Yes, in the ways most owners worry about: Microsoft doesn't use your prompts, Copilot's answers or the files it reads to train its models, and that content stays under your Microsoft 365 data protection terms. The real privacy risk sits inside your own business. Copilot can show each employee anything they already have permission to open.
That second point catches out small firms far more often than anything Microsoft does. Years of "share with everyone" folders, forgotten Teams channels and anyone-with-the-link files were harmless while nobody went looking. Copilot goes looking on every prompt. So the honest answer to "is it private?" is: private from outsiders by contract, and exactly as private internally as your permissions are tidy.
A naming note before the detail. Microsoft now calls the paid product Microsoft Copilot and the free one Microsoft Copilot Chat, although licences and admin screens may still say Microsoft 365 Copilot during the transition. Microsoft says the rename changes nothing about privacy or security. I'll use "Copilot" for the paid licence and "Copilot Chat" for the free one.
What Microsoft actually commits to, in plain words
Microsoft's own privacy documentation for Copilot, last updated in August 2026, makes a short list of promises. Each one matters for a different reason.
- No training on your content. Prompts, responses and data Copilot pulls from Microsoft Graph (the index of your mail, files, chats and calendars) aren't used to train the foundation models, including the ones Copilot runs on.
- Same terms as your other Microsoft 365 data. Prompts and responses are processed and stored in line with the contract you already have for Exchange, SharePoint and Teams, with Microsoft acting as your data processor under its Data Protection Addendum.
- No human abuse review. Azure OpenAI offers abuse monitoring that can involve people reading flagged content. Microsoft says its Copilot services have opted out of it.
- Permissions are respected. Copilot only surfaces content a user has at least view access to. If a file is encrypted with a sensitivity label, Copilot honours the usage rights that label grants.
- Feedback is optional and separate. If a user clicks thumbs down and sends feedback, Microsoft may use it to improve the product (not to train the foundation models). Admins can control whether staff can send feedback at all.
What the list doesn't promise matters just as much. Nothing in it stops a junior member of staff asking Copilot about partner pay if the spreadsheet is sitting in a site the whole firm can open. Microsoft's documentation says so directly: it tells you to use the permission models in SharePoint and Teams so the right people have the right access.
Four routes a Copilot prompt can take
When someone types a question, the prompt doesn't always stay in one place. Knowing the routes tells you which settings to check.
| Route | What travels | Which terms apply | Your control |
|---|---|---|---|
| Your own data (Graph) | The prompt plus snippets from mail, files and chats the user can open | Your Microsoft 365 contract and Data Protection Addendum | Permissions, sensitivity labels, restricted content discovery |
| Web search via Bing | A short generated search query, not the full prompt or your files | Separate Product Terms commitments; Microsoft is controller, and the Data Protection Addendum doesn't apply | The Allow web search in Copilot policy; each user's Web content toggle |
| Third-party models | Prompts sent to Anthropic's Claude models when a user or feature selects them | Microsoft's terms for standard Anthropic models; Anthropic's own terms for models labelled "with Data Retention" | AI providers operating as Microsoft subprocessors, in the admin centre |
| Agents | A query built from the prompt, the user's history and data they can reach | Whatever the agent's own privacy statement says | Integrated apps in the admin centre |
The web route deserves a closer look, because it's the one people misread. Microsoft says the query sent to Bing is a few words derived from the prompt, with the user's name, domain and tenant ID removed, and it isn't used to improve Bing, build advertising profiles or train models. But the query can still contain whatever words the prompt was about. Microsoft's own example shows a question about a named person turning into a Bing search for that name.
Picture a mortgage adviser typing: "What's public about the company run by my client [name], and does it affect her self-employed income application?" The search that goes to Bing could plausibly be "[company name] directors accounts". Stripped of identifiers, yes, but it still names the company. If your firm's rules say client names never leave your systems, either switch web search off for advice staff or teach them to ask the web question separately, without names.
The third-party model route is newer. Microsoft now offers Anthropic's Claude models inside Copilot, and in many regions they are switched on by default, while in others the default is off. Standard Claude models run with Anthropic as a Microsoft subprocessor under Microsoft's terms. Models marked "Anthropic models with Data Retention" are different: they're off until an admin opts in, and if you do, Anthropic stores most inputs and outputs for up to 30 days under its own terms rather than Microsoft's. For a firm with strict client contracts, that's a setting to decide on deliberately, not by default.
