In this piece
ChatGPT Enterprise vs Microsoft Copilot vs Custom RAG: Which Should a DACH Company Shortlist?
Short version for a company in Austria, Germany, or Switzerland: shortlist Microsoft Copilot when work and governed knowledge already live in Microsoft 365. Shortlist ChatGPT Enterprise when a broader assistant and connections across several systems matter more. Build custom RAG when a defined workflow needs controls, retrieval behavior, hosting, or model choices that managed products do not provide and you can maintain the system. No product label establishes GDPR compliance. Roles and duties depend on the actual processing, purposes, and contracts.
This is a procurement and engineering view, not a vendor pitch. Product names, prices, and data terms were checked on 2 September 2026 and can vary by market, commitment, workspace eligibility, feature, and negotiated contract. Verify the linked vendor pages and your final order form before signing.
Want a neutral read on which of these fits your company?
Book Free ConsultationThe comparison at a glance
The dimensions that usually decide this, side by side. Re-check commercial and technical terms for the exact tenant and configuration.
| Dimension | ChatGPT Enterprise | Microsoft Copilot | Custom RAG |
|---|---|---|---|
| Pricing | Enterprise is custom-priced and may use credit- or token-based commercial terms | Microsoft Copilot and Copilot Business require an eligible base plan; list prices and promotions vary by market and commitment | Engineering, infrastructure, model, retrieval, evaluation, security, and operations costs |
| Prerequisites | An eligible contracted workspace; residency and advanced controls depend on plan and workspace eligibility | An eligible Microsoft 365, Office 365, Teams, Exchange, SharePoint, OneDrive, or other listed base plan, depending on the Copilot license | Product ownership plus engineering, security, data, and operations capacity |
| Uses customer data for foundation-model training by default | No | No | Depends on the models, vendors, contracts, and telemetry you configure |
| What it is grounded in | General knowledge plus opt-in connectors | Your Microsoft 365 data, permission-trimmed | Your own corpus, any source |
| European location controls | Eligible new Enterprise workspaces can select Europe (EEA plus Switzerland) for in-scope storage; eligible workspaces can add in-region GPU inference, while exclusions and global non-GPU processing remain | EU tenant traffic is covered by EU Data Boundary commitments, with documented exclusions for features such as Bing web queries and Anthropic processing | Only the locations and subprocessors your complete architecture and contracts actually enforce |
| Governance and admin | SSO, SCIM, IP allowlists, connector gating, compliance logs | Purview, DLP, sensitivity labels, restricted SharePoint search | Whatever you build |
| Portability | Export and migration depend on workspace features, connectors, and contract | Deep Microsoft 365 integration increases migration work | Can be designed for portability, but infrastructure and data-model choices still create dependencies |
| Time to value | Usually a managed-product rollout | Usually faster when identity, permissions, content, and governance are already ready | Depends on corpus quality, authorization, integrations, evaluation, and operating requirements |
One caveat that matters for a DACH audience: Microsoft documents that customer data sent to enabled Anthropic models is processed in the United States and is outside the EU Data Boundary, while stored customer data remains within the boundary. Bing web queries also have a separate exclusion. If location is a selection criterion, map each enabled feature and model rather than treating Copilot as one uniform processing path.
ChatGPT Enterprise
ChatGPT Enterprise is a managed assistant with company controls and connections to multiple business systems. OpenAI states that business data is not used to train its models by default and offers a DPA, custom retention, identity and administration controls, and published security attestations. Some regulated features require a specific workspace configuration, so confirm the exact control rather than inferring it from the plan name. European data residency is available to eligible new Enterprise workspaces for in-scope stored content, and eligible workspaces can add in-region GPU inference. Non-GPU processing, system data, apps, and unsupported features have documented exclusions. Enterprise pricing is custom, with credit- or token-based structures available under some agreements.
Microsoft Copilot
If work already happens in Microsoft 365, Copilot can ground responses in data the signed-in user may access through Microsoft Graph. Microsoft states that prompts, responses, and Graph data are not used to train foundation models. The product previously called Microsoft 365 Copilot is now Microsoft Copilot; eligible base licenses are broader than E3 and E5. Copilot Business provides the same core capabilities for eligible Microsoft 365 Business customers and is capped at 300 seats per tenant. Copilot Chat's web-grounded mode is included with eligible subscriptions, while work-grounded chat requires a Copilot license. Pricing varies by market, billing term, and promotion. The deployment risk is overexposure through existing permissions, sharing links, or poorly governed content, so review access and sensitivity controls before rollout.
