Compliance
Microsoft 365 Copilot in China (mainland)
Structured issue-spotting for deploying Microsoft 365 Copilot in China (mainland), read against the rules for that jurisdiction.
- Source
- Rules engine over a generic brief — no anchored quote on this page
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01What this reading assumes
- Jurisdiction
- China (mainland)
- Principal framework
- Personal Information Protection Law (PIPL), in force since 1 November 2021. Requires a lawful basis, notice, and separate consent for defined activities including providing personal information to a third party, publicising it, processing sensitive personal information and sending it abroad. Sensitive personal information needs a specific purpose, sufficient necessity and strict protective measures. A personal information protection impact assessment is required before high-risk processing, including any outbound transfer. Article 38 sets the outbound routes. Entrusted processing must be governed by a contract that fixes purpose, period, method and protective measures.
- Delivery assessed
- Enterprise SaaS
- Data leaves the network
- unknown — the deciding question for a hosted product
- Vendor home jurisdiction
- the United States
- Verified vendor positions
- none — every vendor position below is a question, not an assurance
- Rules evaluated
- 27
- Rules fired
- 19
Assumptions about use
- An internal deployment used by employees, not a public-facing product.
- A person reads the output before acting on it — but that is not recorded, so the engine reports it as a gap rather than assuming it.
- No significant automated decision is taken about a person by the system alone.
02Issues to work through
China
Foreign legal process against data stored in China
Data Security Law Article 36 prohibits organisations and individuals in China from providing data stored in China to a foreign judicial or law-enforcement authority without approval from the competent Chinese authority. A foreign-headquartered vendor holding your content can face a request in its home jurisdiction, which puts it — and you — between two legal systems.
- Required checks
- Ask what the vendor does when it receives legal process from an authority outside China.
- Check whether the contract requires the vendor to notify you before responding, where it lawfully can.
- Consider whether the material in scope makes an in-China deployment the simpler answer.
- Vendor questions
- What is your process for responding to a government request for customer content, and do you publish a transparency report?
- Will you commit to notifying us before disclosure where you are legally permitted to?
- Technical controls
- Hold encryption keys yourself where the service supports it, so disclosure of ciphertext is not disclosure of content.
Human review required — take this to your counsel
Separate consent is a separate act
PIPL treats several activities as needing separate consent rather than general consent: providing personal information to another handler, disclosing it publicly, processing sensitive personal information, and providing it outside China. Sending content to a third-party model provider abroad can engage more than one of these at once, and a checkbox in a general privacy policy does not satisfy any of them.
- Required checks
- List which of the separate-consent triggers this deployment engages.
- Design a consent flow that is genuinely separate and records what was shown and when.
- Decide what happens to a person who does not give it — the service still has to work.
- Technical controls
- Store the consent record with the version of the notice that was displayed.
Human review required — take this to your counsel
Three outbound routes, and the thresholds that decide which one
PIPL Article 38 offers a CAC security assessment, certification by an accredited body, or the CAC standard contract, plus a residual limb for other conditions set by law or by the CAC. The certification route was completed by measures in force since 1 January 2026, so an analysis that lists only two routes is out of date. The 2024 cross-border provisions relaxed the volume thresholds and set the validity of a passed assessment result at three years, while the 2022 measures still state two years in their own text.
- Required checks
- Count the volumes: the thresholds turn on how many individuals’ personal information leaves China in a calendar year, and whether any of it is sensitive.
- Establish whether the organisation is a critical information infrastructure operator, which changes the answer.
- Choose the route deliberately and plan the lead time — an assessment is not a form.
- Vendor questions
- Will you sign the CAC standard contract, and will you support a filing with the provincial authority?
- Is there an in-China deployment option, and is it operated by a Chinese entity?
- Technical controls
- Instrument the egress so the volume of personal information leaving China is measured rather than estimated.
Human review required — take this to your counsel
Classify the data before deciding where it may go
The Data Security Law establishes a data classification and grading protection system, with heavier duties attaching to important data. Until the corpus has been classified, it is not possible to say whether important data is in it — and every downstream decision about processing location and outbound transfer depends on that answer.
- Required checks
- Classify the repositories in scope against the applicable sector catalogue before indexing.
- Record the classification and who made it, because it will be asked for.
- Re-check when the corpus expands; the classification is about content, not about the system.
- Technical controls
- Carry the classification label through ingestion so it constrains where a document may be processed.
Human review required — take this to your counsel
Whether a foreign model provider is available in mainland China at all
Major model providers publish the countries and territories where they offer access, and mainland China is frequently absent. Procuring the service through an intermediary does not cure a restriction in the provider’s own terms, and a service that stops working after a policy change is worse than one that was never designed in. Establish availability and the contracting entity before the architecture depends on it.
