Skip to main content
WAIMAKERS
About UsCareersContact
|
Schedule Free Call
Back to AI Tools & Comparison
ChatGPTvsMicrosoft CopilotComparison

ChatGPT vs Microsoft Copilot

OpenAI & Microsoft

ChatGPT & Microsoft Copilot GDPR Compliance Report - European Clients

Version: June 2026 - prepared by WAIMAKERS B.V.


1 Purpose

This report provides European clients with insights into how ChatGPT and Microsoft Copilot subscriptions handle personal data in relation to the General Data Protection Regulation (GDPR). Both platforms use large language models but differ in enterprise data protection and compliance.


Capability & feature comparison

Beyond compliance, here is how the two compare on everyday capabilities. This compares Microsoft 365 Copilot (the paid work product); the free consumer Copilot has far fewer features. Mid-2026 - features evolve quickly.

Capability What it is ChatGPT (OpenAI) Microsoft 365 Copilot
Reasoning models Slower "thinking" mode for hard problems ✅ GPT-5.5 Thinking / Pro ✅ GPT-5.x + Anthropic Claude (model picker)
Grounding in your org data Answers built from your mail, files, chats ⚠️ Only via connectors ✅ Native (Microsoft Graph)
Web search Live web answers with citations ✅ All plans ✅ Bing web grounding
Deep research Agent researches → cited report ✅ Deep Research ✅ Researcher agent
Custom assistants / agents Build your own assistants and agents ✅ Custom GPTs + GPT Store ✅ Agent Builder + Copilot Studio
AI agents / computer use Takes actions autonomously, drives a browser ✅ ChatGPT agent ✅ Copilot Studio agents + computer use
Skills Packaged reusable instructions/scripts ⚠️ Beta (business tiers) ❌ Uses agents + Prompt Gallery instead
Connectors & plugins (MCP) Connect to apps and data ✅ Apps & Connectors, MCP ✅ Graph connectors + MCP (Copilot Studio)
Office files (Excel / PowerPoint / Word) Build & edit real Office documents ⚠️ Weaker at Office formatting ⚠️ Excel improved (now runs Claude); PowerPoint weaker
Code & data analysis Runs code on your data, builds charts ✅ Advanced Data Analysis ✅ Analyst agent + Python in Excel
Image generation Create images from a prompt ✅ Native image model ✅ Copilot Designer
Voice mode Spoken conversation ✅ Advanced Voice ✅ Copilot Voice
Memory Remembers context across sessions ✅ All plans ✅ Copilot Memory
Office integration AI inside Word, Excel, PowerPoint, Outlook, Teams ❌ Not native ✅ Native across Office apps
Meeting notes & summaries Capture and summarise meetings ❌ Not native ⚠️ Native to Teams; output quality mixed
Apps & platforms Where you use it Web, desktop, mobile, Codex Office apps, Teams, Windows, Edge, web, mobile

A ✅ marks that a capability is available - not how capable or mature it is. A feature existing in Copilot does not mean it matches a frontier assistant in practice; where each tool genuinely excels is summarised below.

What each is best at

  • ChatGPT (OpenAI) - a frontier assistant built by the lab that makes the models, so new capabilities arrive first and in their most complete form: general reasoning, research, coding, native image generation, voice, and Custom GPTs. Strong as a standalone, general-purpose assistant for open-ended work.
  • Microsoft 365 Copilot - an AI layer woven into the Microsoft 365 apps you already use, grounded in your organisation's own data (Microsoft Graph). Best for drafting in Word and Outlook, summarising Teams meetings, and answering from internal files - for people who work mostly inside Office.

Our take: the key difference is structural. Copilot doesn't build its own frontier models - it runs OpenAI's (and now Anthropic's) behind the Microsoft 365 experience, so on raw capability it sits a step behind the labs that make the models. In our hands-on use it's clearly weaker for most document work: its Excel plugins lag well behind Claude's, and its meeting summaries are mediocre. Where it has closed the Excel gap, it's largely because it now runs Anthropic's Claude inside those Office experiences. Copilot's genuine, repeatable advantages are trust and reach: your data stays on Microsoft servers (a GDPR and procurement story most organisations already accept), and it lives natively inside Outlook, Teams and Office. It's worth being clear that this trust is a choice of which company you trust, not a capability gap - OpenAI, Anthropic and Microsoft all commit not to train on your business data; Copilot's edge is simply that most organisations already trust Microsoft. Use Copilot to bring AI into Microsoft 365 on your own data; use a frontier assistant like ChatGPT or Claude when the work rewards capability.

Copilot doesn't build its own AI models - it runs other companies' models, so it sits further from the innovation.

