Resources · 11 June 2026

Can accountants use ChatGPT with client data? UK confidentiality and GDPR

By the Operating Bench Team · Last reviewed 11 June 2026

It is the question almost every practice is quietly asking: can we put client data into ChatGPT? The useful answer is not a flat yes or no. It depends on the account, the data, and the controls around it.

The default answer: not in a free consumer account

A free or personal ChatGPT-style account is the wrong place for client data. The reasons are practical:

So the blanket rule for a practice is simple: client-identifiable or financial data does not go into free or personal AI accounts. That single line removes most of the risk.

When it can be acceptable

AI can absolutely be used in a practice. The safe version looks like this:

A simple test for staff

Before pasting anything into an AI tool, ask: would I be comfortable if this exact text appeared somewhere outside the practice? If the answer is no, either the tool must be one approved for that data, or the data needs anonymising first. When in doubt, leave it out and ask.

Make it a rule, not a hope

The way to make this stick is not a one-off email. It is a short AI acceptable use policy, an approved-tools list so staff know which tools are fine for what, and a one-page guide they can actually remember. That turns “be careful with AI” into something the whole practice applies consistently.

Our AI Safe-Use Pack for accountants and bookkeepers gives you all of that as editable documents, including a data classification guide that spells out what may go into AI tools and what may not. If you want the sector-neutral version, the general pack covers the same ground.

This article is general information, not legal or professional advice. Check your own obligations and your professional body’s guidance before relying on AI with client data.

Frequently asked questions

Can accountants use ChatGPT with client data?
Not in a free or personal ChatGPT account: those tiers may train on your inputs and usually have no Data Processing Agreement, which is incompatible with client confidentiality. It can be acceptable in an approved business-grade tool with proper data terms, ideally with identifying details stripped out and every output checked by a competent person.
Is it a GDPR breach to put client data into AI?
It can be. Much client data is personal data under UK GDPR, so a third party processing it needs a lawful basis and a Data Processing Agreement. Free consumer tools rarely offer that, which is why client-identifiable or financial data should only ever go into approved tools.
How can a practice use AI safely?
Use an approved business or enterprise tool where your data is not used for training and a DPA is in place, minimise or anonymise the data, and have a competent person check every output. Write it into a short AI policy with an approved-tools list so staff apply it consistently.

Sources & further reading

External links are provided for reference and open in a new tab. This article is general information, not legal advice.

Share this LinkedIn X

One email when it matters

A short note when the rules change or we publish something genuinely useful for UK organisations. No spam, unsubscribe in one click.