Can Lawyers Use ChatGPT? Client Confidentiality & GDPR
Yes, lawyers can use AI like ChatGPT — but only with a contract and without real client data. Here is how to protect confidentiality and meet the GDPR.
Yes, lawyers can use AI tools like ChatGPT — but not every version is safe. Client confidentiality and the GDPR set clear limits. Typing real client data into a public AI tool can breach your duty. A business account with a contract, plus pseudonymised input, makes it far safer. This article explains what matters.
Can lawyers use AI at all?
AI is already part of everyday firm work: research, drafts, summaries. In principle, this is allowed. The question is not whether, but how.
- Free public versions are rarely fit for real client data.
- Business accounts with a contract give you more control.
- You, the lawyer, stay responsible — not the vendor.
- Professional rules and data protection apply together.
- A clear internal AI policy is a must.
What client confidentiality requires
Client confidentiality is protected by professional secrecy rules and by data protection law. Disclosing protected information to a third party can breach your duty. In most jurisdictions this duty is both an ethical and a legal obligation.
- Professional secrecy covers what a client tells you.
- A public AI tool can count as a third party.
- Even typing real data can be a disclosure.
- The duty also binds your staff.
- Breaches can carry professional and legal sanctions.
Personal account or business contract?
You may involve a service provider only if it is contractually bound to confidentiality. For AI, that means a Data Processing Agreement (DPA) under Article 28 GDPR with a business account, not a personal one. According to OpenAI's Enterprise Privacy documentation, business data is not used to train its models by default — but always confirm this in the current documentation.
- Personal accounts usually offer no DPA.
- Business and Enterprise plans allow a DPA under Article 28.
- The contract must cover instructions, deletion and sub-processors.
- Check whether your input is used for training.
- Without a contract, the confidentiality link is missing.
The simplest lever: no identifying data
The safest and simplest lever is data minimisation under Article 5 GDPR. What the AI never sees, it cannot disclose. Replace names, addresses and case numbers with placeholders before you send.
- Do not use real names in the prompt.
- Remove addresses, dates of birth and case numbers.
- Describe the case in the abstract, not in detail.
- Pseudonymise data before sending.
- Restore the real values only locally.
Checklist before your first prompt
Before you put a real case into an AI, run through these points. The order helps you avoid mistakes.
- 1Confirm the account type and vendor.
- 2Sign a DPA under Article 28.
- 3Check the training and deletion rules.
- 4Pseudonymise identifying data.
- 5Document your decision internally.
| Scenario | Main risk | Recommendation |
|---|---|---|
| Personal AI account + real client names | Disclosure to a third party, possible training | Avoid |
| Business/Enterprise with a DPA (Art. 28) | Processing governed by contract | Possible after review |
| Pseudonymised input | Fewer identifiable data exposed | Recommended, in addition |
| Free tool without a contract | No legal basis or DPA | Do not use |
| Article 9 data (e.g. health) | Higher legal requirements | Extra caution |
This is where ONYRI Sanitize fits in. It detects sensitive data in your text and swaps it for reversible placeholders before the text reaches the AI. The mapping table stays in your browser and is never sent to a server. After the reply, the real values are restored. Important and honest: this is pseudonymisation, not anonymisation. Pseudonymised data stays personal data (GDPR recital 26). ONYRI reduces exposure, but it replaces neither a DPA nor a legal basis.
The core rule is simple: the fewer identifiable data the AI sees, the smaller the risk. Sort out the contract, choose the right account, and minimise what you type. That keeps client confidentiality protected.
Frequently asked questions
- Can lawyers use ChatGPT for firm work?
- Yes, with limits. Use a business plan with a contract, and avoid entering identifiable client data.
- Does using AI breach client confidentiality?
- Only if you disclose identifiable protected information without a proper contract and suitable safeguards.
- Do I need a DPA with the AI vendor?
- Yes, when personal data is processed. Article 28 GDPR requires a data processing agreement.
- Is pseudonymisation enough for GDPR compliance?
- No. It reduces risk, but pseudonymised data stays personal data and still needs a legal basis.
Sources & references
- GDPR (Regulation (EU) 2016/679), Art. 5, 6, 28 — EUR-Lex
- Generative AI and data protection oversight — European Data Protection Board
- Guidance on AI and data protection — Information Commissioner's Office (ICO)
- Enterprise Privacy (vendor documentation) — OpenAI
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.