Guide7 min read

AI for Tax Advisors: Protecting Client Data Under GDPR

How tax advisors can use AI like ChatGPT without breaching confidentiality duties (StGB 203) or GDPR. Practical steps, a risk table, and organizational duties.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

Yes, tax advisors may use AI tools. But never with real client data in plain text. Typing names, tax IDs, or amounts straight into ChatGPT, Copilot, or Gemini risks two violations at once: a breach of the statutory duty of confidentiality (Section 203 of the German Criminal Code) and a breach of the GDPR. The fix is simple. You replace sensitive details with placeholders (pseudonyms) before you send anything, then work with the AI.

Why AI is especially sensitive for tax advisors

Tax advisors are bound by a statutory duty of secrecy. They may not disclose secrets entrusted to them. When you enter client data into an AI tool, that data leaves your firm and lands on third-party servers. That alone can break confidentiality and breach the GDPR at the same time. Two sets of rules apply here:

  • Criminal law: Section 203 of the German Criminal Code (StGB) penalizes the disclosure of private secrets. Tax advisors are named explicitly. A breach can be punished by up to one year in prison or a fine.
  • Professional law: The German Tax Advisory Act (StBerG) requires confidentiality. A breach can lead to professional sanctions from the chamber.
  • Data protection law: The GDPR requires a legal basis, data minimisation (Art. 5), and a contract with every processor acting on your behalf.
  • Special categories: Health or social data is specially protected under GDPR Art. 9. It never belongs in an AI tool unprotected.

Which client data is critical

Not every field carries the same risk. But the typical data in a tax firm is almost always identifying. The table below shows which item carries which risk, and how to protect it before you work with an AI.

Client dataRiskProtective measure
Client name and addressDirectly identifying; possible breach of secrecy under StGB 203Replace with a token before input
Tax ID or tax numberUnique identifier; high re-identification riskTokenize, never send in plain text
Amounts (revenue, profit, salary)Can point back to a person or companyMask or tokenize the values
Health or social dataSpecial category under GDPR Art. 9; strictest protectionDo not enter at all, or tokenize strictly
Company name and trade registerIdentifies the client; often a trade secretReplace with a placeholder
Bank details (IBAN, BIC)Direct attribution; risk of misuseTokenize before input
Typical client data, its risk, and the matching protective measure.

How to anonymize before the AI

The safest rule is easy to remember: no plain text goes to the AI. You replace every sensitive detail with a placeholder and restore the real values only in the answer. Here is the step-by-step approach:

  1. 1Scan the text: which names, numbers, amounts, and addresses appear?
  2. 2Replace each sensitive item with a neutral token, for example [CLIENT_1] or [TAX_ID_1].
  3. 3Send only the anonymized text to the AI. The real values stay with you.
  4. 4Restore the original values in the answer once the result comes back.
  5. 5Do not store client data in chat histories you cannot control.

Doing this by hand is possible but error-prone. A single missed tax number is enough for a violation. That is why a tool that handles the replacement automatically and locally helps.

What ONYRI Sanitize handles for you

ONYRI Sanitize is built for exactly this step. It detects sensitive data in your text and replaces it with reversible tokens before the text reaches an AI. What matters is how this works technically:

  • Detection runs 100 percent in your browser. The mapping from token to real value never leaves your browser.
  • When you use the built-in Chat, only the already-anonymized text is sent to the AI model, never the original data.
  • The real values are restored only in the answer, right inside your browser.
  • You can add your own rules, for example for client numbers or your firm's internal codes.

To be clear: ONYRI pseudonymizes, it does not make your data anonymous in the legal sense. That lowers your risk clearly and supports data minimisation under GDPR Art. 5. It does not replace a legal review or any of the duties below.

Organizational duties in the firm

Technology alone is not enough. Alongside anonymization, you need clear rules and contracts. These points belong in every firm that uses AI:

  • Data processing agreement (DPA): Every external service processing data on your behalf needs a contract under GDPR Art. 28. Check whether the AI vendor offers one.
  • Check vendor statements: Whether a service uses inputs for training differs by plan. According to OpenAI, content from its business and API tiers is not used for training by default. Such statements change often, so check the vendor's current documentation.
  • Internal policy: Put in writing which AI tools are allowed and that only anonymized text may be entered.
  • Training: Every staff member must know which data never goes to an AI in plain text.
  • No special categories: Health and social data (GDPR Art. 9) never belongs in an AI tool unprotected.

Frequently asked questions

Can tax advisors use ChatGPT at all?
Yes, for general tasks without client data it is fine. As soon as real client data is involved, you must anonymize it first and respect the duty of secrecy under StGB 203 and the GDPR.
Does anonymization make my data GDPR-compliant?
No, not automatically. Anonymization lowers your risk and supports data minimisation. But pseudonymized data remains personal data under GDPR Recital 26. Your duties, such as a DPA and a legal basis, still apply.
What happens if I breach the duty of secrecy?
Section 203 StGB allows up to one year in prison or a fine. On top of that, professional sanctions from the chamber and GDPR fines are possible.
Are my inputs used to train the AI?
That depends on the vendor and plan. According to OpenAI, business and API content is not used for training by default. Because such rules change often, check the current documentation and sign a data processing agreement.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next