Can you put client information into ChatGPT?
Can staff put client details into ChatGPT?
Why the account decides it, and six checks to make first.
Not into a personal or free account.
Possibly into a business account, once you have made six checks and written down a rule.
And whatever you decide, assume someone on your team is already doing it, because in most small firms someone is.
The account type decides most of the answer
“ChatGPT” covers several products with different terms.
The question that matters is which one your staff log into before they paste something in.
| Personal or free account | Business plan or API | |
|---|---|---|
| Used to train models? | Can be, unless each user switches it off | Not by default, according to OpenAI |
| Data processing agreement? | No | Available, once you sign it |
| Who controls the account? | The employee | The firm |
| When someone leaves | Their chat history leaves with them | You remove their access |
The missing processing agreement is usually what settles it.
UK GDPR requires one whenever a supplier processes personal data on your behalf.
Without it you cannot show the supplier acts only on your instructions.
So a personal account is the wrong place for client details, whatever its privacy settings say.
Confidentiality is a separate problem
Data protection is about people’s personal data.
Confidentiality covers everything a client tells you, including figures about their business that identify nobody.
In February 2024 ICAEW warned its members that inputting client data of any kind into tools such as ChatGPT is a potential breach of confidentiality.
So check your engagement letters and client contracts too.
Some forbid passing client information to a third party without consent, and an AI provider is a third party.
Six checks before client data goes in
- —A signed data processing agreement. Business plans offer one, but it only protects you once you have completed and signed it.
- —Training switched off. Confirm it in the terms for the plan you are on.
Do not rely on a setting each employee has to remember. - —Company accounts only. If staff use their own logins, you cannot see what they shared or delete it, and you lose it all when they leave.
- —Where the data goes. Most AI providers process in the United States.
That transfer needs a legal route, such as the UK extension to the EU–US Data Privacy Framework or the UK’s international data transfer agreement. - —How long it is kept. Find out how long the provider keeps prompts, files and chat histories, and whether you can delete them when a client asks.
- —Your privacy notice. If client personal data will go into an AI tool, your notice should say so.
Health, criminal record or children’s data also usually means a data protection impact assessment first.
Your profession may have its own rules
UK GDPR is the floor.
Regulated firms answer to more than that, and generic AI advice tends to drift into American rules that do not apply here.
- —Accountants have ICAEW’s confidentiality warning above, and its guidance on generative AI.
- —Solicitors have the SRA’s and the Law Society’s guidance, and privilege to protect as well as confidentiality.
- —Recruiters should read the ICO’s findings from its audits of AI recruitment tools, especially before any tool sorts or screens candidates.
- —Financial advisers and brokers have the FCA’s Consumer Duty, which applies to AI-assisted communications as to any other.
What staff can use it for today
Most of the time AI saves needs no client information at all.
Job advert templates, first drafts of generic emails, explaining a rule, structuring a report or a checklist: none of these need a name in them.
Be careful with “anonymised”.
Removing a name is not enough if the role, the town and the date still point to one person.
If someone could trace the text back to a person, treat it as personal data.
A rule for your team this afternoon
Use AI freely for work with no client information in it. Do not paste client names, contact details, financial records or documents into any AI tool until the firm has approved one. If something goes in by mistake, say so the same day.
Getting it checked
For most small firms the six checks above are an afternoon’s work: read the terms, sign the agreement, move everyone onto company accounts, update the privacy notice.
Write the result down as a one-page policy so the rule outlives the conversation.
Any AI supplier you use should be able to show you the same things: a processing agreement and a list of who else handles your data.
Ours are public: our data processing agreement and our sub-processor list.
When the question is bigger than one tool, such as which work to put through AI at all, an AI audit answers it.
This guide explains the questions to ask.
It is not legal advice.
For a decision about your own firm, check the ICO’s guidance or speak to a data protection adviser.
Frequently asked questions
Is ChatGPT GDPR compliant?
No tool is compliant on its own; your use of it is.
A business plan with a signed data processing agreement can support compliant use.
A personal account used for client work usually cannot.
Does ChatGPT train on what my staff type in?
It depends on the plan.
OpenAI says it does not train on business plans or its API by default.
It can train on personal accounts unless each user switches the setting off.
Is removing the client's name enough?
Often not.
A role, a town and a date can identify somebody as surely as a name.
Treat anything someone could trace back to a person as personal data.
What should staff use ChatGPT for until we have checked?
Use it for work with no client information in it.
Templates, generic emails and document outlines save most of the time, at none of the risk.
Keep reading
Get started
See it on your own business
Opafex is live in beta.
Tell us your first agent’s job and we’ll set you up.