Copilot Training NZ, home

9 min read. Updated 6 October 2026

Is our data safe in Microsoft 365 Copilot? Plans, training, residency and admin controls

Safe enough for most NZ businesses, if you know which Copilot your people are using, where the data goes, and which switches your administrator has left on by default.

Illustration generated with AI.

First, find out which Copilot you actually have

Microsoft has renamed the product: Microsoft 365 Copilot is now Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. The commitments below apply under either name1. Owners often ask whether Copilot is safe as if there were one product. There are several, and the answer changes between them. The question that matters is whether a person signs in with their work account (a Microsoft Entra ID account in your tenant) or with a personal Microsoft account. The commitments in this guide apply to work accounts only.

Microsoft 365 Copilot Chat is the chat experience most Microsoft 365 business users can open from Teams, Outlook or the Microsoft 365 Copilot app. Microsoft 365 Copilot is the paid add-on that also reads your mailbox, calendar, Teams chats and SharePoint files through Microsoft Graph. For organisations on a Microsoft 365 Business Basic, Standard or Premium plan, Microsoft sells the same capabilities as Microsoft 365 Copilot Business, which supports up to 300 seats per tenant8. Microsoft says Copilot Business follows the same data policies your organisation already sets for its Microsoft 365 for business tenant8.

Both Copilot Chat and the licensed product run under what Microsoft calls enterprise data protection. That means prompts and responses are covered by the Microsoft Products and Services Data Protection Addendum and the Product Terms, with Microsoft acting as a data processor, the same footing as the email in Exchange and the files in SharePoint2.

  • Ask your IT provider for a list of who holds a Microsoft 365 Copilot or Copilot Business licence, and who has Copilot Chat only.
  • Check that staff use Copilot signed in with their work account. A free consumer Copilot on a personal account is a different service with different terms.
  • Write the answer down. You will need it for your AI usage policy and for any privacy impact assessment.

Does Microsoft train its AI on our data?

No, not for work accounts. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation large language models, including the ones Microsoft 365 Copilot uses1. The enterprise data protection page repeats the same commitment for Copilot Chat2.

Two details are worth knowing. First, Microsoft may use optional feedback that a user sends with the thumbs-up or thumbs-down buttons to improve the product, though not to train the foundation models, and administrators can manage that feedback1. Second, Microsoft says Microsoft 365 Copilot has opted out of the abuse monitoring in Azure OpenAI that can include human review of content1. If a client or board asks whether a Microsoft person reads your prompts as a matter of course, that is the passage to point to.

Copilot sees what each person can already open

This is where most real risk sits for a small business, and it has nothing to do with Microsoft training a model. Microsoft 365 Copilot only surfaces organisational data that the individual user has at least view permission to1. If a payroll spreadsheet sits in a SharePoint site shared with everyone in the company, Copilot will happily summarise it for anyone who asks. The permissions were wrong before Copilot arrived; Copilot just makes the mistake easy to find.

Content that is encrypted with Microsoft Purview sensitivity labels is handled according to the usage rights each user holds1. SharePoint Advanced Management, which Microsoft says is included with a Microsoft 365 Copilot licence, adds oversharing reports and access reviews that help site owners tidy up14. Cleaning up permissions is a separate job that your administrator or IT provider should do before rollout, so this guide does not cover it.

Where your Copilot data is stored, and where it is processed

Microsoft stores a record of each interaction: the prompt, the response and citations to the content used. It calls this the content of interactions, and it forms each user's Copilot activity history1. Users can delete their own activity history through the My Account portal, and administrators can search it and set retention through Microsoft Purview1.

Storage location is where New Zealand businesses need to read carefully. Microsoft's data residency overview lists New Zealand as a local region geography with an Auckland datacentre region7. But for New Zealand the durable commitments on data location come through the Multi-Geo and Advanced Data Residency add-ons, not through the standard Product Terms commitment that some other countries get7. Advanced Data Residency covers Microsoft 365 Copilot, including the content of interactions, and it can be bought by tenants on Microsoft 365 Business Basic, Standard or Premium as well as enterprise plans5,6. The catch for a small business is that the add-on must cover 100% of the paid licences in the tenant before the residency commitment applies6.

Processing is a separate question from storage. Microsoft says Copilot's calls to the language model are routed to the closest datacentres in the region but can go to other regions when capacity is tight, and that customers outside the European Union may have their queries processed in the EU and other countries or regions1. In plain terms: a residency add-on can keep the stored record in New Zealand, but it does not promise that the model's processing happens here.

Under the Privacy Act 2020, using a cloud provider that only processes information on your behalf is generally treated as a use by your business rather than a disclosure, but you remain responsible for the information and for keeping it secure under information privacy principle 511,12. The practical test is simple: could you explain to a customer, in one or two sentences, where their information goes when a staff member pastes it into Copilot?

  • In the Microsoft 365 admin center, open Settings, then Org settings, then Organization profile, and read the Data location card to see where your tenant's data is stored today.
  • If a contract or a government client requires New Zealand storage, price Advanced Data Residency for the whole tenant, not just the Copilot users.
  • Record in your privacy impact assessment that model processing may happen offshore, even when storage is local.

Three settings that are on by default

Most of Copilot's privacy story is good. The parts that catch owners out are defaults that were switched on for convenience. Read these with your administrator, decide, and write the decision down.

