How to use Microsoft 365 Copilot safely – without exposing private data

How to use Microsoft 365 Copilot safely – without exposing private data | Better AI Decisions

Home / AI for Small Business

AI FOR SMALL BUSINESS

How to use Microsoft 365 Copilot safely — without exposing private data

Microsoft 365 Copilot can work with the Word documents, emails, spreadsheets, meetings and other information you already use at work. That’s what makes it useful. It’s also why you need to understand what it can access before you start asking it questions about your business.

The good news is that you don’t need to be an IT expert to use Copilot sensibly. A few simple habits can make a big difference.

The short answer

Microsoft 365 Copilot doesn’t simply open every file in your business and hand it to everyone. It works within the permissions already set up in Microsoft 365. But if you’ve given someone access to information they shouldn’t have, Copilot can potentially use that information when answering their questions.

So the biggest security question isn’t just “Is Copilot safe?” It’s “Who can already access my business information?”

We’ll send a password for the resource area and regular UK-focused AI updates. Unsubscribe anytime.

What is Microsoft 365 Copilot?

If you’ve used ChatGPT, you’ve probably got the basic idea.

Microsoft 365 Copilot is Microsoft’s AI assistant built into Microsoft 365. Depending on your subscription and setup, you can use it in applications such as Word, Excel, PowerPoint, Outlook, Teams and other Microsoft 365 services.

You can ask it to do things such as:

  • Summarise a long document.
  • Draft an email.
  • Rewrite some text.
  • Find information in your Microsoft 365 content.
  • Summarise a meeting.
  • Analyse information in a spreadsheet.
  • Help create a presentation.
  • Suggest actions from meeting notes.

For a small business, that could save quite a bit of time.

Imagine you run a plumbing business.

You’ve got a pile of emails from customers, suppliers and staff. Copilot might help summarise a long email conversation or turn your meeting notes into a list of jobs.

Or perhaps you run a café.

You could use Copilot in Word to turn your rough notes into a staff procedure, or help write a supplier email.

A hairdresser could use it to draft a customer newsletter.

A retailer could ask it to summarise sales information in Excel.

So why worry about privacy?

Because your Microsoft 365 account contains real business information.

That could include customer names and addresses, employee information, invoices, contracts, prices, supplier details, bank information and commercially sensitive plans.

You need to understand what happens when AI starts working with that information.

The good news about Microsoft 365 Copilot

Let’s deal with one common fear first.

You may have heard that if you use AI with confidential business information, that information is automatically used to train the AI for everyone else.

That’s not how Microsoft describes Microsoft 365 Copilot for work.

Microsoft says that prompts, responses and data accessed through Microsoft Graph aren’t used to train the foundation large language models used by Microsoft 365 Copilot. It also says Copilot operates within your organisation’s existing permissions.

That’s very different from simply pasting confidential business information into an unknown AI website.

But there’s an important catch.

Copilot isn’t a magic security boundary.

It follows the permissions that already exist in Microsoft 365.

Microsoft puts it quite clearly. Copilot only surfaces organisational information that the individual user already has permission to access.

That means if you’ve accidentally given everyone in your business access to a folder containing staff salaries, Copilot may make that information easier for those people to find.

The underlying problem isn’t necessarily Copilot.

It’s the existing access.

“Copilot doesn’t fix bad permissions. It can make the consequences of bad permissions easier to discover.”

That’s probably the single most important thing to understand before using it.

The biggest risk may already be in your Microsoft 365 set-up

Here’s a situation that’s surprisingly easy to create.

You run a small business with five employees.

Years ago, someone created a SharePoint folder called “Company Documents”.

Inside it are:

  • staff information
  • supplier contracts
  • old customer lists
  • pricing information
  • invoices
  • marketing material
  • management documents

Everyone in the company can access the folder.

You don’t think much about it because nobody normally goes looking through it.

Then you introduce Copilot.

An employee asks:

“Summarise our current supplier contracts and tell me which suppliers have the best payment terms.”

If that employee already has permission to see the contracts, Copilot may be able to use that information.

That’s not Copilot breaking into a locked filing cabinet.

The filing cabinet wasn’t locked.

This is why Microsoft talks about preventing “oversharing” when preparing Microsoft 365 for Copilot. Existing permissions and poorly governed content can affect what Copilot can return to users.

For a small business, this sounds technical.

It doesn’t need to be.

The simple question is:

“Can people in my business see files they don’t actually need to see?”

If the answer is yes, fix that before giving Copilot a bigger role.