- Required checks
- Check the provider’s current availability page and keep a dated copy of what it said.
- Identify which entity would contract with the Chinese operating company.
- Identify the domestic alternative you would fall back to, and cost it.
- Vendor questions
- Is the service offered to an entity established in mainland China, and under which contract?
- Do you operate, or partner for, an in-China instance?
- Technical controls
- Keep the model behind an abstraction so a provider change is a configuration change.
A personal information protection impact assessment, kept for three years
PIPL requires an impact assessment before processing sensitive personal information, using personal information for automated decision-making, entrusting processing or providing information to another handler, and sending it abroad. The assessment and the processing record must be retained. An AI deployment usually triggers more than one of these at once.
- Required checks
- Run one assessment covering every trigger the deployment engages, rather than several partial ones.
- Record the retention period for the assessment itself.
- Vendor questions
- Will you provide the technical detail we need to complete the assessment?
Human review required — take this to your counsel
Localisation duties for critical information infrastructure
The Cybersecurity Law, republished after the amending decision of 28 October 2025, requires personal information and important data collected and generated by a critical information infrastructure operator in China to be stored in China, with a security assessment where it genuinely has to go abroad. Article numbers changed in the republication — the localisation duty is Article 39 in this text — so a citation to a pre-amendment article number is unsafe.
- Required checks
- Establish whether the entity is a critical information infrastructure operator; it is not always obvious.
- Where it is, treat storage location as fixed and design around it rather than debating it.
- Vendor questions
- Is there a deployment option that keeps all data inside mainland China, and who operates it?
Human review required — take this to your counsel
Entrusted processing needs a contract that fixes the boundaries
Where processing is entrusted to another party, PIPL requires an agreement setting the purpose, period and method of processing, the categories of personal information, the protective measures, and the rights and duties of each side, together with supervision of the entrusted party. Onward entrustment needs the handler’s consent.
- Required checks
- Check the agreement fixes purpose, period, method, categories and measures — not just confidentiality.
- Confirm the vendor may not sub-entrust without your consent.
- Establish what happens to your data when the contract ends.
- Vendor questions
- Who are your sub-processors for this service, and where are they located?
- What is returned or deleted at termination, and on what timescale?
Settle whether the generative AI measures reach this service
The Interim Measures apply to using generative AI technology to provide content-generation services to the public inside China. Services with public-opinion attributes or social mobilisation capability must undergo a security assessment under the applicable rules. An internal enterprise assistant is normally outside that scope, but the scope question has to be settled and recorded, because the answer drives filing and assessment obligations.
- Required checks
- Decide whether the service is provided to the public in China, and write down why.
- If it is, establish whether it has public-opinion attributes or social mobilisation capability.
- Where either applies, plan for the security assessment and algorithm filing lead time.
- Vendor questions
- Have you completed the security assessment and algorithm filing for your service in China?
Human review required — take this to your counsel
PIPL — a basis, and a notice that matches what you are doing
PIPL applies to processing the personal information of natural persons inside China, and Article 3 extends it to processing outside China aimed at offering products or services to people in China or analysing their behaviour. Processing needs a statutory basis and a notice that truthfully describes the purposes, methods, categories and retention period. An AI feature added to an existing system usually changes all four, which means the notice changes too. A separate set of simplified measures for handlers of fewer than 100,000 individuals’ personal information takes effect on 1 September 2026 and was not yet applicable when this page was reviewed.
- Required checks
- Rewrite the notice for the AI processing rather than appending a sentence to the old one.
- Identify the statutory basis; consent is common but not the only route.
- Check whether the organisation would fall inside the small-handler simplified measures once they apply.
The standard contract carries a filing obligation with a deadline
Where the standard contract route is used, the handler must file the contract with the provincial cyberspace administration within ten working days of it taking effect, together with a personal information protection impact assessment. The filing is often discovered late, after the contract has already been signed.
- Required checks
- Complete the impact assessment before signing, not after.
- Diarise the ten-working-day filing window from the effective date.
- Confirm who inside the organisation owns the filing.
- Vendor questions
- Will you execute the CAC standard contract without amendment, and how quickly?
Human review required — take this to your counsel
Cross Cutting
Confidentiality duties bind independently of data protection law
Material can be entirely free of personal data and still be the material a contract stops you disclosing. Client retainers, non-disclosure agreements, supplier contracts and common-law duties are the usual sources, and several of them require consent before a third party processes the material at all — which a model API call is.
- Required checks
- Review the confidentiality clauses in the contracts covering the material going into the system.
- Identify any contract requiring notice or consent before a subcontractor processes the material.
- Decide whether the deployment needs a confidentiality carve-out negotiated into new contracts.
