Is It Safe for an Accountant to Use ChatGPT With Client Data?

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Is It Safe for an Accountant to Use ChatGPT With Client Data?
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Is It Safe for an Accountant to Use ChatGPT With Client Data?

Yes, if client data goes into ChatGPT Business or Enterprise (or a tool built on OpenAI's API) with OpenAI's data processing addendum signed, your engagement letter mentions AI, and a qualified person checks every output. On Free, Go, Plus or Pro, keep identifiable client information out: the model-training switch gives you no contract and no control over what colleagues paste.

"Safe" has three layers, and most practices only check the first. There's where the data goes (the plan and its terms), what your professional code of ethics expects of you (confidentiality now explicitly covers digital tools), and whether the answer that comes back is right. A practice can get the privacy settings perfect and still damage a client relationship by sending an AI-drafted figure nobody checked.

Follow me on Instagram@sagnikteaches

Which ChatGPT plan the data actually lands in

The plan decides two things that matter for client work: whether OpenAI may use the content to train its models, and whether you have a business contract covering how it processes that data. Personal plans and business plans differ on both.

Connect on LinkedInSagnik Bhattacharya
PlanTraining on your chats by defaultContract for client dataFirm controlIdentifiable client data?
Free, Go ($8), Plus ($20)Yes, unless each user switches it off in Data controlsConsumer terms onlyNone: each person owns their accountNo. Anonymised or public material only
Pro ($100 or $200 a month)Same as PlusConsumer terms onlyNoneNo. More capacity, same terms
Business ($25 a seat monthly, $20 billed annually, two-seat minimum)NoData processing addendum availableWorkspace admin, shared Projects, admin-enabled appsYes, with the addendum signed and a written policy
Enterprise (custom quote)NoData processing addendum availableAdmin controls, custom retention period (minimum 90 days)Yes
API (inside another tool)NoAddendum available with OpenAI; also check the tool vendor's own termsDepends on the toolYes, if the vendor's terms are as good as OpenAI's

OpenAI's enterprise privacy page is the document to save to your compliance file: it states that business-plan and API data isn't used for training by default and that OpenAI will sign a data processing addendum for business customers. On Business, chats are kept until the user deletes them, and deleted chats are removed from OpenAI's systems within 30 days unless the law requires otherwise. Only Enterprise lets an owner set a shorter, workspace-wide retention period.

Subscribe on YouTube@codingliquids

The two-seat minimum catches sole practitioners. A one-person practice either pays for two Business seats (roughly $40 to $50 a month) or stays on Plus and anonymises everything. For a practice holding hundreds of client files, the extra $20 a month is the cheaper side of that choice. The fuller comparison of personal and business terms is in the tutorial on whether ChatGPT trains on client data.

What your code of ethics adds on top of the settings

Many national accountancy bodies base their ethics codes on the one written by the International Ethics Standards Board for Accountants (IESBA). Its five fundamental principles are integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour. Technology-related revisions took effect on 15 December 2024, and they matter here in three ways:

  • Confidential information is defined broadly. It covers any information, in any form, that isn't publicly available. A client's aged debtors report pasted into a chat window counts just as much as a letter in a filing cabinet.
  • Confidentiality runs through the whole data lifecycle. Collecting, using, transferring, storing and eventually destroying client data are all covered, so "where does this chat live afterwards, and for how long?" is an ethics question, not only an IT one.
  • Competence includes understanding your tools. Relying on an output you can't evaluate is a due-care problem. IESBA's July 2026 staff publication on emerging technologies repeats that accountants remain responsible for the judgements and decisions in their work, and says dedicated AI guidance will follow.

Check your own body's version of the code and any AI guidance it has published. The details and the wording differ, but none of them treats "the software did it" as a defence.

Sorting client data by what can go in, and where

A plan decision alone doesn't settle it. Even on Business, some data shouldn't go into a chat because the task doesn't need it. Sort by data type, not by client.

