is slow on big sites. "For sites with more than 500,000 items, an update to Restricted Content Discovery could take more than a week to fully process and reflect in search and Copilot experiences."
Behind the interim control, Microsoft's deployment blueprint (dated 6 May 2026) sets out the real work in three steps: remediate oversharing, set up guardrails, meet regulations. The detailed version (dated 17 April 2026) is the closest thing to a checklist Microsoft publishes, and the order it gives is the right one:
- Run the SharePoint Advanced Management content management assessment and the Purview data risk assessment to find sites "with oversized audiences, EEEU usage, broken inheritance, inappropriate sharing, and those that are inactive or ownerless". EEEU is Everyone except external users, and it is the single most common cause of the complaint above.
- Put Restricted Content Discovery on the high-risk sites while they are reviewed.
- Run site access reviews so owners remove excess users and company-wide sharing links, fix broken inheritance, and confirm someone owns the site.
- Then remove the interim control, and change the tenant defaults so new sites cannot recreate the problem: restrict Anyone links and company-wide sharing groups, require sensitivity labels at site creation, and use Restricted Access Control on business-critical sites.
One thing a smaller firm should read before buying. Microsoft's licensing page sells the Copilot add-on to Business Basic, Business Standard and Business Premium tenants, however, the remediation guide above says the capabilities it describes require "Microsoft 365 E3 or Microsoft 365 E5 (or Office 365 E3 or Office 365 E5)". A tenant on a Business plan can buy the licence and then find it is being told to fix a permissions problem with tools it may not have. That is a question for your reseller before the licence is bought.
Free download
Get the AI Vendor Due Diligence Checklist
The questions we work through before a client signs with an AI vendor, covering data handling, contracts and transfers, security and operations, model and product risk, and exit risk.
For engineers and technical leads assessing an AI vendor before integration.
- ·What personal data actually goes to the vendor, and whether it trains the model by default
- ·The DPA, the subprocessor chain, and the transfer mechanism if data leaves the UK or EEA
- ·Exit risk: whether data and logs can be exported, what lock-in exists, and your fallback if the vendor changes pricing or terms
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.
The two toggles that change the legal position
Everything above is about access control inside your tenant. These two settings change where processing happens and, in one case, who your processor is.
Anthropic models
Microsoft now offers Anthropic's Claude models inside Copilot, Researcher, Copilot Studio and the Office apps, with Anthropic onboarded as a Microsoft subprocessor. The page for this is dated 2 September 2026. It says the models are on by default "for most customers in commercial cloud (excluding EU/EFTA and UK)", and that for the EU, EFTA and the UK the setting exists but "the default is set to No users". An administrator has to turn it on. The setting is in the Microsoft 365 admin centre under Copilot, then Settings, then AI providers operating as Microsoft subprocessors.
Here is what turning it on does, in Microsoft's words:
"Anthropic models deployed in Microsoft offerings such as Microsoft Copilot, Researcher, Copilot Studio, Power Platform, and Copilot in Microsoft 365 apps are currently excluded from the EU Data Boundary, and when applicable, in-country processing commitments."
For the standard models, Microsoft's Product Terms and DPA still apply and Anthropic acts as a subprocessor under Microsoft's oversight. So the Article 28 chain holds, however, the line in your records that says processing stays inside the EU Data Boundary stops being true the moment the toggle moves.
The models Microsoft labels "Anthropic models with Data Retention" are a different arrangement altogether. The page names Claude Fable 5 and Claude Mythos 5 as examples at the time of writing. For these, the page says data "is stored by Anthropic and not subject to your Microsoft Customer Agreement including commitments in the Product Terms and DPA", that "Anthropic acts as an independent processor", and that use "is subject to acceptance of Anthropic's Commercial Terms of Service and Anthropic's Data Protection Addendum." Anthropic then "stores most inputs and outputs for up to 30 days before deleting them", flagged content for up to two years, and trust and safety classification scores for up to seven years.
That is a new processor, on its own contract, with its own retention, created by a checkbox in the admin centre. It is off by default everywhere. It needs a separate opt-in even where standard Anthropic models are on. It also needs its own line in your records of processing and a look at your DPIA, because the DPIA you wrote for Copilot did not have Anthropic in it.
One more detail from the same page for anyone in the EU or UK who switched Anthropic on under the earlier arrangement: "you need to opt in again. The toggle is set to Off by default." So a tenant that thinks it has Claude enabled may not, and a tenant that re-enables it is accepting the new terms.