Caution

Don’t assume “it’s in Microsoft 365” means “everyone should have access”

Microsoft 365 makes it very easy to share documents.

That’s useful.

It’s also easy to forget who you’ve shared something with.

A document might be shared with:

  • one person
  • a team
  • the whole organisation
  • an external person
  • a guest
  • a wider SharePoint site

Reviewing those permissions becomes more important when AI can help people find and summarise information.

Microsoft says Copilot uses the same underlying access controls as other Microsoft 365 services.

So don’t think:

“Copilot can see everything.”

Think:

“Copilot can work with information I already have permission to access.”

That’s a much better way to understand it.

What should you never put into Copilot?

There isn’t a single list of information that every business must keep away from Copilot.

It depends on your subscription, configuration, policies, the type of information and what you’re asking Copilot to do.

But you should still be careful with highly sensitive information.

Think before entering or asking Copilot to process things such as:

  • passwords
  • banking credentials
  • security codes
  • private encryption keys
  • confidential information that isn’t needed for the task
  • highly sensitive employee information
  • information about someone’s health
  • private customer information
  • commercially sensitive information
  • information supplied to you under a confidentiality agreement

The principle is simple.

Don’t give an AI more information than it needs to do the job.

That’s good practice whether you’re using Copilot, another AI tool or no AI at all.

The ICO’s guidance on AI and data protection emphasises data minimisation and security. In plain English, you should think carefully about what personal information you’re using and put appropriate safeguards around it.

Tip

Ask “Does Copilot need this?”

Before putting information into a prompt, ask:

“Does Copilot actually need this information to do what I’m asking?”

If the answer is no, leave it out.

For example, instead of:

“Write an email to John Smith at 14 High Street explaining that his £3,275 invoice is overdue.”

You could write:

“Write a polite email to a customer explaining that an invoice is overdue.”

You can add the specific details yourself afterwards.

You haven’t lost much time.

You’ve reduced the amount of unnecessary personal and financial information being included in the prompt.

Copilot can see more than the document in front of you

This is another point worth understanding.

Microsoft 365 Copilot can use information from across the Microsoft 365 environment where the user has permission to access it.

Microsoft describes this as using Microsoft Graph to connect Copilot to organisational information such as documents, emails, calendar information, chats, meetings and contacts.

That can make Copilot much more useful.

But it also means you shouldn’t think of it simply as:

“An AI button inside Word.”

Depending on the Copilot feature you’re using, the information available to it can extend beyond the document currently open on your screen.

Imagine you ask:

“Prepare a summary of everything we discussed with this customer.”

That could involve information from several places in Microsoft 365.

That’s convenient.

It also means you need to be comfortable with the access you’ve already given people.

If you’re the only person running your business, this is relatively straightforward.

If you have several employees, temporary staff, contractors or external collaborators, it’s worth spending some time reviewing your Microsoft 365 sharing arrangements.

What about private customer and employee information?

This is where you need to be particularly careful.

Suppose you’re a small employer.

You have an Excel spreadsheet containing employee information and perhaps notes about absences, pay and other matters.

You shouldn’t casually ask:

“Analyse this spreadsheet and tell me which employees are unreliable.”

There are several problems here.

The information may be personal.

The question may be unfair or based on assumptions.

And an AI-generated summary isn’t necessarily a sound basis for making a decision about a person.

The ICO says that data protection law applies when personal information is used with AI. It also stresses the importance of meaningful human oversight where AI is involved in decisions about individuals.

For a small business, the practical rule is simple:

Use Copilot to help you work with information.

Don’t let it quietly become the decision-maker.

A simple example

Imagine you own a small retail shop.

You ask Copilot:

“Look at these customer complaints and tell me which customers are likely to cause problems in future.”

That sounds like a useful shortcut.

But what exactly does “likely to cause problems” mean?

Copilot might spot patterns in the information. It might also make assumptions that aren’t fair or accurate.

A much safer use would be:

“Summarise the main issues raised in these customer complaints and group them by topic.”

Now Copilot is helping you understand the information.

You’re still making the judgement.

That’s a much better role for AI.

Don’t let Copilot make you think a private document is automatically safe

There’s another important distinction.

Microsoft’s business protections are not the same thing as saying:

“Anything I do with Copilot is automatically compliant with UK data protection law.”

It isn’t.

You remain responsible for how your business uses personal information.

The ICO’s AI guidance says organisations need to consider lawfulness, fairness, transparency, data minimisation, accuracy, security and accountability when using AI with personal data.

Microsoft can provide the technology and security controls.

It can’t decide whether your particular use of customer or employee information is appropriate.

