Three questions, not one #
"Can I put client data into ChatGPT" is really three questions stacked on top of each other, and they have different answers with different people responsible for them.
Is it personal data?
If it identifies a living individual, UK GDPR applies and the practice is the one accountable for how it is processed.
The ICO publishes guidance and resources on artificial intelligence, including detailed guidance on applying UK GDPR principles to AI systems, guidance on explaining decisions made with AI, and an AI and data protection risk toolkit for assessing risks to individual rights and freedoms. Those are the documents your assessment should be built on, not a supplier's marketing page.
Is it confidential?
Confidentiality is a separate duty from data protection, and it covers information that is not personal data at all. A company's unpublished results are confidential without being anybody's personal data. Your professional body's code and your own engagement terms set the standard here, and they are the documents to read.
Can you rely on what comes back?
This one gets forgotten because it is not a legal question. It is a competence question.
The nearest regulator has already said the quiet part #
Accountancy does not have a single regulator publishing on this in the way the legal profession does, so the most useful precedent comes from next door. In its Risk Outlook report on the use of artificial intelligence in the legal market, published on 20 November 2023, the Solicitors Regulation Authority warned about three things.
-
Staff uploading sensitive client information to public AI tools
-
A model reproducing confidential details from one matter in an answer about another
-
Fabricated material
It noted that “AI drafted legal arguments have included non-existent cases”.
On responsibility it was unambiguous.
you will remain responsible and accountable for the outputs from AI you are using
The SRA does not regulate accountants, and nothing in its rules binds your practice. But the three risks it describes are not legal risks. They are risks of the tool, and they land the same way in a practice handling tax affairs.
What usually goes wrong first #
Not a data breach. A governance gap. Somebody finds a tool genuinely useful, uses it on a real piece of work because it saves an hour, and nobody has ever said whether that is allowed. Six months later the practice discovers it has an undocumented dependency and no record of what has been put where.
That failure has nothing to do with the technology and everything to do with the fact that no decision was taken. Two things prevent it, and neither requires buying anything: a clear position on what may and may not go into which tools, and somebody named who owns that position.
Which parts of this decision run on rules #
Runs on rules
- Knowing which systems hold client data (though most practices have never written the list down)
- Knowing who has access to what
- Recording that a decision was taken, and when
Judgement
- Deciding whether a category of information may be used at all (it belongs to the practice)
- Assessing risk to individuals (informed by ICO guidance)
- Reviewing output before it reaches a client (always)
What this consultancy will not do #
We will not tell you
- That a particular tool is safe for client data
- That a configuration is compliant
- That a supplier’s assurances are sufficient
Those are conclusions a practice has to reach for itself, with its supervisor and its own risk assessment, and any consultant who offers them cheaply is offering you their risk appetite rather than an answer.
What we will do is help you separate the work that needs client data from the work that does not, because a surprising amount of the admin load in a practice is date arithmetic and status tracking that never has to see a client's figures at all.
That distinction is where most of the safe ground is. It runs through the deadline calendar and what has actually changed for practices, and the free audit starts by drawing it.