Web grounding
Copilot can send a search query to Bing to improve an answer. The enterprise data protection page is precise about the legal effect: "The Bing search service operates separately from Microsoft 365 and has different data-handling practices covered by the Microsoft Services Agreement between each user and Microsoft, together with the Microsoft Privacy Statement. This means that Microsoft acts as an independent data controller responsible for complying with all applicable laws and controller obligations." The same page's footnote adds that "The EU Data Boundary doesn't apply to web search queries."
Microsoft limits the damage. The query is "generated from the prompt into a few words", sent "with user and tenant identifiers removed", not shared with advertisers and not used for training. Your documents stay in the tenant. What leaves is a few words, as a controller-to-controller flow outside the DPA, which your privacy notice probably does not mention. An administrator can turn web grounding off.
What Microsoft has already handled
To be fair to the product, the list is long. It is why the answer at the top is yes.
Prompts, responses and anything read through Microsoft Graph "aren't used to train foundation LLMs". That is stated three separate times on the privacy page. It is in the contract, so there is no opt-out to go looking for. Interactions are stored "in alignment with contractual commitments with your organization's other content in Microsoft 365", encrypted, searchable by an administrator through Purview, deletable by the user, and subject to whatever retention policy you set for them. Microsoft has opted Copilot out of the Azure OpenAI abuse monitoring that involves human review of content. For EU customers, "Microsoft Copilot is an EU Data Boundary service", and Copilot was added to the data residency commitments in the Product Terms on 1 March 2024.
Microsoft also holds a certification under the EU-US Data Privacy Framework, shown on the official register on 5 September 2026 as active and under re-certification review. That one is worth checking rather than assuming. On the same register the same day, OpenAI and Anthropic returned no record at all, under either status. Copilot is covered by ISO 42001 as well as ISO 27001.
One item that will matter to anyone reading this because of workplace monitoring: Microsoft says it restricts "generative AI or models from being used" to make "inferences, judgments, or evaluations about an employee's performance, attitude, internal or emotional state, or personal characteristics." That does not settle the UK law on monitoring staff with AI, but it removes one of the uses a DPIA would otherwise have to confront.
What to write down
The Copilot deployment itself is a processing activity and it needs the paperwork any other one needs. Four items cover most of it.
A DPIA. Copilot reads across the whole tenant, including HR and finance content, for every licensed user, which is the kind of large-scale, systematic processing Article 35 is aimed at. The DPIA should record the oversharing assessment, what was remediated, and which interim controls are on and when they come off. If the Anthropic toggle is on, the DPIA needs a section that was not in the template.
A records of processing entry. Processor: Microsoft, under the DPA. Subprocessors: OpenAI and, if enabled, Anthropic, both as listed by Microsoft. Processing location: EU Data Boundary, with the two exceptions above stated. If the Data Retention models are on, a second processor entry for Anthropic with its own DPA and its own retention.
A retention policy for Copilot interactions, set in Purview, because the default is to keep them with everything else.
A dated note of the Restricted SharePoint Search position. Whether it was ever on, whether it is still on, and the 31 January 2027 date beside it.
The check that takes five minutes
Open the Microsoft 365 admin centre and go to Copilot, then Settings, then AI providers operating as Microsoft subprocessors. Note whether Anthropic shows No users or a list of users, and whether the Data Retention setting beneath it is on.
Then ask whoever runs SharePoint two questions. Is Restricted SharePoint Search enabled, and how many sites in the tenant are shared with Everyone except external users. The first answer tells you whether you have a January deadline, and the second tells you how big the real job is, because every one of those sites is somewhere Copilot will answer from until somebody fixes it.
Write down what you found and the date. If you have not done the sharing assessment, that is the place to start, and it is the part Copilot cannot do for you.
Want your Copilot tenant read against the actual settings? That is a £500 scoping review: your subprocessor toggles, sharing defaults, interim controls, DPA position and DPIA, every finding traced to Microsoft's own page. Written report in one week.
Sources, all read 5 September 2026: Microsoft Learn, "Data, Privacy, and Security for Microsoft Copilot" (dated 9 July 2026); "Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat" (29 May 2026); "Anthropic models in Microsoft Online Services" (2 September 2026); "Restricted SharePoint Search" (6 July 2026); "Restrict discovery of SharePoint sites and content" (27 July 2026); "Secure & Governed Data Foundation for Microsoft Copilot" (6 May 2026); "Configure a secure and governed foundation for Microsoft Copilot" (17 April 2026); "License Options for Microsoft Copilot" (19 May 2026); Microsoft 365 Message Center MC1395311 (18 June 2026). Data Privacy Framework register checked 5 September 2026.
Free download
Get the AI Vendor Due Diligence Checklist
The questions we work through before a client signs with an AI vendor, covering data handling, contracts and transfers, security and operations, model and product risk, and exit risk.
