All insights
Cyber

How secure is data in ChatGPT? What accountants need to know

Is data entered into ChatGPT secure? What accountants need to know about client confidentiality, data sovereignty, and responsible AI use in a firm.

Nathan James
Founder, Worktopia
27 July 20268 min read
Where does client data go once you hit enter?

It's Tuesday afternoon, a partner meeting starts in twenty minutes, and one of your accountants has a client's profit and loss statement open in one window and ChatGPT in the other. They copy the figures, paste them in, and ask for a plain summary and a few talking points.

Thirty seconds later they've got exactly that. They close the tab and walk into the meeting looking sharp.

Nobody did anything malicious. Nobody even thought they were doing something risky, and that's the part worth sitting with. The accountant found a faster way to do their job and used it, the same way they'd use a calculator or a spreadsheet formula.

Now multiply that moment across your staff and across a week. You start to get a sense of how much client financial information is leaving your firm without anyone deciding that it should.

So before anyone asks whether ChatGPT is a security problem, it's worth answering a simpler question first: once your accountant hits enter, where does that client data actually go?

Looking to strengthen your security practices?
The Essential Eight, Explained for Accounting Firms
Read →

Where the data goes once you hit enter

The text doesn't stay on the accountant's screen. It travels out of your firm's environment to the servers of whichever company runs the tool, gets processed there, and comes back as an answer. That round trip is the whole point of the product. It's also where your control over the data ends.

What happens next depends entirely on the type of account your staff are using, and this is where most firms get caught out.

Consumer
The Free and Personal Tiers

On the consumer tiers of most generative AI tools, the default setting lets the provider keep what you type and use it to improve the model. In practice, that means:

Your client's numbers become training material for a large language model.
Other people outside your firm go on to use that model.
Some providers let you turn this off in the settings, and some hold chat history for a set period such as 30 days before deletion.

The defaults are rarely the ones you'd choose if you understood what they meant. Very few staff have read the settings, because nothing about the experience prompts them to.

Business
The Enterprise Tier

There's a real distinction here that matters for accountants. A ChatGPT Enterprise account behaves differently:

Data entered isn't used to train the underlying AI models.
The terms give the business a proper contract to point to.

But almost nobody in a typical firm is on Enterprise. They're signed in with a personal login, often the same one they use at home, and the confidential information they're pasting in is handled under consumer terms that were never written with your professional obligations in mind. The tool looks the same on the surface, but what sits behind it is not.

Who can access the data and where it lives

Once the data has left your firm, two questions decide how exposed you are: who can reach it, and which country it's sitting in.

Who can reach it

The honest answer is that you no longer know. Depending on the provider and the account, the list of people and systems that could touch your client's personal data includes:

The provider's own staff.
The sub-processors it relies on to run the service.
Anyone who obtains the data through a legal request, or through a breach of the provider itself.

These are large AI-powered platforms holding enormous volumes of user data, which makes them a target. The point isn't that any single one of these things is likely to happen tomorrow. It's that you've handed personally identifiable information to a party you don't control, and you can't tell a client with a straight face who has seen it.

Which country it’s in

Jurisdiction is the second problem, and for an Australian finance firm, it's the sharper one.

The servers processing that P&L are almost always offshore, most commonly in the United States. So your client's financial information is now stored and governed under another country's laws rather than ours. That's the data sovereignty issue in plain terms, and it isn't a technicality. Where personal information physically lives determines:

Whose rules apply to it.
Who can compel its release.
What protections your client actually has.

A firm that can't say where its client data is being held has already lost the thread on data protection.

Of all the compliance and data privacy laws accountants need to adhere to, is the Essential Eight one of them?
Is the Essential Eight Mandatory for Accounting Firms?
Read →

Why this collides with your obligations

Here's where the ordinary Tuesday afternoon runs into the rulebook. As an accountant, you're carrying obligations that were built long before anyone typed a tax position into a chatbot, and those obligations don't bend just because the tool is convenient.

Four of them are worth naming.