DataExamples in a practiceBusiness or EnterprisePersonal plan
PublicFiled accounts, published price lists, a client's own website copyFineFine
Client business recordsTrial balance, management accounts, supplier list, budgetFine for a defined taskOnly after stripping names and anything that identifies the client
Personal identifiersTax reference numbers, bank account details, dates of birth, home addresses, payroll recordsOnly when the task genuinely needs them; usually it doesn'tNever
Sensitive personal detailsHealth information in a claim, a divorce settlement, a bereavement, criminal mattersAvoid unless there is a clear reason and a partner has agreedNever
Access detailsOnline banking logins, accounting-software passwords, authentication codesNeverNever

The practical trick is to export only the columns the task needs. Asking for a commentary on a client's gross margin needs revenue and cost lines by month, not the nominal ledger with every customer's name. Take a sales-ledger export from a small tour operator, before and after trimming (illustrative):

BEFORE (straight from the accounting software)
Date       | Customer          | Customer email          | Invoice | Net     | Paid from
03/08/2026 | [surname] family  | [name]@example.com      | INV-2231| 1,840.00| acct ****8812
04/08/2026 | [club name]       | [secretary]@example.org | INV-2232| 6,200.00| acct ****1093

AFTER (what actually goes into the chat)
Month   | Customer type | Net
2026-08 | Private group | 1,840.00
2026-08 | Club booking  | 6,200.00

The margin question gets the same answer from both versions. Only the first puts a family's name, an email address and partial bank details into another system. The step-by-step method is in how to anonymise client data before you paste it into AI.

Three practices, three sensible set-ups

These are illustrations, not clients, but they cover the situations most small practices are in.

A sole practitioner doing books for holiday-let owners

The work is bookkeeping and year-end accounts for around 40 owners, plus the odd query about cleaning costs and platform fees. On Plus, the practitioner can safely ask ChatGPT to draft a plain-English explanation of why a client's profit differs from their bank balance, using made-up round numbers. What they can't do is upload a client's booking-platform payout report with guest names on it. The decision point comes sooner than most people expect, and a quick sum shows why. Say rewriting each file into round, nameless figures takes 20 minutes and the practitioner does it for 12 files a month: that's four hours. At an internal rate of $60 an hour, the anonymising costs $240 a month, against $40 for two Business seats billed annually. Business doesn't remove the need to trim (bank details and guest names still stay out), but it does remove the rewriting of every name and number, which is where most of those 20 minutes go.

A six-person practice already on Microsoft 365

Client folders live in SharePoint and email runs through Outlook. Here ChatGPT Business isn't automatically the right home. Microsoft 365 Copilot Business (about $21 a user a month on annual billing) works inside the files the practice already stores, respects existing folder permissions and doesn't train on business content by default. The practice might still give two staff ChatGPT Business seats for heavier drafting, but it should write down which tool is approved for which job so client files don't end up in both.

A practice whose clients include a letting agency

The agency's rent schedules include tenant names, addresses and arrears. That's personal data about people who never agreed to anything with the accountant. Before asking ChatGPT Business to spot unusual arrears patterns, the bookkeeper replaces tenant names with property references and deletes the address column. The analysis is just as good, and the accountant holds less of the tenants' data in one more place.

This practice also gets the awkward request most eventually face. At the end of the engagement, the letting agency asks for confirmation that its data has been removed from "any AI systems". Because the practice set up a shared Project per recurring job rather than per client, the agency's rent schedules sit in a handful of chats inside the "arrears review" Project. The bookkeeper searches the workspace chat history for the agency's name and its property references, deletes each chat and uploaded file, and notes the date on the file. OpenAI removes deleted Business chats from its systems within 30 days unless the law requires otherwise, so the letter to the client says the chats were deleted on that date and will be purged within 30 days, rather than promising instant erasure. A practice that pastes client data into personal accounts can't make even that statement, because it has no way to find every chat.

Wording for the engagement letter

Clients don't need a technical briefing, but they should be able to find out that you use AI and on what terms. A clause along these lines works for most practices; adapt it to your own letter and have your professional body's template or adviser check the final version.

