Copilot Flex Routing: The GDPR Problem – Interview with Marc Arndt

Marco Arndt im Interview zu CoPIlot Flex Routing

Flex Routing, GDPR and the question of who really owns your data.

Microsoft has quietly introduced Copilot Flex Routing (live since April 17, 2026), a feature that automatically reroutes company data to the US, Canada, or Australia when capacity is limited. No opt-in, no notification, no choice.

We have Marc Arndt, We asked our VP of Software Engineering and Architecture: What does this mean specifically for companies in Europe? What do regulated organizations need to demand from an AI solution today? And how does EVANA ensure that your data never leaves the EU?

Many companies are currently relying on AI assistants like Microsoft Copilot. Why is the question of data processing and data storage location being discussed so critically right now?

Excellent question. This is a highly topical issue at the moment for several interconnected reasons:

1. GDPR and data transfers

When employees use AI assistants like Copilot, requests are often processed on servers located in the US. For companies based in the EU, this raises GDPR concerns: personal data processed outside the EU without adequate safeguards violates data protection law. The EU has recently exerted considerable pressure in this area, particularly after the Schrems II ruling, which invalidated the Privacy Shield framework.

2. Data sovereignty

Companies want to know where their data is physically stored and which legal system applies to it. US cloud providers are subject to the CLOUD Act, meaning US authorities can potentially access data stored on US servers. This poses a significant risk for European companies handling sensitive data.

3. Confidential data leaks

Employees naturally insert sensitive information into AI assistants: contracts, source code, personal data, company strategies. Many AI providers:

  • Save inputs for model training (unless an opt-out has been explicitly configured)
  • temporarily hold data for processing
  • Data may be shared with third parties

4. Regulatory pressure

European data protection authorities, such as the BfDI in Germany and the CNIL in France, have begun issuing guidelines and launching investigations into the use of AI assistants in companies. Italy temporarily banned ChatGPT in 2023 due to data protection concerns.

5. The „Microsoft Copilot Problem“

Copilot is deeply integrated with Microsoft 365 and can access emails, documents, and Teams chats. While this is extremely powerful, it also means that even more sensitive data flows through Microsoft's infrastructure. Chief Information Security Officers (CISOs) in companies are increasingly asking: "What does Microsoft actually do with this data?"„

It's the combination of deep integration (AI sees more of your data than ever before), cross-border processing (often to the US), and the uncertainty about how providers handle and secure this data. And all this while regulators are actively monitoring and issuing fines.

What does Microsoft Flex Routing mean specifically for companies in Europe, and why is it more than just a technical detail from the perspective of data protection, compliance, and risk management?

Microsoft Flex Routing went live on April 17, 2026, but what exactly does that mean?

  • If Copilot capacity is limited in the EU, your data (prompts, emails, files) may be automatically and by default transferred to the USA, Canada or Australia for AI inference.
  • Data at rest remains in the EU, but inference and processing can leave the EU.
Why this is a real compliance problem:
  • GDPR: Inference is processing. Cross-border transfers require a legal basis.
  • NIS2 / DORA: Silent routing changes are a provider risk that may need to be disclosed.
  • Microsoft introduced Flex Routing as an opt-out, not an opt-in. Most administrators will not change the default setting.
  • The responsibility to recognize, assess, and act on this lies with you, not with Microsoft.

Unlike traditional software deployments, where IT administrators explicitly review and approve new features, Copilot Flex appears to have been introduced as an automatic default feature. Many organizations are thus unknowingly subjected to expanded data processing to which they never consciously consented.

According to GDPR Article 6, a valid legal basis, usually consent or legitimate interest, is required before personal data may be processed. Consent must be freely given, specific, informed, and unambiguous. By enrolling customers by default, Microsoft has, according to critics, circumvented this requirement. This is particularly relevant for organizations in the EU, whose employees' emails, documents, and conversations now flow through AI processing pipelines. The argument is that…„It was stated in the terms of service.“This does not constitute informed, conscious consent, especially since the opt-out is buried deep in admin panels and the changes were not proactively communicated.

Several European data protection authorities are investigating whether Copilot Flex's implementation model violates the GDPR's consent and transparency requirements. Class action lawsuits have been filed in Germany and France, seeking damages for unauthorized data processing. Microsoft's position that Copilot Flex is a legitimate extension of existing contractual relationships is likely to face regulatory challenges, as authorities are increasingly clarifying that contractual practicality does not outweigh fundamental data protection rights.

What requirements do regulated or data-sensitive companies place on an AI solution today if they want to operate in compliance with GDPR and retain control over their data?

This is a complex issue that is rapidly evolving in light of the race between legislation and technology. Here's a brief overview of the current situation and why choosing the right partner is crucial for your data.

Legal basis and contractual basis

RequirementMeaning
Article 28 GDPR (Data Processing Agreement)A signed data processing agreement with the AI provider that explicitly defines the purpose, scope, and limits of the processing.
No automatic onboardingExplicit opt-in, no opt-out. Silent or automatic activation of AI functions is an immediate exclusion criterion for many EU organizations.
Clear purposeThe AI may only use data for the specifically stated purpose, not for model training, improvement or "service optimization", unless separately consented to.
Data minimizationThe AI only processes what is absolutely necessary for the specific purpose. By default, it does not process complete email archives, all documents, or full chat histories.