The TPB's AI guidance
In July 2026 the Tax Practitioners Board finalised its guidance on AI and the Code of Professional Conduct. Code Item 6 is blunt: without a legal duty to do so, you must not disclose information about a client's affairs to a third party without that client's permission. Putting their figures into an AI tool can be that disclosure, depending on how the tool is set up, and the permission has to come first.
Confidentiality under APES 110
You're bound to keep client information confidential and to use it only for the purpose it was given to you. Pasting it into a public AI tool discloses it to a third party your client never agreed to, for a purpose they were never told about.
The Privacy Act and the Australian Privacy Principles
If the data is personal information, and a client's financial details usually are, sending it to a provider whose servers sit overseas can engage the cross-border disclosure rules. Those rules put the responsibility for what happens to that data squarely back on you.
Your engagement letter
You've almost certainly made promises about how the firm handles client data that a personal ChatGPT login quietly breaks.

That last one is newer than most firms realise, and it carries a detail worth knowing: the TPB says a general third-party authority may be acceptable, but it recommends telling the client whether AI tools may be used, who the information goes to, where that happens, and where it is stored. A generic clause names none of that. We've unpacked what that means for your engagement letters, and for the systems behind them, here: Do accounting firms need client consent to use AI?

The uncomfortable part is that most firms can't even tell whether they've crossed these lines, because nobody wrote anything down and nobody was watching. There's no record of:

What went in.
Which account it went through.
Whether the retention setting was on or off.

When a client asks how you keep their information secure, or when an insurer asks the same at renewal, "we think we're fine" is not an answer that holds up. If this is happening in your firm right now with no policy behind it, that gap is a genuine liability, and it's one you'd want to close before someone else finds it for you.

The same technology, pointed the other way
Frontier AI cyber threats, for accounting firms
Read →

The reportable breach angle

Now play that ordinary Tuesday afternoon forward a few months. A client's financial details went into a public tool, and somehow that becomes known: the provider has an incident, a client asks a pointed question, or a staff member mentions it in the wrong room. Suddenly you're not dealing with a productivity shortcut. You're dealing with a possible notifiable data breach.

Under the Notifiable Data Breaches scheme, if personal information is disclosed in a way that's likely to cause serious harm, the firm has to notify both the affected client and the OAIC. That triggers a sequence no partner wants:

A hard conversation with the client about how their information left the firm.
A notification that becomes part of your public record.
Questions from your insurer, who will want to know what controls you had in place.

The damage here isn't really the paperwork. It's that a client trusted you with their numbers, and you can't show that you looked after them. For a firm that sells trust, that's the expensive part.

Why banning ChatGPT isn’t the answer

The instinct at this point is to send an all-staff email banning ChatGPT and be done with it. That feels decisive. It also doesn't work.

A ban does two things, both bad. It pushes the behaviour underground, where staff quietly use their phones or personal laptops and you lose whatever visibility you had. And it throws away something real, because these tools genuinely save your people hours on summarising, drafting, and first-pass analysis. Staff didn't start using AI to create risk. They started because their work got faster.

So the honest position isn't "stop." It's "not like this." The problem was never that an accountant wanted a quick summary. The problem was that the only tool within reach handed your client's data to a third party offshore. Fix the tool and the setup, and the productivity stays while the exposure goes.

Not convinced financial services need specialised IT?
General IT vs. Accounting-Firm IT: What’s Actually Different
Read →

Setting up responsible AI use

Getting this right isn't a year-long project that lands on the practice manager's desk. It comes down to three things working together.

01
A Written AI-Use Policy
Staff can't follow a rule that lives in someone's head. A short, clear policy sets out:
Which tools are approved, and which aren't.
What client data can go into them, and what can never leave the firm.
Who to ask when something falls outside the rules.
This is the document you hand a partner, an auditor, or an insurer when they ask what your position on AI is.
02
The Right Accounts and Setup
The tool isn't the enemy. The consumer login is. A properly configured business or enterprise tier changes the picture:
Data entered isn't used to train the underlying models.
Retention can be controlled rather than left on by default.
You get a real contract and a defensible answer on where data is processed.
Same speed for your staff: a setup you can stand behind.
03
Know Who’s Using What
You can't govern a tool you're pretending nobody uses. Responsible AI use starts with an honest look at what your people are already doing, because that's the only way to bring the shadow usage into the light and put controls around it.

