Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document identifies four categories of data processed by Copilot: AI-generated suggestions, user feedback including reactions and support ticket feedback, user prompts and associated context, and pseudonymous engagement data including accepted/dismissed completions, error messages, system logs, and product usage metrics.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot.
The agreement discloses that Copilot processes prompt content including code and context inputs, which may include source code, intellectual property, or sensitive business information submitted by users during coding sessions. Pseudonymous engagement data, including system logs and product usage metrics, is also collected from user interactions.
Cross-platform context
See how other platforms handle Data Categories Processed by Copilot and similar clauses.
Compare across platforms →Monitoring
GitHub has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Data used Suggestions: These are the AI-generated code lines or chat responses provided to users based on their prompts. Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets. Prompts: These are inputs for chat or code, along with context, sent to Copilot's AI to generate suggestions. User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics.Excerpt from GitHub's Copilot Business Privacy Statement
(1) REGULATORY LANDSCAPE: The disclosure of four data categories, including prompt content and pseudonymous identifiers, engages GDPR data subject rights obligations and the requirement to maintain a Record of Processing Activities under Article 30. The collection of pseudonymous identifiers implicates GDPR Article 4's definition of personal data, as pseudonymous data may still constitute personal data if re-identification is reasonably possible. CCPA requires businesses to disclose categories of personal information collected, which this Trust Center page partially fulfills. (2) GOVERNANCE EXPOSURE: Medium. The document does not specify retention periods for any of the four data categories, data subject rights mechanisms applicable to prompt or engagement data, or the legal bases under GDPR for each processing activity. These omissions create compliance gaps for enterprise customers required to maintain complete data processing records. (3) JURISDICTION FLAGS: EU and UK customers must assess whether prompt content submitted to Copilot constitutes personal data under GDPR, particularly where code contains names, credentials, or identifiable information. Illinois customers and organizations subject to BIPA should assess whether any biometric-adjacent data is implicated. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations using Copilot should conduct a data mapping exercise to identify whether any source code or prompt inputs submitted to Copilot contain personal data, trade secrets, or regulated information, and assess whether GitHub's processing of that data is covered by appropriate contractual safeguards. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should supplement this Trust Center disclosure with GitHub's full Privacy Statement and Data Protection Agreement to obtain complete information on retention schedules, legal bases for processing, and data subject rights procedures applicable to each of the four data categories.
This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot.
The agreement discloses that Copilot processes prompt content including code and context inputs, which may include source code, intellectual property, or sensitive business information submitted by users during coding sessions. Pseudonymous engagement data, including system logs and product usage metrics, is also collected from user interactions.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.