Microsoft Copilot is GDPR compliant for your prompts and answers, and it is not for its web search. That single split is the whole answer, and Microsoft states both halves itself. Prompts, responses and the Microsoft Graph data behind them are covered by the Microsoft Products and Services Data Protection Addendum, Microsoft acts as your processor, and none of it trains foundation models. The moment Copilot looks something up on the web, a different set of rules applies: the DPA does not cover those queries, the EU Data Boundary does not apply to them, and Microsoft is no longer your processor but an independent controller.

And web search is on unless somebody switched it off.

6Copilot variants with different data protection
0DPA coverage for generated web search queries (Microsoft Learn)
AnDefault state of web search when no policy is set
7Points the DSK found lacking in the DPA, Nov 2022

Which Copilot Are You Actually Asking About?

Most of the confusion around this question is not legal, it is naming. Microsoft sells at least six things called Copilot, their data protection differs, and in 2026 Microsoft renamed the two most important ones: Microsoft 365 Copilot is now Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. Licences and screens still show the old names during the transition, so the name in your tenant is not a reliable signal.

Work out which row you are in before you read any further, because the answer changes completely between the first and the last one.

VariantDPA appliesTrains modelsEU Data BoundarySuitable for personal data
Copilot (free, consumer account) NoPossible No No
Copilot Pro (consumer subscription) NoPossible No No
Microsoft Copilot Chat (Entra ID, commercial) Yes NoYes, except web searchYes, configured
Microsoft Copilot (former M365 Copilot licence) Yes NoYes, except web searchYes, configured
Copilot Studio (self-built agents)Yes, for the platform NoDepends on connectorsPer agent assessment
GitHub CopilotSeparate termsPlan dependentSeparate assessmentSeparate assessment

The two consumer rows are the ones that quietly cause incidents. An employee who opens copilot.microsoft.com with a private account, or the Copilot sidebar in Edge, is outside every commercial commitment you signed. Whether that is happening in your company is an empirical question, not a policy question.

Find out which AI tools your people already use

An anonymous survey shows which tools, accounts and use cases are already in the building, before you write a policy against the wrong ones.

Start the free check

What Is Covered: Prompts, Answers, Your Permissions

For the commercial rows, the picture is genuinely solid, and it is worth saying so plainly because the alarmist version of this article is not accurate. According to Microsoft Learn, prompts and responses carry the same contractual commitments as your mail in Exchange and your files in SharePoint: encryption at rest and in transit, tenant isolation, GDPR support, ISO/IEC 27018, and the DPA with Microsoft as processor. Copilot inherits your identity model, your permissions, your sensitivity labels and your retention policies, and interactions are auditable.

The EU Data Boundary has been fully implemented since February 2025, and German supervisory practice has moved with it: the seven points the Datenschutzkonferenz raised against the addendum in November 2022 have largely been addressed, as dr-datenschutz.de sets out. Prompts, responses and Graph data are also not used to train foundation models.

The Web Search Gap, in Microsoft's Own Words

Here is the part that almost no guide to this question states clearly. When Copilot decides that web information would improve an answer, it writes a short search query and sends it to the Bing search service. Microsoft's documentation is unambiguous about what that means legally:

> The Microsoft Products and Services Data Protection Addendum (DPA) doesn't apply to the use of generated web search queries. Also, HIPAA compliance and the EU Data Boundary don't apply to generated search queries.

And about the role: Bing operates separately from Microsoft 365, the queries fall under the Microsoft Services Agreement between each user and Microsoft, and Microsoft acts as a data controller there, not as your processor. Microsoft does add commitments in the Product Terms: the queries are not used to improve Bing, not used for advertising profiles, not shared with advertisers, not used to train models, and treated as confidential. Those are real, and they are still controller commitments rather than your AVV.

The obvious objection is that a three-word search query cannot carry much. Microsoft answers that objection itself, in its own example table. One row reads:

> Prompt: Who is my manager and what public information is available about them? — Generated search query: [Manager name]

So the query is not always harmless. It can be a named employee, derived from your Graph data, sent outside the DPA and outside the EU Data Boundary. The query can also be informed by the contents of a document the user has open or explicitly references. Microsoft does exclude the whole prompt, whole files, whole web pages and any Entra ID identifiers, and strips user and tenant identifiers before sending. What remains is still a personal datum in the cases that matter to a works council.

Inside your AVV and the EU Data Boundary

  • Prompts and responses

  • Microsoft Graph data behind an answer

  • Your permissions, labels and retention rules

  • Auditability via Purview and eDiscovery

  • No training on your data

Outside both

  • Generated web search queries sent to Bing

  • Microsoft as independent controller, not processor

  • Anthropic models used inside Copilot

  • Third-party agents with their own terms

  • Anything done in a consumer Copilot account

Easy to miss, and specific: Microsoft's own footnote states that Anthropic models are currently excluded from the EU Data Boundary and, where applicable, from in-country processing commitments. If somebody in your tenant enabled Anthropic models in Copilot, that is a second route out of the boundary, independent of web search.