Data storage location and data sovereignty

  • EU data storage location: All data must be processed and stored exclusively within the EU/EEA. No transfer to third countries without explicit authorization.
  • No dependence on US hyperscalers as standard: Providers must offer EU-native deployment options (e.g. German or French data centers) or on-premises operation.
  • Mechanisms for cross-border transfers: Standard Contractual Clauses (SCCs), adequacy decisions or equivalent legal instruments for any necessary data transfer abroad.
  • CLOUD Act awareness: US providers are legally obligated to hand over data to US authorities, regardless of where it is stored. This is a significant warning sign for sensitive EU data.

Data retention, deletion and portability

  • Defined retention periods: Clear, contractually agreed-upon deadlines after which data is deleted. No vague wording.
  • Right to erasure: The provider must comply with erasure requests without undue delay and provide proof.
  • Data portability: The customer can access all their data at any time in a usable, portable format (GDPR Art. 20).
  • No training with customer data: An explicit contractual prohibition on using customer data for training AI models. For most regulated companies, this is non-negotiable.

Security and technical measures (Art. 32 GDPR)

  • Encryption at rest and in transit: Minimum standard AES-256, TLS 1.2+
  • Access controls: Role-based access control (RBAC), audit logging with proof of who accessed what and when.
  • Pseudonymization and anonymization: Sensitive data should be de-identified before processing, wherever possible.
  • Incident reporting: The provider must inform the customer of data breaches within 72 hours of becoming aware of them (GDPR Art. 33).
  • Penetration tests and certifications: SOC 2 Type II, ISO 27001 and/or independent security audits are increasingly required.

Transparency, explainability and human control

  • Explainability: Companies must be able to understand why an AI produced a particular output.
  • No black-box processing: For consequential decisions (hiring, loan granting, medical triage), automated decision-making in accordance with GDPR Art. 22 requires human review and the possibility to contest the decision.
  • Audit trails: Complete logging of all AI prompts, inputs and outputs to ensure traceability.
  • Bias and accuracy monitoring: Ongoing checks to ensure that AI output does not discriminate or produce significantly erroneous results for protected groups.

Industry-specific requirements

Additional requirements apply to healthcare and medical technology:

ThemeRequirement
Article 9 GDPRHealth data is considered "particularly sensitive" data. The hurdle for lawful processing is very high, generally requiring explicit consent and a specific purpose.
HIPAA (in the case of US references)If US entities access the data, HIPAA Business Associate Agreements may be required.
Medical Device RegulationIf AI contributes to clinical decisions, it may fall under the MDR (EU) or FDA (USA) as a regulated medical device.
Audit readinessRegulatory authorities (BfArM, FDA, health insurance companies) can request evidence of data governance at any time.

The same applies to the financial sector:

  • BaFin and EBA guidelines on AI governance
  • Record retention for supervisory audits
  • No AI-generated advice without a human review process.

Provider governance and due diligence obligations

  • Data Protection Impact Assessment (DPIA): Regulated companies conduct a DPIA before deploying an AI solution. Providers must supply the necessary technical information for this purpose.
  • Vendor risk assessment: Security questionnaires (SIG, VSA), penetration test results, SOC 2 reports
  • Sub-processors: All sub-processors must be disclosed. Customers have the right to object to new sub-processors.
  • Exit regulations: Clear conditions for data migration and deletion at contract termination
  • Insurance coverage: Requirements for cyber liability and professional liability insurance are becoming increasingly common.

The checklist that a CISO or DSB goes through before signing.

☐ Data processing agreement signed (in accordance with Art. 28 GDPR)
☐ Data storage location confirmed (EU processing only)
☐ No training with our data (contractual and technical guarantee)
☐ Retention and deletion policy defined and auditable
☐ SCC or adequacy decision for cross-border transfers available
☐ Reporting deadline for data breaches: max. 72 hours
☐ SOC 2 / ISO 27001 or independent audit available
☐ DSFA feasible with the support of the provider
☐ Human review level available for consequential decisions
☐ No automatic onboarding, no silent AI activation
☐ Full audit trail of AI processing available
☐ Data portability guaranteed (Art. 20 GDPR)
☐ List of sub-processors disclosed, right to object granted
☐ Exit and termination clauses protect our data

The core principle is: control and accountability. Regulated companies must be able to answer three questions to their data protection authority with "yes":

  • Where exactly does our data go?
  • Who processes them and for what purpose?
  • How can we check this and, if necessary, unplug it?

If an AI provider cannot clearly and contractually answer all three questions, with technical evidence rather than marketing jargon, reputable, regulated organizations will not enter into a business relationship. The reputational and financial risk of a GDPR violation (up to €20 million or 41,000 of global annual revenue, whichever is higher) simply outweighs the productivity gains of an AI assistant.

How does EVANA technically ensure that company data is processed in accordance with European data protection regulations and that customers receive maximum transparency about their data flows?

EVANA is a European-First company, wholly owned and operated within the EU.

