QuestionLegal ServicesAI GovernanceData Protection

Can solicitors use ChatGPT with client data?

16 September 2026
Answered by Rohit Parmar-Mistry

Short answer

A quick answer first, then the fuller context below.

Solicitors should not use ChatGPT with client data unless the firm has approved the exact tool, account type, data terms and human review process. If those controls are missing, keep client data out and use anonymised or governed workflows instead.

What this points to

This usually points to Secure AI implementation

If this question reflects a real workflow, supplier, data or governance decision inside the firm, do not treat the answer as theory. Use it to decide whether you need a light assessment, a deeper audit, a controlled implementation path, governance support or recovery from a genuinely stalled AI attempt.

Detailed answer

The fuller context, trade-offs and practical steps behind the short answer.

Why solicitors ask this before using ChatGPT on client work

Solicitors can use AI tools in legal work, but client data changes the risk profile. The practical question is not whether a chatbot is useful. It is whether the firm can protect confidentiality, comply with UK GDPR, control where data goes, and evidence human professional review before anything reaches a client.

For most firms, the safest default is simple: do not put identifiable client information, privileged material, special category data, matter documents or commercially sensitive details into a public AI tool unless the firm has approved that exact tool, account type and processing arrangement.

The safe answer for solicitors using ChatGPT with client data

Solicitors should not use ChatGPT with client data unless the firm has a documented approval covering confidentiality, data processing terms, retention settings, access controls and review responsibilities. If those controls are not in place, use anonymised prompts, internal approved tools, or a controlled workflow where client data stays inside the firm's governed environment.

This is not a ban on AI-assisted legal work. It is a governance requirement. Drafting, summarising, research support and first-pass analysis can be useful, but the firm needs to know what information is being processed, by whom, under which terms, and how the output is checked before it influences advice or client communication.

Check where AI is already touching client data

What counts as client data in this context

Client data is broader than a name in a prompt. It can include matter facts, document extracts, chronology details, contract clauses, witness information, case strategy, financial records, personal data, special category data, commercially sensitive information and privileged communications.

Even a prompt that looks anonymous can still reveal enough context to identify a client, dispute, transaction or individual. A safe policy should define what staff must never enter into unapproved AI tools, what can be used after redaction, and which tasks require an approved firm-managed environment.

The checks a firm should complete before approval

Before solicitors use ChatGPT or a similar tool with client data, the firm should answer five questions in writing:

  • Processing role: is the provider acting as a processor, controller, or something else for the data entered?
  • Contract terms: is there an Article 28-style data processing agreement or equivalent enterprise contract covering the actual product tier?
  • Training and retention: can prompts, files and outputs be used to train models, retained for review, or accessed by provider staff?
  • Location and access: processing and storage locations, plus the people able to access logs, files and outputs.
  • Firm controls: does the firm have SSO, account ownership, audit logs, user guidance, matter-level restrictions and a route for incident review?

If any answer is unknown, the tool should not receive client data. Unknown is not a safe processing basis.

How to use AI safely when the firm still wants the efficiency

A workable operating model separates low-risk AI use from client-data use. General drafting support, structure suggestions, training examples and policy templates can often be handled with synthetic or anonymised material. Client-specific work should move through approved tools, controlled data access and human review gates.

For legal teams, a useful minimum standard is:

  • approved AI tool list with permitted and prohibited uses;
  • prompting rules for anonymisation and redaction;
  • matter-type rules for privilege, litigation, employment, family, immigration and other sensitive work;
  • audit trail showing who used which tool, for which purpose, and what review happened;
  • named professional owner for output quality and client communication;
  • incident route for accidental disclosure or use of an unapproved tool.

Put practical AI governance around legal work

What the human review needs to prove

Human review should be more than a quick read-through. The reviewer should check legal accuracy, missing context, invented facts, outdated law, confidentiality risks, tone, and whether the output is appropriate for the client and matter. Where AI materially influenced a document or recommendation, the file should contain enough evidence to show professional judgement remained with the firm.

That evidence does not need to be heavy. It can be a matter note, workflow log, checklist or approval record. The important point is that the firm can explain what AI did, what it did not do, what data was used, and who accepted responsibility for the final work.

Conclusion

Solicitors can benefit from ChatGPT-style tools, but client data should only be used inside a governed setup. If the firm cannot prove the contract terms, data handling, retention position, access controls and review process, the right answer is to keep client data out and redesign the workflow.

Build an approved AI workflow for client-facing work

Frequently asked questions

Direct follow-up answers written for searchers, buyers and internal decision makers.

Can a solicitor paste a client email into ChatGPT?

Not unless the firm has approved that exact use, tool tier and data processing setup. A client email may contain confidential, privileged or personal data, so the safe default is not to paste it into an unapproved public tool.

Is anonymising the facts enough?

Sometimes, but not always. Redaction must remove details that identify the client, matter or individual indirectly. Sensitive matters often need a stricter rule than basic anonymisation.

Does using ChatGPT make the provider a data processor?

It depends on the product terms and the way the service is configured. The firm should verify the provider's role, contract terms, retention settings and training position before client data is used.

Can AI outputs be sent to clients if a solicitor checks them?

They can only be used if the solicitor performs a proper professional review and the underlying AI workflow complies with the firm's confidentiality, data protection and quality rules.

What should a firm do first?

Map where AI is already being used, classify the data involved, approve a small set of controlled use cases, and record the review evidence needed for each client-facing workflow.

Need More Specific Guidance?

Every organisation's situation is different. If you need help applying this guidance to a specific process, book a discovery call or take the assessment first.