Almanac
Microsoft/copilotMicrosoft 365

Consultant KB for the whole Microsoft Copilot estate. Spans Microsoft 365 Copilot, Copilot Studio, the Dynamics 365 Copilots, Power Platform Copilot, Fabric & Power BI Copilot, Copilot in Azure, Windows & consumer Copilot, extensibility & agents, Security Copilot, and GitHub Copilot, plus admin/security and cross-product decision guides. Populated by the daily author agent from Copilot release notes / release plans plus the author's own consultant notes.

feature-copilot-data-residency.mdv1 · history
CurrentApplies to AllUpdated 2 months agoSource Microsoft Learn

What it does

The EU Data Boundary (EUDB) is Microsoft's commitment to store and process customer and personal data for EU and EFTA customers within the EU boundary. Copilot processing falls under it, with some documented exceptions.

Key facts

  • EUDB covers storage and processing of customer data and personal data for eligible tenants inside the EU/EFTA region.
  • Microsoft 365 Copilot reasoning happens within the boundary for eligible tenants, and stored interaction data follows your existing Microsoft 365 data location.
  • Web-grounded queries (Bing) and some troubleshooting or third-party scenarios can involve processing outside the boundary, these are documented as exceptions.
  • Your tenant's data residency is set by geography at provisioning and reported in the admin centre's data location tools.

When to use / skip

This is a briefing document for EU clients and their legal teams, not a toggle. Have the answer ready before the DPO asks. Non-EU clients can skim it.

Configuration decisions

  • Confirm the tenant's provisioned data location and whether Advanced Data Residency applies.
  • Decide whether to allow web-grounded Copilot queries given the boundary exception.
  • Document which optional connected experiences are enabled and where they process.

Gotchas

  • EUDB is not the same as multi-geo or a guarantee of a single country. It's a regional boundary, and clients often conflate "in the EU" with "in Germany". Be precise.
  • The web-grounding exception is the one that trips people up in DPIAs. Flag it explicitly rather than letting it surface later.
  • Existing tenant data location doesn't move just because EUDB exists. Provisioning geography still governs where mailboxes and sites live.

Consultant notes

  • For EU clients, EUDB plus the DPA usually satisfies the residency question, but only if you name the documented exceptions yourself. Legal trusts the consultant who volunteers the caveats.
  • Pull the tenant's actual data location from the admin centre rather than assuming, multi-national groups often have a surprising provisioning history.
  • If web grounding is a sticking point for the DPO, you can disable it and revisit. That single decision often unblocks sign-off.

Review when the EU Data Boundary scope or exceptions change.

Was this accurate?