  • Web search. When enabled, Copilot sends a short search query derived from the prompt to Bing with user and tenant identifiers removed2. Those web queries are not covered by the Data Protection Addendum; Bing handles them under the Microsoft Services Agreement and Privacy Statement as an independent data controller2. Administrators manage this with the Allow web search in Copilot policy in the Cloud Policy service for Microsoft 365, by user or group3.
  • Anthropic models. Since 7 January 2026 Anthropic has been a Microsoft subprocessor for Microsoft 365 Copilot, and Microsoft turned Anthropic models on by default for most commercial tenants outside the EU, EFTA and UK4. Microsoft says Anthropic models are excluded from in-country processing commitments where those apply4. A global administrator can review this under Copilot, then Settings, then AI providers operating as Microsoft subprocessors, and can limit access to named users or security groups4.
  • File upload and memory. File upload is enabled by default in both Microsoft 365 Copilot and Copilot Chat, and changing it means a request to Microsoft Support10. Copilot memory, which keeps saved memories and custom instructions in a hidden folder in the user's Exchange mailbox, is on by default through the Enhanced personalization control9.

What the Privacy Act and NZ regulators expect from you

Microsoft's terms deal with Microsoft's side. Your side is set by the Privacy Act 2020. The Office of the Privacy Commissioner's guidance on AI expects organisations to have senior leadership approval, to do a privacy impact assessment before using an AI tool, to be clear with people about how their information is used, and to have a human check outputs before acting on them12.

Every agency must appoint at least one privacy officer under section 201 of the Privacy Act 2020, and that person should be in the room when Copilot settings are decided13. If a prompt or an overshared file leads to a privacy breach that has caused or is likely to cause serious harm, section 114 of the Privacy Act 2020 requires you to notify the Commissioner as soon as practicable15.

The NCSC's AI guide for small businesses names data leaks and privacy breaches, unreliable or manipulated outputs, and supply-chain weaknesses as the key risks when using tools such as Microsoft Copilot16. Treat its checklist as a sensible second opinion on the settings above.

A worked example: a Tauranga property management office

Picture a generic property management firm in Tauranga with a small office team and a larger group of property managers who live in Outlook. Tenant files hold bank details, references and, sometimes, health information supplied with tenancy applications.

The owner confirms with their IT provider that everyone already has Copilot Chat and that six staff are on Copilot Business. The provider reports that a SharePoint site called Tenancies is shared with everyone, so the clean-up starts there. The owner decides to keep web search on for marketing and admin staff, who write listings and research suburbs, but to turn it off for the property managers who work with tenant files. Anthropic models are limited to a small security group until the privacy officer has read the subprocessor terms. File upload stays on, because staff need to summarise inspection reports, but the AI usage policy says tenant documents are only uploaded inside work mode. The decisions take an afternoon and fit on one page, which goes into the privacy impact assessment.

Your checklist before staff use Copilot with client data

Work through these with your administrator and your privacy officer. None of them requires a consultant, but each needs a named owner.

  • Confirm every user signs in with a work account, and block or discourage personal Copilot for work tasks.
  • List who has a Copilot licence and who has Copilot Chat only.
  • Read the Data location card, and decide whether you need Advanced Data Residency.
  • Decide on web search, Anthropic models, file upload and memory, and record the reason for each choice.
  • Fix sites and Teams that are shared with everyone, starting with HR, finance and client folders.
  • Turn on audit logging in Microsoft Purview so Copilot activity is recorded.
  • Update your privacy statement if Copilot changes how customer information is used.
  • Brief staff on what the settings mean before the first licence is assigned.

Questions

Is Copilot Chat safe to use with client information if we have not bought licences?

Copilot Chat signed in with a work account has enterprise data protection, so prompts and responses sit under the same contractual terms as your email and files2. It does not read your mailbox or SharePoint unless a user uploads a file, which is enabled by default10. Set a policy on what may be pasted in before you rely on it.

Does Microsoft keep our Copilot data in New Zealand?

Not by default. Durable New Zealand storage commitments come with the Advanced Data Residency or Multi-Geo add-ons7. Even then, the language model may process queries in other regions1.

Can we turn off the Anthropic models inside Copilot?

Yes. A global administrator can disable Anthropic as a Microsoft subprocessor in the Microsoft 365 admin center, or limit it to chosen users or groups4. Some features only work when Anthropic models are enabled, so test before you switch it off for everyone4.

Do we need a privacy impact assessment for Copilot?

The Privacy Act does not make one compulsory, but the Privacy Commissioner expects organisations to do one before using a generative AI tool12. For most small businesses a short, honest assessment is enough.

Train your team

  1. ScopeHeadcount, sites, Microsoft 365 plan and licences, and the teams you want to start with.
  2. PlanWe propose a course, a pilot group and a format, and agree the files and meetings to use.
  3. TrainOn-site or over Teams, in Outlook, Word, Excel and Teams, with your own work.
  • In person
  • Remote
  • Half-day workshop
  • Full-day workshop
  • Team rollout

Independent training by TheColab. Not affiliated with Microsoft.

Enquire

Tell us about your team. We reply by email with a suggested course and format.

We use these details only to reply to you, and store them securely with TheColab. Privacy

Sources