Microsoft Bing Searches not DPA protected: Protect Sensitive Data

As organizations increasingly use AI agents to deliver real-time answers, it is critical to understand how web search features are governed under Microsoft’s data protection policies.

Effective August 1, 2025, Microsoft clarified that the Data Protection Addendum (DPA) does not apply when using Bing Grounding – i.e., Bing web searches – within Azure AI Foundry or Copilot Studio.

 

 

When Do You Use Bing Search in Azure AI Foundry or Copilot Studio?

You use Grounding with Bing Search in Azure AI Foundry or Copilot Studio when your AI agents need real-time public web data to answer questions like:

  • “What’s the latest news in the retail industry?”
  • “What are the top cybersecurity threats this week?”

In these cases, Bing grounding helps your agents search the public web, retrieve relevant chunks, and generate responses with citations.

This data is not protected under the DPA, so it is best used for general-purpose, non-sensitive queries.

-> Some agents are built to answer questions using live web data (e.g., news, weather, current events).

-> Others may rely only on internal documents or structured data and won’t use Bing at all.

Tip: You can enable or disable Bing grounding per agent.

 

Implications for Your Organization

For organizations using Azure AI Foundry or Copilot Studio to build or deploy AI models that interact with Bing search:

  • Data may leave your compliance zone: Bing search results might be processed outside your geographic or regulatory boundaries.
  • Not suitable for sensitive workflows: Avoid using Bing search for regulated or confidential data, such as healthcare, finance, or government projects.

Microsoft Product Terms – 2025-08-01 – Page 19

 

Microsoft Product Terms – 2025-08-01 – Page 120

 

Microsoft Product Terms – 2025-08-01 – Page 21

 

Microsoft Product Terms – 2025-08-01 – Page 135

 

What exactly do the Terms of Use for Grounding with Bing Search and Grounding with Bing Custom Search state?

When using Bing Search capabilities in Azure AI Foundry, the Terms of Use apply. In short, these are the main points you should be aware of:

Rule What It Means for You
Not Covered by Standard Privacy Terms Bing results are outside Microsoft’s enterprise privacy protections. Do not treat Bing data like other Azure data.
Separate Data Responsibility You and Microsoft are independent data controllers under GDPR. You must manage your own compliance.
No AI Training Allowed You cannot use Bing results to train AI models. Do not feed Bing data into your own AI systems.
Must Keep Microsoft’s Links and Credits You must show Bing citations exactly as provided. No editing or hiding of sources.
Data May Leave Your Region Bing data may be processed outside your preferred region. Be cautious with location-sensitive data.

 

How About Microsoft 365 Copilot / Copilot Chat? DPA-Protection with Conditions

When using Microsoft 365 Copilot or Copilot Chat, things are different:

  • If users stay within Microsoft 365 data (e.g., emails, documents, Teams), everything is DPA-covered.
  • If users opt in to use Bing web search, that part is not covered by the DPA, but Microsoft applies extra safeguards:

Bing Query Data Protections (when used via Copilot):

  • Microsoft has no ownership rights over the query data.
  • Query data is not used to improve Bing.
  • No advertising or tracking is applied.
  • No sharing with advertisers or third parties.
  • No AI model training using query data.
  • Query data is treated as confidential and protected with technical and organizational safeguards.

This means, while Bing search itself is not DPA-covered, Microsoft 365 Copilot adds strong protections when Bing is used optionally by authenticated enterprise users.

 

Microsoft Product Terms – 2025-08-01 – Page 94

 

Impact on Licensing and Compliance

This update affects how customers should design and govern AI solutions that rely on Bing search integration.

  • Review your compliance policies to ensure Bing search usage aligns with internal and regulatory data handling requirements.
  • Avoid Bing Search grounding in Azure AI Foundry or Copilot Studio for sensitive use cases.

 

More information

Terms of Use for Grounding with Bing Search and Grounding with Bing Custom Search: https://www.microsoft.com/en-us/bing/apis/grounding-legal-enterprise.

 

 

Overwhelmed by Microsoft Licensing?

At SCHNEIDER IT MANAGEMENT, we understand the full scope of Microsoft licensing, including its hidden implications, compliance risks, and cost-saving opportunities.

Ensure that you are properly licensed and protected in case of an audit by reaching out to our licensing experts at SCHNEIDER IT MANAGEMENT.

Des questions sur l'octroi de licences ?
Nos experts ont des réponses.

Partager l'article

Articles connexes

SCHNEIDER IT MANAGEMENT 2016-10-04 Logo Standard 480 x 480
Salle de presse
Dernières infos sur
l’octroi de licences.