> Quelle: https://souverana.ch/en/insights/microsoft-copilot-datenschutz/
> Sprache: en

# Using Microsoft Copilot safely: what data protection allows

Microsoft closes almost every contractual gap, except for web search. What Swiss companies need to check on Copilot and Azure OpenAI.

Analysis · Published 21 Jul 2026 · Updated 24 Aug 2026 · Joel Barmettler

## Is Microsoft Copilot fit for data protection?

**Yes, as long as Copilot does not search the web. Under the usual business-customer contracts (Microsoft Customer Agreement, DPA?), Microsoft 365 Copilot and Azure OpenAI Service are usable for professional secrecy too, with the necessary addenda. As soon as Copilot draws on Bing web search, a different contractual framework applies, one that barely guarantees confidentiality any more. And the user does not control what gets passed to the search.**

**In brief**

-   Do not rely on Microsoft’s confidentiality assurance for web search. It is not phrased with the binding contractual term and, in doubt, does not apply.
-   If you want to turn off web search, budget time for training. On the add-on licence, the switch sits hidden in the context menu and must be set separately for every query.
-   If you buy through a reseller, you have no way out. The opt-out from manual abuse monitoring is open today only to customers Microsoft manages directly.
-   Anyone wanting out of Copilot lock-in finds the way out in the same house. Azure AI Foundry also hosts open models such as Llama or DeepSeek.
-   When coding, clarify the retention period. GitHub Copilot keeps data from active accounts indefinitely unless your contract states otherwise.

The Zurich law firm VISCHER writes in its market overview from July 2026 that it cannot understand why Microsoft is unable to offer a data-protection-compliant solution for web search, the way competitor Google does. VISCHER is a law firm. The legal assessment is theirs; the architecture assessment that follows is ours.

This is the fourth part of our “Provider Data-Protection Check” series, following the same framework as the others: contracts, data residency, professional secrecy, ways out.

Series · Provider Data-Protection Check

1.  1[Is ChatGPT GDPR-compliant? What OpenAI's contracts cover](/en/insights/chatgpt-dsgvo-konform/)
2.  2[Anthropic Claude and Swiss data protection: what to check](/en/insights/anthropic-claude-datenschutz/)
3.  3[Google Gemini & data protection: what SMEs need to know](/en/insights/google-gemini-datenschutz/)
4.  4Using Microsoft Copilot safely: what data protection allowsYou are reading this part
5.  5[Proton Lumo: what privacy-friendly AI looks like](/en/insights/proton-lumo/)

## What VISCHER takes issue with in Copilot and Azure OpenAI

Copilot comes in many editions; like VISCHER, we focus on the two relevant business variants: Microsoft 365 Copilot Chat, included automatically in many Microsoft 365 setups for business customers, and the paid add-on licence Microsoft 365 Copilot. Both are governed in principle by the same contracts as the rest of Microsoft 365 and Azure, and according to VISCHER these are sound under data-protection law once the necessary country or professional/official secrecy addenda are in place.

As soon as Copilot draws on Bing web search, the picture changes completely. The usual contractual elements (Microsoft Customer Agreement, Microsoft DPA) no longer apply. Different terms take over, even for business customers. Microsoft has added extra assurances for what it calls Query Data: it will not use customer data for service improvement, training or advertising, and treats it as confidential. VISCHER points to a detail that makes the difference: the text calls this data “confidential information” but does not use the contractually defined term “Confidential Information” from the Microsoft Customer Agreement. In doubt, that agreement’s confidentiality clause therefore does not apply. The Microsoft DPA does not apply to the Bing part either: Microsoft considers itself the controller here, so the DPA’s processor model does not apply. VISCHER’s conclusion: web search in Copilot and in Azure OpenAI Service meets neither data-protection nor professional/official secrecy requirements, with reservations for trade secrets as well.

Three options remain for companies. First, turn off web search for all employees, which markedly reduces the tool’s appeal. Second: on the add-on licence, each person can turn off web search individually per query, hidden in the context menu and not user-friendly. The distinction between “work” and “web” mode helps only partly: web search can run even in “work” mode, as long as it has not been explicitly turned off. Third: [instruct employees↗](/en/insights/ki-governance/) not to enter personal data or confidential information into Copilot queries, similar to an instruction for search engines. The difference is that with a classic search engine, users know what they type in; with Copilot, they do not control what the system additionally passes to the search.

