NewsData ProtectionAI RegulationMicrosoft

Microsoft Copilot Collects User Data Automatically – Without Active Consent

Microsoft has introduced a feature that gathers chat histories and user activity from Bing, Edge, and MSN – often without users actively agreeing. This raises data protection concerns.

Automatic data collection without active consent

Microsoft Copilot Collects User Data Automatically – Without Active Consent

Microsoft Copilot is collecting user data without requiring active consent. The new "Microsoft usage data" feature gathers information from everyday activities across Microsoft services – including chat histories with the AI assistant, Bing search queries, and browsing data from Edge, according to newsbytesapp.com. The issue: data collection can already be automatically enabled without users consciously approving it.

Key Facts

  • "Microsoft usage data" feature automatically collects chat histories, search queries, and personal information from Microsoft services
  • Data collection is in some cases pre-enabled by default, without explicit user consent
  • Microsoft justifies the collection for product improvement and faster bug fixes
  • Users can disable the feature in Memory settings and delete previously shared data

Why Microsoft Does This

Microsoft defends automatic data collection by arguing that the gathered information serves performance optimization. The usage data is meant to help develop Copilot and related products like Bing, MSN, and Edge functionally, as well as fix errors more quickly. Personalized data is indeed valuable for modern AI systems – but the question remains: how transparent and voluntary is this data collection really?

Control Exists – But Only After the Fact

Users do have the option to stop data collection retroactively. In Copilot's Memory settings, the feature can be disabled. Additionally, previously shared personal information can be deleted via the "Facts you've shared" section. This gives users some control – but only after their data has already been collected.

Part of a Larger Pattern

This case is not isolated. It reflects a broader debate about data collection by AI assistants. While providers like Microsoft emphasize the necessity of personalized data to improve their services, user and regulatory sensitivity is growing regarding what information is automatically collected and how transparently default settings are communicated. Particularly in the EU, where the AI Act and GDPR impose strict requirements on transparency and consent, such practices could face increasing scrutiny.

What This Means for German Businesses

For companies using Copilot or other Microsoft AI services, an important compliance question arises: if sensitive business data is processed through Copilot, it may end up in Microsoft's data collection system – and thus in training and optimization processes. Organizations should examine what data they share via such systems and whether automatic default settings align with their data protection policies. The question of data deletion and control becomes particularly relevant for businesses with high data protection requirements.

Sources

Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.

Share
← All articles

All analyses are based on i6eal's own measurements or on clearly labelled sources. Figures are snapshots and may change; corrections are disclosed transparently.