All insights
Cyber

How Secure is Data in ChatGPT? What Accountants Need to Know

Is data entered into ChatGPT secure? What accountants need to know about client confidentiality, data sovereignty, and responsible AI use in a firm.

Nathan James
Founder, Worktopia
27 July 20268 min read
Where does client data go once you hit enter?

It's Tuesday afternoon, a partner meeting starts in twenty minutes, and one of your accountants has a client's profit and loss statement open in one window and ChatGPT in the other. They copy the figures, paste them in, and ask for a plain summary and a few talking points.

Thirty seconds later they've got exactly that. They close the tab and walk into the meeting looking sharp.

Nobody did anything malicious. Nobody even thought they were doing something risky, and that's the part worth sitting with. The accountant found a faster way to do their job and used it, the same way they'd use a calculator or a spreadsheet formula.

Now multiply that moment across your staff and across a week. You start to get a sense of how much client financial information is leaving your firm without anyone deciding that it should.

So before anyone asks whether ChatGPT is a security problem, it's worth answering a simpler question first: once your accountant hits enter, where does that client data actually go?

Looking to strengthen your security practices?
The Essential Eight, Explained for Accounting Firms
Read →

Where the Data Goes Once You Hit Enter

The text doesn't stay on the accountant's screen. It travels out of your firm's environment to the servers of whichever company runs the tool, gets processed there, and comes back as an answer. That round trip is the whole point of the product. It's also where your control over the data ends.

What happens next depends entirely on the type of account your staff are using, and this is where most firms get caught out.

Consumer
The Free and Personal Tiers

On the consumer tiers of most generative AI tools, the default setting lets the provider keep what you type and use it to improve the model. In practice, that means:

Your client's numbers become training material for a large language model.
Other people outside your firm go on to use that model.
Some providers let you turn this off in the settings, and some hold chat history for a set period such as 30 days before deletion.

The defaults are rarely the ones you'd choose if you understood what they meant. Very few staff have read the settings, because nothing about the experience prompts them to.

Business
The Enterprise Tier

There's a real distinction here that matters for accountants. A ChatGPT Enterprise account behaves differently:

Data entered isn't used to train the underlying AI models.
The terms give the business a proper contract to point to.

But almost nobody in a typical firm is on Enterprise. They're signed in with a personal login, often the same one they use at home, and the confidential information they're pasting in is handled under consumer terms that were never written with your professional obligations in mind. The tool looks the same on the surface, but what sits behind it is not.

Who Can Access the Data and Where It Lives

Once the data has left your firm, two questions decide how exposed you are: who can reach it, and which country it's sitting in.

Who Can Reach It

The honest answer is that you no longer know. Depending on the provider and the account, the list of people and systems that could touch your client's personal data includes:

The provider's own staff.
The sub-processors it relies on to run the service.
Anyone who obtains the data through a legal request, or through a breach of the provider itself.

These are large AI-powered platforms holding enormous volumes of user data, which makes them a target. The point isn't that any single one of these things is likely to happen tomorrow. It's that you've handed personally identifiable information to a party you don't control, and you can't tell a client with a straight face who has seen it.

Which Country It’s In

Jurisdiction is the second problem, and for an Australian finance firm, it's the sharper one.

The servers processing that P&L are almost always offshore, most commonly in the United States. So your client's financial information is now stored and governed under another country's laws rather than ours. That's the data sovereignty issue in plain terms, and it isn't a technicality. Where personal information physically lives determines:

Whose rules apply to it.
Who can compel its release.
What protections your client actually has.

A firm that can't say where its client data is being held has already lost the thread on data protection.

Of all the compliance and data privacy laws accountants need to adhere to, is the Essential Eight one of them?
Is the Essential Eight Mandatory for Accounting Firms?
Read →

Why This Collides With Your Obligations

Here's where the ordinary Tuesday afternoon runs into the rulebook. As an accountant, you're carrying obligations that were built long before anyone typed a tax position into a chatbot, and those obligations don't bend just because the tool is convenient.

Three of them are worth naming.

Confidentiality under APES 110
You're bound to keep client information confidential and to use it only for the purpose it was given to you. Pasting it into a public AI tool discloses it to a third party your client never agreed to, for a purpose they were never told about.
The Privacy Act and the Australian Privacy Principles
If the data is personal information, and a client's financial details usually are, sending it to a provider whose servers sit overseas engages the cross-border disclosure rules. Those rules put the responsibility for what happens to that data squarely back on you.
Your engagement letter
You've almost certainly made promises about how the firm handles client data that a personal ChatGPT login quietly breaks.

