Skip to content
AI & automation · · 2 min read

ChatGPT at work: using AI without breaching the GDPR

AI tools like ChatGPT save time, but what happens to confidential data? Practical rules for safe, GDPR-proof AI use in the office.

By Limburg Cyber Group

AI tools have become a fixture of the workplace. Employees use ChatGPT to draft emails, summarise texts, or write code, often without management even knowing. That saves time, but it also creates a real risk: what happens to the data you paste into such a tool?

For accountants, lawyers, and advisors in particular, who work with confidential client information, this is a serious question. Below we lay out plainly how to use AI without breaching the GDPR.

The core problem: where does your data go?

When you paste text into a free, public AI tool, that information leaves your organisation. Depending on the tool and its settings, that data may be stored or even used to train the model. Paste in personal data or trade secrets, and you may breach the GDPR, and violate your duty of confidentiality towards clients.

The answer is not to “ban AI”. That does not work anyway, people will just use it in secret. The answer is clear agreements and the right tools.

Five practical rules

  1. No personal or confidential data in public tools. No client names, ID numbers, case files, or financial details in the free version of an AI chatbot.
  2. Anonymise before you enter anything. Need a text summarised? Strip out names and identifiable details first.
  3. Use business versions with a processing agreement. Paid business subscriptions often guarantee that your data will not be used for training, and come with the data processing agreement the GDPR requires.
  4. Always check the output. AI sometimes invents confident nonsense (“hallucinations”). For legal or financial work, human review is not a luxury but a necessity.
  5. Write it down in an AI policy. A single page on what is and is not allowed, so everyone knows where they stand.

An AI policy does not have to be complicated

Many business owners assume such a policy must be a thick document. It does not. A good AI policy fits on one page and answers three questions: which tools may we use, which data may never go in, and who checks the results? That alone removes the biggest risk.

Using AI safely and productively

The biggest opportunity in AI is not in one-off chats, but in smartly automating recurring work, in a way where you decide where your data stays. Think of automatically sorting incoming mail, drafting letters based on your own templates, or summarising internal documents in a closed environment.

That is where most time is saved, without your data leaving the building. We wrote about it earlier in five tasks you can automate today.

Need help?

Want to use AI responsibly, with a policy that fits your profession and the right tools underneath it? See our AI & automation service or book a conversation. We think along soberly, without the hype.

Read more

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.