← articles

Is ChatGPT safe for client data?

It depends on the plan, and on whose rules the firm answers to. The regulators and professional bodies quoted here, from Britain, the United States and Europe, each set conditions on putting client information into an AI tool, and some say it should not go into a public tool at all. OpenAI's own pages set different terms for its personal plans, its business plans and its API. This puts the two side by side for law firms, accountants and anyone else holding confidential client data, with every OpenAI statement read on 3 October 2026. This is not legal advice.

8 min read sources checked 3 October 2026 jump to sources

Private AI for your firm Book a 15-min intro call

// the rules: Britain

What British regulators say

Paragraph 6.3 of the Code of Conduct for Solicitors, issued by the Solicitors Regulation Authority (SRA) for England and Wales, requires solicitors to keep the affairs of current and former clients confidential "unless disclosure is required or permitted by law or the client consents".1

On 17 August 2026 the SRA published a warning notice on the misuse of AI. It states that "Both free to use and paid for AI systems may pose risks to client confidentiality", and that "Client information should only be entered into AI systems where appropriate contractual, technical and organisational safeguards are in place to protect confidentiality." The notice adds that firms should satisfy themselves that client data "is not used to train AI models except where explicitly authorised and appropriate to do so, and is not retained longer than necessary".2

The Law Society's guide "Generative AI – the essentials", updated in June 2026, says confidential data should not go into "a free, online generative AI service where you have no operational relationship with the vendor other than use". It also states: "Careful consideration needs to be taken when client data is to be shared with a third-party AI vendor."3

ICAEW's guidance on generative AI and ethics states that respecting client confidentiality "means not loading confidential information into public Generative AI tools, even if such information has become publicly available." Its reason: "There is limited visibility and control over who the information is shared with, how it is secured and how long it is retained."4

Where the information is personal data, guidance from the Information Commissioner's Office (ICO), the UK's data protection regulator, states that "The UK GDPR imposes a legal obligation on controllers and processors to formalise their working relationship", and reads Article 28(3) as requiring a written contract every time a controller uses a processor.5

// the rules: United States

What American bodies say

The American Bar Association issued Formal Opinion 512, its first formal ethics opinion on generative AI, on 29 July 2024. The ABA's release summarises its reading of Model Rule 1.6: "a lawyer using GAI must be cognizant of the duty to keep confidential all information relating to the representation of a client, regardless of its source, unless the client gives informed consent."6 The opinion's own PDF returned an access error when requested for this article, so the wording here is the ABA's release.

For accountants, the AICPA Code's Confidential Client Information Rule provides: "A member in public practice shall not disclose any confidential client information without the specific consent of the client." Its interpretation on third-party service providers sets out two routes before confidential client information is disclosed to one: a contract under which the provider maintains confidentiality, with reasonable assurance that it has procedures to prevent unauthorised release, or "specific consent from the client".7

For tax practitioners, the IRS Office of Professional Responsibility published guidelines on AI use on 24 June 2026. They state that "GAI platforms may present risks regarding the unauthorized disclosure of sensitive taxpayer information, especially when data is uploaded to unsecured or public systems", and that "Practitioners must strictly handle all client data using only secure, enterprise-approved AI." The same guidelines point to the civil and criminal preparer penalties in sections 6713 and 7216(a) of the Internal Revenue Code.8

// the rules: Europe

What European bodies say

The Council of Bars and Law Societies of Europe published a guide on generative AI for lawyers on 2 October 2025. It states that "The professional rules apply to all client data", and that lawyers "should refrain from entering any personal, confidential or other data related to the client into the user interface of the GenAI" unless appropriate safeguards are in place. The safeguards it lists include a data protection agreement limiting use of the data to the firm's purposes, and "setting up AI systems to run locally or within a secured environment controlled by the law firm".9

On 6 August 2024 the Dutch Data Protection Authority reported that it had received breach notifications caused by employees entering personal data into AI chatbots. In one, an employee of a GP practice had entered patients' medical data; in another, a telecom employee had entered a file that included customer addresses. The authority states: "By entering personal data into AI chatbots, the companies that offer the chatbot may gain unauthorised access to those personal data." Where an employee does this against the employer's agreements, it states, "this means there is a data breach".10

