ChatGPT and professional secrecy: what a firm can hand to an AI

Chartered accountants and wealth management advisors are bound by professional secrecy and responsible for their clients' data. Here is what to check before uploading a client file to an AI tool.

The principle: an AI tool is a third party

Uploading a client document to an AI tool means sending it to the company that runs the tool. For a chartered accountant as for a wealth management advisor, that transfer engages two obligations at once: professional secrecy, and the General Data Protection Regulation (GDPR), under which the firm is the controller of its clients' data.

So the right question is not "is AI allowed?" but "who is this document sent to, and what do they do with it?".

What the Order of Chartered Accountants recommends

“Do not upload personal, sensitive and/or confidential data: no client emails, FEC or DSN files… that have not been anonymised, to sites you do not control (to respect GDPR and professional secrecy).”

Conseil national de l'ordre des experts-comptables, "Comment utiliser ChatGPT ?" (our translation)

The same notice asks users to always check the answers they get, because AI "can make mistakes or invent".

Five questions to ask an AI vendor

  • Are my documents used to train its models? A vendor's consumer and business offerings do not always follow the same rules: read the terms of the plan you actually use.
  • Does it offer a data processing agreement? Article 28 of the GDPR requires a contract between the firm and its processor. That contract governs what the vendor may do with your clients' data.
  • Where is the data stored, and where is it processed? Hosting in France says nothing about where the analysis runs. Processing outside the European Union is still a data transfer, subject to specific safeguards.
  • Who can access it, and for how long is it kept? Ask who at the vendor can see the documents, and how to delete them at the end of the engagement.
  • Do the answers cite their sources? A conclusion that points to the document in the file and to the text of law can be checked in seconds. A conclusion without a source has to be redone.

Before uploading a document

  • Anonymise what you can. Names, tax numbers, IBANs, addresses: what the analysis does not need does not have to leave the firm.
  • No personal account for client documents. A free version or an individual subscription rarely comes with the contract the GDPR requires: check before uploading a file.
  • Tell your clients. The GDPR requires you to tell clients who receives their data; the engagement letter is the natural place to do it.
  • Keep the sign-off. The tool prepares, the professional decides and signs: responsibility for the advice stays with them.

How Patrimind and Numexia answer these questions

Data is hosted by Scaleway in France, and AI processing runs in European regions as a priority. Our model providers are contractually bound not to reuse your data to train their models.

Every conclusion points to the document in the file and to the text of law it rests on: checking stays quick, and the decision stays yours.

Are you a wealth management advisor? Patrimind and our regulatory guides for advisors have their own site, in French: patrimind.intellectuality.fr

See how a client file is handled

We show you what the agent reads, what it concludes and where its sources come from.

NumexiaPatrimind