
Knowledge/Answer
Senior-led answer · Business Central
Is Business Central GDPR-compliant, and where does the data live?
Business Central can be run in a GDPR-compliant way. Your data sits in Microsoft's EU data centres, Microsoft is the processor, and responsibility for the configuration stays with you.
Contents
Your question in detail?
A senior-led conversation gets to the heart of your situation.
Related service
Business Central can be run in a GDPR-compliant way. The decisive part is not the platform, but how you set up permissions, data flows and AI in the project. Where the data lives is settled, the responsibility for the configuration stays with you.
Where does your data reside?
Business Central Online runs in the Microsoft cloud. For customers with an EU tenant region, Microsoft stores the core data in data centres inside the EU and assigns the service to the EU Data Boundary. In normal operation, your productive business data therefore does not leave the European area.
Source: Microsoft Learn: What is the EU Data Boundary?
The qualifier "in normal operation" matters. There are defined exceptions, certain support scenarios for instance, in which data can leave the area. You should know those exceptions and have them documented rather than assume them, because in an audit nobody asks about the rule, they ask about the exceptions.
In practice that means: check the region when the environment is created, record which region was chosen, and know who could change it later. It is a decision of a few minutes with an effect across years.
Who is responsible for what?
Microsoft is the processor, you remain the controller in the sense of the GDPR. That division of roles is not negotiable and has an uncomfortable consequence: the platform can be fully compliant and your own system still not be.
Source: Microsoft Learn: General Data Protection Regulation
The basis is the data processing agreement that Microsoft provides through its online terms. The platform brings the technical and organisational measures with it. Whether your system ends up compliant, however, is decided by how you set it up: which roles see which data, how long documents are retained, which interfaces pass data outwards.
These three points are project work and not a setting you make once. They belong in the implementation, not in a review months after go-live when the structures have long since grown.
Which part will no data centre take off your hands?
The most common gap in mid-sized companies is not where the data sits but the permission structure that has grown over the years. If in practice everyone sees everything, an EU data centre helps little, because the GDPR asks about purpose limitation and data minimisation and not about geography.
Source: Microsoft Learn: Security in Business Central
Data minimisation, clean roles and a deliberate approach to personal data fields are therefore the real effort. The usual starting point is a handful of broad roles that have grown by individual permissions over the years, until nobody can say precisely why who is allowed to see what.
This is exactly where we start: we set up permissions, retention and data flows so that control stays with you. The test for it is simple: can you say, for any given role, within two minutes which personal data it sees?
How do AI and Copilot look from a GDPR perspective?
Copilot and AI agents work on your business data. For the EU the same regional boundaries apply as for Business Central itself, and Microsoft does not use your business data to train its foundation models.
Source: Microsoft Learn: Copilot FAQ
What matters is that you clarify, before switching it on, which data an agent may see and change. That control is provided for and documented, but it has to be set deliberately, otherwise the preconfigured default scope applies, and nobody chose that one on purpose.
Source: Microsoft Learn: Configure Copilot and agent capabilities
The substance stays the same as without AI: an unclean data foundation does not get better through an agent, only effective faster, and in both directions. AI sharpens an unclean data foundation, it does not heal it. This article puts the practice in order and does not replace legal advice.
“
Business Central is not GDPR-compliant at the push of a button. The system becomes compliant through the way you set it up.
Frank Maier, founder of DGP
Frequently asked questions
Briefly asked
Does my Business Central data live in the EU?
With an EU tenant region the productive business data sits in EU data centres and falls under the EU Data Boundary. Support and exception scenarios are worth clarifying up front rather than assuming.
Is Microsoft the processor?
Yes. Microsoft is the processor, you remain the controller within the meaning of the GDPR. The data processing agreement is part of the Microsoft online terms.
Can I use Copilot in a GDPR-compliant way?
In principle yes, within the same regional boundaries as Business Central. What matters is which data the assistant may see and change, and that is for you to decide.
Does the cloud make my project automatically compliant?
No. The platform provides the prerequisites. Compliance comes from your configuration: roles, retention and interfaces.
More insights
Related questions
Knowledge · International
Why do international multi-country rollouts of Business Central fail?
International multi-country rollouts of Business Central fail on coordination, not software: country exceptions quietly erode the standard template, governance across borders is missing, and local data realities stay undiscovered until they delay go-live. Whoever fixes template, data foundation and decision paths before the first wave keeps the rollout steerable.
01.08.2026
Read →Knowledge · International
How do you build a global template for an ERP rollout?
A global template is a decision, not a document: which processes and data apply group-wide, and who decides on exceptions.
04.08.2026
Read →Knowledge · International
ERP rollout: all countries at once, or one after another?
Big bang, waves or pilot: the sequence decides risk, pace, and whether your team survives the rollout.
04.08.2026
Read →How is your data foundation set up?
A first conversation in which we assess your starting position. Senior-led, without detours.