How to Turn Web Search Off, Exactly

There are two controls, one for admins and one for users, and the default matters more than either. If nobody configures the admin policy, web search is available. Microsoft's US government clouds get the safe default and turn it off; EU commercial tenants do not. So the absence of a decision is a decision here.

1

Open Cloud Policy service for Microsoft 365

The setting lives only there, not in the Copilot admin surface people look at first.

2

Configure the policy Allow web search in Copilot

It applies to both Microsoft Copilot and Microsoft Copilot Chat, and it can target the whole tenant or specific user groups.

3

Pick one of the three states deliberately

Enabled everywhere, disabled everywhere, or disabled in Work mode while Web mode and Copilot Chat keep it. The middle option is the one most regulated teams want.

4

Know what the middle option costs

Choosing disabled in Work mode also disables web search in Researcher and Cowork. Decide that consciously rather than discovering it later.

5

Do not reach for optional connected experiences instead

Setting Allow the use of additional optional connected experiences in Office to disabled does stop web search, but it also restricts many other Microsoft 365 features. It is a sledgehammer for this nail.

6

Tell users about their own toggle

If the admin allows web search, the Web content toggle is on by default per user. Users can switch it off under Settings, Personalization, Advanced, Web search, and the choice persists across devices.

7

Verify instead of assuming

Web search query citations show users the exact queries sent, and admins can see them next to prompt and response in Purview DSPM for AI, or audit and eDiscovery them. Citations live 24 hours in the thread; the audit trail does not expire that fast.

Do You Need a DPIA, and Does the Works Council Have to Agree?

Usually yes to both, and that is independent of how well Microsoft's contracts read. Copilot reaches across mailboxes, chats and file storage on behalf of a person, which is exactly the profile the Datenschutzkonferenz lists as requiring a data protection impact assessment under Art. 35 GDPR. The trigger is the breadth of access and the possibility of new processing without a clear purpose limitation, not the vendor.

Co-determination follows the same fact pattern. In Germany, § 87 Abs. 1 Nr. 6 BetrVG covers technical systems suitable for monitoring behaviour or performance, and a tool that can summarise who wrote what and when is suitable on its face. In Austria the equivalent is § 96a ArbVG. Our works council co-determination guide and the rollout playbook go through the sequence; the short version is that involving the works council after the pilot is more expensive than involving it before.

Check your AI governance before the DPIA

A free assessment that walks the same ground a supervisory authority would: access scope, purpose limitation, documentation, deletion. It gives you the gaps in writing.

Start the free check

The Bigger Risk Is Not the Contract, It Is Your Permissions

Copilot respects your permissions, which sounds reassuring until you notice it is a statement about Copilot and not about your permissions. In most organisations, SharePoint and OneDrive have accumulated years of broad shares, and a person who could theoretically have found a salary list through search will now be handed it in a summary. Nothing was breached; the tool simply made existing over-permissioning usable.

That is not a GDPR question about Microsoft, it is an Art. 32 question about you, and it is the part of a Copilot rollout that actually takes time. We wrote it up separately in Copilot oversharing and the permissions problem. If you want the audit view of the same ground, AI agent audit trails and RBAC covers what a reviewer will ask for.

If the Answer for Your Case Is No

There are cases where the honest conclusion is that Copilot does not fit: a works council that will not accept a monitoring-capable tool across all mailboxes, a sector that needs every processing step inside the EU without carve-outs, or a company that simply does not have the Microsoft 365 licensing the commercial commitments depend on. In those cases the question stops being about Microsoft and becomes a question about your architecture: which knowledge should the assistant see, who decides that, and where does it run.

That is the ground we build on with Teamo AI, and there is a direct comparison in Teamo AI vs Microsoft Copilot plus a broader field in Microsoft Copilot alternatives. If your driver is residency rather than features, European AI data sovereignty is the better starting point, and the EU ChatGPT alternative comparison puts fifteen options side by side.

The short version

The short version. Commercial Copilot is GDPR-capable for prompts and answers, with the DPA, no model training and the EU Data Boundary behind it. Two carve-outs are stated by Microsoft itself: generated web search queries, where the DPA and the boundary do not apply and Microsoft is an independent controller, and Anthropic models, which are currently outside the boundary. Web search is available unless an admin sets Allow web search in Copilot in Cloud Policy. Consumer Copilot and Copilot Pro are not suitable for personal data at all. A DPIA under Art. 35 and works council involvement under § 87 Abs. 1 Nr. 6 BetrVG (§ 96a ArbVG in Austria) are the normal case, not the exception. And the work that actually takes time is your own permissions, not Microsoft's contract.