// OpenAI's own terms

What OpenAI says about each plan

OpenAI separates services for individuals from services for businesses. For the first: "When you use our services for individuals such as ChatGPT, Sora, or Operator, we may use your content to train our models." For the second: "By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Team, ChatGPT Enterprise, and the API."11 "ChatGPT Team was renamed to ChatGPT Business on August 29, 2025."12

PlanTraining on contentRetentionData Processing Addendum
Free, Plus, Pro May be used to train. With "Improve the model for everyone" off, "your new conversations won't be used to train OpenAI models."11,13 A deleted chat leaves the account view at once and is scheduled for permanent deletion "within 30 days", with security and legal exceptions. A Temporary Chat copy may be kept "for up to 30 days for safety purposes."13 Not among the products OpenAI's privacy page names for its DPA.14
Business (formerly Team) "Business data is excluded from training by default."12 "Your workspace admins can control how long your data is retained." Deleted or unsaved conversations are removed within 30 days, unless the law or harm prevention requires longer.14 Available.14
Enterprise, Edu "By default, we do not use your business data for training our models."14 "Your workspace admins control how long your data is retained." Eligible new workspaces can choose where content is stored at rest; the United Kingdom is one of the listed regions.14,15 Available for Enterprise.14
API "As of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)."16 Abuse-monitoring logs, which can hold prompts and responses, are kept "for up to 30 days" by default. Approved customers can exclude their content through Zero Data Retention.16 Available.14

OpenAI's pages, read on 3 October 2026. Several help pages show only a relative date, such as "Updated: 4 days ago".

// the court order

When deleted did not mean deleted

For part of 2025, deleting a ChatGPT chat did not remove it from OpenAI's systems. In its copyright case against OpenAI, The New York Times asked for user content to be preserved, including "even deleted ChatGPT chats". A court order required it. OpenAI's own page listed who was affected: "ChatGPT Free, Plus, Pro, and Team" and API use "without a Zero Data Retention agreement". It also said: "This does not impact ChatGPT Enterprise or ChatGPT Edu customers."17

"Our obligations under the earlier order ended on September 26, 2025," OpenAI wrote in an update dated 22 October 2025. It still holds "limited historical April–September 2025 user data", stored under legal hold.17

In 2025, a court order outranked the deletion promise. Which plan a firm was on decided whether its deleted chats were swept in.

// where they meet

Where the rules meet the plans

None of the guidance quoted above names a ChatGPT plan, and none of it approves one.

On OpenAI's own pages, a personal plan may train on what is typed into it unless the user switches that off, and it is not among the products OpenAI's privacy page names for a DPA. That is close to the Law Society's free online service with "no operational relationship with the vendor other than use", and to the public tools ICAEW describes. That reading is this article's, not the Law Society's or ICAEW's.

The business plans and the API change two things the guidance asks about: training is off by default, and a Data Processing Addendum is available. Admins of Business and Enterprise workspaces control retention, and Enterprise and API customers can pick where content is stored. Whether that adds up to "appropriate contractual, technical and organisational safeguards", in the SRA's words, is a judgement each firm makes. No regulator quoted here has made it for any plan.

The American texts add client consent as a route of its own. The AICPA interpretation accepts either a confidentiality contract with the provider or the client's specific consent, and the ABA's release puts informed consent at the centre of Rule 1.6.

On every plan, the text goes to OpenAI. The terms decide what OpenAI may do with it once it arrives.

// the other route

A model that stays in the building

One of the safeguards the CCBE lists takes the provider out of the question: AI systems that "run locally or within a secured environment controlled by the law firm".9 The CCBE's technical guide, published on 27 March 2026, adds: "On-premise deployment is often preferred when the users deal with confidential or sensitive data."18

That is what private AI means here: a local AI model on the firm's own hardware, answering from the firm's own documents, with nothing sent to a vendor. The firm takes on the machine and its upkeep instead of a subscription. A model small enough to run in an office is not the model behind ChatGPT, so what it can do on a firm's documents has to be tested on those documents rather than assumed.

I offer this as a service. There is no client case study yet: how it works.

