VendorScore · Productivity suite · Data-access posture

Can Microsoft 365 read your data?

A plain-language answer from Microsoft's public Trust Center and Learn docs. Customer Key is not the same as Microsoft can't read it.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-06, public docs only, not legal advice.

Short answer

Yes. Microsoft can process and decrypt customer content for service operations, even under Customer Key (availability key, service code). Double Key Encryption (DKE) content is the exception: Microsoft cannot decrypt it.

69 / 100 overall

Scored configuration: Microsoft 365 enterprise with Purview Customer Key and Customer Lockbox. Double Key Encryption (DKE) is noted as a higher bar for limited content.

With Microsoft-managed keys and no Lockbox (the default), the report scores key custody and plaintext access lower.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score and key findings) · FAQ policy links re-checked 2026-10-07 · Sources

Key findings

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Microsoft 365 data access, AI training, GDPR and residency

Can Microsoft 365 read your data?

Yes. Microsoft can process and decrypt customer content for service operations, even under Customer Key (availability key, service code). Double Key Encryption (DKE) content is the exception: Microsoft cannot decrypt it. VendorScore rates Microsoft 365 69/100 overall from public documentation (evidence dated 2026-10-06). Scored configuration: Microsoft 365 enterprise with Purview Customer Key and Customer Lockbox. Double Key Encryption (DKE) is noted as a higher bar for limited content.

Does Customer Key or Double Key Encryption (DKE) stop Microsoft reading my data?

Customer Key: no. It gives you control of root keys, but Microsoft 365 service code still uses them, and a Microsoft-held availability key exists for recovery. DKE: yes for DKE-protected files, because you hold a second key Microsoft never has. DKE covers limited content and comes with major usability and search limitations.

Can Microsoft employees read my emails or OneDrive files? What is Customer Lockbox?

Not by default, but access is possible under policy. Microsoft says: "Microsoft engineers don’t have default access to cloud customer data. Instead, they are granted access, under management oversight, only when necessary." Customer Lockbox lets you approve or deny engineer access requests in support scenarios. Service features such as indexing, eDiscovery, DLP and antivirus still process plaintext for non-DKE data.

Does Microsoft train AI on my Microsoft 365 data?

For Microsoft 365 Copilot, Microsoft's documentation says: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot." VendorScore's Microsoft 365 score doesn't cover Copilot, which needs its own review.

Is Microsoft 365 GDPR compliant? Where is the Microsoft DPA?

VendorScore doesn't certify compliance; Microsoft 365 publishes a DPA at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. It is the Microsoft Products and Services Data Protection Addendum, which sets the data processing and security terms for products under Microsoft's Product Terms. Microsoft also says its subprocessors must meet GDPR requirements.

Who are Microsoft's subprocessors for Microsoft 365?

Microsoft's Trust Center data-access page (https://www.microsoft.com/en-us/trust-center/privacy/data-access) links the Microsoft Online Services Subprocessor List. Microsoft says it names new subprocessors at least six months before they may access customer or personal data, and that subprocessors may access data only to deliver the functions Microsoft hired them for.

Can I keep Microsoft 365 data in the EU (EU Data Boundary)?

Yes, within limits. The EU Data Boundary is Microsoft's commitment to store and process Customer Data and personal data for its enterprise online services, including Microsoft 365, in the EU and EFTA, with some documented transfers outside it. For Microsoft 365, customers with a sign-up location in an EU or EFTA country are in scope; customers who bought Multi-Geo Capabilities are not.

Compare Microsoft 365

All comparisons

Sources

Every URL cited on this page. Score and key findings: VendorScore report (microsoft-365.md), evidence dated 2026-10-06. FAQ policy links: vendor pages re-checked 2026-10-07.