TL;DR: Microsoft 365 Copilot on commercial plans does not train on your company data, but the consumer Copilot product does. Most governance problems for small teams come from employees using the wrong tier, or from overly permissive SharePoint access that lets Copilot surface data it shouldn't.
Microsoft Copilot is now embedded in Word, Excel, PowerPoint, Outlook, Teams, and the Microsoft 365 admin portal. For small teams running on M365, it is increasingly hard to avoid. And the governance questions it raises are not fully answered by Microsoft's own documentation, which tends to collapse important distinctions between product tiers.
This guide covers the specific data handling questions your team needs answered before enabling Copilot, the risks that are unique to small teams, and a practical checklist for getting your governance in order.
Does Copilot train on your company data?
This is the first question every governance-conscious team asks, and the answer depends entirely on which Copilot product you are using.
Microsoft 365 Copilot (commercial plan): No. Microsoft explicitly commits that your data is not used to train foundation models. The program governing this is called Commercial Data Protection. Under this commitment, your prompts, responses, and the M365 data Copilot accesses are not used to improve AI models for other customers or for Microsoft's general model training pipeline.
Copilot at copilot.microsoft.com (consumer/free): Different terms apply. The consumer Copilot, accessible at copilot.microsoft.com with a free Microsoft account or a personal account, can use your interactions for service improvement, which may include model training. Microsoft's terms for the consumer product are materially weaker than the commercial terms.
Copilot Pro (individual subscription): Copilot Pro gives individual users access to GPT-4 class models with some M365 integration. It is closer to the consumer product in its data terms than to the enterprise M365 Copilot add-on. Review the terms carefully if anyone on your team is using a personal Copilot Pro subscription.
The governance risk for small teams is straightforward: employees may be using the consumer Copilot because it is free and they do not realize their company has an M365 commercial plan. They type work-related prompts (client names, confidential project details, financial information) into copilot.microsoft.com, and those inputs are processed under consumer terms, not your M365 commercial DPA.
Where does your data go?
For M365 commercial customers, Microsoft processes Copilot data within your Microsoft 365 tenant boundary. Your prompts and the M365 data Copilot retrieves to answer them are not sent to external third parties for processing. Microsoft's AI infrastructure processes the request, and the response is returned to you within the same tenant boundary that governs the rest of your M365 data.
This is meaningfully different from sending data to a separate third-party AI vendor. Your M365 DPA already covers this processing.
EU Data Boundary: This is where things get more specific for European teams. Microsoft has a program called the EU Data Boundary, under which they commit to storing and processing EU customer data in the EU and EFTA countries. For Copilot, Microsoft has extended EU Data Boundary coverage to include Copilot interactions for enrolled customers.
However, there are gaps. Not all data types are covered by the EU Data Boundary by default. Some diagnostic and operational data, telemetry, and support-related data may still be processed or accessed from outside the EU. Microsoft publishes documentation on what is and isn't in scope. If you are in the EU and data residency is a compliance requirement, verify your specific tenant's EU Data Boundary enrollment status in the admin center; it is not automatic.
DPA status: what you already have
Microsoft provides a Data Processing Agreement for all M365 commercial customers through their standard Product Terms. Specifically, the Microsoft Products and Services Data Protection Addendum (DPA) covers Copilot as part of M365 services. You do not need to negotiate a separate DPA or request one separately.
This is an advantage over many AI tool vendors where DPA access requires an enterprise contract or a specific negotiation. With M365, the DPA is part of your standard commercial agreement.
The DPA covers the standard GDPR controller-processor relationship. Microsoft acts as a data processor for your M365 data, including Copilot interactions. You remain the data controller. Standard Contractual Clauses for international transfers are also included.
For small teams on M365 Business Basic, Business Standard, or Business Premium plans, this coverage applies. You do not need an Enterprise Agreement to have DPA coverage for Copilot.
The real governance risk: what Copilot can access
The data training question gets most of the attention, but the more immediate governance risk for small teams is access scope. Copilot can retrieve and surface any M365 content that the signed-in user has permission to access. That includes:
- SharePoint sites and document libraries
- Teams messages and channel conversations
- Teams meeting transcripts (if recording and transcription are enabled)
- Outlook emails and calendar data
- OneDrive files
- Data from connected apps via Microsoft Graph
Copilot does not have access beyond what the user can access through normal M365 permissions. It does not bypass permission boundaries. But it makes accessing and synthesizing that data dramatically faster and easier, which means that any permissions that were technically permissive but practically obscure become suddenly very surfaceable.
In a small team setting, SharePoint permissions are often set loosely. Everyone has access to everything because it is easier to manage that way. With Copilot, a user can now type "summarize the last six months of conversations about the acquisition" and Copilot will retrieve and summarize Teams messages, emails, and documents about that topic, pulling from any SharePoint site, Teams channel, or mailbox the user can access.