That’s your responsibility.

Be careful with personal Microsoft accounts

This is an easy mistake for a small business.

You have Microsoft 365 at work.

You also have a personal Microsoft account.

You open Copilot while signed into the wrong account.

Now you’re dealing with a completely different service and different privacy arrangements.

Microsoft distinguishes between Microsoft 365 Copilot used with a work or school account and Copilot used with a personal Microsoft account.

So check which account you’re using.

If you’re working on business information, make sure you’re using the business Microsoft 365 environment intended for that work.

Don’t copy confidential business information into a personal AI account simply because it’s convenient.

Microsoft 365 Copilot can also use web search in some situations.

That’s useful when you need current information.

But it creates another reason to pay attention to what you’re asking.

Microsoft says that when web search is used, Copilot may send search queries to Bing based on your prompt. Microsoft also describes separate data-handling arrangements for those web searches.

You don’t need to understand the technical architecture.

Just remember this:

If your question contains confidential business information, don’t assume that adding “search the web” makes it harmless.

Keep prompts focused.

For example, instead of:

“Search the web and tell me how our customer John Smith’s company is performing.”

Ask:

“What are the main factors I should consider when assessing a customer’s financial reliability?”

You can then apply those factors yourself using the information you have.

How to use Copilot safely in a small business

You don’t need a 50-page AI policy.

Start with a few rules everyone can understand.

  1. Use your business Microsoft 365 account – Don’t mix personal and business accounts when working with company information.
  2. Give people access to what they need – If someone doesn’t need access to a folder, don’t give them access.
  3. Review old shared folders – Look at the folders and documents you’ve accumulated over the years. Ask who can access them.
  4. Don’t put passwords into Copilot – Ever. Use a password manager or another appropriate security system instead.
  5. Don’t paste unnecessary personal information into prompts – If the task can be completed without a name, address, phone number or other personal detail, leave it out.
  6. Check important answers – Copilot can make mistakes. Read the output before sending it to a customer or using it to make a decision.
  7. Keep a human in charge – Especially when the answer affects a customer, employee, payment, contract or other important business decision.
  8. Be careful with third-party agents and add-ons – Microsoft 365 can be extended with additional agents and services. Microsoft advises checking the privacy statement and terms of an agent to understand how it handles your organisation’s data.

You don’t have to use Copilot for everything

This is worth saying.

Microsoft 365 Copilot can be useful.

But that doesn’t mean you should use it everywhere simply because you’ve paid for it.

If you’re a self-employed plumber and Copilot saves you 20 minutes writing customer emails, great.

If you’re a two-person café and you don’t have a problem that Copilot solves, don’t invent one.

AI isn’t automatically an improvement.

A useful question is:

“What job am I trying to make easier?”

Then decide whether Copilot is actually the best answer.

Sometimes it will be.

Sometimes a template, spreadsheet or five-minute conversation will be better.

A 15-minute Copilot safety check

If you’re already using Microsoft 365, here’s a useful exercise.

Set aside 15 minutes.

Look at:

  • Who can access your main SharePoint folders?
  • Who can access staff information?
  • Who can access customer information?
  • Who can access financial information?
  • Which documents are shared externally?
  • Are former employees still listed?
  • Are old accounts still active?
  • Are there folders where “everyone” has access?
  • Are you using personal Microsoft accounts for business information?
  • Does everyone know what information they shouldn’t put into AI?

You don’t need to fix everything in one afternoon.

Start with the obvious problems.

If you’re unsure how your Microsoft 365 permissions are configured, ask whoever manages your Microsoft 365 account to review them.

For a very small business, that might be you.

And if you don’t feel confident doing it, paying someone for a short security review can be much cheaper than dealing with a serious data breach later.

The golden rule

There’s one rule that ties all of this together.

“Give Copilot the minimum information and access it needs to do the job — and make sure the people using it only have access to information they actually need.”

That isn’t complicated.

It’s just sensible housekeeping.

Microsoft 365 already has security and permission controls. Copilot works within those controls rather than creating a completely separate set of permissions.

But those controls are only as good as the way you’ve set up and managed your Microsoft 365 environment.

If your filing cabinet is badly organised, putting an AI assistant in front of it doesn’t solve the problem.

It can make the problem easier to see.

Microsoft 365 Copilot AI Safety Small Business UK Business Data Protection

AI FAQs

Questions people ask about Microsoft 365 Copilot and data privacy

These are the practical questions UK business owners are asking about using Copilot safely.

Is Microsoft 365 Copilot safe for small businesses?

