Updated september 8, 2026
Summary: Microsoft Copilot and Google Gemini collect user prompts, metadata and interaction logs that can be retained and reviewed by the vendor. A sovereign private AI runs on infrastructure you control, meaning no prompt ever leaves your jurisdiction.

Copilot privacy refers to the question of what happens to the text, files and instructions that employees submit to AI assistants such as Microsoft Copilot or Google Gemini inside their daily productivity tools. For IT managers, CISOs and Data Protection Officers, the answer involves data retention policies, contractual commitments, jurisdictional exposure and GDPR obligations that are often less clear than vendor marketing suggests.

What Data Do Microsoft Copilot and Google Gemini Actually Collect?

Both assistants collect more than just the text of a prompt. They also log contextual data that is less visible to end users.

When an employee uses Microsoft Copilot inside Microsoft 365, the assistant can access emails, calendar entries, Teams messages and SharePoint documents to generate a response. Microsoft processes this content on its own infrastructure. Interaction data, including the prompt, the response, and metadata such as timestamps and user identifiers, is retained by default for up to 30 days for safety and abuse monitoring, according to the Microsoft Privacy Statement (2024). Enterprise administrators can adjust retention settings through the Microsoft 365 compliance centre, but the default applies unless actively changed.

Google Gemini for Workspace operates similarly. Prompts typed into Gmail, Docs or Meet are sent to Google’s servers for processing. Google’s infrastructure is primarily located in the United States, which means data is subject to US jurisdiction including the CLOUD Act, regardless of where the employee sits.

Let op: Contractual commitments from a vendor (such as “we do not train on your data”) are not the same as technical guarantees. The data still travels to and is processed on infrastructure you do not own or audit.

Are Employee Prompts Used for AI Training?

The short answer for enterprise tiers is: not for foundational model training, according to both vendors. But the full picture requires more precision.

Microsoft states that Copilot for Microsoft 365 does not use customer content to train its foundational large language models. Google makes a similar commitment for Gemini for Workspace enterprise accounts. These are contractual positions, documented in their respective Data Processing Addenda.

However, both companies reserve the right to process prompts for purposes including abuse detection, service improvement and safety. The European Data Protection Board addressed exactly this ambiguity in its April 2024 opinion, confirming that AI systems processing personal data must apply data minimisation and purpose limitation as required by GDPR Articles 5 and 25. Processing for “service improvement” is not automatically a lawful purpose under Article 6 GDPR without a valid legal basis and prior transparency to data subjects.

Anu Talus, Chair of the European Data Protection Board, stated in 2024: “Organisations must understand not just what data an AI processes, but where it goes, who can access it, and for how long. Contractual assurances are not the same as technical guarantees.”

Wojciech Wiewiórowski, the European Data Protection Supervisor, has also raised concerns: “The use of employee data by AI productivity tools raises serious questions under GDPR about lawful basis, transparency and data subject rights.”

Aspect Microsoft Copilot Google Gemini (Workspace)
Data processed Emails, documents, Teams chats, prompts Emails, documents, Meet transcripts, prompts
Default prompt retention Up to 30 days Varies by product and admin settings
Used for foundational model training No (enterprise contract) No (enterprise contract)
Infrastructure jurisdiction US-based (subject to CLOUD Act) US-based (subject to CLOUD Act)
Admin audit controls Microsoft 365 compliance centre Google Admin console
See how Qsentinel solves this in practice.Start a 10-user pilot →

How a Sovereign Private AI Assistant Differs

A sovereign private AI processes prompts entirely within infrastructure the organisation owns or explicitly controls, with no data leaving to a third-party vendor during inference.

The key architectural difference is where inference happens. In a sovereign model, the language model itself runs on servers located in a defined jurisdiction, whether an on-premise data centre or a dedicated hosted environment in a country with compatible data protection law (Switzerland, for example, operates outside EU jurisdiction but maintains strong equivalence through its revised Federal Act on Data Protection, the revFADP). No prompt is ever transmitted to a US hyperscaler, which eliminates CLOUD Act exposure entirely.

This matters for organisations handling categories of data listed in GDPR Article 9 (health data, legal files, HR records), for regulated sectors under NIS2, and for public sector entities that must comply with national sovereignty requirements. A sovereign AI assistant also allows the organisation to set its own data retention to zero: prompts can be discarded immediately after a response is generated, with no log retained anywhere outside the organisation’s control.

Managed Nextcloud Enterprise deployments, such as those offered by Qsentinel with integrated private AI and post-quantum encryption, are built on this principle: the AI assistant runs within the same sovereign boundary as the document store, so neither files nor prompts cross a jurisdictional line.

Let op: Post-quantum encryption protects data in transit and at rest from future decryption attacks. It does not protect prompts from being read by the vendor during live processing. Genuine prompt privacy requires local inference, not just stronger encryption on data sent externally.

FAQ

Does Microsoft Copilot use my prompts to train its AI models?

Microsoft states that Copilot for Microsoft 365 does not use customer content to train foundational models. However, interaction metadata is retained for up to 30 days for safety and abuse monitoring, and this distinction carries weight under GDPR Article 5.

Does Google Gemini for Workspace collect employee prompts?

Yes. Prompts and responses are processed on Google’s infrastructure. For enterprise customers, Google contractually commits that this data is not used to train foundational models, but the data still transits servers outside the organisation’s direct control.

What is a sovereign AI assistant?

A sovereign AI assistant runs on infrastructure within a defined legal jurisdiction or on the organisation’s own servers. Prompts are never sent to a third-party cloud vendor. The organisation retains full control over data storage, retention and access logs.

Which GDPR articles are most relevant for AI assistants in the workplace?

Article 5 (data minimisation and purpose limitation), Article 25 (data protection by design and by default), and Article 28 (processor agreements) are the most directly applicable. The EDPB confirmed this applicability to AI systems in its April 2024 opinion.

Can post-quantum encryption protect prompts sent to a cloud AI?

No, not during processing. Post-quantum encryption protects data in transit and at rest from future decryption attacks, but it does not prevent the AI vendor from accessing plaintext prompts at the moment of inference. Genuine protection requires that prompts are processed locally, not encrypted and then sent externally.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Does Microsoft Copilot use my prompts to train its AI models?
Microsoft states that Copilot for Microsoft 365 (the enterprise product) does not use customer content to train foundational models. However, interaction metadata is retained for up to 30 days for safety and abuse monitoring, and this distinction matters legally under GDPR.
Does Google Gemini for Workspace collect employee prompts?
Yes, prompts and responses are processed on Google's infrastructure. For enterprise customers, Google contractually commits that this data is not used to train foundational models, but the data still transits and is processed on servers outside your control.
What is a sovereign AI assistant?
A sovereign AI assistant runs on infrastructure entirely within a defined legal jurisdiction, or on your own servers. Prompts are never sent to a third-party cloud vendor. The organisation retains full control over data storage, retention and access logs.
Which GDPR articles are most relevant for AI assistants in the workplace?
Article 5 (data minimisation and purpose limitation), Article 25 (data protection by design and by default), and Article 28 (processor agreements) are the most directly applicable. The EDPB confirmed this in its April 2024 opinion on AI systems.
Can post-quantum encryption protect prompts sent to a cloud AI?
Post-quantum encryption protects data in transit and at rest from future decryption attacks, but it does not prevent the AI vendor from accessing plaintext prompts during processing. Genuine protection requires that prompts are processed locally, not encrypted data sent to a third party.