We use business-grade software, including artificial intelligence tools, to help prepare your records, analysis and correspondence. These tools are provided under contracts that prevent your information being used to train the provider's AI models. Everything prepared with their help is reviewed by a member of our team before it is relied on or sent to you. If you would prefer that we do not use AI tools on your work, tell us and we will record that on your file.

The last sentence matters. It gives an objecting client a clear route, and it forces the practice to have a way of flagging files, which in turn makes the policy real. In practice the flag can be simple: a "NO AI" tag on the client record in the practice management software, and the same two words at the start of the client's folder name, so anyone opening the folder to drag a file into a chat sees it first. When one client of a six-person practice replies to the new clause saying they would rather not, the partner adds both flags that afternoon and mentions it at the Monday team meeting. That client's management accounts commentary is then written by hand, which takes about 15 minutes longer each month, a small price for keeping the promise. More on scope and wording is in the tutorial on AI engagement letters for accountants.

A fifteen-minute check before anyone pastes a client file

  1. List every AI tool in use, including personal accounts and browser extensions. Ask people directly; the honest answer is usually longer than the official one.
  2. Pick the approved tool for client data and cancel or restrict the rest for client work.
  3. Sign the data processing addendum and save a copy with the date. Read the vendor's list of sub-processors while you're there. The tutorial on what to check in a vendor's data processing agreement covers the clauses worth reading.
  4. Set up the workspace: remove anyone who has left, decide which connected apps (OpenAI's current name for what it used to call connectors) are allowed, and create a shared Project per recurring job rather than per client.
  5. Write the one-page rule: which data types may go in, who reviews outputs, what happens if someone makes a mistake. A template is in the AI acceptable use policy for a small professional firm.
  6. Add the engagement-letter clause for new clients and send a short notice to existing ones at the next renewal.
  7. Diary a review in six months, because plan names, prices and settings change.

The one-page rule from step 5 doesn't need legal language. A filled-in version for an illustrative four-person practice:

  • Approved tool: ChatGPT Business, practice workspace only. Personal ChatGPT, Gemini or Claude accounts are for non-client work.
  • May go in: trial balances, management accounts, budgets, supplier lists and anonymised ledgers, for a named task.
  • Strip first: bank account numbers, tax reference numbers, dates of birth, home addresses, individual payroll lines.
  • Never goes in: passwords, banking logins, authentication codes, anything from a client flagged "NO AI".
  • Review: every figure recalculated and every client-facing draft read by a qualified member of staff before sending.
  • Mistakes: tell the practice manager the same day; no blame for reporting, the breach log records it.

Check that the rule is working rather than assuming it. Once a quarter, ask each person to open ChatGPT on every device they use for work and confirm it shows the practice workspace, not a personal account, and compare the workspace member list with the staff list. A leaver who still has a seat, or a phone still signed in to a personal account, is the kind of gap this turns up.

Here is the kind of slip the checklist exists to prevent, and a sensible way to respond. In a four-person practice (an illustration), a bookkeeper working late photographs a client's payroll summary and asks the ChatGPT app on her personal phone to total the pension deductions. It comes to light a fortnight later when she mentions how quick it was. The partner doesn't need to panic, but does need to act: the chat is deleted and the account's training switch checked, the incident goes in the practice's breach log with the date and the data involved, and the partner asks the practice's data-protection adviser whether it needs reporting. Then the rule gets one extra line: client documents are never photographed into a personal app, and the approved business app goes on work phones instead. Nobody was careless on purpose; the approved route simply wasn't the easiest one.

Where "safe" still fails: wrong answers sent with confidence

Privacy is the risk everyone asks about. The risk that actually reaches clients more often is an answer that is fluent and wrong. ChatGPT can state an allowance or deadline from the wrong tax year, mix up rules from another country, or add up a column incorrectly and present the total without hesitation. None of that is a data breach, and all of it is a professional competence problem.