For engineers and technical leads assessing an AI vendor before integration.
- ·What personal data actually goes to the vendor, and whether it trains the model by default
- ·The DPA, the subprocessor chain, and the transfer mechanism if data leaves the UK or EEA
- ·Exit risk: whether data and logs can be exported, what lock-in exists, and your fallback if the vendor changes pricing or terms
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.
Frequently Asked Questions
Is Microsoft 365 Copilot GDPR compliant?
It can be run in a GDPR compliant way, and Microsoft's side of the arrangement is in good order: the Data Protection Addendum applies with Microsoft as processor, prompts and responses and anything read through Microsoft Graph are not used to train foundation models, and for EU customers Copilot is an EU Data Boundary service. The compliance problem sits on the customer's side. Copilot surfaces any content a user already has at least view permission on, so a tenant with loose SharePoint permissions has an access control failure that Copilot makes easy to find. Two admin settings, Anthropic models and web grounding, take processing outside the EU Data Boundary and need to be recorded if they are on.
Does Microsoft Copilot see everything in SharePoint?
It sees everything the signed-in user could already open. Microsoft's documentation says Copilot only surfaces organisational data to which individual users have at least view permissions, and that it uses the same access controls as the rest of Microsoft 365. The practical difference is discoverability. A file shared with Everyone except external users, or a site with broken permission inheritance and no owner, was technically open before Copilot arrived. Almost nobody found it. Copilot's index does.
Is Restricted SharePoint Search being retired?
Yes. Microsoft's own page says new enablement is blocked from 31 July 2026, and Message Center notice MC1395311 of 18 June 2026 gives 31 January 2027 as the retirement date with no extensions or exceptions, with the PowerShell cmdlets following on 28 February 2027. Microsoft's warning in that notice is that if no action is taken, restricted content may become discoverable after the retirement. The recommended replacement is Restricted Content Discovery applied site by site, and then fixing the underlying permissions so neither control is needed.
Is Copilot inside the EU Data Boundary?
For EU customers, yes, with two stated exceptions. Web search queries sent to Bing are outside the Boundary and outside the Data Protection Addendum, with Microsoft acting as an independent controller for them. Anthropic models used inside Copilot are, in Microsoft's words, currently excluded from the EU Data Boundary and, when applicable, in-country processing commitments. In the EU, EFTA and the UK those models are set to No users by default and an administrator has to turn them on.
What happens if an admin turns on Anthropic models in Copilot?
Two things, depending on which models. Standard Anthropic models run with Anthropic as a Microsoft subprocessor, so Microsoft's Product Terms and DPA still apply, but processing leaves the EU Data Boundary. The models Microsoft labels Anthropic models with Data Retention (Fable 5.0 and Mythos 5 at the time of writing) are different: Anthropic acts as an independent processor, Microsoft's DPA does not cover them, Anthropic stores most inputs and outputs for up to 30 days and flagged content for up to two years, and the administrator has to accept Anthropic's own commercial terms and data processing addendum at the toggle. That is a new processor relationship created by a checkbox, and it belongs in your records.
Start with a £500 scoping review
If you need GDPR documentation, AI Act work, or a compliant AI build, the first step is a written scoping review. You get a written report you can act on.
Related Articles
GDPR
ChatGPT / OpenAI DPA Explained (2026): What the Data Processing Agreement Covers, How to Sign It, and What It Leaves to You
OpenAI's Data Processing Addendum is the Article 28 contract that lets you run the OpenAI API on personal data and stay GDPR compliant. What the DPA actually covers (training, retention, sub-processors, transfers), the exact click path to execute it, and the controller duties it does not cover.
GDPR
GDPR-Compliant LLM APIs: OpenAI vs Anthropic vs Google (2026)
Which LLM API can you run on personal data and stay GDPR compliant: OpenAI, Anthropic, or Google? All three can be configured to comply on the right tier, and the differences are in the defaults: who trains on your data, the DPA, EU data residency, retention, and transfers. A side-by-side for 2026, plus where Mistral and self-hosting fit.
GDPR
Is the Gemini API GDPR Compliant? It Depends Which Gemini You Use (2026)
Google's Gemini has two front doors with very different data terms, and the GDPR answer turns on which one you use. The free Google AI Studio tier trains on your data and humans may read it. The paid Gemini API and Vertex AI do not train on your data, and Vertex AI gives you the Cloud Data Processing Addendum, EU data residency, and retention controls. Here is how to tell them apart and configure the compliant path: the DPA, residency, data minimisation, the DPIA, transfers, and what the EU AI Act adds.