The Dutch government's Microsoft 365 Copilot DPIA (data protection impact assessment), dated 17 December 2024, found four high risks and advised government organizations not to use it. Two updates later, on 27 May 2026, the count stood at two medium and nine low. Microsoft changed enough to clear the red flag. On the last two, it offered no new information or effective additional measures.
Those two medium risks are inaccurate personal data in Copilot's answers, where the sticking point is a "Workplace Harms" filter that Microsoft has described in two sentences and customers cannot switch off, and diagnostic data kept for up to 18 months without adequate justification. The nine low risks are different: the government's memos say organizations can mitigate them themselves.
Then the regulator weighed in. On 13 July 2026 the Dutch data protection authority, the Autoriteit Persoonsgegevens (AP), published its advice to the municipality of Haarlemmermeer, which had consulted it before piloting Copilot with 15 to 20 staff. The AP concluded that the plan as described would infringe the GDPR. Most of the measures it listed are work the customer does, not Microsoft, and that list is what a private company should copy into its own Microsoft 365 Copilot DPIA.
Who ran the Dutch Copilot assessments, and why do the counts differ?
Two Dutch bodies commissioned the same consultancy, Privacy Company, to assess Copilot in parallel. SLM Rijk, the central government's vendor management office at the Ministry of Justice and Security, assessed Copilot on the government's Microsoft 365 E5 license. SURF, the IT cooperative for Dutch higher education and research, assessed the education license and shared the technical testing. The tests ran in spring 2024 in Word, Excel, PowerPoint and Outlook.
The totals differ by one. SURF's version carries an extra low risk about inaccurate author names in Copilot replies, so if you have seen "two medium and ten low", that is the education figure from SURF's May 2026 update. For a private company on an enterprise license, the government report is the closer match, and it is the one this post follows.
| Date | Document | Government (E5) | SURF (education) | Government advice |
|---|---|---|---|---|
| December 2024 | Original DPIA | 4 high, 6 low | 4 high, 7 low | Do not use |
| 11 September 2025 | First update | 2 medium, 8 low | 2 medium, 9 low | Usable under conditions, provided an AI usage policy is in place |
| 27 May 2026 | Second update | 2 medium, 9 low | 2 medium, 10 low | Unchanged; weigh whether the medium risks are acceptable |
In a status memo dated 30 July 2026, the office, renamed SLM Cloud, advised restraint in deploying Copilot, "partly in light of digital autonomy and sovereignty" (our translation from the Dutch).
What were the four high risks, and what did Microsoft change?
The December 2024 report rated these four as high:
- People could not exercise their right of access to diagnostic data, because Microsoft's answers to access requests were incomplete and hard to understand.
- Generated text containing inaccurate personal data could cause significant economic or social disadvantage.
- Microsoft did not adequately document the "Required Service Data" it collects, including telemetry from the web apps, so customers lost control of it.
- Unknown retention periods for that data raised the risk that pseudonymized records could be re-identified.
Three of the four came down to Microsoft's transparency, and the report said government bodies could not mitigate two of them on their own. One test result is hard to forget. Asked to write a police report about a non-binary person from a first-person incident account with no gender indicated, Copilot changed the prompt's "they" to "he". The covering memo of 18 December 2024 put the verdict in one line: "Based on the current findings of the DPIA, M365 Copilot cannot yet be used in a compliant way" (our translation).
Between December 2024 and May 2026, the updates credit Microsoft with these changes:
- Access requests return telemetry and Required Service Data (main events only), with a Readme.
- New public documentation of what Required Service Data is and how it is structured.
- Two of three agreed accuracy features: a sidebar of source references, and an admin option to make the "AI-generated results may be inaccurate" warning bold and link it to your internal AI policy. The third, deep citations inside sources, was due in June 2026.
- Enterprise admins can let users switch off the Harmful Content filter per chat.
- Purview data loss prevention for Copilot prompts in enterprise tenants.
- A recommended group policy to block Bing in free and paid Copilot.
- An annual meeting on accuracy, plus an escalation route for complaints about wrong personal data.
That moved the access and transparency risks down to low and the other two to medium.