A typical request from a practice, with anonymised figures for a guest-house client, shows how this slips through:

Prompt:
A client runs a guest house. Profit for the year was 38,400 but the
bank balance fell by 6,100. Using only these figures, explain in plain
English (under 120 words) why profit and cash differ:
new kitchen equipment 22,500 (capitalised), loan repayments 18,000,
owner's drawings 8,500, depreciation 4,500.

Sample output (illustrative):
"Although the guest house made a profit of 38,400, your bank balance
fell by 6,100. Several payments left the bank without reducing profit:
22,500 on kitchen equipment, 18,000 of loan repayments and 8,500 you
drew for yourself. Depreciation of 4,500 also reduced your cash. You
may be able to claim tax relief on the equipment, which could cut your
tax bill by around 5,000."

Two things need fixing before this goes anywhere near the client. Depreciation isn't a cash payment: it reduced profit, so it gets added back, and the numbers only reconcile that way (38,400 plus 4,500, minus 22,500, 18,000 and 8,500, is minus 6,100). And the "around 5,000" of tax relief was invented; no rate was supplied, so the model made one up. The rest of the draft is fine and saves ten minutes. That is the normal pattern: mostly useful, with one or two confident errors that only a qualified reader spots.

Three habits catch most of it:

  • Never let AI supply a rate, threshold or deadline. Give it the figure from your own source and ask it to explain, not to look up.
  • Recalculate any number it produces in the spreadsheet or the accounting software. Language models predict text; they aren't calculators.
  • Read the draft as the client will. If the email would embarrass you with a wrong figure in it, the reviewer's sign-off is the control, not the tool.

Why models do this, and how to spot it, is explained in AI hallucinations explained for business owners.

A yes-or-no rule for the practice wall

Before a client's information goes into ChatGPT, three answers must all be yes:

  1. Is this the practice's approved business account, with the addendum signed?
  2. Does the task genuinely need this data, with everything else stripped out?
  3. Will a qualified person check the output before anyone relies on it?

If any answer is no, anonymise, use a different tool, or do it by hand. Practices that stick to those three questions rarely have anything to explain to a client later.

Client data and ChatGPT: follow-up questions from practices

If I switch off model training on ChatGPT Plus, is client data then safe?

It is safer, not safe enough for identifiable client records. The training switch stops your chats being used to improve models, but you are still on consumer terms with no data processing addendum, no admin control over what colleagues paste, and no firm-owned workspace. Use Plus for anonymised or public material only, and move to a business plan before real client files go in.

Can I upload a client's bank statement PDF to ChatGPT Business?

You can, but ask whether the task needs the whole statement. Account numbers, bank details and individual payees rarely help the analysis. Export the transactions to a spreadsheet, delete the identifying columns, and upload that. If the statement includes personal spending by a sole trader, you are also handling personal data about their family, so keep uploads to the minimum.

Do I need each client's consent before using ChatGPT on their work?

Consent is not always the legal basis you rely on, but clients should know. A short clause in the engagement letter explaining that you use business-grade AI tools under contract, with human review, covers most practices. If a client objects, flag their file so nobody uses AI on it. Ask your professional body or a data-protection adviser if your situation is unusual.

Is Microsoft 365 Copilot or Claude safer than ChatGPT for a practice?

Not inherently. Microsoft 365 Copilot, Claude Team and ChatGPT Business all keep business content out of model training by default. The better choice is usually the one that fits where your files already live: a practice running on Microsoft 365 often finds Copilot simpler to govern because it respects existing file permissions.

Further reads

Sources: OpenAI enterprise privacy page and OpenAI help articles on chat retention and data controls; OpenAI ChatGPT Business pricing; IESBA technology-related revisions to the Code (effective 15 December 2024) and IESBA staff publication on emerging technologies (July 2026).

Want your practice's AI set-up checked before files go in?

On a 1:1 call we'll look at which AI tools your team already uses, decide which plan should hold client data, and draft the handful of rules and settings that make it defensible.

Book a 1:1 call with me