Event details
We are very excited to announce a Microsoft 365 Copilot and Bing Chat Enterprise AMA! Get answers to your questions around Microsoft 365 copilot and Bing Chat enterprise from our team of experts
...
Sarah_Gilbert
Updated Aug 10, 2023
djjeff80
Aug 08, 2023Copper Contributor
There're just two issues for me related to the GDPR:
Issue 1:
Is Microsoft hosting its Graph Service in Europe for European customers too?
At the moment, it seems to be a Microsoft Black Box running somewhere in the cloud in the world taking and answering requests. And to get needed information about documents and metadata, Graph needs to have full access.
Issue 2:
Copilot has full access to my documents by default, as long as there's no entry in Purview blocking it, hasn't it?
If that's the case, my data wouldn't be mine and I have no chance to change that as long as I don't have enough rights on Purview (which is the default setup in most companies in real).
Or is everything blocked by default and you've to call your local Purview administrator to allow sharing my data?
In case of a file share: If you allow it, is only your own personal data allowed to share as long as not every group member also allows that?
Btw:
"Microsoft 365 Copilot calls to the LLM are routed to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization periods [...] EU traffic stays within the EU Data Boundary while worldwide traffic can be sent to EU and other geographies for LLM processing."
So, Microsoft 365 Copilot ain't 100% GDPR compliant. Only if there's the capacity, data will stay in EU area. If I'm offering internal business data in a Copilot request for finding a solution, KI engine is also allowed to use this data for learning purposes outside of the E.U. This seems to be a K.O. criteria for Copilot for most of the larger companies and gouvernments 🤔