Which risks remain after May 2026, and who has to act?
Here is the government report's own list, with its measures condensed.
| Finding | Status after the 2026 update | Who has to act |
|---|---|---|
| Inaccurate personal data in output; the Workplace Harms filter is undocumented and cannot be disabled | Medium | Microsoft on the filter. You on the rest: usage policy, checking personal data, licenses off accounts with HR data access, Bing off, audit logging |
| Up to 18 months' retention of pseudonymized diagnostic data, unexplained | Medium | Microsoft. The report lists no customer measure except deleting accounts or ending the contract |
| Transparency of Required Service Data (was high) | Low | You: update privacy notices from Microsoft's new documentation; set telemetry to "required" |
| Access requests for diagnostic data (was high) | Low | You: file a test request and compare the output with the documentation |
| Incidental transfers to support staff in 30 third countries | Low | You: use professional support, not in-app support |
| Flex routing outside the EU Data Boundary, new in March 2026 | Low | You: on new tenants, change the default and disable it |
| Wrong personal data regenerated after a complaint | Low | You: file a Professional Services support request |
| Further processing by Microsoft through defaults (Bing, the public Feedback forum, free Copilot versions) | Low | You: disable them |
| Microsoft mailings to licensed users | Low | You: use the central opt-out |
| Chilling effects: Copilot logs as an employee monitoring system | Low | You: write purpose rules for dialogue and log data |
| Loss of control over content in the Microsoft Graph | Low | You: Copilot DLP, labeling, SharePoint and Outlook cleanup |
Read the last column. Microsoft holds one risk outright and shares another. The low risks sit with you, and the government's September 2025 memo says so directly: "The low risks can be mitigated by the organizations themselves, through technical and organizational measures" (our translation).
Low is an honest rating, and nothing in the May 2026 report is high. Low does not mean handled, though: the September 2025 memo urged government bodies to implement every measure before use. Flex routing has its own write-up in our post on the GPT-5.6 subprocessor change, including where the setting lives.
What did the Dutch DPA add?
Under Article 36 of the GDPR, a controller whose DPIA shows a high risk it cannot mitigate must consult its supervisory authority before processing starts. Haarlemmermeer filed that request on 11 June 2025, for a pilot covering its customer contact center, its objections and appeals process, and communications. The AP published the advice alongside a practical checklist for organizations deploying generative AI.
Its conclusion, in our translation: the intended processing "would infringe the GDPR". The formal advice is a single sentence: "Do not start the intended processing until the measures above have been taken."
One caveat outweighs the rest. The municipality relied on the December 2024 report, so the AP assessed the four original high risks. It said the GDPR's response deadline left too little time to assess the September 2025 update, and noted that some of that update's measures were marked confidential. The advice is therefore not a ruling on Copilot as it stood in 2026. Its reasoning about the customer's side does not depend on the version:
- A reference DPIA is not your DPIA. The AP said the government report "does not meet the requirements of Article 35 GDPR", while offering valuable insight into how Copilot works (our translation).
- "Supporting the employee" is not a purpose. The AP found that description too vague and too general to count as a specified, explicit purpose.
- Data you already hold still counts. The AP rejected the municipality's view that the pilot involved no new processing of personal data.
- A vendor gap is the controller's problem. If a supplier offers no settings to limit what the AI can reach, the organization is not released from the GDPR, and the system cannot be put into use.
- Decision workflows raise Article 22. The AP found it very likely that objections and appeals involve individual decisions with legal effects, and said human involvement has to stay decisive.
- The groundwork comes first. A current record of processing, a picture of what personal data you hold, labeling, an authorization review and a check of existing cloud processing. The AP was explicit that this work should not begin only once the AI system is in use.
It also endorsed the government report's preconditions: block Bing in Copilot, block the free consumer versions, close the public Feedback forum, stop the pre-filled sign-up for Microsoft marketing email, and set retention for prompts and responses centrally. It added that a small pilot in the lowest-risk use cases may be needed to verify the measures, and must itself comply.
