AI, Data Privacy and GDPR: What Accountants Need to Know (2026)
Pasting client data into AI tools raises real GDPR questions most firms haven't worked through — data processing terms, third-party personal data, international transfers. Here's the practical guide.
Most accountants have, at some point, pasted a client's spreadsheet, a draft set of accounts, or a payroll file into ChatGPT or a similar tool to save time. Very few have stopped to work out what that actually means under GDPR. It's not a hypothetical compliance question — client financial data almost always contains personal data, and once it leaves your systems and enters a third-party AI tool, you've made a data processing decision whether you meant to or not.
What Actually Happens When You Paste Client Data Into an AI Tool
This depends entirely on which tool and which plan. Free, consumer-facing AI tools have historically used input data to help train and improve their models unless a user actively opts out — meaning a client's financial information could, in principle, be retained and used beyond the single conversation. Enterprise and business-tier agreements from the same providers typically include contractual commitments not to train on submitted data and set defined retention periods. The practical takeaway: "we use AI" is not a policy. Which specific tool, on which specific plan, with which specific data-handling terms, is the actual question that matters.
The GDPR Obligations That Don't Disappear Because AI Is Involved
Feeding personal data into a third-party AI tool makes that provider a data processor (or, in some setups, a joint controller), which means the underlying GDPR requirements still apply in full. A firm needs a lawful basis for the processing, has to observe data minimisation — sending an AI tool a full client dataset when only three fields are relevant to the task is asking for trouble — and, if the AI provider stores data outside the UK or EEA, has to confirm that an appropriate international transfer mechanism is in place. None of this is unique to AI; it's the same processor and transfer analysis a firm should already be doing for any third-party software it uses. AI tools just make it easier to send large volumes of sensitive data somewhere without thinking about it first, because the interface is a text box, not a formal system integration.
The Practical Risks Firms Are Missing
The clearest risk isn't the client's own data — it's the personal data of other people embedded inside it. Payroll files contain employee National Insurance numbers and salary details. Due diligence documents contain data on third parties who never agreed to anything. A firm that has a sensible policy for its own client relationship can still be exposed because nobody thought about the people one step removed from the engagement whose data is sitting inside the same file.
Building an AI Use Policy That Actually Protects You
A workable policy names the specific tools staff are approved to use, states which categories of data are never to be entered into a general-purpose AI tool (unredacted client personal data, third-party personal data, anything covered by a specific confidentiality undertaking), and requires enterprise or no-training-on-input tiers for any tool that will see real client data at all. It should also set out who signs off on adding a new AI tool to the approved list, since "someone in the team started using a new tool" is how most of these exposures actually happen.
How This Differs From the Broader AI Regulation Conversation
It's worth distinguishing this from the wider regulatory picture covered in our EU AI Act guide for finance professionals, which is about how AI systems themselves get classified and governed by risk level, and from our broader AI compliance training guide, which covers what regulators expect of AI governance generally. Data privacy is narrower and more immediate: it's not about whether an AI system is high-risk under a new regulatory framework, it's about the same GDPR obligations that already apply to every other piece of software a firm uses, applied properly to AI tools specifically. If your firm already has a solid GDPR compliance checklist, the AI-specific gap is almost always in that list of approved tools and data categories, not in the underlying legal framework.
FAQ
Is it illegal to use ChatGPT with client data?
Not inherently — but doing so without checking the tool's data-handling terms, without a lawful basis for the processing, and without considering whether the data includes third parties' personal data, creates real GDPR exposure. The fix is usually an enterprise-tier tool and a clear internal policy, not avoiding AI altogether.
Does using AI tools count as sharing data with a third party under GDPR?
Generally yes — the AI provider is acting as a data processor (or in some cases a controller), so the same due diligence a firm applies to any other third-party software vendor should apply here too, including checking for a data processing agreement.
What's the single highest-risk mistake firms make with AI and client data?
Using a free, consumer-tier AI tool for real client work because it's convenient, without checking whether that tier retains or trains on submitted data. Free and paid enterprise tiers from the same provider often have materially different data-handling terms.
None of this means avoiding AI tools — it means treating them the way any other piece of software that touches client data should be treated: with a defined policy, a checked set of vendor terms, and clarity about which categories of data are, and aren't, allowed anywhere near them.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience helping students advance their professional careers.
View all posts by Learnsignal Education Team