// caveats

What this does not establish

  • That any ChatGPT plan meets any regulator's rules. None of the texts quoted names one.
  • That OpenAI's pages still say this. They were read on 3 October 2026, and several show only a relative update date.
  • The full text of ABA Formal Opinion 512, which returned an access error. The ABA's own release is quoted instead.
  • The position in any other country, or for any other AI provider. One set of examples is given for Britain, the United States and Europe.
ClaimSourceRead
1. Paragraph 6.3: confidentiality "unless disclosure is required or permitted by law or the client consents" Solicitors Regulation Authority, Code of Conduct for Solicitors 3 Oct 2026
2. Free and paid AI systems "may pose risks"; client information only with "appropriate contractual, technical and organisational safeguards"; not used to train, not retained longer than necessary Solicitors Regulation Authority, Misuse of AI: warning notice, 17 August 2026 3 Oct 2026
3. No confidential data in a free online service with "no operational relationship with the vendor other than use"; "Careful consideration" before sharing client data with an AI vendor The Law Society, Generative AI – the essentials, updated June 2026 3 Oct 2026
4. Confidentiality "means not loading confidential information into public Generative AI tools"; "limited visibility and control" ICAEW, Generative AI and ethics (no date shown) 3 Oct 2026
5. UK GDPR obligation to formalise the controller–processor relationship; a written contract under Article 28(3) Information Commissioner's Office, When is a contract needed and why is it important? 3 Oct 2026
6. Formal Opinion 512, 29 July 2024; Rule 1.6 duty "unless the client gives informed consent" American Bar Association, ABA issues first ethics guidance on a lawyer's use of AI tools, 29 July 2024. The opinion returned an access error 3 Oct 2026
7. ET 1.700.001: no disclosure "without the specific consent of the client"; ET 1.700.040: a confidentiality contract or "specific consent from the client" AICPA, Code of Professional Conduct (2026 PDF) 3 Oct 2026
8. Risk "when data is uploaded to unsecured or public systems"; "only secure, enterprise-approved AI"; IRC 6713 and 7216(a) IRS Office of Professional Responsibility, Introductory guidelines for responsible AI use in federal tax practice, issue 2026-19, 24 June 2026 3 Oct 2026
9. "The professional rules apply to all client data"; refrain from entering client data unless safeguards exist; safeguards include a data protection agreement and running AI locally CCBE, Guide on the use of generative AI by lawyers, 2 October 2025, pages 17–18 3 Oct 2026
10. Breach notifications from staff entering patients' medical data and customer addresses into AI chatbots; "may gain unauthorised access" Autoriteit Persoonsgegevens (Dutch DPA), Caution: use of AI chatbot may lead to data breaches, 6 August 2024 3 Oct 2026
11. Individual services: "we may use your content to train our models"; business products: "we do not train on any inputs or outputs" by default OpenAI, How your data is used to improve model performance, updated 13 March 2026 3 Oct 2026
12. Team renamed Business on 29 August 2025; "Business data is excluded from training by default" OpenAI Help Center, ChatGPT Business: general FAQ and Managing data, sharing and privacy in ChatGPT Business 3 Oct 2026
13. Training off for new conversations; deleted chats scheduled for deletion within 30 days; Temporary Chat copy up to 30 days OpenAI Help Center, Data controls in ChatGPT, Chat and file retention and Temporary chat 3 Oct 2026
14. No training on business data by default; admins control retention; DPA for ChatGPT Business, ChatGPT Enterprise and the API OpenAI, Enterprise privacy at OpenAI, updated 8 January 2026 3 Oct 2026
15. Data residency for eligible API and new Enterprise/Edu customers; the United Kingdom among the regions OpenAI Help Center, Data residency and inference residency for ChatGPT 3 Oct 2026
16. API data not used for training since 1 March 2023; abuse-monitoring logs up to 30 days; Zero Data Retention for approved customers OpenAI, Data controls in the OpenAI platform 3 Oct 2026
17. Preservation of deleted chats; plans affected and excluded; obligations ended 26 September 2025; April–September 2025 data still held OpenAI, How we're responding to The New York Times' data demands, 5 June 2025, updated 22 October 2025 3 Oct 2026
18. "On-premise deployment is often preferred when the users deal with confidential or sensitive data" CCBE, Technical guide on the use of AI tools and models by lawyers, 27 March 2026 3 Oct 2026

Regulator texts and OpenAI's pages read on 3 October 2026. OpenAI's policies change often. No regulator quoted names or approves a specific product.

Tell me what your firm needs to keep in the building.

Remote, worldwide, in English. Reply within one business day.

Private AI for your firm Book a 15-min intro call

The service this describes: private AI