Data Protection & Confidentiality Assurance Statement
Microsoft 365 Copilot is an enterprise-grade AI capability integrated into Microsoft 365. Here is what you need to know about how your data is protected.
Overview
Microsoft 365 Copilot is an enterprise-grade AI capability integrated into Microsoft 365 (including Outlook, Word, Excel, Teams, and SharePoint). It operates entirely within the customer’s Microsoft 365 tenant and is governed by the same security, compliance, and contractual protections as all Microsoft 365 services.
Enterprise security & data isolation
Microsoft 365 Copilot is designed for commercial and regulated environments and includes: processing within the organisation’s Microsoft 365 tenant, logical data isolation between customers (no cross-tenant access), encryption of data both in transit and at rest, and enforcement of existing Microsoft 365 identity and access controls. Copilot only accesses information that a user already has permission to view — it does not grant or elevate access to data.
Use of data & AI model training
Microsoft provides a contractual assurance that customer data is not used to train foundation AI models and prompts entered into Copilot are not used to improve external models. Responses generated by Copilot are treated as customer data. This ensures that all firm data, including sensitive and confidential legal information, remains private and is not incorporated into any shared or public AI system.
Confidentiality & data handling
All data processed by Copilot remains within Microsoft’s secure cloud environment, is governed by the same permissions, policies, and controls as existing Microsoft 365 data, and is subject to the organisation’s existing security configuration including role-based access control, sensitivity labels, Data Loss Prevention (DLP) policies, and retention and compliance policies. Copilot operates as an extension of Microsoft 365 and does not introduce new data exposure pathways.
Data Processing Agreement (DPA)
The use of Microsoft 365 Copilot is covered under Microsoft’s standard contractual framework, including Microsoft Product Terms and the Microsoft Data Protection Addendum (DPA). Under these agreements: Microsoft acts as a data processor, the customer retains full ownership and control of its data, and Microsoft is contractually bound to use customer data only to provide the service. These terms align with globally recognised standards including GDPR and ISO 27018.
Compliance & regulatory alignment
Microsoft 365 Copilot inherits Microsoft 365’s compliance framework, including GDPR-aligned data protection commitments, enterprise-grade audit logging and monitoring, and support for legal hold, eDiscovery, and retention requirements. This makes the platform suitable for use in regulated industries including legal services, where confidentiality and privilege are critical.
Summary assurance
Based on Microsoft’s published architecture and contractual commitments, we confirm: enterprise-grade AI platform within Microsoft 365, no use of customer data for AI model training, strong data isolation and encryption controls, full alignment with Microsoft 365 security and compliance policies, and covered by Microsoft’s Data Protection Addendum (DPA).
Disclaimer
This document is based on Microsoft’s published documentation and contractual commitments as of May 2025. Customers should ensure their own Microsoft 365 environment is appropriately configured (e.g. permissions, security policies) to meet internal compliance requirements.