How oversharing surfaces in a 14-person law firm
Here's an illustration of the problem most firms actually hit. A small law firm has 14 staff: four partners, six fee earners, two trainees and two in admin. Years ago the office manager created a SharePoint site called Firm Admin and, to save time, gave access to "Everyone except external users". It holds the office procedures manual, but also a partner drawings spreadsheet and a folder of old disciplinary notes.
Nobody browsed there, so nobody noticed. Two weeks after the firm buys Copilot licences, a trainee asks a harmless-sounding question.
Prompt (trainee's account):
Summarise anything in our files about partner drawings or profit share
for last year.
Illustrative Copilot response:
Based on "Partner drawings 2025-26.xlsx" in the Firm Admin site, the
four partners drew a combined figure of ... The largest share went to ...
Sources: Partner drawings 2025-26.xlsx (Firm Admin > Finance)
Copilot did nothing wrong. The trainee always had access; Copilot just found the file in seconds. The fix took the office manager and the firm's IT support about half a day:
- Replaced "Everyone except external users" on Firm Admin with a Partners group, and moved the procedures manual to a separate, firm-wide Knowledge site.
- Applied a sensitivity label with encryption, restricted to partners, to the drawings spreadsheet and the disciplinary folder.
- Switched on restricted content discovery for the HR site, so its files stop appearing in Copilot results even for the people who can open them.
- Re-ran the same prompt from the trainee's account. Copilot now replied that it couldn't find relevant information.
The lesson: test from a junior account before you roll out, not after. For a fuller clean-up plan, see how to clean up SharePoint permissions before turning on Copilot.
Canary prompts to run from a junior account
A canary prompt is a test question designed to find content that shouldn't be reachable. Borrow a staff account with the lowest access level (with the person's agreement), or create a test user with the same group memberships, and run prompts like these:
1. List any files that mention salaries, pay rises or bonuses.
2. Summarise any documents about disciplinary action or grievances.
3. What do our files say about [partner or director name]'s pay?
4. Find spreadsheets containing bank account or sort code details.
5. Are there any documents about redundancies or restructuring?
6. Show me passwords, logins or access codes stored in our files.
7. Summarise client complaints received this year.
8. Which clients owe us the most money?
Record every answer that cites a file the account shouldn't see, with the file path Copilot quotes. That list is your fix list. In the law firm above, prompts 1, 2 and 3 all hit; prompt 6 found a "Wi-Fi and alarm codes" Word document in a general Teams channel, which surprised everyone.
What a clean result looks like (illustrative): "I couldn't find information about salaries in the files you have access to." What a partial fix looks like: Copilot no longer quotes the file but still summarises an email thread where someone pasted the figures. Emails and chats count too, so check mailboxes shared with the whole team.
Admin settings that change the privacy answer
Most of these take minutes once you know where they live. Menu names shift, so search the admin centre if a path has moved.
| Setting | Where | What it does | Sensible start for a small firm |
|---|---|---|---|
| Allow web search in Copilot | Cloud Policy service for Microsoft 365 | Turns Bing grounding on or off for everyone or chosen groups | Off for client-facing advice staff if names must never leave; on for others |
| AI providers operating as Microsoft subprocessors | Microsoft 365 admin centre, Copilot settings | Controls whether Claude models are available, and to whom | Leave standard models to your policy; keep "with Data Retention" models off unless there's a clear reason |
| Integrated apps (agents) | Microsoft 365 admin centre | Shows each agent's permissions, terms and privacy statement; lets you allow or block it | Allow only agents you've read the terms for |
| Feedback controls | Microsoft 365 admin centre | Whether users can send feedback (which may include content) to Microsoft | Allow, but tell staff not to include client material |
| Retention for Copilot interactions | Microsoft Purview | How long prompts and responses are kept before deletion | Match your email retention period |
| Restricted content discovery | SharePoint admin centre (SharePoint Advanced Management) | Keeps chosen sites out of Copilot results | HR, finance and partner sites |
One setting to leave alone unless you mean it: the privacy control for "connected experiences that analyse your content". Microsoft says turning it off removes Copilot from Word, Excel, PowerPoint, Outlook and OneNote entirely. Firms sometimes switch it off during a privacy scare and then wonder why Copilot has vanished.
The SharePoint Advanced Management features are worth knowing about because Microsoft makes a set of them available once at least one Copilot licence is assigned in your tenant. The data access governance reports list sites with broad sharing, which is a faster starting point than clicking through every site by hand.
