Yes, if client data goes into ChatGPT Business or Enterprise (or a tool built on OpenAI's API) with OpenAI's data processing addendum signed, your engagement letter mentions AI, and a qualified person checks every output. On Free, Go, Plus or Pro, keep identifiable client information out: the model-training switch gives you no contract and no control over what colleagues paste.
"Safe" has three layers, and most practices only check the first. There's where the data goes (the plan and its terms), what your professional code of ethics expects of you (confidentiality now explicitly covers digital tools), and whether the answer that comes back is right. A practice can get the privacy settings perfect and still damage a client relationship by sending an AI-drafted figure nobody checked.
Which ChatGPT plan the data actually lands in
The plan decides two things that matter for client work: whether OpenAI may use the content to train its models, and whether you have a business contract covering how it processes that data. Personal plans and business plans differ on both.
| Plan | Training on your chats by default | Contract for client data | Firm control | Identifiable client data? |
|---|---|---|---|---|
| Free, Go ($8), Plus ($20) | Yes, unless each user switches it off in Data controls | Consumer terms only | None: each person owns their account | No. Anonymised or public material only |
| Pro ($100 or $200 a month) | Same as Plus | Consumer terms only | None | No. More capacity, same terms |
| Business ($25 a seat monthly, $20 billed annually, two-seat minimum) | No | Data processing addendum available | Workspace admin, shared Projects, admin-enabled apps | Yes, with the addendum signed and a written policy |
| Enterprise (custom quote) | No | Data processing addendum available | Admin controls, custom retention period (minimum 90 days) | Yes |
| API (inside another tool) | No | Addendum available with OpenAI; also check the tool vendor's own terms | Depends on the tool | Yes, if the vendor's terms are as good as OpenAI's |
OpenAI's enterprise privacy page is the document to save to your compliance file: it states that business-plan and API data isn't used for training by default and that OpenAI will sign a data processing addendum for business customers. On Business, chats are kept until the user deletes them, and deleted chats are removed from OpenAI's systems within 30 days unless the law requires otherwise. Only Enterprise lets an owner set a shorter, workspace-wide retention period.
The two-seat minimum catches sole practitioners. A one-person practice either pays for two Business seats (roughly $40 to $50 a month) or stays on Plus and anonymises everything. For a practice holding hundreds of client files, the extra $20 a month is the cheaper side of that choice. The fuller comparison of personal and business terms is in the tutorial on whether ChatGPT trains on client data.
What your code of ethics adds on top of the settings
Many national accountancy bodies base their ethics codes on the one written by the International Ethics Standards Board for Accountants (IESBA). Its five fundamental principles are integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour. Technology-related revisions took effect on 15 December 2024, and they matter here in three ways:
- Confidential information is defined broadly. It covers any information, in any form, that isn't publicly available. A client's aged debtors report pasted into a chat window counts just as much as a letter in a filing cabinet.
- Confidentiality runs through the whole data lifecycle. Collecting, using, transferring, storing and eventually destroying client data are all covered, so "where does this chat live afterwards, and for how long?" is an ethics question, not only an IT one.
- Competence includes understanding your tools. Relying on an output you can't evaluate is a due-care problem. IESBA's July 2026 staff publication on emerging technologies repeats that accountants remain responsible for the judgements and decisions in their work, and says dedicated AI guidance will follow.
Check your own body's version of the code and any AI guidance it has published. The details and the wording differ, but none of them treats "the software did it" as a defence.
Sorting client data by what can go in, and where
A plan decision alone doesn't settle it. Even on Business, some data shouldn't go into a chat because the task doesn't need it. Sort by data type, not by client.
| Data | Examples in a practice | Business or Enterprise | Personal plan |
|---|---|---|---|
| Public | Filed accounts, published price lists, a client's own website copy | Fine | Fine |
| Client business records | Trial balance, management accounts, supplier list, budget | Fine for a defined task | Only after stripping names and anything that identifies the client |
| Personal identifiers | Tax reference numbers, bank account details, dates of birth, home addresses, payroll records | Only when the task genuinely needs them; usually it doesn't | Never |
| Sensitive personal details | Health information in a claim, a divorce settlement, a bereavement, criminal matters | Avoid unless there is a clear reason and a partner has agreed | Never |
| Access details | Online banking logins, accounting-software passwords, authentication codes | Never | Never |
The practical trick is to export only the columns the task needs. Asking for a commentary on a client's gross margin needs revenue and cost lines by month, not the nominal ledger with every customer's name. Take a sales-ledger export from a small tour operator, before and after trimming (illustrative):
BEFORE (straight from the accounting software)
Date | Customer | Customer email | Invoice | Net | Paid from
03/08/2026 | [surname] family | [name]@example.com | INV-2231| 1,840.00| acct ****8812
04/08/2026 | [club name] | [secretary]@example.org | INV-2232| 6,200.00| acct ****1093
AFTER (what actually goes into the chat)
Month | Customer type | Net
2026-08 | Private group | 1,840.00
2026-08 | Club booking | 6,200.00
The margin question gets the same answer from both versions. Only the first puts a family's name, an email address and partial bank details into another system. The step-by-step method is in how to anonymise client data before you paste it into AI.