- Vendor questions
- Will the vendor accept a confidentiality undertaking beyond its standard terms?
- Which staff at the vendor can access customer content, under what controls?
- Technical controls
- Segregate the most sensitive corpora into an index that the general assistant cannot reach.
Human review required — take this to your counsel
What ends up in a prompt, and where it goes next
Every prompt is a transfer of whatever it contains. Staff paste more than they intend, retrieved context travels with the prompt, and system prompts can often be extracted from the output. Assume anything reaching the model has left your control unless the contract and the architecture say otherwise.
- Required checks
- Write down which categories of information may be entered into a prompt, and tell people.
- Establish what the system prompt contains and whether disclosing it would matter.
- Establish which shadow tools staff are already using; the policy has to name the permitted ones.
- Vendor questions
- Are prompts and completions retained, for how long, and can retention be set to zero?
- Are prompts used for abuse monitoring, and if so who can read them and for how long?
- Technical controls
- Redact or block high-risk patterns before the prompt leaves the application.
- Keep prompt and completion logs out of general-purpose observability tools.
- Set an explicit retention period on prompt logs and enforce it.
The acceptable-use policy may exclude your use case
Acceptable-use policies commonly carve out unsupervised legal, medical and financial advice, decisions about people without human review, and some surveillance and biometric uses. They are incorporated into the contract by reference and change without a signature, so the version that matters is the one live on the day you rely on it.
- Required checks
- Read the acceptable-use policy against your actual use case, not against a summary of it.
- Where a carve-out applies, decide whether human review brings the use back inside the policy.
- Set a reminder to re-read the policy — it changes without notice to you.
- Vendor questions
- Does your acceptable-use policy permit this use case, and will you confirm that in writing?
- How are we notified when the acceptable-use policy changes?
Human review required — take this to your counsel
Being able to reconstruct a decision months later
The question that arrives after a complaint is what the system was shown and what it produced on a particular day. Models change, prompts change, and indexes are rebuilt, so the answer has to be recorded at the time. Without it, the only available response is that the output cannot be reproduced.
- Required checks
- Decide what is recorded per interaction: model and version, prompt template version, retrieved document ids, output, reviewer and outcome.
- Set how long those records are kept, balanced against the retention duties that also apply to them.
- Vendor questions
- Does the vendor pin model versions, and how much notice is given before a model is retired or changed?
- Technical controls
- Version prompt templates in source control and log the version used.
- Log the model identifier and version returned by the provider, not the one you requested.
Vendor documentation has not been verified
We could not verify a data processing agreement, a subprocessor list, a position on training on customer data and a stated processing region for this vendor from a retrieved document. That is a gap in our evidence, not a finding against the vendor: until a document has been fetched and read, nothing here should be treated as settled either way.
- Required checks
- Obtain the current versions of the processing agreement, subprocessor list, security page and any regional-processing commitment.
- Check that what the sales conversation promised also appears in the contract.
- Vendor questions
- Where is your data processing agreement published, and which version applies to us?
- Where is your subprocessor list, and how much notice do we get before it changes?
- Do you train on customer content by default, and where is that stated contractually?
- In which country or region is inference performed, and where are logs retained?
We were not told whether a person reviews the output
Where output influences a decision about a person, the reviewer has to be able to disagree with it. That needs three things a rubber-stamp review lacks: enough information to judge, enough time to judge, and an override that is used often enough to be real. Design it before the volume makes it impossible.
- Required checks
- Name the role that reviews the output and what they see when they do.
- Decide what evidence is retained about each review, so the practice can be shown to exist.
- Set a threshold below which the system must not act without review.
- Vendor questions
- Does the product expose the retrieved context and the confidence behind a suggestion, or only the answer?
- Technical controls
- Show the reviewer the retrieved sources next to the suggestion, not the suggestion alone.
- Record the reviewer’s decision, including overrides, as part of the audit trail.
Human review required — take this to your counsel
An AI deployment creates new copies of the data
Vector indexes, prompt logs, completion caches, evaluation datasets, fine-tuning checkpoints and backups are all copies of the source material in places the existing retention schedule does not mention. Deletion requests are the moment this is discovered, because deleting the source document does not delete its embedding.
- Required checks
- List every store the deployment creates and add each to the retention schedule.
- Establish how a deletion request propagates to the index, the caches and the logs.
- Establish how long backups keep material that has been deleted from the live system.
- Vendor questions
- What does the vendor retain, where, and for how long after we delete our copy?
- Technical controls
- Store the source document id with every embedding so deletion can cascade.
- Set time-to-live on prompt and completion logs rather than relying on manual cleanup.
