Hi,
Interesting update and apologise any naivety shown around my question, like many others we are just starting our journey and focussing on our governance.
In terms of the, to be retired, Commercial Data Protection, what our concern was around where the prompt processing took place as a UK based organisation “To provide chat responses, Copilot uses global data centers for processing and may process data in the United States” https://learn.microsoft.com/en-us/copilot/privacy-and-protections
Can some provide any information/link to confirm how this may be different with EDP as I understand it will be similar to Copilot for M365 based on @
- Prompts and responses will stay within the Microsoft 365 service boundary, and all associated data handling commitments will apply—including support for GDPR, and ISO/IEC 27018 (Copilot for Microsoft 365 runs on the ISO 27018 certified Microsoft 365 platform)