This is the governance gap. The AI does not create a permission problem, but it dramatically amplifies the consequences of existing permission problems.
Tier comparison: Copilot commercial vs consumer vs free
| Feature | M365 Copilot (commercial) | Copilot Pro (individual) | Copilot (consumer/free) |
|---|---|---|---|
| Trains on your data? | No (Commercial Data Protection) | Partially; review terms | Yes, may be used for improvement |
| Processed in your tenant? | Yes | No | No |
| DPA available? | Yes, included in M365 terms | Limited | No |
| GDPR coverage? | Yes, via M365 DPA | Limited | No enterprise terms |
| EU Data Boundary eligible? | Yes (must enroll) | No | No |
| M365 data access? | Full (via Microsoft Graph) | Limited integration | No enterprise M365 access |
| Minimum plan required | M365 Business + Copilot license | Personal Microsoft account | Free Microsoft account |
The difference between the commercial product and the consumer product is not a matter of features; it is a matter of of data handling. Treating them as the same product for governance purposes is the mistake to avoid.
Key risks for small teams
Risk 1: Employees using the consumer Copilot for work. Someone on your team discovers copilot.microsoft.com or the Copilot mobile app on a personal Microsoft account and uses it to draft work emails, summarize reports, or ask questions about client projects. They think they are using a Microsoft product covered by your company's M365 agreement. They are not.
Risk 2: SharePoint permissions not scoped to need. If your SharePoint has broad "everyone in the org" permissions on sensitive sites (HR documents, financial projections, M&A materials), Copilot will surface that content for any user who queries it. The fix is not to disable Copilot; it is to fix the SharePoint permissions that should have been fixed anyway.
Risk 3: Teams meeting transcripts accessible beyond the meeting. If Teams transcription is enabled, meeting transcripts are stored in SharePoint. If those SharePoint locations are broadly accessible, Copilot can retrieve and summarize them for any user with access. Review who has access to meeting transcript storage locations.
Risk 4: Copilot enabled for all users without a usage policy. Turning on Copilot org-wide without a policy on what types of data and queries are appropriate creates exposure. Employees may not know that asking Copilot about a confidential project is functionally equivalent to emailing the project documents to an assistant, except the assistant has access to everything else in your M365 tenant too.
Governance checklist
Work through these steps before enabling or expanding Copilot access in your team:
-
Verify your M365 plan tier. Confirm your subscription includes M365 commercial licensing, not personal or consumer plans. In the Microsoft 365 admin center, go to Billing, then Licenses.
-
Audit who has Copilot licenses assigned. Copilot requires a separate license in addition to M365. In the admin center, check which users have Copilot licenses active. Limit Copilot access to users who have been briefed on appropriate use.
-
Check EU Data Boundary enrollment (EU teams only). In the M365 admin center, go to Settings, then Org settings, then Data location. Verify your tenant's data residency commitments. Enroll in the EU Data Boundary program if you are not already enrolled.
-
Run a SharePoint permissions audit. Export SharePoint site permissions and review which sites have "everyone" or "all authenticated users" access. Scope down access on sensitive sites before enabling Copilot for those users.
-
Review Teams transcription settings. Decide whether Teams meeting transcription should be on by default and where transcripts are stored. Audit who has access to those SharePoint locations.
-
Block consumer Copilot access on corporate devices (if needed). If you have device management via Intune, you can restrict browser access to copilot.microsoft.com for corporate accounts. At minimum, communicate to your team which Copilot product is approved for work use.
-
Add Copilot to your AI acceptable use policy. Your policy should specify which Microsoft Copilot product is approved, what data types should not be used as Copilot prompts, and the expectation that Copilot interactions may surface confidential data.
-
Review your DPA. Confirm your M365 commercial agreement is current. The Microsoft Products and Services DPA is updated periodically. Download the current version from the Microsoft Trust Center and check the date.
For a broader view of how Microsoft 365 Copilot compares to Google Workspace's AI tools on compliance criteria, see Microsoft 365 Copilot vs Google Workspace AI compliance.
If you are tracking DPAs across multiple AI vendors, the AI vendor DPA tracker 2026 has a running comparison. For the broader question of AI assistants and GDPR, see the GDPR-compliant AI assistants comparison 2026.
Teams dealing with AI in their meeting workflows should also read AI meeting transcription data leak compliance 2026 for the specific risks around Teams transcription and third-party tools like Otter.ai and Fireflies.
Related reading
- AI data privacy for small teams GDPR CCPA
- Shadow AI governance tools visibility tech teams
- AI tool register template for small teams
- AI coding tools governance policy GitHub Copilot Cursor
- ChatGPT team vs enterprise compliance 2026
- ChatGPT vs Claude vs Gemini enterprise compliance 2026: the complete c
- OpenAI API governance and data privacy for developers 2026
- Notion AI vs Microsoft 365 Copilot: Compliance for Small Teams