The vendor’s terms may not permit the deployment you are planning
Provider terms routinely restrict things architectures assume: sharing seats, building a competing service, benchmarking and publishing results, reselling capacity, and processing certain data categories. A consumer or self-serve plan often carries different terms from the enterprise agreement, and the enterprise agreement is the one worth reading.
- Required checks
- Identify which contract actually governs — self-serve terms, an order form, or a negotiated agreement.
- Check restrictions on seat sharing and on service accounts, which a shared internal assistant can breach without anyone noticing.
- Check whether the terms allow the categories of data you intend to send.
- Vendor questions
- Which agreement governs our use, and can we have the current version in writing?
- Are there restrictions on the data categories or the industries we may use the service for?
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
03What this reading does not know
- Whether any of the data falls into a special or sensitive category.
- Whether any material is covered by legal professional privilege.
- Whether prompts or documents leave the company network.
- Whether a person reviews the output before it is acted on.
04Instruments these issues point at
- regulationPI Standard Contract MeasuresOne of the three routes under PIPL Article 38. The handler concludes the CAC standard contract with the overseas recipient and files it with the provincial cyberspace administration within ten working days of the contract taking effect, together with a personal information protection impact assessment.
- regulationPI Outbound Certification MeasuresCompletes the certification route under PIPL Article 38 by setting the procedure for certifying an outbound transfer of personal information through an accredited body. Earlier inconsistent certification rules give way to these measures. A cross-border analysis that lists only the security assessment and the standard contract is now incomplete.
- statutePIPLChina’s personal information law. Requires a lawful basis and separate consent for defined activities, imposes heightened rules on sensitive personal information, requires a personal information protection impact assessment for high-risk processing, and sets the outbound transfer routes in Article 38. It applies to processing inside China and, in defined cases, to processing abroad.
- statuteDSLEstablishes a data classification and grading protection system, with heavier duties for important data. Article 36 prohibits organisations and individuals in China from providing data stored in China to a foreign judicial or law-enforcement authority without approval from the competent Chinese authority.
- statuteCSLChina’s network security statute, republished after the 28 October 2025 amending Decision. The amendment added support for artificial intelligence research and for AI ethics and risk monitoring, cross-referenced the PIPL, raised penalty ceilings, and renumbered the articles from 79 to 81.
- regulationCross-border Data Flow ProvisionsRelaxes and restates the outbound transfer thresholds. Sets volume-based exemptions for non-CII handlers, and extends the validity of a passed outbound data security assessment result to three years from the date it is issued. Read together with the 2022 assessment measures, whose original text on the regulator’s site still states two years.
- regulationSmall Handler Simplified MeasuresCreates a lighter PIPL compliance tier for a small personal information handler, defined as one processing the personal information of fewer than 100,000 individuals. Published on 24 July 2026 and applicable from 1 September 2026, so it was adopted but not yet applicable when this page was reviewed.
- regulationOutbound Assessment MeasuresThe CAC-organised security assessment route for sending important data or personal information collected in China abroad. Not repealed, but its trigger thresholds and the validity period of an assessment result are displaced by the 2024 cross-border provisions; the original two-year validity still appears in the text on the regulator’s site.
- regulationGenerative AI Interim MeasuresApplies to the use of generative AI technology to provide text, image, audio or video generation services to the public inside China. Services with public-opinion attributes or social mobilisation capability must undergo a security assessment and complete algorithm filing under the applicable rules. In-house tools that are not offered to the public fall outside the stated scope.
05Vendor documents being watched
- Data processing agreementhttps://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPAnot yet fetched
- Pricinghttps://azure.microsoft.com/en-us/pricing/details/cognitive-services/openai-service/not yet fetched
- Pricinghttps://www.microsoft.com/en-us/microsoft-365/enterprise/microsoft365-plans-and-pricingnot yet fetched
- Privacy policyhttps://privacy.microsoft.com/en-us/privacystatementnot yet fetched
- Security pagehttps://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacynot yet fetched
- Security pagehttps://www.microsoft.com/en-us/trust-centernot yet fetched
- Security pagehttps://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacynot yet fetched
- Supported countrieshttps://azure.microsoft.com/en-us/explore/global-infrastructure/data-residency/not yet fetched
- Supported countrieshttps://learn.microsoft.com/en-us/azure/foundry/foundry-models/concepts/models-sold-directly-by-azure-region-availabilitynot yet fetched
Restrictions recorded for this vendor in China (mainland)
- Azure in mainland China is a separate cloud operated by 21Vianet and is not covered by the global Foundry Models region availability page. Treat model availability there as a separate question with separate contracts.
06Ask about your own deployment
This page reads the rules against a generic organisation. Your size, industry, data and existing contracts change which of these issues matter and which fall away.