Why does all of this land on the customer? The AP supervises the municipality, not Microsoft. For Microsoft, the lead authority under Article 56 of the GDPR is Ireland's Data Protection Commission.
Does a Dutch verdict matter outside the Netherlands?
Not as law. These are two buyers' assessments and one authority's advice to one municipality. Two things travel anyway.
The legal analysis in both DPIAs starts from framework contracts that Dutch buyers negotiated with Microsoft, under which Microsoft acts as processor. A company on different terms has to redo that role analysis against its own contract, and clarifying each party's role is the first Copilot-specific measure on the AP's list.
The duty to assess is not Dutch either. Norway's Datatilsynet, in a November 2024 sandbox report on a Copilot pilot at the university NTNU, wrote: "We consider that, as a general rule, a DPIA will be required when using generative AI tools such as M365 Copilot in connection with the processing of personal data." The UK GDPR keeps the same Article 35 duty. Switzerland's Federal Act on Data Protection requires an impact assessment beforehand where processing is likely to result in a high risk.
What should a private company copy from the DPIA?
If Copilot is already live, run these steps as a retrospective assessment. They do not change.
- Write your own DPIA. Use the Dutch reports as the reference. The government's September 2025 memo itself tells each body to decide whether its own use needs an additional DPIA.
- Name a purpose per use case. Mark the workflows where decisions about people are made, and keep Copilot output from making them.
- Decide what Copilot can reach before it reaches it. Keep licenses off accounts with access to sensitive data such as HR data, label what must stay out, and review permissions. Our 30-day oversharing plan and guide to how Copilot inherits permissions cover the mechanics.
- Close the defaults the DPIA flagged. Bing access in Copilot and Copilot Chat, the free consumer Copilot, the public Feedback forum, Additional Optional Connected Experiences, Microsoft mailings, telemetry above "required", and flex routing on newer tenants. Then set retention for prompts and responses. The government's Dutch-language admin manual (version 3.5, 24 April 2026) walks through most of these.
- Write the usage policy the DPIA prescribes. The measure reads: "Create a generative AI usage policy for employees to define correct usage and explain DLP rules if activated." Add when staff may switch off Harmful Content filtering, a rule that personal data in output gets checked against an independent source, and where complaints about wrong personal data go. Then link it from the accuracy warning.
- Log, sample, and limit the sampling. The DPIA says to enable audit logging and check samples of dialogues against your rules. The same report lists Copilot logs as a chilling-effects risk, so decide in writing what the logs may be used for before anyone reads them.
- Test the rights path. File a test access request, and route complaints about inaccurate personal data through Professional Services support.
- Decide on the two medium risks in writing. The May 2026 memo says choosing Copilot "entails medium GDPR risks" and that acceptance turns on "the nature and sensitivity of the data to be processed and the specific use case" (our translation). If your assessment still ends at high residual risk, Article 36 applies to you as it did to Haarlemmermeer.
- Re-run it when scope changes. The reports exclude Copilot in Teams, Copilot Studio, features added after April 2024, and Anthropic models. Agents and meeting features in your tenant sit outside what the Dutch tested.
Why does the usage policy carry so much of the weight?
Because the government made it the condition. The September 2025 memo said Microsoft's improvements make responsible use possible "provided a policy for AI use has been adopted" (our translation). The May 2026 report repeats that organizations "must draft clear policies about the use of generative AI" and "seriously monitor the quality of work generated with Copilot."
A policy only covers what you can see. The DPIA notes that since mid-September 2024, unlicensed enterprise users have been signed in to the free Copilot Chat automatically, and that its conclusions do not carry over to free versions. Tools that employees adopt on their own sit outside the assessment entirely. Step six assumes you can observe usage at all.
If you need a starting point, our AI acceptable use policy template (DOCX) is drafted as clause text, with a permission matrix that maps your data classes to tool tiers defined by contract.
Last verified: 8 October 2026, against the government DPIA and both updates, the SLM memos of December 2024, September 2025, May 2026 and July 2026, SURF's May 2026 update, the AP's advice and Datatilsynet's NTNU report.
This is not legal advice. Quotations from Dutch documents are our translations, so check the originals with counsel before relying on them.