The uncomfortable part is that most firms can't even tell whether they've crossed these lines, because nobody wrote anything down and nobody was watching. There's no record of:

What went in.
Which account it went through.
Whether the retention setting was on or off.

When a client asks how you keep their information secure, or when an insurer asks the same at renewal, "we think we're fine" is not an answer that holds up. If this is happening in your firm right now with no policy behind it, that gap is a genuine liability, and it's one you'd want to close before someone else finds it for you.

The Reportable Breach Angle

Now play that ordinary Tuesday afternoon forward a few months. A client's financial details went into a public tool, and somehow that becomes known: the provider has an incident, a client asks a pointed question, or a staff member mentions it in the wrong room. Suddenly you're not dealing with a productivity shortcut. You're dealing with a possible notifiable data breach.

Under the Notifiable Data Breaches scheme, if personal information is disclosed in a way that's likely to cause serious harm, the firm has to notify both the affected client and the OAIC. That triggers a sequence no partner wants:

A hard conversation with the client about how their information left the firm.
A notification that becomes part of your public record.
Questions from your insurer, who will want to know what controls you had in place.

The damage here isn't really the paperwork. It's that a client trusted you with their numbers, and you can't show that you looked after them. For a firm that sells trust, that's the expensive part.

Why Banning ChatGPT Isn’t the Answer

The instinct at this point is to send an all-staff email banning ChatGPT and be done with it. That feels decisive. It also doesn't work.

A ban does two things, both bad. It pushes the behaviour underground, where staff quietly use their phones or personal laptops and you lose whatever visibility you had. And it throws away something real, because these tools genuinely save your people hours on summarising, drafting, and first-pass analysis. Staff didn't start using AI to create risk. They started because their work got faster.

So the honest position isn't "stop." It's "not like this." The problem was never that an accountant wanted a quick summary. The problem was that the only tool within reach handed your client's data to a third party offshore. Fix the tool and the setup, and the productivity stays while the exposure goes.

Not convinced financial services need specialised IT?
General IT vs. Accounting-Firm IT: What’s Actually Different
Read →

Setting Up Responsible AI Use

Getting this right isn't a year-long project that lands on the practice manager's desk. It comes down to three things working together.

01
A Written AI-Use Policy
Staff can't follow a rule that lives in someone's head. A short, clear policy sets out:
Which tools are approved, and which aren't.
What client data can go into them, and what can never leave the firm.
Who to ask when something falls outside the rules.
This is the document you hand a partner, an auditor, or an insurer when they ask what your position on AI is.
02
The Right Accounts and Setup
The tool isn't the enemy. The consumer login is. A properly configured business or enterprise tier changes the picture:
Data entered isn't used to train the underlying models.
Retention can be controlled rather than left on by default.
You get a real contract and a defensible answer on where data is processed.
Same speed for your staff: a setup you can stand behind.
03
Know Who’s Using What
You can't govern a tool you're pretending nobody uses. Responsible AI use starts with an honest look at what your people are already doing, because that's the only way to bring the shadow usage into the light and put controls around it.

Set Up Your AI Tools with Security at the Centre

The technology was never the issue. A firm using AI on personal logins with no policy and no oversight is exposed. A firm using it deliberately, on the right accounts and inside clear rules, isn't. The distance between those two firms is a decision nobody has made yet.

Most IT providers can set up a tool, but very few understand why a personal ChatGPT login is a confidentiality problem for an accounting firm specifically, because they don't work in your world.

Worktopia does. We're the MSP built for accounting firms, so we speak compliance, and we know what APES 110 and the Privacy Act ask of you. That means we can sort out the AI question the way it needs sorting: the right accounts, the right settings, a policy your staff will follow, and client data that stays where it's supposed to.

AI, set up so it can't bite you
See how Worktopia handles AI and automation for accounting firms.
Explore →
Nathan James
Founder, Worktopia
Nathan founded Worktopia, which has spent the past decade looking after IT and security for Australian accounting and financial services firms. He spends a good deal of his time helping practices adopt new tools without quietly handing client data to a third party.
Kip, the Worktopia mascot, holding a coffee

Not sure what your staff are pasting in?

Let's sort the AI question properly: the right accounts, the right settings, and a policy your staff will actually follow.