Data Protection with Copilot and AI Builder in Power Automate

How Copilot and AI Builder in Power Automate handle your data, which GDPR points SMEs should consider, and what to do in practice.

Many small and medium-sized businesses now rely on Copilot in Power Automate and on AI Builder to create flows from natural language or to automatically read documents. This almost always raises the same question: what actually happens to the data being processed, and is this compatible with the GDPR? The answer is more nuanced than a simple yes or no, because it depends on which feature you use, where your Power Platform environment is located, and which settings your tenant administrator configures.

This article summarizes how Microsoft, according to its own documentation, handles Copilot and AI Builder data, where this data is technically stored, and which points you should check as the controller under the GDPR before using AI features in production. As of: July 2026.

How Microsoft handles Copilot inputs and outputs

According to the Microsoft FAQ on Copilot data security and privacy your prompts and Copilot's responses are not available to other customers. They are also not used to train or improve models from OpenAI or other third-party providers. Microsoft also does not use your data to train its own AI models, unless your tenant administrator has explicitly consented to this. Copilot is based on Azure OpenAI Service and, according to the documentation, runs entirely within the Azure cloud; connections are encrypted via TLS, and data transfers between Power Platform and Azure OpenAI take place over the Microsoft backbone network rather than the open internet.

Important in practice: Copilot only accesses data that the currently signed-in person already has access to. Existing permissions in Dataverse, SharePoint, or other data sources are therefore not bypassed but respected through authentication and authorization mechanisms.

Where AI Builder data is technically stored

For AI Builder, according to the AI Builder architecture documentation, there is a clear separation between training data and prediction data:

  • Training data: Images and documents used to train a custom model for object detection or document processing remain permanently stored in Dataverse and are used exclusively for the respective model, never shared externally.
  • Prediction data: Images and documents processed at runtime in a Power Automate flow are not permanently stored after processing.
  • Text inputs: Inputs from text scenarios, such as AI prompts, are logged in a separate AI event table in Dataverse so that activities can be monitored afterward.
  • Geo boundaries: As long as Azure OpenAI Service is available in the respective region, your data, according to the documentation, does not leave the geographic boundary of your environment. If the service is not available regionally, administrators can specifically determine whether and how data may be processed across regions.

For access to stored training data, according to the AI Builder administration documentation: only the owner of the model as well as people with the Power Platform roles System Administrator or System Customizer have access. As an SME, you should actively use this role separation rather than leaving it at the default.

GDPR classification for SME use

From a GDPR perspective, as a company that uses Copilot or AI Builder in production, you are the controller, and Microsoft acts as the processor. The technical and organizational measures that Microsoft describes in its documentation, such as encryption at rest and in transit, data isolation between tenants, and role-based access controls, correspond to what Article 32 GDPR requires for security. The basis for the processing agreement is the Microsoft Data Protection Addendum, which contains GDPR-compliant standard contractual clauses, as well as certifications such as ISO/IEC 27018 for the protection of personal data in the cloud.

One point that should reassure many SMEs: the optional data-sharing program, under which Microsoft employees may manually review prompts and outputs for product improvement, is, according to the FAQ on optional data sharing disabled by default and currently explicitly available only for tenants in the US region. For German and European tenants, this option therefore currently does not apply at all; your data always remains within your geographic boundary and is not manually reviewed.

Nevertheless, the responsibility remains with you: the GDPR requires that you only process personal data when a legal basis exists, and that you are able to fulfill data subject rights such as access or erasure. If customer data or employee data ends up in a Copilot prompt or an AI Builder training dataset, the same rules apply as for any other processing.

Practical steps for data-protection-compliant use

  • Check the environment region: Create Power Platform environments for European data in an EU region so that the geo boundary is actually enforced in practice.
  • Conclude a data processing agreement: Make sure the Microsoft Data Protection Addendum is part of your license agreement as a DPA, and document this in your record of processing activities.
  • Restrict roles and permissions: Assign the System Administrator and System Customizer roles only to people who actually need AI Builder training data.
  • Set DLP policies: Set up Data Loss Prevention policies in the Power Platform Admin Center so that the Dataverse connector, which also includes AI Builder, is not combined uncontrolled with non-business connectors.
  • Design prompts deliberately: Avoid entering sensitive personal data, such as health or banking information, unnecessarily into Copilot prompts, even though Microsoft does not use it for training.
  • Monitor activity: Use the AI event table in Dataverse to track which text inputs were processed.

Anyone who sets these points up properly retains control over their own data and can use Copilot and AI Builder productively with a clear conscience. NordFlux supports you with Power Automate consulting at a fixed price when building data-protection-compliant Power Automate flows with AI features.

Frequently Asked Questions

Does Microsoft train its own AI models with our Copilot inputs?

No, not by default. According to Microsoft's documentation, prompts, responses, and the data accessed are not used to train foundation models unless a tenant administrator explicitly enables the optional data-sharing program. This program is also currently only available for tenants in the US region.

Does our data leave the EU with AI Builder?

As long as Azure OpenAI Service is available in your region, your data, according to the documentation, remains within the geographic boundary of your environment. For European companies, this means: create your environment in an EU region, and the data will not leave this area without deliberate approval by an administrator.

Who can access training data in AI Builder?

According to the documentation, only the owner of the respective model as well as people with the System Administrator or System Customizer roles in your organization have access to the training data stored in Dataverse. You should assign these roles deliberately and review them regularly.

Do we need a separate contract for using Copilot and AI Builder?

You generally do not need a separate contract just for AI features. Use falls under your existing Microsoft license agreement, including the Data Protection Addendum, which serves as a data processing agreement under the GDPR. You should still check whether this addendum is actually part of your contractual documents.

Is it enough if we simply don't actively use Copilot?

According to the documentation, Copilot in Power Automate can be disabled via a support request using a PowerShell script, and AI prompts in AI Builder can be turned off directly in the Power Platform Admin Center per environment. Anyone who fundamentally does not want to use AI features can therefore enforce this technically instead of relying solely on non-use.

About NordFlux

NordFlux UG (haftungsbeschränkt)

NordFlux builds digital employees for organisations: automations and AI agents that take over repetitive work. You stay in control.

More about us
Free initial analysis

Concrete questions about automation or AI?

In a free initial analysis we discuss your case directly. No strings attached.