Old version
June 21, 2026 00:29 UTC
e9026bc4fbe1bf6a87a5bfebe7290dbd3ea9dc0456bf8018bdca65b86022740d
CA-V-004046
New version
June 24, 2026 00:33 UTC
26511138518c56fd5be42d6fd5b0a779f11a61a1ff0bdb996a06d1a2c8e02876
CA-V-004172
Share 𝕏 Share in Share
Change Summary
GitHub updated its Copilot Business Privacy Statement on June 24, 2026 by reorganizing and expanding the FAQ section. The document previously listed certification resources and began a FAQ section with limited questions visible. The updated version removes some certification file links and restructures the FAQ to explicitly surface questions about third-party testing, personal data processing, and AI model training, along with detailed descriptions of data categories processed (suggestions, feedback data, prompts, and user engagement data). This reorganization makes privacy-relevant questions and data processing information more directly accessible within the statement.
low severity
6 Sentences added
0 Sentences removed
2 Sentences modified
21 Sentences before
27 Sentences after
Added
Removed
Modified
BeforeAfter
2Overview Resources FAQ Updates Media Compliance SOC 1 SOC 2 SOC 3 ISO 27001:2013 CSA STAR Level 2 TISAX ISO/IEC 42001:2023 Resources View all SOC 1 Type 2 Report SOC 2 Type 2 Report GitHub SOC 3 Report April - September 2025 GitHub.Enterprise.Cloud.SOC.1.Type.2.-.Bridge.Letter.01.Dec.2025.-.31.Dec.2025.pdf fa-lock alpaca-fa-regular GitHub.Enterprise.Cloud.SOC.2.Type.2.-.Bridge.Letter.01.Dec.2025.-.31.Dec.2025.pdf fa-lock alpaca-fa-regular GitHub.Bug.Bounty.DLOE.Apr.-.June.2025.pdf fa-lock alpaca-fa-regular GitHub ISO/IEC 42001:2023 Certificate 2026 fa-lock alpaca-fa-regular GitHub Bug Bounty DLOE July-Sep 2025.pdf fa-lock alpaca-fa-regular 2026 GitHub PCI DSS v4.0.1 Shared Responsibility Matrix.xlsx fa-lock alpaca-fa-regular GitHub_2026-PCI_DSS_AOC_-_Final.pdf fa-lock alpaca-fa-regular FAQ View all fa-chevron-down alpaca-fa-regular fa-chevron-up alpaca-fa-regular How is Copilot data encrypted and protected during transit? fa-chevron-down alpaca-fa-regular fa-chevron-up alpaca-fa-regular What third party testing and certifications does GitHub Copilot have? fa-chevron-down alpaca-fa-regular fa-chevron-up alpaca-fa-regular What personal data does GitHub Copilot process? fa-chevron-down alpaca-fa-regular fa-chevron-up alpaca-fa-regular Does GitHub use Copilot Business or Enterprise data to train AI models?2Overview Resources FAQ Updates Media Compliance SOC 1 SOC 2 SOC 3 ISO 27001:2013 CSA STAR Level 2 TISAX ISO/IEC 42001:2023 Resources View all SOC 1 Type 2 Report SOC 2 Type 2 Report GitHub SOC 3 Report April - September 2025 GitHub.Enterprise.Cloud.SOC.1.Type.2.-.Bridge.Letter.01.Dec.2025.-.31.Dec.2025.pdf GitHub.Enterprise.Cloud.SOC.2.Type.2.-.Bridge.Letter.01.Dec.2025.-.31.Dec.2025.pdf GitHub.Bug.Bounty.DLOE.Apr.-.June.2025.pdf GitHub ISO/IEC 42001:2023 Certificate 2026 GitHub Bug Bounty DLOE July-Sep 2025.pdf 2026 GitHub PCI DSS v4.0.1 Shared Responsibility Matrix.xlsx GitHub_2026-PCI_DSS_AOC_-_Final.pdf FAQ View all How is Copilot data encrypted and protected during transit?
3Data used fa-check alpaca-fa-regular Suggestions: These are the AI-generated code lines or chat responses provided to users based on their prompts. fa-check alpaca-fa-regular Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets. fa-check alpaca-fa-regular Prompts: These are inputs for chat or code, along with context, sent to Copilot's AI to generate suggestions. fa-check alpaca-fa-regular User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics.3What third party testing and certifications does GitHub Copilot have?
4What personal data does GitHub Copilot process?
5Does GitHub use Copilot Business or Enterprise data to train AI models?
6Data used Suggestions: These are the AI-generated code lines or chat responses provided to users based on their prompts.
7Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets.
8Prompts: These are inputs for chat or code, along with context, sent to Copilot's AI to generate suggestions.
9User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics.
Stay ahead of the changes

Watch this before it changes again

Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.