This guide explains the general position in plain terms. It is not legal advice. For a decision about your own firm, speak to your data protection lead or a qualified adviser.
Does UK GDPR stop a firm using AI on client work?
No. UK GDPR and the Data Protection Act 2018 do not ban any technology. They set rules for how personal data is handled, whatever the tool. An AI system that reads a client file, drafts a letter or summarises a meeting is processing personal data in the same legal sense as your practice management system or your email. The questions are the familiar ones: who decides what happens to the data, on what basis, where it goes, how long it is kept and who can see it.
That framing matters because it stops AI being treated as a special case. Most firms already have the governance they need. What is usually missing is the step of applying it to the new tools staff have started using.
Are we the controller or the processor?
For client work, your firm is usually a controller of the personal data in its files, and sometimes a processor acting on a client's instructions. The distinction decides who carries which obligations, so establish it before anything else.
- You as controller: you decide why and how personal data is used. If you bring in an AI provider to handle that data for you, the provider is typically your processor, and UK GDPR expects a written contract setting out what it may do with the data.
- You as processor: some engagements, such as payroll or outsourced administration, may make you a processor for your client. Then you may need the client's authorisation before appointing a sub-processor, and an AI provider could be one.
- The provider acting on its own account: if a tool's terms let it use your inputs for its own purposes, such as improving its models, it may be acting as a controller for that use. That is the arrangement to look for in the terms and, for client material, usually to avoid.
What lawful basis covers AI processing?
Every processing activity needs a lawful basis under UK GDPR. Using AI does not change the basis you already rely on for the client work itself, but it can raise the question of whether the new use fits within it. If you process a client's employee records to deliver a service, drafting part of that service with an AI tool is likely to sit within the same purpose. Feeding the same records into a tool that trains on them is a different purpose and needs separate thought.
Special category data, such as health information, and criminal offence data carry extra conditions. Firms in healthcare, financial advice and law handle this routinely and should be especially careful about which tools touch it.
When do we need a data protection impact assessment?
UK GDPR requires a data protection impact assessment where processing is likely to result in a high risk to individuals. The ICO publishes guidance on what tends to count, and new technologies processing personal data at scale or in sensitive contexts are among the situations it highlights. The ICO has also published guidance on AI and data protection that is worth reading in full before a significant rollout.
Even where an assessment is not strictly required, working through one is a sound way to think a new AI use through. A practical version covers:
- What the process does, step by step, and which personal data enters it.
- Where that data travels, including the provider, any sub-processors and the countries involved.
- How long each copy is kept, and how it is deleted.
- What could go wrong for the people in the data, such as disclosure, inaccuracy or unfair decisions.
- What controls reduce those risks, such as access limits, human review and retention settings.
- Who signed it off, and when it will be looked at again.
What should we check in an AI provider's terms?
Read the business terms and the data processing terms, not the marketing page. The points that matter most for client work:
- Whether your inputs and outputs are used to train or improve the provider's models, and whether you can switch that off.
- How long prompts, files and outputs are retained, and whether you control deletion.
- Where the data is stored and processed, and what safeguards apply to any transfer outside the UK.
- Which sub-processors the provider uses, and how you are told about changes.
- What security commitments and breach notification terms are in the contract.
- Who at the provider can access your content, and in what circumstances.
If the answers are unclear, the tool is not ready for client material, however useful it looks.
How does client confidentiality fit alongside data protection?
Data protection covers personal data. Confidentiality covers far more: commercial terms, strategy, pricing, disputes, anything a client shares in trust. A document with no personal data in it can still be deeply confidential. So the data protection analysis is necessary but not sufficient.
Professional bodies set their own expectations here. Regulated firms answer to bodies such as the SRA, ICAEW, ACCA, RICS or the FCA, and each expects confidential information to be protected whatever the technology. Engagement letters and client confidentiality agreements often go further, and some restrict the use of third party services outright. Check them before assuming a tool is allowed. Our own position is simple: we work under whatever confidentiality agreement a client already uses with its other suppliers, and nothing a client shares is used for anyone else.
What practical controls should a firm put in place?
- An approved tools list. Name the tools staff may use for client work and the accounts they must use them through. The shadow AI problem starts where this list is missing.
- A written policy. Set out what may go into which tool, and who approves exceptions. Our guide to writing an AI policy gives a structure.
- Human review before anything leaves the firm. A named person checks and approves AI drafted work. See reviewing AI output on client work.
- Updated privacy information. Your privacy notice should describe the processing you actually do, including significant use of AI providers.
- A record of processing. Add AI tools to your records of processing activities alongside every other system.
- A route for rights requests. Know how you would find and retrieve a person's data held in an AI tool if they asked.
Where should a firm start?
Start with one process rather than a firm wide decision. When a single job is mapped properly, you can see exactly which data it touches, which systems it passes through and where review happens, and the data protection questions become specific and answerable. That is how we approach any rebuild: the mapping in week one records every input and handoff, which is the same information a sound impact assessment needs. The audit identifies which process to look at first.