Azure OpenAI Service via the API looks more favourable: here, your own application decides whether and when web-search access happens. Anyone building the application themselves can simply leave that access out.

## GitHub Copilot: a different contract from Microsoft 365

VISCHER deliberately leaves GitHub Copilot out of its own overview: the piece covers “only” selected variants for and around Office, not Copilot in tools such as Copilot Studio or GitHub. That is not a coincidence: GitHub Copilot runs on its own legal track. What follows is therefore our own research into GitHub’s publicly available contract documents, as of July 2026, not a VISCHER assessment.

Risk

On the consumer tiers Copilot Free, Pro and Pro+, GitHub states that since 24 April 2026 it trains on code, prompts and suggestions by default, unless someone actively opts out. Business and Enterprise customers are explicitly excluded from this change: according to GitHub, their interaction data still does not feed into training.[The GitHub Blog](https://github.blog/news-insights/company-news/updates-to-github-copilot-interaction-data-usage-policy/)

If GitHub Copilot is bought directly from GitHub, the GitHub Copilot Product Specific Terms and a separate GitHub DPA apply, not the Microsoft Customer Agreement and not the Microsoft DPA from the previous section. If GitHub is instead bought through a Microsoft contractual relationship (Enterprise Agreement), the Microsoft Product Terms for GitHub offerings apply instead. Which of the two contracts applies depends on the purchase route, not the product name.

For business use, the same basic rule applies as for every other provider in this series: only Copilot Business or Copilot Enterprise are an option, never a personal Free or Pro account. On data retention, GitHub names no fixed period for active accounts and a 90-day deletion window for terminated accounts; Enterprise contracts can agree different periods.[GitHub Docs](https://docs.github.com/en/site-policy/github-terms/github-terms-of-service) Neither GitHub nor VISCHER makes a statement on professional secrecy; anyone subject to professional-secrecy duties should exercise the same caution here as with Microsoft 365 Copilot’s web grounding.

## Professional secrecy: what already works today

For law firms, medical practices, fiduciaries and banks, the question of [professional secrecy↗](/en/insights/berufsgeheimnis-cloud/) matters more than general GDPR or revFADP compliance. On Microsoft 365 Copilot and Azure OpenAI Service, VISCHER reaches a cautiously positive conclusion here: use with professional and official secrets is possible, provided the necessary contract addenda are in place, abuse monitoring is turned off, and Bing search is not used with professional-secrecy data.

Note

Abuse monitoring is the provider’s review of requests and responses. An automated filter works like a doorman who turns people away by fixed rules without photocopying their ID: that is unproblematic under data-protection law. The case is different when a Microsoft employee reviews the matter manually: the customer then has no influence over who examines the data, or how.

On the positive side, SMEs too can obtain these contract addenda without difficulty. Two limitations remain. Anyone buying Microsoft cloud services through a Cloud Solution Provider, meaning a reseller, often does not get the necessary addenda formally signed; for this case, VISCHER points to its own workaround for the missing signature on Microsoft cloud contracts. And the opt-out from manual abuse monitoring is open today only to customers Microsoft manages directly, not to customers going through a reseller. According to VISCHER, Microsoft is testing a new process to change this for individual professional groups such as law firms.

Key figure

30 days

That is how short the new notice period in the Microsoft DPA is before a new AI sub-processor goes into use; it used to be 6 months. Customers can still disable use of such a sub-processor for at least 6 months after the notice.

Source: VISCHER, AI Tools Market Overview Part 31, as of July 2026

## Flex Routing: the silent configuration trap

A newer feature deserves particular attention: Flex Routing. Microsoft introduced it for performance reasons: for better load balancing, AI responses are no longer necessarily generated in Europe but are partly distributed worldwide. According to VISCHER, that is unproblematic under data-protection law. For professional secrecy, however, it very much is a problem, because the processing then leaves the “EU Data Boundary”, Microsoft’s commitment to keep data within the EU and EFTA.

Risk

VISCHER reports cases where Flex Routing was quietly activated for individual customers, disguised as an ordinary service update. Check your cloud configuration regularly for this reason, even long after setup.