Three practices, three sensible set-ups
These are illustrations, not clients, but they cover the situations most small practices are in.
A sole practitioner doing books for holiday-let owners
The work is bookkeeping and year-end accounts for around 40 owners, plus the odd query about cleaning costs and platform fees. On Plus, the practitioner can safely ask ChatGPT to draft a plain-English explanation of why a client's profit differs from their bank balance, using made-up round numbers. What they can't do is upload a client's booking-platform payout report with guest names on it. The decision point comes sooner than most people expect, and a quick sum shows why. Say rewriting each file into round, nameless figures takes 20 minutes and the practitioner does it for 12 files a month: that's four hours. At an internal rate of $60 an hour, the anonymising costs $240 a month, against $40 for two Business seats billed annually. Business doesn't remove the need to trim (bank details and guest names still stay out), but it does remove the rewriting of every name and number, which is where most of those 20 minutes go.
A six-person practice already on Microsoft 365
Client folders live in SharePoint and email runs through Outlook. Here ChatGPT Business isn't automatically the right home. Microsoft 365 Copilot Business (about $21 a user a month on annual billing) works inside the files the practice already stores, respects existing folder permissions and doesn't train on business content by default. The practice might still give two staff ChatGPT Business seats for heavier drafting, but it should write down which tool is approved for which job so client files don't end up in both.
A practice whose clients include a letting agency
The agency's rent schedules include tenant names, addresses and arrears. That's personal data about people who never agreed to anything with the accountant. Before asking ChatGPT Business to spot unusual arrears patterns, the bookkeeper replaces tenant names with property references and deletes the address column. The analysis is just as good, and the accountant holds less of the tenants' data in one more place.
This practice also gets the awkward request most eventually face. At the end of the engagement, the letting agency asks for confirmation that its data has been removed from "any AI systems". Because the practice set up a shared Project per recurring job rather than per client, the agency's rent schedules sit in a handful of chats inside the "arrears review" Project. The bookkeeper searches the workspace chat history for the agency's name and its property references, deletes each chat and uploaded file, and notes the date on the file. OpenAI removes deleted Business chats from its systems within 30 days unless the law requires otherwise, so the letter to the client says the chats were deleted on that date and will be purged within 30 days, rather than promising instant erasure. A practice that pastes client data into personal accounts can't make even that statement, because it has no way to find every chat.
Wording for the engagement letter
Clients don't need a technical briefing, but they should be able to find out that you use AI and on what terms. A clause along these lines works for most practices; adapt it to your own letter and have your professional body's template or adviser check the final version.
We use business-grade software, including artificial intelligence tools, to help prepare your records, analysis and correspondence. These tools are provided under contracts that prevent your information being used to train the provider's AI models. Everything prepared with their help is reviewed by a member of our team before it is relied on or sent to you. If you would prefer that we do not use AI tools on your work, tell us and we will record that on your file.
The last sentence matters. It gives an objecting client a clear route, and it forces the practice to have a way of flagging files, which in turn makes the policy real. In practice the flag can be simple: a "NO AI" tag on the client record in the practice management software, and the same two words at the start of the client's folder name, so anyone opening the folder to drag a file into a chat sees it first. When one client of a six-person practice replies to the new clause saying they would rather not, the partner adds both flags that afternoon and mentions it at the Monday team meeting. That client's management accounts commentary is then written by hand, which takes about 15 minutes longer each month, a small price for keeping the promise. More on scope and wording is in the tutorial on AI engagement letters for accountants.
A fifteen-minute check before anyone pastes a client file
- List every AI tool in use, including personal accounts and browser extensions. Ask people directly; the honest answer is usually longer than the official one.
- Pick the approved tool for client data and cancel or restrict the rest for client work.