What Copilot keeps about each conversation
Copilot stores each prompt and response, with citations to the sources used, as the user's Copilot activity history. That history is what lets someone reopen yesterday's chat. It's encrypted at rest and, like the rest, not used for model training.
- Users can delete their own Copilot activity history from the My Account portal.
- Admins can search it with Content search or eDiscovery in Microsoft Purview, and set retention policies for Copilot interactions.
- Web queries generated from prompts can be audited too, and in Copilot Chat users see the exact search terms in the citations for 24 hours.
This has a privacy upside and a governance catch. The upside: if a client asks what your firm put into AI about them, you can find out. The catch: prompts are now business records. A fee earner who types "draft a letter telling the client we missed the deadline" has created a searchable record of that admission. Tell staff to treat Copilot like email, not like a private notepad.
For meetings, where transcripts and recaps add another layer, see Copilot in Teams meetings: recaps, actions and privacy settings.
Free Copilot Chat and the paid licence carry different exposure
Both versions come under Microsoft's enterprise data protection when staff sign in with a work account, and neither trains on your content. The difference is how far each one can reach.
Copilot Chat, included with business plans at no extra cost, is grounded in the web and works on the file or Outlook message a user has open. It doesn't search across SharePoint by itself. The paid Copilot licence (Copilot Business is $21 per user a month on an annual plan, for organisations up to 300 users) reasons across mail, meetings, chats and files together. That reach is exactly what makes it useful and exactly what exposes oversharing.
So a firm can often run Copilot Chat safely before any clean-up, and should do the permission work before buying the paid licence. If you're still deciding between the two, Copilot Chat vs Microsoft 365 Copilot covers what each includes.
A realistic mistake worth warning staff about: someone installs the consumer Copilot app on their phone, signs in with a personal Microsoft account, and pastes in a client's email to get a quick reply drafted. None of the business protections above apply to that session, because it isn't your tenant. It usually shows up only when the person mentions it. Prevent it with a one-line rule ("work AI only through your work account") and by checking which account appears in the corner of the Copilot window during training.
A before-and-after of one overshared file
Sharing links cause as much trouble as site permissions. Here's the pattern with an illustrative client list at the same law firm.
Before: a fee earner shared "Client matter list 2026.xlsx" with a colleague months ago using a link that works for anyone in the organisation. Anyone inside the firm who ever received that link can open it, and Copilot can use it in their answers.
After: the link is removed, the file is shared with the two named colleagues who need it, and the default sharing link type for the tenant is changed to "Specific people". Copilot now cites the file only for those two.
Changing the default link type is one of the highest-value settings in the whole exercise, because it stops the problem recurring every time someone clicks Share in a hurry.
How long the privacy work takes, and what it costs
As a rough guide for a firm of 10 to 20 people, assuming your IT support or a capable office manager does the work:
- Canary prompt testing: about an hour.
- Reviewing site permissions and sharing links using the data access governance reports: two to four hours, depending on how many sites have grown up over the years.
- Labels, restricted content discovery and policy settings: one to two hours.
- Writing a half-page staff rule and running a 20-minute briefing: an hour.
Call it one working day. If you pay an IT provider at, say, $90 an hour, that's roughly $450 to $700, against a Copilot bill of $21 per user a month. For a firm that's about to give every member of staff a search engine over its own files, it's the cheapest insurance in the project. The Microsoft 365 Copilot readiness checklist puts these steps in order alongside licensing and training.
When Microsoft's promises aren't enough on their own
For most small businesses, Microsoft's terms plus tidy permissions answer the privacy question. A few situations need more than that:
- Client contracts that restrict subprocessors. Some professional clients list approved subprocessors. If Claude models are switched on, Anthropic is one. Check before you enable them, and ask your solicitor if the contract wording is unclear.
- Regulated advice firms. Mortgage advisers and financial planners often have record-keeping duties. Copilot prompts may count as records, so match Purview retention to what your compliance rules require.
- Special category data. Health, criminal records or similar information in HR files raises the stakes of any oversharing. Label and restrict those folders first.
- Staff monitoring worries. Microsoft says Copilot blocks inferences about an employee's performance, attitude or emotional state from their communications. That's a product safeguard, not permission to use Copilot for performance reviews.