## Where Copilot stands on the sovereignty scale

The contract question is one layer. The other is the architecture: which jurisdiction does the processing really fall under, how open is the model behind it, where does operation run, and can you get out of the system again if in doubt? How we define sovereignty is set out in the foundational article [What is sovereign AI?](/en/insights/was-ist-souveraene-ki/). The same six axes apply concretely to Copilot and Azure OpenAI Service:

less sovereign more sovereign →

Jurisdiction

US

EU

Switzerland

Model

closed

open weights

open + training data

Software

proprietary

open code

true open source

Operation

US cloud

Swiss provider

in-house

Data

provider may train on it

contractually forbidden

technically impossible

Integration

proprietary API

open standards

in-house

On jurisdiction, Copilot today mostly sits in the middle thanks to the EU Data Boundary, closer to the EU than to the US. Switzerland, as an EFTA state, belongs to the same Boundary circle (completed in February 2025),[Microsoft Learn](https://learn.microsoft.com/en-us/privacy/eudb/eu-data-boundary-learn) and Microsoft also operates its own data centres near Zurich and Geneva since 2019.[Microsoft News](https://news.microsoft.com/source/emea/2026/02/how-microsoft-is-addressing-digital-sovereignty-in-switzerland/) Flex Routing can push this classification back to the left in individual cases, and the US CLOUD Act? reaches Microsoft as an American company regardless of server location anyway. On operation, Copilot stays on the left: a hyperscaler service that you rent. On integration, it stays on the left too: a proprietary Microsoft API and app that makes switching providers difficult.

The model axis shows the widest range, and this is exactly where the difference lies between plain Copilot consumption and the API route via Azure OpenAI Service. Through Copilot you use closed models: GPT from OpenAI, or optionally an Anthropic model such as Claude. For the latter, Anthropic itself currently processes on its own systems in the US, even though Microsoft passes on the data-protection obligations through its DPA; this variant is therefore ruled out for professional secrecy. VISCHER has learned that Anthropic plans to also run its models on data centres in Europe towards the end of the year.

## The escape route: Azure AI Foundry

Anyone working through the Azure OpenAI API ends up in Azure AI Foundry, Microsoft’s model catalogue with over 1,900 entries (as of mid-2026, the number keeps changing).[Microsoft Learn](https://learn.microsoft.com/en-us/azure/foundry/concepts/foundry-models-overview) Alongside the closed OpenAI and Anthropic models, it also offers open models? such as Meta Llama, Mistral, DeepSeek or Cohere, available partly as ready-made serverless endpoints and partly as deployments on dedicated compute you book yourself.

This matters for the sovereignty calculation: an open model on Azure AI Foundry can later also be run at a different provider, whereas a closed GPT model runs exclusively at Microsoft or OpenAI. Anyone starting with Azure OpenAI Service today and choosing an open model keeps this path open without leaving the hyperscaler infrastructure right away. Jurisdiction and operation stay unchanged with Microsoft; only the model axis shifts to the right.

## How to get started

Before a broad rollout, clarify four points. First, whether your company buys Microsoft cloud services directly or through a reseller, because that determines whether the abuse-monitoring opt-out is reachable at all. Second, whether the necessary contract and professional-secrecy addenda are actually signed. Third, how you turn off web search for sensitive data, technically and organisationally, per user or for the whole organisation. Fourth, whether a given use case gets more control from Azure OpenAI Service with an open model than from the ready-made Copilot app.

Want the Microsoft cloud contracts, the abuse-monitoring opt-out and the model choice assessed for your case?

[AI architecture & solution selection](/en/leistungen/ki-architektur/)

The remaining parts of the series examine OpenAI, Anthropic and Google using the same framework, plus Proton as a counter-model.

The author

![Portrait of Joel Barmettler](/_astro/joel-barmettler.CGKHGWrV_sJ0IG.webp)

Joel Barmettler

AI Architect · Souverana, Zurich

Joel Barmettler guides Swiss companies from AI strategy to integration: sovereign, confidential and production-ready. He built the Swiss AI Hub as its architect and today co-owns its architecture; he personally leads every Souverana mandate. Mandates from one-person firms to Fortune 500 corporations.

