Home / AI Service Directory / Microsoft 365 Copilot

Microsoft 365 Copilot

Microsoft · Chat assistant · US · www.microsoft.com/microsoft-365/copilot

Last verified 2026-09-15
Entry services/microsoft-365-copilot.yaml
Training on your data (default tier)
Not used to train foundation models
Retention
Follows the tenant's own retention policies
Data residency
EU Data Boundary supported, with stated exceptions

Vendor data-handling terms

Training on your data (default tier)
Not used to train foundation models

Applies to prompts, responses, and data accessed through Microsoft Graph under enterprise data protection, which covers Microsoft 365 Copilot and Microsoft 365 Copilot Chat for signed-in work accounts.

Consistent with our other Copilot offers, the prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation models .
checked 2026-09-15
Microsoft Learn, Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat
Retention
Follows the tenant's own retention policies

Copilot interactions are stored in the user's mailbox and governed by the organisation's retention and audit settings, under the same contractual terms as Exchange and SharePoint data.

With EDP, prompts and responses are protected by the same contractual terms and commitments widely trusted by our customers for their emails in Exchange and their files in SharePoint. / Copilot respects your identity model and permissions , inherits your sensitivity labels , applies your retention policies, supports audit of interactions, and follows your administrative settings.
checked 2026-09-15
Microsoft Learn, Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat
Data residency
EU Data Boundary supported, with stated exceptions

Web search queries are outside the EU Data Boundary, and Anthropic models offered inside Copilot are excluded from it and from in-country processing commitments.

Our commitments to privacy include support for the General Data Protection Regulation (GDPR) , the EU Data Boundary [3] , ISO/IEC 27018 , and our Data Protection Addendum . / [3] The EU Data Boundary doesn't apply to web search queries. / In addition, Anthropic models are currently excluded from the EU Data Boundary and when applicable, in-country processing commitments.
checked 2026-09-15
Microsoft Learn, Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat
Data processing agreement
Covered by the Microsoft Data Protection Addendum
Our commitments to privacy include support for the General Data Protection Regulation (GDPR) , the EU Data Boundary [3] , ISO/IEC 27018 , and our Data Protection Addendum .
checked 2026-09-15
Microsoft Learn, Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat

Domains and endpoints

observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.

HostRoleSource
substrate.office.comapiobserved
m365.cloud.microsoftappvendor-documented
copilot.cloud.microsoftappvendor-documented

Assessment

Work accounts with enterprise data protection: low

Reasoning: No foundation-model training on prompts or responses, the tenant's own retention, labels, permissions, and audit apply, and the service sits under the existing Microsoft DPA and EU Data Boundary. The two stated exceptions matter for EU deployers: web search queries leave the boundary, and any Anthropic model selected inside Copilot is outside it. The exposure that remains is what Copilot can reach through Graph, which is a permissions question, not a vendor-terms question.

Flags: EU Data Boundary exceptions (web search, Anthropic models) · Assessed 2026-09-15. The assessment is Unseen's; the terms above are the vendor's.

Changelog

  • 2026-09-15Documented. Training, retention, residency, and DPA terms verified against Microsoft Learn's enterprise data protection page.
  • 2026-09-15Listed from the Unseen catalogue with observed domains.

Corrections

Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.

Edit on GitHub