Data storage location: Everything remains within the EU

storageAll customer documents and metadata are stored exclusively in Frankfurt am Main when not in use. At no point during storage does the data leave the German legal system.

AI processingWe are currently working with Mistral in France. The key aspect here is:

  • Mistral receives data only temporarily: The data is transferred, processed in memory, and the result is returned. Mistral does not store a single byte.
  • Mistral acts as a pure computing service provider under a signed data processing agreement (Art. 28 GDPR) which explicitly prohibits any form of data storage, logging or use for model training.
  • The data never leaves the EU/EEA and therefore meets the territorial scope of the GDPR (Art. 3) as well as the requirements for an adequate level of protection within the Union.

For the customer, this means: Even if Mistral is involved in the processing, their data does not cross any border outside the EU, is never stored outside of Germany, and is no longer accessible to Mistral after the inference process is complete.

Technical Architecture: Defense in Depth

layermeasure
Encryption at restAES-256 encryption of all stored documents and metadata
Encryption during transmissionTLS 1.2+ for all internal and external data flows
Access controlsRole-based access control (RBAC) with granularity at the user and document level
Audit loggingImmutable log of every access, request, and processing operation with timestamp and attribution.
Network isolationPrivate VPC topology; no public internet exposure of the processing pipelines
No training with customer dataContractual and technical prohibition: Neither EVANA nor Mistral use customer data for training or improving models.
Data minimizationThe AI processing operates on the minimum dataset required for each process. Complete document archives are not used by default.

GDPR legal framework

  • Article 28 of the Data Processing Agreement with Mistral, signed and available upon request. It defines the purpose limitation, the non-storage clause, and restrictions for sub-processors.
  • Standard contractual clauses are not required because the data does not leave the EU. This is a significant compliance advantage compared to US-based AI providers.
  • Record of processing activities (Art. 30 GDPR): EVANA maintains a complete record of processing activities, which includes all AI processing paths, data categories and legal bases.
  • DSFA-ready: We provide the technical and organizational information that customers need to carry out their own data protection impact assessment before deployment.

Customer transparency and control

Customers can review and control their data at any stage:

  • Real-time visibility of data flows: Customers have access to a processing dashboard that shows which documents have been processed.
  • Retention control: Customers define retention policies. EVANA implements the automatic deletion as planned and provides a cryptographic proof of deletion.
  • Right to be forgotten: Deletion requests will be fulfilled within 72 hours with a confirmation certificate.
  • Data portability: All customer data can be exported at any time in open, structured formats (GDPR Art. 20).
  • No silent processing: AI processing only takes place on explicitly selected documents. No automatic searching or background processing without user consent.

Certifications and compliance status

  • ISO 27001 certified: The information security management system has been independently audited.
  • TÜV-audited: Technical safety measures have been independently verified.
  • 100 % GDPR compliant: No exceptions, no opt-outs, no grey areas.

From your perspective, what is the crucial difference between a generally deployed AI solution and a specialized, security-oriented platform like EVANA, especially for companies that want to digitize sensitive documents and processes?

The fundamental difference: Whose interests align with yours?

 General AI solutionSecurity-oriented platform (EVANA)
The provider's core incentiveHe needs your data to improve the model.Protect customers; data must remain secure and private.
Data handlingSaved, frequently used for training (unless opt-out)Ephemeral or never saved. No training.
Data storage locationUS processing is common, cross-border standard.Exclusively within the EU. Data does not leave the legal system.
Risk of automatic onboardingHigh: Functions activate silently (Copilot Flex)None: Processing only occurs with explicit user action.
Compliance burdenThe customer inherits the provider's compliance gaps.The provider proactively delivers compliance evidence.
Audit trailLimited, supplier-controlledComplete, unalterable, and accessible to the customer
GDPR legal basis„Contractual legitimate interest“, legally controversialClean, EU-internal processing. No transfer mechanisms required.
Regulated industriesRequires extensive data processing agreement negotiations.Integrated: BaFin, DORA, ISO 27001, immediately auditable
transparencyBlack Box: Customers cannot verify what happens to their data.Open architecture: The customer can see exactly where the data flows.

The real risk that nobody talks about

With a generic AI solution, the problem isn't that the provider is acting maliciously. The problem is that your data and the provider's model improvement are structurally intertwined in their business model. They need to retain and process your input to remain competitive. This creates a constant tension between what they promise in the data processing agreement and what their technical incentives compel them to do.

With a platform like EVANA, the incentive structure is reversed: your data is a liability, not an asset. EVANA can only benefit by keeping data private, secure, and compliant. Because if it fails to do so, the company loses regulated customers and thus its very reason for being.

The three questions every CISO should ask

When evaluating an AI provider:

  • Where does my data physically go? If the answer is "we cannot guarantee EU-only," you have already violated the GDPR for every sensitive use case.
  • Can you prove that our data will not be used for training? Not just contractually, but with technical proof: ephemeral processing, no persistence, no logging of inputs.
  • What happens if we terminate the contract? Can they prove the deletion, issue a deletion certificate, and enable full data portability? Or are we left with an encrypted pile of data that we can't verify?

More posts

Send Message

Scroll to Top