Building custom solutions that extend, automate, and integrate Microsoft 365 apps.
Enterprise data protection (EDP) does not mean zero data retention.
Supported documentation shows these points:
- EDP is a set of contractual protections and controls under the Data Protection Addendum and Product Terms for Microsoft Copilot and Microsoft Copilot Chat.
- With EDP, prompts and responses are protected under the same enterprise terms used for Microsoft 365 customer data.
- Prompts and responses are not used to train foundation LLMs.
- Copilot prompts, responses, and related interaction data can be stored, audited, discovered, retained, and deleted within Microsoft 365 compliance systems.
For retention behavior, the documentation explicitly states:
- Data about user interactions with Microsoft Copilot includes the user prompt and Copilot response, including citations.
- This interaction data is stored and encrypted.
- Admins can use Content search and Microsoft Purview to view and manage this stored data.
- Admins can use Microsoft Purview retention policies for data related to chat interactions with Copilot.
- Copilot interaction data is stored within Microsoft 365 services and can be discovered, audited, and retained using Microsoft Purview capabilities.
- Microsoft 365 can capture audit records for Copilot prompts, responses, and referenced content.
- Retention policies for AI apps include user prompts and responses for Microsoft 365 Copilot.
- For Copilot Chat with enterprise data protection, prompts and responses are logged, and the same retention policies used for Microsoft Copilot can be used for Copilot Chat.
For Copilot APIs specifically, the available documentation supports this narrower conclusion:
- Compliance controls, audit logging, and monitoring apply to Copilot API interactions.
- Audit logging for Copilot and AI interactions is available through Microsoft Purview.
That means the documented behavior for Copilot APIs is aligned with retention/compliance infrastructure rather than a zero-data-retention model.
What cannot be concluded from the available documentation:
- No documentation here states that Microsoft 365 Copilot APIs provide a Zero Data Retention (ZDR) offering.
- No documentation here provides API-by-API retention differences for Copilot Chat API, Retrieval API, Search API, or Meeting Insights API.
- No documentation here explicitly maps Copilot API interaction storage to a specific substrate such as Exchange Online.
- No documentation here explicitly explains whether an Interaction Export API exists because prompts and responses are persisted in a particular Microsoft 365 store.
What is supported for policy behavior:
- Retention policies for AI apps can automatically retain or delete user prompts and responses.
- If multiple retention policies or holds apply, standard Microsoft Purview retention principles apply, including retaining data for the longest duration when conflicts exist.
- Retention and deletion behavior follows configured Microsoft Purview retention policies.
So, based on the available documentation, the clearest answer is:
- EDP and ZDR are different concepts.
- EDP protects prompts and responses under Microsoft 365 enterprise privacy, security, compliance, and audit controls.
- Microsoft 365 Copilot and Copilot API interactions are documented as subject to logging, auditing, discovery, and retention in Microsoft 365/Purview.
- A zero-data-retention guarantee for Microsoft 365 Copilot APIs is not documented here.
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat
- How data is protected and audited in Microsoft 365 and Microsoft Copilot
- Data, Privacy, and Security for Microsoft Copilot
- Use Microsoft Purview to manage data security & compliance for Microsoft 365 Copilot & Microsoft 365 Copilot Chat
- Learn about retention for Copilot & AI apps
- Security and authentication for Microsoft 365 Copilot APIs
- Privacy and protections