  • Wouter van Haaften, WAIMAKERS

2. ChatGPT Comparison of Versions

Plan GDPR-Compliant? EU Data Residency Processing/Storage Retention Guide Price* DPA / Policy Quote
Free / Plus ⚠️ Limited for business ❌ No Global; U.S.-based infra Undefined; persists unless deleted €23/mo (incl. VAT NL) “Business data not used for training; consumer plans can opt out.”
ChatGPT Go (lower consumer tier, where available) ❌ Not suitable for business ❌ No Global; no EU residency option Undefined Check current OpenAI pricing No business GDPR safeguards; consumer terms only. No DPA available.
ChatGPT Business (renamed from Team, Aug 29, 2025) ✅ Yes ❌ No (no EU-only option yet) OpenAI infra; contracting via OpenAI Ireland Ltd. Deleted/unsaved chats removed ≤30 days €25/seat/mo (monthly) or €20/seat/mo (annual), excl. VAT; credit pack system available for overflow usage “We do not train on business data by default.” DPA available.
ChatGPT Enterprise / Edu ✅ Yes ✅ Yes (regional at-rest + inference residency where supported) Customer content can be stored in the selected supported region; GPU inference residency is available in supported regions when enabled Admin configurable; deleted chats removed ≤30 days Custom (EUR) OpenAI documents ChatGPT storage regions, inference regions, and excluded features.
OpenAI API (Business/Edu) ✅ Yes ✅ Yes (eligible API projects/endpoints) API residency is eligibility-, project-, and endpoint-dependent; non-US residency requires approved abuse-monitoring controls and a ZDR amendment Up to 30 days by default for abuse monitoring; ZDR/MAM available only for approved eligible use cases Usage-based (USD list; invoiced in EUR) “API inputs/outputs may be retained up to 30 days by default; ZDR/MAM and residency require eligibility/approval.”
  • Guide prices based on publicly available info as of June 2026. VAT handling varies by plan/company status.

3. Microsoft Copilot Comparison of Versions

Plan GDPR-Compliant? EU Data Residency Processing/Storage Retention Guide Price* DPA / Policy Quote
Microsoft Copilot (web) ⚠️ Limited ❌ No Global datacenters; consumer terms Not specified Free Consumer protections only; no M365 DPA.
Copilot Pro (consumer) (retired to new customers; superseded by Microsoft 365 Premium) ⚠️ Limited ❌ No Global datacenters; consumer terms Not specified Legacy; no longer sold to new customers (support ends Aug 1, 2026) Personal plan; no M365 DPA.
M365 Copilot Chat (work) ✅ Yes ✅ Yes (EU Data Boundary) Commercial tenant w/ Entra ID; ⚠️ web search excluded Configurable via Purview/M365 Included with eligible M365 license Covered by DPA & EU Data Boundary; web search excluded. Now a Core Online Service under EU Data Boundary (Sept 2025).
M365 Copilot (add-on) ✅ Yes ✅ Yes (EU Data Boundary) EU Data Boundary for M365 content; Anthropic Office models outside EUDB if enabled Configurable via M365 policies €28.10/user/mo (annual, excl. VAT); Microsoft pricing and bundled SKUs change frequently, so verify current prices before purchase. Prompts/responses are not used to train foundation models for others; GDPR-supportive under Microsoft commercial terms and DPA. ⚠️ Anthropic/Claude in Word/Excel/PowerPoint can be on by default for EU/EFTA/UK tenants created after Mar 25, 2026 and is excluded from EU Data Boundary.
GitHub Copilot Business ✅ Yes ⚠️ Conditional Depends on tenant & GitHub region ~30 days $19 USD/user/mo (EUR billed at FX) Covered by GitHub Enterprise DPA; separate from M365.
Microsoft Security Copilot ✅ Yes ⚠️ Limited Azure datacenters; SCU workloads Usage-based; retention per product Priced per SCU/hour Capacity billed hourly per SCU.
  • Guide prices as of June 2026, excl. VAT/discounts.

4. Key Differences

  • Foundation: Both rely heavily on OpenAI models; Microsoft Copilot now also uses Anthropic and other models.
  • ChatGPT: General-purpose assistant (standalone app + API).
  • Copilot: Productivity AI in Microsoft 365, GitHub, Security.
  • Compliance:
    • ChatGPT: regional at-rest and inference residency are available for eligible Enterprise/Edu workspaces; API residency and ZDR/MAM controls require endpoint, project, contract, and approval checks.
    • Copilot: EU Data Boundary (M365); ⚠️ web search excluded; Anthropic/Claude Office model setting requires tenant-level review because it may be on by default for EU/EFTA/UK tenants created after Mar 25, 2026 and is outside EUDB.

