Using personal and sensitive data with Copilot
There is no universal rule that all personal or sensitive data must be excluded from approved enterprise AI. Organisations take different positions depending on policy, risk appetite, data type and technical controls. Start with your organisation's policy, then assess the purpose, necessity, sensitivity and controls.
Last reviewed 2026-10-09
Why there is no single 'PII yes/no' rule
Microsoft Copilot and Copilot Chat with enterprise data protection are designed to process organisational data. Microsoft states that prompts, responses and Microsoft Graph data are not used to train foundation models, and Copilot operates in the user's security context. That does not make every use appropriate: UK GDPR duties, lawful basis, purpose limitation, data minimisation, security, retention and any additional rules for special category or criminal-offence data still apply. The ICO explicitly says there is no one-size-fits-all approach to AI security; controls should reflect the risks of the particular processing.
Real examples: organisations have reached different conclusions
| Organisation / example | Published position | What it demonstrates | Source |
|---|---|---|---|
| UK Government DSIT – Redbox | Redbox is approved for information up to and including OFFICIAL SENSITIVE, but its published terms say users should not upload personally identifiable information. | A system can be approved for sensitive/classified organisational information while still prohibiting PII. Security classification and personal-data rules are separate questions. | GOV.UK Algorithmic Transparency Record – DSIT Redbox |
| Single Source Regulations Office (SSRO) – Microsoft 365 Copilot | SSRO says Copilot operates in its secure Microsoft 365 environment and is used with OFFICIAL information, but staff must not input special category personal data or highly classified material. | An organisation can accept ordinary business/personal information within a protected tenant while drawing a stricter boundary around special category or highly classified data. | SSRO – approach to responsible AI use |
| Greater London Authority (GLA) – Microsoft Copilot and other AI tools | The GLA states that its staff guidance advises employees never to enter personal data into AI tools. | A public body can choose a deliberately conservative organisational policy even where the underlying enterprise technology provides data-protection controls. | London Assembly – AI in the GLA (3) |
| Microsoft Purview DLP example | Microsoft documents policies that block prompts containing chosen sensitive information types, such as EU debit-card numbers or physical addresses, and exclude files labelled Personal or Highly Confidential from Copilot processing. | Organisations can turn policy choices into technical controls rather than relying only on user training. | Microsoft Learn – Purview DLP for Microsoft 365 Copilot and Cowork |
These examples are useful because they show that 'sensitive', 'classified' and 'personal' data are not interchangeable concepts, and that organisations can legitimately choose different policy positions.
A practical decision path
1. Does organisational policy permit this category of data in this AI service?
If no or unclear, stop and follow the organisation's approval route. If yes, continue.
2. Are you using an approved organisational AI environment?
Confirm the account, tenant, enterprise data protection and any required admin controls. Do not assume a consumer AI service has the same protections.
3. Are you authorised to use the information for this purpose?
AI does not create a new lawful basis, permission or need-to-know entitlement.
4. Do you need all of the information?
Remove or pseudonymise names, identifiers or sensitive fields if they are unnecessary for the task. Data minimisation still applies.
5. Is it special category, criminal-offence or otherwise high-risk information?
Check the relevant lawful basis/condition, organisational policy, DPIA requirements and any additional DPO/security approval.
6. What record will the AI interaction create?
Copilot prompts and responses can be logged, retained and available for audit/eDiscovery. Consider whether the prompt itself is appropriate as an organisational record.
7. Is the AI assisting a person or making a consequential decision?
Use additional controls and human accountability where outputs influence regulated, employment, safeguarding, assessment or other consequential decisions.
Use this before placing personal or sensitive information into Copilot or another approved AI service.
Examples for an awarding organisation
A centre contact list containing names, roles and work email addresses may be acceptable in approved organisational Copilot if policy permits it and the information is needed for the task. An EQA report containing identifiable staff and operational observations deserves a stronger check of purpose, permissions and minimisation. A malpractice or safeguarding file containing health information, allegations or criminal-offence information should be treated as high risk and may require specific policy approval, a DPIA or a prohibition, depending on the organisation.
Examples and guidance to look up
- DSIT Redbox – Algorithmic Transparency Record
- SSRO – approach to responsible Artificial Intelligence use
- Greater London Authority – AI in the GLA (3)
- ICO – security and data minimisation in AI
- ICO – special category data rules
- Microsoft – enterprise data protection in Copilot
- Microsoft – Purview DLP for Copilot and Cowork
Sources
- Microsoft – Enterprise data protection in Microsoft Copilot and Copilot Chat — checked 2026-10-09
- Microsoft – Purview DLP for Microsoft 365 Copilot and Cowork — checked 2026-10-09
- ICO – How should we assess security and data minimisation in AI? — checked 2026-10-09
- ICO – What are the rules on special category data? — checked 2026-10-09
- DSIT – Redbox Algorithmic Transparency Record — checked 2026-10-09
- SSRO – Responsible Artificial Intelligence use — checked 2026-10-09
- Greater London Authority – AI in the GLA (3) — checked 2026-10-09