It can be, provided you use it properly and have sensible Microsoft 365 permissions and security controls in place. Microsoft says Microsoft 365 Copilot works within users’ existing permissions and that prompts, responses and Microsoft Graph data aren’t used to train the foundation models.

The bigger risk may be poor access controls that already exist in your Microsoft 365 account.

Can Microsoft Copilot see all my files?

No. Microsoft says Copilot only accesses organisational information that the individual user has permission to access.

However, that can still include a lot of information if your Microsoft 365 permissions are too broad.

Can I use Microsoft Copilot with confidential business information?

Microsoft 365 Copilot for work is designed to provide business data protections, and Microsoft says prompts, responses and data accessed through Microsoft Graph aren’t used to train the foundation models.

That doesn’t mean you should put every piece of confidential information into Copilot. Only provide information that’s needed for the task and make sure your organisation’s access controls are appropriate.

Can I put customer information into Copilot?

It depends on what information you’re using, why you’re using it and how you’ve configured your Microsoft 365 environment.

If you’re processing personal information, UK data protection requirements still apply. The ICO recommends a risk-based approach and appropriate safeguards when AI is used with personal data.

Avoid putting unnecessary personal information into prompts.

Can my employees use Copilot to read other people’s emails?

Copilot doesn’t simply give employees permission to read somebody else’s email. Microsoft says it works within the user’s existing permissions.

But if you’ve already given someone inappropriate access to information, Copilot may make that information easier for them to discover and summarise.

That’s why reviewing permissions matters.

Should I use Microsoft Copilot or ChatGPT for my business?

There’s no universal answer.

If your business already runs heavily on Microsoft 365, Copilot’s ability to work within that environment may make it particularly useful.

But the best AI tool is the one that solves a real problem without creating unnecessary risk or cost.

You don’t need to use AI simply because everyone else is.

Sources

  1. Microsoft — Data, Privacy, and Security for Microsoft 365 Copilot ★★★★☆ Vendor documentation
    Microsoft’s documentation explains how Microsoft 365 Copilot accesses organisational information through Microsoft Graph, how existing permissions control access and how prompts, responses and accessed data are handled.
  2. Microsoft — Microsoft 365 Copilot architecture and how it works ★★★★☆ Vendor documentation
    Useful technical background on how Copilot accesses Microsoft 365 information and why existing user permissions matter.
  3. Microsoft — Frequently asked questions about Microsoft 365 Copilot Chat ★★★★☆ Vendor documentation
    Explains Copilot’s use of existing access controls and Microsoft’s approach to prompts, responses and organisational data.
  4. Microsoft — Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat ★★★★☆ Vendor documentation
    Details Microsoft’s enterprise data protection commitments, including treatment of prompts and responses and the relationship with Microsoft Graph data.
  5. Information Commissioner’s Office — Artificial intelligence ★★★★★ UK regulator
    The ICO’s central AI guidance explains how UK data protection requirements apply to organisations using AI and provides links to detailed guidance and a practical AI risk toolkit.
  6. Information Commissioner’s Office — Guidance on AI and data protection ★★★★★ UK regulator
    Covers lawfulness, fairness, transparency, data minimisation, accuracy, security and accountability when personal information is used in AI systems. The ICO currently notes that this guidance is under review following changes made by the Data (Use and Access) Act 2026.
  7. Information Commissioner’s Office — How do we ensure individual rights in our AI systems? ★★★★★ UK regulator
    Explains individual rights and the importance of meaningful human oversight when AI is involved in decisions affecting people.
  8. National Cyber Security Centre — AI and cyber security ★★★★★ UK cyber security authority
    Provides UK-focused guidance on the security risks associated with generative AI and practical considerations for organisations.

⚠️ Evidence note: Microsoft’s statements about Microsoft 365 Copilot’s data handling describe Microsoft’s product architecture and contractual commitments. They shouldn’t be read as a guarantee that every possible use of Copilot is appropriate for every business.

In particular, “Microsoft doesn’t use prompts and responses to train its foundation models” does not mean “you can safely put anything into Copilot”. Your own permissions, Microsoft 365 configuration, business processes and legal responsibilities still matter.

The ICO’s guidance also makes clear that organisations using AI with personal information need to take a risk-based approach and put appropriate safeguards in place. Its current guidance is under review following changes to UK data protection law in 2026, so businesses should check the latest ICO material when making decisions about higher-risk uses of AI.

Check your access before you add AI

Before you start using Copilot across your business, spend 15 minutes checking who can access your important files and folders. Good AI security starts with good basic security.

Explore more practical guidance →