Using ChatGPT, Claude and Gemini Safely with CA Client Data
A practical data-handling checklist for CA firms using everyday AI tools. Understand approved accounts, redaction, privacy settings and why turning off training is not a complete confidentiality solution.
A client reminder can be drafted from a few anonymised lines. A payroll register or tax notice may contain considerably more sensitive information. Treating both uploads as equally harmless is a poor starting point for AI adoption.
The first question is not whether the AI tool can read the file. It is whether the firm is authorised to share that material through that account. This guide is a practical control checklist, not a replacement for professional confidentiality obligations or legal advice.
Choose the approved account and purpose
A personal account, a paid consumer subscription and an organisation-managed workspace can have different terms and controls. Paying for a service does not by itself make every client upload appropriate.
Before starting, identify the permitted task, approved account, data category and reviewer. Where firm policy, client arrangements or law require approval, obtain it before the upload rather than relying on a favourable answer generated afterwards.
For a simple writing task, provide the smallest amount of information needed. There is usually no reason to attach an entire engagement folder to rewrite one paragraph.
Remove more than the client name
Replacing “Client A” for the company name is useful, but it may leave enough information to identify the client. Review:
- PAN, Aadhaar, GSTIN, bank details and addresses.
- Signatures, employee names, personal contact details and remuneration.
- Invoice identifiers, unusual amounts and references to counterparties.
- Filenames, comments, tracked changes, hidden tabs and document properties.
- Credentials, OTPs, access tokens and private links.
Do not upload passwords or OTPs to obtain drafting assistance. Where a number is irrelevant, replace it with a fictional amount rather than retaining it merely because the name was removed.
Check the actual privacy controls
ChatGPT: review Data Controls and the terms applicable to the account or workspace. Model-improvement settings and temporary-chat behaviour should be checked for the workflow being used.
Claude: review the privacy and model-improvement settings, including any applicable incognito or organisational arrangements.
Gemini: review Keep Activity and whether the account is personal or governed by organisation-specific terms. The data-handling position is not identical across those account types.
Settings and products change. Verify the live account rather than copying an old screenshot of a toggle into the firm's policy.
“Not used for training” is not “never processed or retained”
Training, retention, access and authorisation are separate questions. A model-improvement preference does not automatically mean no service processing, no safety review, no stored copy or permission under the client's engagement terms.
Similarly, a temporary or incognito mode is not a substitute for minimising the data. Review any connected services separately because another service may handle information under its own terms.
For these basic daily tasks, the firm can avoid that extra complexity by not connecting inboxes or shared drives.
A safer version of a common request
Instead of uploading a full salary register to ask for a staff reminder, use a fictional context:
Draft a polite reminder asking an employee to submit the missing reimbursement documents. Use [Employee], [Month] and [Internal Target Date] as placeholders. Do not include salary, medical or bank information. Do not suggest disciplinary consequences.
The drafting task remains useful while the sensitive source data stays outside the chat.
For an authorised document-analysis task, review the redacted copy before uploading. Drawing a black box over text may not remove the underlying text; use a proper redaction process and verify the resulting file.
Keep a simple team rule
A workable internal rule can separate public or fictional material, redacted approved work and restricted records needing further approval. Specify who reviews exceptions and where final approved outputs are stored.
Do not publish client chats through share links. Before forwarding an AI draft, check that hidden drafting notes, copied identifiers or material from another matter have not entered the response.
If sensitive data is uploaded accidentally, follow the firm's incident process, remove accessible copies where possible and assess any required escalation. Do not assume deletion reverses all processing instantly.
Frequently asked questions
Is a free tool automatically unsafe and a paid tool automatically safe?
No. The relevant factors include account terms, settings, firm approval and the data being shared—not simply the subscription price.
Is changing the client's name enough?
Not necessarily. Other details can still identify the person or business. Review the whole file and the minimum information needed.
Can a junior upload a document because a manager wants a quick answer?
Speed does not replace the approval process. The task and data-sharing route should both be authorised.
Build the habit before expanding use
assureOffice encourages useful technology with deliberate controls. Start AI adoption with public or fictional examples, then expand only within a reviewed client-data policy.