Microsoft Copilot Data Protection, Configuring the M365 Tenant Properly
Introduction
Microsoft 365 Copilot has been available since November 2023 and is bookable for SMEs in the M365 Business licence universe since March 2024. The central marketing message, "Copilot does not train on your data", is correct but incomplete. What actually happens, and whether it is compliant with DSG and GDPR, depends on tenant configuration, sensitivity labels, permission cleanup, and, importantly, the understanding that Copilot does not remove existing permission gaps but exposes them. A 50-employee company with "permissive" SharePoint permissions discovers, after Copilot rollout, that the payroll list is suddenly searchable by any employee via a prompt.
This article delivers the tenant configuration checklist:
- What Copilot is, the three components grounding, LLM, output
- EU Data Boundary and tenant storage location
- Sensitivity labels and Microsoft Information Protection (MIP)
- Permission cleanup as a precondition ("oversharing")
- DLP for Copilot, available in Purview since 2025
- Audit logging, data residency and retention
- Mandatory steps before rollout: DPIA, DPA, record of processing
Legal basis: DSG Art. 6, 8, 12, 19, 22; GDPR Art. 6, 28, 32, 35; Microsoft Online Services Terms including DPA (as of 2024-09), Microsoft Product Terms, supplementary "Microsoft Copilot for Microsoft 365 Privacy and Security Overview" (continuously updated).
The three Copilot components
Copilot consists procedurally of three steps. First: grounding. A user's prompt is enriched via Microsoft Graph with organisation-specific content, emails, Teams messages, SharePoint documents, OneDrive files the user is authorised to access. Second: LLM inference. The enriched prompt is sent to an Azure-hosted OpenAI model within the M365 service boundary. Third: output processing. The response is checked through DLP, sensitivity label and content safety filters before being shown.
Important for the data protection assessment: no step leaves the M365 tenant to an external OpenAI endpoint. The LLM runs in Azure under Microsoft contract terms (not OpenAI contract terms). Prompts and outputs are not used for model training, neither by Microsoft nor OpenAI. This is contractually secured in the Microsoft Product Terms and the DPA. What happens to grounding: Microsoft Graph accesses the organisation's data while respecting existing permissions. If a user is allowed to access a file, Copilot can use its content in the prompt.
EU Data Boundary and tenant location
For EU tenants (defined by the tenant's "sign-up country" in the EU/EFTA and EEA), Microsoft guarantees the EU Data Boundary, processing of customer data and pseudonymised personal data within the EU. Switzerland: Microsoft operates two Swiss data centre regions (Zurich, Geneva) selectable as "Switzerland" region for M365. Swiss tenants can keep customer data in Switzerland. Important: Copilot processing has been explicitly integrated into the EU Data Boundary since May 2024; Swiss tenants benefit via the Switzerland region.
Practical relevance: anyone operating a US tenant (sign-up country US) does not get the EU Data Boundary. Swiss subsidiaries of global groups should check whether their tenant is in the Switzerland region or the US region, this is a question of group architecture, not of choice at the M365 setup time. Tenant migration is possible but laborious (several months, with downtime in individual services). Before Copilot rollout, tenant geography and data residency conditions should be checked.
Sensitivity labels and MIP
Microsoft Information Protection (MIP) allows assigning sensitivity labels to documents (e.g. Public, Internal, Confidential, Restricted) that control encryption, watermarks, access restrictions and, since 2024, Copilot-specific rules. A "Confidential" label with encryption excludes that Copilot uses the content of such a labelled file in grounding, unless the user has "co-author" rights. A "Restricted" label can prohibit Copilot grounding altogether.
Precondition is a completed label strategy: the company must have defined its data classification, created labels in the compliance console, applied them to existing content via auto-labelling policies (pattern-based), and trained users to set labels manually. Without MIP strategy, Copilot is legally "blind", every file a user has access to is material. With MIP strategy, Copilot becomes a controlled tool. MIP rollout typically takes 3–6 months for a 200-employee firm, it must be completed before the Copilot rollout, not in parallel or after.
Permission cleanup
Copilot is transparent against existing permissions, and therefore against existing permission errors. "Oversharing", too-broad default permissions in SharePoint and OneDrive (e.g. "Everyone except external users" on an entire site), leads Copilot to include content as relevant that the prompting user formally may read but would never actively have found. Classic example: the payroll list ends up by accident in a generally permissioned HR site. Copilot answers the question "Who earns the most in the company?" with precise figures.
Before rollout, three permission exercises are required. First: use Microsoft 365 Admin Center / Microsoft Graph Data Connect or third-party tools (SquaredUp, AvePoint, Sharegate) to identify sites/libraries with "Everyone" permission and correct them. Second: standardise sharing links in OneDrive to "Specific people" or "Only people in your organisation". Third: enable Restricted SharePoint Search so that Copilot only includes explicitly approved sites (Restricted Mode available since spring 2025). These three exercises are not "nice-to-have", they are the precondition for lawful Copilot use.
DLP, audit logging, retention
Since 2025 Microsoft Purview explicitly supports DLP rules for Copilot prompts and outputs. Rules can prevent Copilot from using content from specific sites, prevent outputs from containing sensitive patterns (Swiss social security numbers, credit cards, IBAN), or prevent prompts with certain keywords from being accepted at all. Configuration via Microsoft Purview Compliance Center, activation per location and user group. Important: DLP rules only apply when actively configured, the default configuration is "no restriction".
Audit logging: Copilot interactions are captured in the Unified Audit Log (Microsoft Purview Audit), who issued which prompt when, which files were used in grounding, which sensitivity labels were involved. Retention by default 90 days (E3) or 1 year (E5), extendable to 10 years with the audit add-on. Of relevance for Swiss companies under FINMA supervision: audit data is in the EU Data Boundary; Switzerland region stores locally. For the DPIA and the record of processing under Art. 12 DSG, the audit configuration must be documented.
Mandatory steps before rollout
DPIA: introducing Copilot is a new processing activity that typically carries high risk (processing of extensive personal data, novel technology) and therefore requires a DPIA under Art. 22 DSG / Art. 35 GDPR. Contents: description of the processing, necessity/proportionality, risks for data subjects, technical and organisational measures (sensitivity labels, DLP, permission cleanup, training).
DPA: the Microsoft DPA automatically counts as a processing agreement within the meaning of Art. 9 DSG / Art. 28 GDPR, it is part of the Online Services Terms. Swiss public bodies and FINMA-regulated firms should supplement the DPA with a Swiss-specific data processing addendum that incorporates standard contractual clauses and, since 2023, the Swiss annex. Record of processing under Art. 12 DSG: separate entry for Copilot with purposes (productivity, content creation, knowledge search), data categories, recipients (Microsoft), retention, TOMs. Update the staff regulations and the AI policy accordingly.
How SIDD supports you
SIDD runs Copilot rollouts end to end: from the initial DPIA, MIP strategy, permission cleanup, DLP configuration through to training and ongoing audit. We combine legal compliance expertise with M365-specific technical know-how so that the configuration not only meets regulatory text but also operationally holds up. For FINMA-regulated clients we also accompany the FINMA SN 08/2024 requirements on AI outsourcing.
More on our AI and cloud compliance offering at Swiss data protection adviser and for the parallel ISMS view at ISMS & ISO 27001. Further reading: ChatGPT at work, AI policy template and EU AI Act guide. To plan a concrete rollout, request a quote via our quote form or reach us via the contact form.