Custom RAG
A custom retrieval system is justified when a defined workflow needs hosting, authorization, corpus coverage, evaluation, or model choices that managed products cannot meet. It is not automatically sovereign, portable, secure, or cheaper: those properties depend on the complete architecture, providers, contracts, telemetry, and operations. Budget for data preparation, source-native authorization, ingestion and deletion, evaluation, observability, incident handling, and ongoing model or index changes, not just inference. Enforce effective permissions before content reaches the model and test sharing, inheritance, revocation, and stale-index failure paths. We go deep on that in our RAG production-readiness checklist for the EU.
There is also a middle ground worth naming: tools like Microsoft Copilot Studio and Azure AI Foundry, or OpenAI's agent tooling, let you customize and ground a managed product without building retrieval from scratch. That is often the pragmatic answer when "buy" is too rigid and "build" is too much.
How to choose
Pick by the constraint that actually binds you, not by which demo was shiniest.
- Choose Microsoft Copilot when you have an eligible base plan, the value is work-grounding in Microsoft 365, and the exact EU Data Boundary, web-query, model, and governance configuration meets your requirements. Clean permissions first.
- Choose ChatGPT Enterprise when its assistant, supported apps, administration, retention, and contracted Europe controls fit the workflow and risk assessment better than a Microsoft-centered deployment.
- Build custom RAG when you need residency or sovereignty on your own terms, permission-aware retrieval over a proprietary corpus, or model portability, and you have or will hire the engineering and MLOps to carry the maintenance.
- Start smaller than you think. For most teams the right first move is Copilot or ChatGPT Enterprise plus a focused enablement push, and a custom build only once a specific high-volume workflow clearly justifies it. We describe that order in how to roll out AI internally in 2026.

"No product badge settles GDPR compliance. Map the real processing and roles, then test the contract, location controls, permissions, retention, and operating procedures against that use case."
The DACH data-protection part you cannot skip
Map roles from the actual purposes and essential means. Your company may be a controller for its use, while a vendor can be a processor for contracted processing and a controller for separate purposes. Establish an Article 6 basis, transparency, minimisation, retention, security, rights handling, and a valid Chapter V transfer route where needed. Article 28 terms are required where the vendor acts as processor; a DPIA is required where the planned processing is likely to create high risk. The EU-US Data Privacy Framework adequacy decision remains in force. The General Court dismissed the first annulment action in September 2025, and an appeal is pending, so record which certified recipient and transfer route you actually use rather than calling the framework invalid or automatically requiring SCCs. Consumer accounts may not provide the company controls or processor terms needed for personal data. Residency itself is a deep topic we cover in EU data residency for AI apps in 2026.
Frequently Asked Questions
Does ChatGPT Enterprise train on our data?
Does Microsoft Copilot train on our data?
Is Microsoft Copilot GDPR compliant?
ChatGPT Enterprise in Austria, is it allowed under data protection law?
Where is our data stored and processed in Europe?
What about Schrems II and US data transfers?
Do we need an AVV or DPA?
When should we build a custom RAG instead of buying?
Can our team keep using free or Plus ChatGPT for work?
What does Copilot cost and what do we need first?
If the answer is a standard tool plus training, that rollout is our AI enablement service: the AVV and residency questions settled, permissions cleaned up, one scoped use case shipped before anyone rolls it out company-wide. If the answer is custom RAG, AI software development in Austria is the build side, and Twinsoft AI shows what the surrounding production system has to include.
Final thoughts
Choose from the workflow and constraints. Microsoft Copilot is a natural shortlist when governed work already lives in Microsoft 365. ChatGPT Enterprise can fit a broader assistant deployment across supported systems. Custom RAG is justified when a defined use case needs controls or retrieval behavior the managed products cannot provide.
Then validate the exact edition, model, feature, contract, processing roles, transfer route, location exclusions, permissions, retention, and operating controls. Pilot one bounded workflow and measure quality, risk, adoption, and total cost before expanding.