Event banner
Prevent data loss and insider risks for Microsoft 365 Copilot with Microsoft Purview
Event details
Quick question from the recent Purview AI webinar: If Purview captures individual user prompts and responses for monitoring, how does this comply with GDPR?
Seems like a potential conflict between AI governance needs and data privacy requirements - especially regarding consent and data minimization.
Are there specific configurations or best practices to handle this properly under European data protection law?
Thanks!
Prompts and responses are stored in Teams and in the substrate, DSPM for AI displays that data.
Depending on the need, you can use eDiscovery+Graph to delete this information if it pertains to data removal, or alternatively you could use auto retention to delete information ongoing based on a specific data classifier.
Search for and delete Copilot data in eDiscovery | Microsoft Learn
Automatically apply a retention label to Microsoft 365 items | Microsoft Learn