Do law firms need a DPA before using AI tools?
Yes, if the AI tool will process client personal data, a law firm should have a suitable data processing agreement in place before any client material is entered. The DPA is not a paperwork extra. It is the contract that sets out processor duties, security controls, sub-processor rules, deletion obligations and the limits on how the provider may use the data.
For solicitors, the question is wider than UK GDPR alone. Client confidentiality, privilege, supervision, file quality and professional accountability all matter. A firm can use AI safely, but only when the tool, task and data type have been approved and the final judgement remains with a competent human reviewer.
The direct answer for client data
A DPA is needed before using AI tools on client personal data where the provider acts as a processor for the firm. The firm should also confirm that prompts, files and outputs are not used to train or improve the provider's models, that data transfers have a lawful route, and that the provider gives enough evidence for the firm's own audit trail.
Internal experimentation with anonymous, synthetic or already public material is lower risk, but it should still sit inside an approved AI policy. The operational mistake is letting fee-earners test public AI tools with real matter details before procurement, compliance and supervision have decided what is allowed.
Map the AI risk controls before client data enters a tool
What the DPA should prove before legal work starts
A useful DPA for AI-assisted legal work should answer practical questions, not simply state that the vendor is compliant. It should identify the provider's processor role, describe the categories of personal data processed, explain where data is processed and stored, name or control sub-processors, define retention and deletion terms, and set out breach notification duties.
The agreement should also deal with AI-specific risks. The firm should look for clear no-training commitments, restrictions on human access to client content, access controls, logging, export and deletion rights, and evidence that the product tier being used is covered by the stated security certifications. If those points are unclear, the safe answer is not to put client personal data into the tool yet.
How this connects to SRA duties and client confidentiality
Even a well-written DPA does not remove the firm's professional duties. The firm still needs to decide which legal tasks AI may support, which tasks are out of scope, who reviews outputs, and how errors are caught before advice reaches the client. AI should assist controlled workflow steps such as first-draft research notes, summarisation or internal checklists only where the matter risk and data controls are suitable.
Higher-risk work needs tighter rules. Privileged information, vulnerable-client matters, regulated advice, litigation strategy, negotiation positions and final client communications should not be routed through an unapproved or weakly governed AI tool. Where AI is allowed, the file should show what tool was used, what data was entered, who reviewed the output and why the final legal judgement is defensible.
Keep AI policy, vendor review and audit evidence current
A practical implementation checklist
- Classify the use case: separate research, drafting, review, client communication and decision support.
- Classify the data: mark whether the workflow touches personal data, special-category data, privileged material or commercially sensitive matter information.
- Check the contract: require a DPA, no-training terms, sub-processor controls, retention terms, deletion rights and transfer safeguards.
- Check the product tier: consumer, team, enterprise and API terms can differ materially.
- Set review rules: name the professional owner and require human review before the output affects a client or matter file.
- Keep evidence: log the approved tool, task, data boundary, reviewer and exception handling route.
This is where many firms need more than a policy PDF. The controls have to be reflected in procurement, permissions, training, matter-opening guidance and everyday supervision. Otherwise the DPA exists but the operational behaviour still creates risk.
When the answer should be no for now
The firm should pause use if the provider will not sign suitable processing terms, cannot explain data location, reserves broad rights to train on inputs, lacks deletion controls, or cannot provide evidence of security and access logging. It should also pause if staff cannot explain what data they are sending or who will review the output.
A pause is not anti-AI. It is a control decision. The safer pattern is to start with low-risk workflows, approved tools and clear review gates, then expand only after the evidence trail shows the controls work in practice.
Turn approved AI use cases into controlled implementation steps
Conclusion
Law firms can use AI tools, but client personal data should not enter those tools until the DPA, no-training terms, data-transfer position, human review process and audit trail are clear. The core governance test is simple: could the firm explain to a client, regulator or insurer what data was used, why the tool was approved, who checked the output and what evidence proves the control worked?
Need a safer AI route for your firm?
If this article reflects a live decision in your practice, the useful next step is to map the workflows, confidentiality risks, supplier controls and governance gaps before tools spread informally.