If any of these apply, involve your data-protection adviser before rollout rather than after. And if your business is weighing Copilot against other assistants on privacy as well as cost, whether Microsoft 365 Copilot is worth it for a small business weighs the whole decision.
More questions about Copilot and your data
Can Microsoft staff read what my team types into Copilot?
Microsoft says its Copilot services have opted out of the abuse-monitoring programme that involves human review in Azure OpenAI, and prompts and responses are handled as your organisation's content under its data protection terms. Optional feedback that users choose to send is different: it can be used to improve the product, so admins should decide whether feedback is allowed.
If we switch off web search, does Copilot stay fully inside Microsoft 365?
Switching off the Allow web search in Copilot policy stops Copilot generating Bing queries, so answers draw on your organisation's data and the model's own knowledge. It also stops the Researcher tool searching the web. You lose current public information, so some firms leave it on and train staff never to ask about named clients.
Is the free Copilot Chat as private as the paid Copilot?
Both come under Microsoft's enterprise data protection when staff sign in with their work accounts, and neither trains foundation models on your prompts. The difference is reach: the paid licence can search mail, chats and SharePoint across everything the user can open, so it exposes oversharing much faster than the free version.
Can we stop Copilot using one sensitive SharePoint site?
Yes. Tighten the site's permissions first. If some people still need access but you don't want the content turning up in Copilot answers, restricted content discovery, one of the SharePoint Advanced Management features available once a Copilot licence is assigned, keeps that site out of Copilot results. Encrypting sensitivity labels are another option.
Further reads
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How the main AI assistants stack up on data-protection duties.
- What Is Prompt Injection and Should a Small Business Worry? — The attack that turns a harmless-looking email into instructions for Copilot.
- What to Check in an AI Vendor's Data Processing Agreement — What to read in the processing terms that sit behind these promises.
- Is Gemini Safe for Confidential Business Data in Workspace? — The same privacy question answered for Google Workspace.
- Can Solicitors Use ChatGPT Without Breaching Confidentiality? — Confidentiality duties for law firms using any AI assistant.
- Microsoft 365 Copilot Pricing: Business vs Enterprise Licences — Which Copilot licence you need before any of this applies.
- What to Check in an AI Tool's Privacy Policy and Terms — Seven checks for any AI tool's privacy policy and terms, the words to search for, and how ChatGPT, Claude, Gemini and Copilot compare.
- How to Stop AI Tools Training on Your Business Data — The exact training switches in ChatGPT, Claude, Gemini, Copilot and Perplexity, plus the hidden AI features most owners forget to check.
- Reusing Past Client Work With AI Without Leaking Client Data — How consultants and small firms turn old client reports into a reusable AI library: contract checks, three reuse tiers, sanitising, and access controls.
- Is It Safe for an Accountant to Use ChatGPT With Client Data? — Which ChatGPT plans an accounting practice can defend for client data, what never goes in, and the engagement-letter wording to add.
- Where Should a Small Manufacturer Start With AI? — Why a small manufacturer's first AI project belongs in the office, how to score the options, and a six-week RFQ pilot with real numbers.
- 10 Admin Tasks a Small Clinic Can Hand to AI This Month — Ten low-risk admin jobs a small clinic can give to AI in the next four weeks, each with a prompt, a sample output and the check to run.
- ChatGPT or Copilot for a Microsoft 365 Business? — Decide whether a Microsoft 365 team needs paid Copilot, ChatGPT or included chat, using a two-user cost and workflow trial.
- Copilot in Outlook: How to Triage Email and Draft Replies Faster — Prioritise, Summary by Copilot, Draft with Copilot and Coaching, set up properly. A photography studio's morning inbox shows the routine and the traps.
- Google Workspace vs Microsoft 365 for AI: Which Suits Your Business? — A side-by-side of Gemini in Workspace and Copilot in Microsoft 365: what's included, real annual costs for small teams, and a worked choice for a dry cleaner.
- Copilot in Excel: What It Can and Can't Do With Your Numbers — The Copilot pane's three modes tested on a pet shop's sales file, the margin formula it got wrong, and what to do with old COPILOT() cells.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Microsoft Learn: Data, Privacy, and Security for Microsoft Copilot (updated Aug 2026); Data, privacy, and security for web search in Microsoft Copilot and Microsoft Copilot Chat (Aug 2026); Anthropic models in Microsoft Online Services (Sep 2026); Microsoft Copilot Business FAQ; SharePoint Advanced Management documentation. Checked 27 September 2026.