Set up your AI tools with security at the centre

The technology was never the issue. A firm using AI on personal logins with no policy and no oversight is exposed. A firm using it deliberately, on the right accounts and inside clear rules, isn't. The distance between those two firms is a decision nobody has made yet.

Most IT providers can set up a tool, but very few understand why a personal ChatGPT login is a confidentiality problem for an accounting firm specifically, because they don't work in your world.

Worktopia does. We're the MSP built for accounting firms, so we speak compliance, and we know what APES 110 and the Privacy Act ask of you. That means we can sort out the AI question the way it needs sorting: the right accounts, the right settings, a policy your staff will follow, and client data that stays where it's supposed to.

The short version
Nobody has to do anything malicious. An accountant pasting client figures into a chatbot is a disclosure to a third party, made without anyone deciding it should happen.
The account tier decides almost everything. Consumer logins may keep what your staff type and use it to improve a model; business and enterprise tiers contractually do not.
Once the data has left, you can't say who reached it or whose laws govern it. If that ever becomes known, you may be looking at a notifiable data breach.
Banning AI backfires. It pushes use onto personal phones where you have no visibility, and throws away real productivity.
The fix is three things: a short written policy, business-tier accounts configured properly, and an honest look at what your staff already use.
The TPB's July 2026 AI guidance says client data entered into an AI tool can be a disclosure to a third party, and that disclosure needs the client's permission first.
AI, set up so it can't bite you
See how Worktopia handles AI and automation for accounting firms.
Explore →

Common questions

Do accountants need client consent before putting client data into ChatGPT?
Yes, in most real cases. Code Item 6 requires the client's permission before client information is disclosed to a third party, unless you have a legal duty to disclose it, and the TPB's July 2026 guidance says that can include entering client information into AI tools, depending on how the tools are configured and used. The guidance also recommends telling the client four things: whether AI tools may be used, who the information goes to, where that happens, and where the data is stored. In our experience, the consumer AI accounts most staff use are configured exactly that way.
Is it safe to put client data into ChatGPT?
Not on a personal account. On consumer tiers, what you type leaves your firm, is processed on overseas servers, and may be kept by the provider under terms written for individuals, not for professional confidentiality. On a properly configured business or enterprise tier, with a policy behind it, the same task can be done defensibly. The tool isn't the problem; the account and the absence of rules are.
Does ChatGPT use what you type to train its models?
On consumer tiers the default typically allows it, unless you find and change the setting, and chat history may be retained for a period either way. On enterprise tiers, data entered isn't used to train the underlying models and the business gets a contract that says so. Most staff are on the consumer tier without knowing the difference exists.
Is pasting client data into an AI tool a privacy breach?
It can be. Client financials are usually personal information under the Privacy Act, and sending them to a provider whose servers sit overseas can engage the cross-border disclosure rules, with the responsibility staying on your firm. If the disclosure is likely to cause serious harm, the Notifiable Data Breaches scheme requires notifying the client and the OAIC, and a practice handling tax file numbers is covered for TFN information even if the small business turnover exemption would otherwise apply. APES 110 confidentiality obligations apply on top.
Should an accounting firm ban ChatGPT?
No, and firms that try usually make things worse. A ban pushes use onto personal phones and home laptops where there's no visibility at all, and it throws away real productivity. The working answer is a short written AI-use policy, business-tier accounts configured properly, and an honest look at what staff already use.
What should an AI-use policy for an accounting firm cover?
Three things, briefly: which tools are approved, what client data may go into them and what must never leave the firm, and who to ask when something falls outside the rules. One page that staff actually read beats ten pages nobody does. It's also the document you hand an insurer or auditor when they ask where the firm stands on AI.
Nathan James
Founder, Worktopia
Nathan founded Worktopia, which has spent the past decade looking after IT and security for Australian accounting and financial services firms. He spends a good deal of his time helping practices adopt new tools without quietly handing client data to a third party.
Kip, the Worktopia mascot, holding a coffee

Not sure what your staff are pasting in?

Let's sort the AI question properly: the right accounts, the right settings, and a policy your staff will actually follow.

Book a strategy call or call 1300 856 912