Can staff put client data into ChatGPT under UK GDPR?

Sometimes. It depends on the tool version, the type of data and the controls in place. UK GDPR applies and your firm stays responsible for the data.

Why the answer is not a flat no

Banning all client data from AI tools sounds safe, but it often pushes staff towards workarounds you cannot see. A defensible position depends on three things: which version of the tool staff use, what kind of data goes in, and what controls sit around it.

UK GDPR and the Data Protection Act 2018 apply whenever personal data is entered into an AI tool. Your organisation remains responsible for that data as the data controller, even when the processing happens on someone else's platform.

Consumer and business accounts are different

Terms differ between consumer and business versions of AI tools, including whether your inputs may be used to train models. A member of staff using a free personal account is working under terms your firm has never reviewed or agreed.

  • Personal or free accounts: Treat these as unsuitable for client data. You have no contract in place, little visibility and terms that may allow inputs to be used for training.

  • Business accounts: These may offer contractual terms and admin controls suited to business use, but check rather than assume. Read the terms for the specific version you pay for, including how inputs are stored and used.

Personal data and confidential data carry different risks

Two separate sets of duties apply, and staff often blur them.

  • Personal data: Names, contact details, health information and anything else that identifies a person bring UK GDPR into play. A Data Protection Impact Assessment is required where processing is likely to result in a high risk to individuals.

  • Confidential commercial data: Client strategy, pricing, deal terms and financials may contain no personal data at all. Confidentiality duties under client contracts or professional rules still apply alongside data protection law.

Controls that make use defensible

  • Approve specific tools: Name the versions staff may use for client work and discourage the rest. Put the rules in a short AI acceptable use policy so nobody has to guess.

  • Classify data simply: Give staff three tiers: never enter, enter only in approved tools, and safe in any tool. Simple categories get followed.

  • Minimise and anonymise: Remove names and identifying details where the task does not need them. Most drafting and summarising works just as well without them.

  • Check client contracts: Review confidentiality clauses for your largest clients first. Where the position is unclear, ask the client.

  • Keep a human in the loop: Require review of AI output before it reaches a client. This catches errors and any details that should not be there.

  • Find existing use: Staff may already be using AI in ways you do not know about. Learning how to spot shadow AI shows you where your real exposure sits.

What is still developing

The ICO is developing a statutory code of practice on AI and automated decision-making, and it has not yet been finalised. Expect more detailed guidance, but do not wait for it, because the existing duties already apply. This is general guidance rather than legal advice, so take advice on your own situation, particularly if you handle sensitive personal data or work under strict professional rules.

Want to talk this through?