- Sign the data processing addendum and save a copy with the date. Read the vendor's list of sub-processors while you're there. The tutorial on what to check in a vendor's data processing agreement covers the clauses worth reading.
- Set up the workspace: remove anyone who has left, decide which connected apps (OpenAI's current name for what it used to call connectors) are allowed, and create a shared Project per recurring job rather than per client.
- Write the one-page rule: which data types may go in, who reviews outputs, what happens if someone makes a mistake. A template is in the AI acceptable use policy for a small professional firm.
- Add the engagement-letter clause for new clients and send a short notice to existing ones at the next renewal.
- Diary a review in six months, because plan names, prices and settings change.
The one-page rule from step 5 doesn't need legal language. A filled-in version for an illustrative four-person practice:
- Approved tool: ChatGPT Business, practice workspace only. Personal ChatGPT, Gemini or Claude accounts are for non-client work.
- May go in: trial balances, management accounts, budgets, supplier lists and anonymised ledgers, for a named task.
- Strip first: bank account numbers, tax reference numbers, dates of birth, home addresses, individual payroll lines.
- Never goes in: passwords, banking logins, authentication codes, anything from a client flagged "NO AI".
- Review: every figure recalculated and every client-facing draft read by a qualified member of staff before sending.
- Mistakes: tell the practice manager the same day; no blame for reporting, the breach log records it.
Check that the rule is working rather than assuming it. Once a quarter, ask each person to open ChatGPT on every device they use for work and confirm it shows the practice workspace, not a personal account, and compare the workspace member list with the staff list. A leaver who still has a seat, or a phone still signed in to a personal account, is the kind of gap this turns up.
Here is the kind of slip the checklist exists to prevent, and a sensible way to respond. In a four-person practice (an illustration), a bookkeeper working late photographs a client's payroll summary and asks the ChatGPT app on her personal phone to total the pension deductions. It comes to light a fortnight later when she mentions how quick it was. The partner doesn't need to panic, but does need to act: the chat is deleted and the account's training switch checked, the incident goes in the practice's breach log with the date and the data involved, and the partner asks the practice's data-protection adviser whether it needs reporting. Then the rule gets one extra line: client documents are never photographed into a personal app, and the approved business app goes on work phones instead. Nobody was careless on purpose; the approved route simply wasn't the easiest one.
Where "safe" still fails: wrong answers sent with confidence
Privacy is the risk everyone asks about. The risk that actually reaches clients more often is an answer that is fluent and wrong. ChatGPT can state an allowance or deadline from the wrong tax year, mix up rules from another country, or add up a column incorrectly and present the total without hesitation. None of that is a data breach, and all of it is a professional competence problem.
A typical request from a practice, with anonymised figures for a guest-house client, shows how this slips through:
Prompt:
A client runs a guest house. Profit for the year was 38,400 but the
bank balance fell by 6,100. Using only these figures, explain in plain
English (under 120 words) why profit and cash differ:
new kitchen equipment 22,500 (capitalised), loan repayments 18,000,
owner's drawings 8,500, depreciation 4,500.
Sample output (illustrative):
"Although the guest house made a profit of 38,400, your bank balance
fell by 6,100. Several payments left the bank without reducing profit:
22,500 on kitchen equipment, 18,000 of loan repayments and 8,500 you
drew for yourself. Depreciation of 4,500 also reduced your cash. You
may be able to claim tax relief on the equipment, which could cut your
tax bill by around 5,000."
Two things need fixing before this goes anywhere near the client. Depreciation isn't a cash payment: it reduced profit, so it gets added back, and the numbers only reconcile that way (38,400 plus 4,500, minus 22,500, 18,000 and 8,500, is minus 6,100). And the "around 5,000" of tax relief was invented; no rate was supplied, so the model made one up. The rest of the draft is fine and saves ten minutes. That is the normal pattern: mostly useful, with one or two confident errors that only a qualified reader spots.
Three habits catch most of it:
- Never let AI supply a rate, threshold or deadline. Give it the figure from your own source and ask it to explain, not to look up.
- Recalculate any number it produces in the spreadsheet or the accounting software. Language models predict text; they aren't calculators.
- Read the draft as the client will. If the email would embarrass you with a wrong figure in it, the reviewer's sign-off is the control, not the tool.
Why models do this, and how to spot it, is explained in AI hallucinations explained for business owners.
A yes-or-no rule for the practice wall
Before a client's information goes into ChatGPT, three answers must all be yes:
- Is this the practice's approved business account, with the addendum signed?