[Book an intro call](https://meet.brevo.com/joel-barmettler/30-minute-meeting) [More about Souverana](/en/) [LinkedIn](https://www.linkedin.com/in/joel-barmettler-b9ab361b7)

## Frequently asked questions

Is Microsoft Copilot compliant with data protection?

Microsoft 365 Copilot Chat and the add-on licence run under the usual business-customer contracts (Microsoft Customer Agreement, DPA), which, in the assessment of the Zurich law firm VISCHER, are compatible with professional secrecy too. The exception is web search via Bing: as soon as Copilot searches the web, different terms apply that barely guarantee confidentiality any more.

Can I use Microsoft Copilot for professional secrecy (lawyer, doctor, bank)?

In principle yes, if three conditions are met: the necessary contract addenda are signed, manual abuse monitoring is disabled, and Bing web search is not used with professional-secrecy data. If your company buys Copilot through a reseller, the abuse-monitoring opt-out is currently not available; that only applies when Microsoft manages you directly.

What does web grounding mean in Copilot?

Web grounding is the web search that Copilot switches on via Bing so that answers include current information from the internet. As soon as it is active, the normal contractual framework (MCA, DPA) no longer applies; instead, one for consumers applies, which, according to VISCHER, meets neither data-protection nor professional-secrecy requirements.

What is the difference between Microsoft 365 Copilot and Azure OpenAI Service?

Microsoft 365 Copilot is the app integration into Word, Outlook and Teams, intended for end users. Azure OpenAI Service is the programming interface for your own applications: here, your application itself controls whether and how web-search access happens, which gives more control.

What is the EU Data Boundary, and does it apply to Switzerland?

The EU Data Boundary is Microsoft's commitment to process and store customer data and pseudonymised personal data within the EU and EFTA for most Azure and Microsoft 365 services. Switzerland belongs to it as an EFTA state (the Boundary was completed in February 2025); Microsoft is additionally extending in-country processing for Copilot to Switzerland by the end of 2026. That changes nothing about the US CLOUD Act, which continues to apply to Microsoft as an American company.

Is GitHub Copilot suitable for enterprise use?

On the Business and Enterprise tiers, yes: GitHub does not train on your code there. GitHub Copilot runs under its own contract, though, either GitHub's own Product Specific Terms or, when bought through a Microsoft contractual relationship, the Microsoft Product Terms for GitHub offerings, not under the Microsoft Customer Agreement for Microsoft 365 Copilot. Personal tiers such as Free or Pro have trained on your code by default since April 2026.

LinkedIn

## Share this article

Ready-formatted graphics and a suggested post for your LinkedIn feed: download, copy, post.

![Four configuration points for Microsoft Copilot: turn off Bing web search (works per query), opt out of abuse monitoring (only for directly managed customers), check Flex Routing (can leave the EU Data Boundary), sign the professional-secrecy addenda.](/media/microsoft-copilot-datenschutz-en/infografik.png)

[Download infographic (PNG)](/media/microsoft-copilot-datenschutz-en/infografik.png)

Suggested post

Have you bought Copilot licences? Four settings decide what happens to data protection afterwards.

Starting with Copilot makes sense once your data already sits in SharePoint and Outlook, and it holds up well from a data-protection point of view. The default settings do not, though.

According to the market overview by the Zurich law firm VISCHER, these are the four: Bing web search falls outside the contractual framework, and on the add-on licence the switch against it works per query rather than tenant-wide. The opt-out from manual abuse monitoring is open today only to directly managed customers, not to those with a reseller. Flex Routing can process responses outside the EU Data Boundary for load balancing, sometimes activated quietly. And the professional-secrecy addenda, while available to SMEs too, often go unsigned when bought through a reseller.

Our conclusion: with these four points in place, Copilot is usable for professional secrecy too, according to VISCHER. Without them, the licence is bought and confidentiality is open. Anyone who wants to keep an exit route chooses an open model through Azure AI Foundry, one that can later run somewhere else.

Assessment, not legal advice. The article carries the product table, our own assessment of GitHub Copilot, and seven questions before rollout. Link in the comments.

#AI #DataProtection #Microsoft #Switzerland
