If you work under GDPR, one question shadows every AI decision you make. Where does our data end up?
For Microsoft 365 Copilot, the comforting headline is that it’s an EU Data Boundary service. The catch? “Inside the boundary” now carries conditions, and a couple of them flip on by themselves unless someone stops them.
If you’re a regulated body, a council, a financial services firm, a healthcare provider, anyone tied to strict data residency rules, that’s not a line to skim past. It’s a compliance call. So let’s walk through what the EU Data Boundary really promises, where the exceptions hide, and what you need to check.
What the EU Data Boundary Actually Is
The EU Data Boundary is Microsoft’s promise to keep customer data for its big enterprise services, such as Microsoft 365, Azure, Dynamics 365, and the Power Platform, stored and processed within the EU and EFTA.
For Copilot, that usually boils down to two things. Your prompts are processed in EU or EFTA data centres, and the responses from those interactions are stored there too. EU traffic stays inside the boundary; worldwide traffic can travel more freely.
Layered on top are Microsoft’s baseline commitments, and these matter for any GDPR assessment. Your prompts, responses, and Microsoft Graph data aren’t used to train the foundation models.
That’s a big part of why Copilot ranks among the more GDPR-friendly AI tools for European organisations; Microsoft has genuinely put the work into this residency framework.
So far, so reassuring. The devil, as ever, is in exceptions.
Exception One Flex Routing
Now, the change that blindsided many organisations. It goes by the name Flex Routing.
What does it do? It lets Copilot’s large language model processing spill outside the EU Data Boundary into the US, Canada, or Australia when demand spikes. The thinking is resilience. When EU infrastructure is groaning under load, Microsoft can push inferencing elsewhere to keep things snappy.
Two things turn this from a technical footnote into a compliance matter.
One, it’s a default. Flex Routing is switched on for eligible EU/EFTA tenants, so unless someone checks the setting, it’s just running.
Two, your data at rest stays within the EU boundary, but the processing itself can briefly step outside it, and any privacy officer worth their salt will ask the obvious question: is that a third-country transfer, and what legal basis supports it?
Microsoft leans on its existing data protection terms and transfer mechanisms here. Whether that clears your own risk bar is a call only you can make, and if you’re under NIS2, DORA or sector rules, it earns a documented answer, not a shrug.
Here’s the reassuring part, though: you can switch it off. Disable Flex Routing, and processing stays within the EU Data Boundary even during peak demand.
Exception Two Third-Party Models
The second exception is quieter, and just as worth your attention in a compliance review.
Copilot keeps getting more multi-model, with Anthropic’s Claude now sitting alongside OpenAI’s models. Handy, no doubt, but there’s a residency string attached: Anthropic models, delivered as a subprocessor, currently sit outside the EU Data Boundary.
In practice, it’s the admins who decide whether third-party models power their Copilot experiences, and additional terms may apply when they do.
If EU data residency is a hard line for your organisation, this is exactly the setting to look at on purpose, not by accident. We’ve dug into the wider picture in our guide on OpenAI as a subprocessor, and honestly, the two decisions go hand in hand.
Both exceptions point to the same lesson. Model choice and where your data is processed are things you now configure, not things you assume.
The Country-Level Detail Everyone Gets Wrong
One misconception is worth killing off right now, because it catches out team after team.
The EU Data Boundary does not mean your data stays in your own country. A German organisation, say, isn’t promised German-only storage just by being inside the boundary. The boundary is regional. Not national.
Need storage pinned to one specific country? That’s a different product entirely: Advanced Data Residency, an add-on that parks stored Copilot-interaction content in a local country region.
It touches storage, does not process, needs a subscription for every user in the tenant, and runs independently of the Flex Routing setting. If you’ve got real national residency requirements, that’s the lever to reach for, not the boundary on its own.
Your Compliance Checklist
None of this makes Copilot unsafe for regulated use. It just makes it something you set up on purpose. A clear, repeatable routine handles the lot.
- Review Flex Routing in the Microsoft 365 admin centre and decide, consciously, whether to keep it on or disable it
- Check third-party model settings, since Anthropic models sit outside the EU Data Boundary
- Confirm whether Advanced Data Residency is needed for any country-specific storage requirements
- Complete a DPIA before rolling Copilot out to staff who process personal data
- Tighten SharePoint permissions and apply sensitivity labels, because Copilot surfaces what users can already access, faster
- Configure Purview DLP and audit logging for Copilot interactions
- Set a review cadence for Microsoft’s DPA and EU Data Boundary documentation, as these terms change
Work through that, and you shift from hoping you’re compliant to actually knowing it.
This is the exact groundwork our AI Enablement Programme is built around. As an ISO 27001–certified Microsoft partner, Stallions Solutions treats data residency and governance as the first design decision in any Copilot rollout, doubly so for public-sector and regulated clients, where the margin for error is wafer-thin.
Final Thoughts
The EU Data Boundary is a real strength of Microsoft 365 Copilot, and one of the big reasons European organisations trust it.
But a boundary with built-in exceptions is only as strong as the attention you give it. Flex Routing, third-party models, country-level residency- each one turns “where does our data go?” from a settled answer into a setting you own.
When handled with care, Copilot can absolutely meet strict data residency and GDPR obligations. The organisations that get it right are simply the ones that check the settings, write down their decisions, and treat this as an ongoing governance job rather than a box ticked once and forgotten.
If you’d like help reviewing your Copilot configuration against your regulatory obligations, that’s exactly what we do.
Book a free assessment, and we’ll make sure your AI meets the standards your organisation is held to- honest advice, no hard sell.
Frequently Asked Questions
Is Microsoft 365 Copilot within the EU Data Boundary?
Yes. For EU customers, Copilot is an EU Data Boundary service, so prompts are normally processed and responses stored within the EU or EFTA, with some exceptions like Flex Routing and third-party models.
What is Flex Routing?
Flex Routing lets Copilot’s LLM processing occur outside the EU Data Boundary, in the US, Canada or Australia, during peak demand. It’s enabled by default for eligible EU/EFTA tenants and can be disabled in the admin center.
Does the EU Data Boundary keep my data in my own country?
No. The boundary is regional, covering the EU and EFTA, not national. For country-specific storage, you need the Advanced Data Residency add-on.
Are third-party models like Claude inside the EU Data Boundary?
No. Anthropic models, provided as a subprocessor, are currently excluded from the EU Data Boundary. Admins choose whether to enable them.
Is Copilot GDPR compliant?
Copilot is among the more GDPR-friendly enterprise AI tools, thanks to EU data residency, dedicated data protection terms and no-training commitments, provided you configure the exceptions correctly and complete a DPIA.