- Does the task genuinely need this data, with everything else stripped out?
- Will a qualified person check the output before anyone relies on it?
If any answer is no, anonymise, use a different tool, or do it by hand. Practices that stick to those three questions rarely have anything to explain to a client later.
Client data and ChatGPT: follow-up questions from practices
If I switch off model training on ChatGPT Plus, is client data then safe?
It is safer, not safe enough for identifiable client records. The training switch stops your chats being used to improve models, but you are still on consumer terms with no data processing addendum, no admin control over what colleagues paste, and no firm-owned workspace. Use Plus for anonymised or public material only, and move to a business plan before real client files go in.
Can I upload a client's bank statement PDF to ChatGPT Business?
You can, but ask whether the task needs the whole statement. Account numbers, bank details and individual payees rarely help the analysis. Export the transactions to a spreadsheet, delete the identifying columns, and upload that. If the statement includes personal spending by a sole trader, you are also handling personal data about their family, so keep uploads to the minimum.
Do I need each client's consent before using ChatGPT on their work?
Consent is not always the legal basis you rely on, but clients should know. A short clause in the engagement letter explaining that you use business-grade AI tools under contract, with human review, covers most practices. If a client objects, flag their file so nobody uses AI on it. Ask your professional body or a data-protection adviser if your situation is unusual.
Is Microsoft 365 Copilot or Claude safer than ChatGPT for a practice?
Not inherently. Microsoft 365 Copilot, Claude Team and ChatGPT Business all keep business content out of model training by default. The better choice is usually the one that fits where your files already live: a practice running on Microsoft 365 often finds Copilot simpler to govern because it respects existing file permissions.
Further reads
- Questions to Ask Before Buying AI That Touches Client Data — The questions to ask any AI vendor before client files go near it.
- Does Microsoft 365 Copilot Keep Your Business Data Private? — How Copilot handles business data if your practice runs on Microsoft 365.
- Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools — Stop staff pasting client data into personal AI accounts.
- 7 AI Mistakes That Put an Accounting Firm's Client Trust at Risk — Seven ways AI use can quietly damage client trust in a practice.
- How Much Does AI Cost a Small Accounting Firm? — What business-grade AI plans cost a small practice per year.
- What to Check in an AI Tool's Privacy Policy and Terms — How to read an AI tool's privacy terms without a lawyer.
- Rolling Out AI in a Bookkeeping Practice Without Losing Control — A staged AI rollout for bookkeeping practices: control points, an inventory of AI already in your software, a pilot, sampling rates and client wording.
- What an AI Implementation Looks Like in a Small Accounting Firm — A seven-person practice followed through 12 weeks of AI implementation: time audit, tools switched on, records chasing, costs and what went wrong.
- AI Readiness Checklist for Accountants, Solicitors, Consultants — Twenty checks, grouped and scored, that tell an accountancy, law or consulting firm whether it is ready to pilot AI or has gaps to fix first.
- How to Automate Client Onboarding in a Small Accounting Practice — Six stages to take a small accounting practice from signed proposal to first job with fewer manual touches, and where AI helps or must not decide.
- ChatGPT Prompts for Bookkeepers: Client Queries, Chasers, Notes — Twelve copy-ready prompts for client replies, record chasers and file notes, each shown with an illustrative output and the fix it needs.
- How Accountants Use AI to Explain Tax to Clients in Plain English — A facts-block method for turning tax computations into plain-English client explanations, with prompts, a readability check and a review routine.
- How Small Tax Practices Use AI Through the Busy Season — A season-long plan for tax preparers: what to build eight weeks out, how AI handles intake, chasers and the inbox, and where preparer review stays in charge.
- How Accountants Use AI to Spot Errors in Client Books — The error checks worth running on every client file, the tools that run them, and how to turn thirty flags into the six corrections that matter.
- Can AI Do My Business Taxes? What It Can Safely Prepare — What AI can safely prepare for your business tax return, where its tax answers go wrong, and a year-end pack you can build before the accountant sees it.
- How to Choose an Accountant Who Uses AI Well — What good AI use inside an accountancy practice looks like, eight questions for the first meeting, and how a café compared three firms.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI enterprise privacy page and OpenAI help articles on chat retention and data controls; OpenAI ChatGPT Business pricing; IESBA technology-related revisions to the Code (effective 15 December 2024) and IESBA staff publication on emerging technologies (July 2026).