Compliance8 min read

Can Lawyers Use ChatGPT? Client Confidentiality & GDPR

Yes, lawyers can use AI like ChatGPT — but only with a contract and without real client data. Here is how to protect confidentiality and meet the GDPR.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

Yes, lawyers can use AI tools like ChatGPT — but not every version is safe. Client confidentiality and the GDPR set clear limits. Typing real client data into a public AI tool can breach your duty. A business account with a contract, plus pseudonymised input, makes it far safer. This article explains what matters.

Can lawyers use AI at all?

AI is already part of everyday firm work: research, drafts, summaries. In principle, this is allowed. The question is not whether, but how.

  • Free public versions are rarely fit for real client data.
  • Business accounts with a contract give you more control.
  • You, the lawyer, stay responsible — not the vendor.
  • Professional rules and data protection apply together.
  • A clear internal AI policy is a must.

What client confidentiality requires

Client confidentiality is protected by professional secrecy rules and by data protection law. Disclosing protected information to a third party can breach your duty. In most jurisdictions this duty is both an ethical and a legal obligation.

  • Professional secrecy covers what a client tells you.
  • A public AI tool can count as a third party.
  • Even typing real data can be a disclosure.
  • The duty also binds your staff.
  • Breaches can carry professional and legal sanctions.

Personal account or business contract?

You may involve a service provider only if it is contractually bound to confidentiality. For AI, that means a Data Processing Agreement (DPA) under Article 28 GDPR with a business account, not a personal one. According to OpenAI's Enterprise Privacy documentation, business data is not used to train its models by default — but always confirm this in the current documentation.

  • Personal accounts usually offer no DPA.
  • Business and Enterprise plans allow a DPA under Article 28.
  • The contract must cover instructions, deletion and sub-processors.
  • Check whether your input is used for training.
  • Without a contract, the confidentiality link is missing.

The simplest lever: no identifying data

The safest and simplest lever is data minimisation under Article 5 GDPR. What the AI never sees, it cannot disclose. Replace names, addresses and case numbers with placeholders before you send.

  • Do not use real names in the prompt.
  • Remove addresses, dates of birth and case numbers.
  • Describe the case in the abstract, not in detail.
  • Pseudonymise data before sending.
  • Restore the real values only locally.

Checklist before your first prompt

Before you put a real case into an AI, run through these points. The order helps you avoid mistakes.

  1. 1Confirm the account type and vendor.
  2. 2Sign a DPA under Article 28.
  3. 3Check the training and deletion rules.
  4. 4Pseudonymise identifying data.
  5. 5Document your decision internally.
ScenarioMain riskRecommendation
Personal AI account + real client namesDisclosure to a third party, possible trainingAvoid
Business/Enterprise with a DPA (Art. 28)Processing governed by contractPossible after review
Pseudonymised inputFewer identifiable data exposedRecommended, in addition
Free tool without a contractNo legal basis or DPADo not use
Article 9 data (e.g. health)Higher legal requirementsExtra caution

This is where ONYRI Sanitize fits in. It detects sensitive data in your text and swaps it for reversible placeholders before the text reaches the AI. The mapping table stays in your browser and is never sent to a server. After the reply, the real values are restored. Important and honest: this is pseudonymisation, not anonymisation. Pseudonymised data stays personal data (GDPR recital 26). ONYRI reduces exposure, but it replaces neither a DPA nor a legal basis.

The core rule is simple: the fewer identifiable data the AI sees, the smaller the risk. Sort out the contract, choose the right account, and minimise what you type. That keeps client confidentiality protected.

Frequently asked questions

Can lawyers use ChatGPT for firm work?
Yes, with limits. Use a business plan with a contract, and avoid entering identifiable client data.
Does using AI breach client confidentiality?
Only if you disclose identifiable protected information without a proper contract and suitable safeguards.
Do I need a DPA with the AI vendor?
Yes, when personal data is processed. Article 28 GDPR requires a data processing agreement.
Is pseudonymisation enough for GDPR compliance?
No. It reduces risk, but pseudonymised data stays personal data and still needs a legal basis.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next