GitHub · GitHub Copilot Business Privacy Statement · View original document ↗

Data Categories Processed by Copilot

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time GitHub changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity GitHub recorded 6 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for GitHub Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The document identifies four categories of data processed by Copilot: AI-generated suggestions, user feedback including reactions and support ticket feedback, user prompts and associated context, and pseudonymous engagement data including accepted/dismissed completions, error messages, system logs, and product usage metrics.

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot.

Consumer impact (what this means for users)

The agreement discloses that Copilot processes prompt content including code and context inputs, which may include source code, intellectual property, or sensitive business information submitted by users during coding sessions. Pseudonymous engagement data, including system logs and product usage metrics, is also collected from user interactions.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact GitHub Support to submit a data subject access or deletion request covering prompt and engagement data associated with your Copilot account.

Cross-platform context

See how other platforms handle Data Categories Processed by Copilot and similar clauses.

Compare across platforms →

Monitoring

GitHub has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Data used Suggestions: These are the AI-generated code lines or chat responses provided to users based on their prompts. Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets. Prompts: These are inputs for chat or code, along with context, sent to Copilot's AI to generate suggestions. User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics.

Excerpt from GitHub's Copilot Business Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The disclosure of four data categories, including prompt content and pseudonymous identifiers, engages GDPR data subject rights obligations and the requirement to maintain a Record of Processing Activities under Article 30. The collection of pseudonymous identifiers implicates GDPR Article 4's definition of personal data, as pseudonymous data may still constitute personal data if re-identification is reasonably possible. CCPA requires businesses to disclose categories of personal information collected, which this Trust Center page partially fulfills. (2) GOVERNANCE EXPOSURE: Medium. The document does not specify retention periods for any of the four data categories, data subject rights mechanisms applicable to prompt or engagement data, or the legal bases under GDPR for each processing activity. These omissions create compliance gaps for enterprise customers required to maintain complete data processing records. (3) JURISDICTION FLAGS: EU and UK customers must assess whether prompt content submitted to Copilot constitutes personal data under GDPR, particularly where code contains names, credentials, or identifiable information. Illinois customers and organizations subject to BIPA should assess whether any biometric-adjacent data is implicated. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations using Copilot should conduct a data mapping exercise to identify whether any source code or prompt inputs submitted to Copilot contain personal data, trade secrets, or regulated information, and assess whether GitHub's processing of that data is covered by appropriate contractual safeguards. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should supplement this Trust Center disclosure with GitHub's full Privacy Statement and Data Protection Agreement to obtain complete information on retention schedules, legal bases for processing, and data subject rights procedures applicable to each of the four data categories.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over the accuracy and completeness of data practice disclosures made to consumers and businesses regarding data collection and use.
    File a complaint →

Provision details

Document information
Document
GitHub Copilot Business Privacy Statement
Entity
GitHub
Document last updated
May 11, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015174
Document ID
CA-D-00775
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
26511138518c56fd5be42d6fd5b0a779f11a61a1ff0bdb996a06d1a2c8e02876
Analysis generated
July 9, 2026 07:21 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Copilot Business Privacy Statement
Record ID: CA-P-015174
Captured: 2026-07-09 07:21:59 UTC
SHA-256: 26511138518c56fd…
URL: https://conductatlas.com/platform/github/github-copilot-business-privacy-statement/provision/CA-P-015174/data-categories-processed-by-copilot/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does GitHub's Data Categories Processed by Copilot clause do?

This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot.

How does this clause affect you?

The agreement discloses that Copilot processes prompt content including code and context inputs, which may include source code, intellectual property, or sensitive business information submitted by users during coding sessions. Pseudonymous engagement data, including system logs and product usage metrics, is also collected from user interactions.

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.