The document identifies four categories of data processed by Copilot: AI-generated suggestions, user feedback including reactions and support ticket feedback, user prompts and associated context, and pseudonymous engagement data including accepted/dismissed completions, error messages, system logs, and product usage metrics.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot.
Introduces granular transparency regarding specific data types processed by Copilot, enabling customers to understand their data exposure in operational terms.
View full change record →The agreement discloses that Copilot processes prompt content including code and context inputs, which may include source code, intellectual property, or sensitive business information submitted by users during coding sessions. Pseudonymous engagement data, including system logs and product usage metrics, is also collected from user interactions.
Cross-platform context
See how other platforms handle Data Categories Processed by Copilot and similar clauses.
Compare across platforms →"Data used Suggestions: These are the AI-generated code lines or chat responses provided to users based on their prompts. Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets. Prompts: These are inputs for chat or code, along with context, sent to Copilot's AI to generate suggestions. User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics.Excerpt from GitHub's Copilot Business Privacy Statement
(1) REGULATORY LANDSCAPE: The disclosure of four data categories, including prompt content and pseudonymous identifiers, engages GDPR data subject rights obligations and the requirement to maintain a Record of Processing Activities under Article 30.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot.
The agreement discloses that Copilot processes prompt content including code and context inputs, which may include source code, intellectual property, or sensitive business information submitted by users during coding sessions. Pseudonymous engagement data, including system logs and product usage metrics, is also collected from user interactions.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.