5. GDPR Recommendations

  • General use: ChatGPT Business or Enterprise (EU at-rest).
  • M365 productivity: M365 Copilot add-on; disable web search.
  • Dev work: GitHub Copilot Business or ChatGPT Enterprise.
  • Security ops: Microsoft Security Copilot with SCU controls.

6. Compliance Considerations

  • ChatGPT: Free/Plus unsuitable for personal data; Business lacks EU residency; Enterprise/Edu needed for EU storage; ChatGPT Go offers only consumer-level terms with no business DPA or EU data residency.
  • Copilot: Web search outside EU Data Boundary; consumer plans lack DPAs; Anthropic/Claude now a subprocessor and Office model provider, but excluded from EU Data Boundary. For EU/EFTA/UK tenants created after Mar 25, 2026, the app-level setting can be on by default, so admins should verify it before EUDB-sensitive rollouts.
  • Shared: Conduct DPIA, review DPAs, train staff.
  • Regulatory actions: Italy’s Garante fined OpenAI €15M (Dec 2024) for GDPR violations related to ChatGPT, but the Court of Rome upheld OpenAI's appeal and annulled the fine in March 2026 (judgment No. 4153/2026, published 18 March 2026); during the investigation OpenAI established its EU headquarters in Ireland and, under the one-stop-shop mechanism, the Irish DPC became OpenAI's lead supervisory authority. The EDPB issued an Art. 64 opinion on AI model training and personal data (Dec 2024). The Irish DPC is the lead supervisory authority for OpenAI in Europe.

7. Cost Comparison (Illustrative)

  • Small team (10 users):
    • ChatGPT Business: ~€300/mo excl. VAT.
    • M365 Copilot add-on: ~€281/mo excl. VAT (annual).
  • Medium enterprise (100 users):
    • M365 Copilot add-on: ~€2,810/mo excl. VAT (annual).
    • ChatGPT Enterprise: Custom.
  • Security Copilot: SCU/hour, variable.

8. Implementation Roadmap

  1. Assessment (Weeks 1-2): DPIA, licensing, use cases.
  2. Pilot (Weeks 3-6): Configure retention/DLP; monitor usage.
  3. Rollout (Weeks 7-12): Training, governance, compliance review.

9. Disclaimer

This report is informational only and not legal advice. Verify terms directly with vendors. WAIMAKERS B.V. applies these principles internally but cannot be held liable. Compliance responsibility rests with the customer.


References

OpenAI:

  • https://openai.com/enterprise-privacy - OpenAI Enterprise Privacy
  • https://openai.com/index/introducing-data-residency-in-europe - OpenAI Data Residency in Europe
  • https://help.openai.com/en/articles/9903489-data-residency-for-chatgpt - Data residency and inference residency for ChatGPT
  • https://help.openai.com/en/articles/10503543-data-residency-for-the-openai-api - Data Residency for the OpenAI API
  • https://openai.com/policies/data-processing-addendum - OpenAI Data Processing Addendum (updated Jan 1, 2026)

Microsoft Copilot:

  • https://learn.microsoft.com/microsoft-365-copilot/microsoft-365-copilot-privacy - Microsoft 365 Copilot Privacy Documentation
  • https://learn.microsoft.com/en-us/microsoft-365/copilot/copilot-anthropic-apps - Copilot in Microsoft 365 apps with Anthropic models

Regulatory:

  • https://www.garanteprivacy.it/ - Italy Garante €15M fine on OpenAI (Dec 2024); annulled by the Court of Rome (March 2026) on jurisdictional grounds
  • https://www.edpb.europa.eu/ - EDPB Art. 64 Opinion on AI model training and personal data (Dec 2024)

Disclaimer

This overview is intended solely as an informative tool. We strongly advise customers to thoroughly review all Data Processing Agreements (DPAs) and privacy documentation before deploying ChatGPT or Microsoft Copilot in production environments - especially when personal data, proprietary business information, or confidential content are processed. WAIMAKERS applies this same principle internally; all tools we use have been thoroughly assessed and included in our own privacy and security documentation. Customers should always carefully evaluate the official documentation, terms, and DPAs of each AI provider they use. WAIMAKERS cannot be held legally liable for any mistakes, errors, inaccuracies, or for the accuracy, currency, or completeness of the information in this document; the ultimate responsibility for GDPR compliance rests with the customer.

Prepared and issued by WAIMAKERS B.V. - June 2026.

Need help navigating AI?

Schedule Free Call
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAgentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy