Is data entered into ChatGPT secure? What accountants need to know about client confidentiality, data sovereignty, and responsible AI use in a firm.
It's Tuesday afternoon, a partner meeting starts in twenty minutes, and one of your accountants has a client's profit and loss statement open in one window and ChatGPT in the other. They copy the figures, paste them in, and ask for a plain summary and a few talking points.
Thirty seconds later they've got exactly that. They close the tab and walk into the meeting looking sharp.
Nobody did anything malicious. Nobody even thought they were doing something risky, and that's the part worth sitting with. The accountant found a faster way to do their job and used it, the same way they'd use a calculator or a spreadsheet formula.
Now multiply that moment across your staff and across a week. You start to get a sense of how much client financial information is leaving your firm without anyone deciding that it should.
So before anyone asks whether ChatGPT is a security problem, it's worth answering a simpler question first: once your accountant hits enter, where does that client data actually go?
The text doesn't stay on the accountant's screen. It travels out of your firm's environment to the servers of whichever company runs the tool, gets processed there, and comes back as an answer. That round trip is the whole point of the product. It's also where your control over the data ends.
What happens next depends entirely on the type of account your staff are using, and this is where most firms get caught out.
On the consumer tiers of most generative AI tools, the default setting lets the provider keep what you type and use it to improve the model. In practice, that means:
The defaults are rarely the ones you'd choose if you understood what they meant. Very few staff have read the settings, because nothing about the experience prompts them to.
There's a real distinction here that matters for accountants. A ChatGPT Enterprise account behaves differently:
But almost nobody in a typical firm is on Enterprise. They're signed in with a personal login, often the same one they use at home, and the confidential information they're pasting in is handled under consumer terms that were never written with your professional obligations in mind. The tool looks the same on the surface, but what sits behind it is not.
Once the data has left your firm, two questions decide how exposed you are: who can reach it, and which country it's sitting in.
The honest answer is that you no longer know. Depending on the provider and the account, the list of people and systems that could touch your client's personal data includes:
These are large AI-powered platforms holding enormous volumes of user data, which makes them a target. The point isn't that any single one of these things is likely to happen tomorrow. It's that you've handed personally identifiable information to a party you don't control, and you can't tell a client with a straight face who has seen it.
Jurisdiction is the second problem, and for an Australian finance firm, it's the sharper one.
The servers processing that P&L are almost always offshore, most commonly in the United States. So your client's financial information is now stored and governed under another country's laws rather than ours. That's the data sovereignty issue in plain terms, and it isn't a technicality. Where personal information physically lives determines:
A firm that can't say where its client data is being held has already lost the thread on data protection.
Here's where the ordinary Tuesday afternoon runs into the rulebook. As an accountant, you're carrying obligations that were built long before anyone typed a tax position into a chatbot, and those obligations don't bend just because the tool is convenient.
Three of them are worth naming.
The uncomfortable part is that most firms can't even tell whether they've crossed these lines, because nobody wrote anything down and nobody was watching. There's no record of:
When a client asks how you keep their information secure, or when an insurer asks the same at renewal, "we think we're fine" is not an answer that holds up. If this is happening in your firm right now with no policy behind it, that gap is a genuine liability, and it's one you'd want to close before someone else finds it for you.
Now play that ordinary Tuesday afternoon forward a few months. A client's financial details went into a public tool, and somehow that becomes known: the provider has an incident, a client asks a pointed question, or a staff member mentions it in the wrong room. Suddenly you're not dealing with a productivity shortcut. You're dealing with a possible notifiable data breach.
Under the Notifiable Data Breaches scheme, if personal information is disclosed in a way that's likely to cause serious harm, the firm has to notify both the affected client and the OAIC. That triggers a sequence no partner wants:
The damage here isn't really the paperwork. It's that a client trusted you with their numbers, and you can't show that you looked after them. For a firm that sells trust, that's the expensive part.
The instinct at this point is to send an all-staff email banning ChatGPT and be done with it. That feels decisive. It also doesn't work.
A ban does two things, both bad. It pushes the behaviour underground, where staff quietly use their phones or personal laptops and you lose whatever visibility you had. And it throws away something real, because these tools genuinely save your people hours on summarising, drafting, and first-pass analysis. Staff didn't start using AI to create risk. They started because their work got faster.
So the honest position isn't "stop." It's "not like this." The problem was never that an accountant wanted a quick summary. The problem was that the only tool within reach handed your client's data to a third party offshore. Fix the tool and the setup, and the productivity stays while the exposure goes.
Getting this right isn't a year-long project that lands on the practice manager's desk. It comes down to three things working together.
The technology was never the issue. A firm using AI on personal logins with no policy and no oversight is exposed. A firm using it deliberately, on the right accounts and inside clear rules, isn't. The distance between those two firms is a decision nobody has made yet.
Most IT providers can set up a tool, but very few understand why a personal ChatGPT login is a confidentiality problem for an accounting firm specifically, because they don't work in your world.
Worktopia does. We're the MSP built for accounting firms, so we speak compliance, and we know what APES 110 and the Privacy Act ask of you. That means we can sort out the AI question the way it needs sorting: the right accounts, the right settings, a policy your staff will follow, and client data that stays where it's supposed to.