AI & Data Privacy

Why Pasting Case Files Into ChatGPT Could Violate Client Confidentiality

A general-purpose chatbot is a third party. The moment a client document goes into one, you have made a disclosure decision — whether or not you thought of it that way.

Casealyze Editorial · Dispute workflow research 11 min read

It usually starts as a shortcut. A 60-page submission lands at 6pm, someone needs the key dates by morning, and there is a chat window open in the next tab. Paste, summarise, done. Nobody made a decision about disclosure — and that is precisely the problem.

The duty of confidentiality does not distinguish between disclosing to a person and disclosing to a service. When client material is transmitted to a third-party system, the relevant question is not whether anyone read it. It is whether reasonable efforts were made to prevent unauthorised access or disclosure before it was sent.

Key takeaways

  • A general AI tool is a third-party service. Sending client material to one is a disclosure event that needs a basis.
  • Three duties bite at once: professional secrecy, arbitral confidentiality, and the data protection statute governing the file.
  • Every GCC state now has a data protection regime, and the GDPR reaches you whenever the file concerns people in the EU — wherever your firm sits.
  • Consumer and business tiers of the same product often have completely different data-retention and training terms.
  • “Secure by design” is a set of verifiable properties — encryption, tenant isolation, retention limits, no training on your data — not a marketing line.

Three duties, not one

Sending a case document to an outside service engages three separate obligations at the same time, enforced by three different sets of people. Firms tend to think about one of them and get caught by another.

The first is professional secrecy. Every jurisdiction in the region imposes a confidentiality duty on advocates through its law regulating the legal profession, enforced by the bar association or the ministry of justice, and in several states a breach can carry criminal as well as disciplinary consequences. That duty is owed to the client, and it does not switch off because the recipient is software rather than a person.

The second, in dispute work specifically, is arbitral confidentiality. Under the DIAC Arbitration Rules 2022, arbitrations administered by the centre are confidential (Article 38); the LCIA Rules and most other institutional rules impose the same; tribunals issue confidentiality orders; and the underlying contract usually carries its own non-disclosure clause. A disclosure that breaches an undertaking given to a tribunal is a problem whether or not any statute is engaged.

The third is data protection law — the layer that has changed most in the past three years, and where most practices in the region are furthest behind.

What the data protection regimes require

The shape is the same everywhere, even though the statute changes at each border. If you decide why and how personal data is processed, you are a controller; the AI vendor processing it for you is a processor; and you need a lawful basis, a written arrangement with that processor, security appropriate to the risk, and a defensible answer on where the data physically sits. A case file is dense with personal data — parties, witnesses, employees, and often health or criminal-conduct detail — so none of this is an edge case.

United Arab Emirates

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data has been in force since 2 January 2022, setting controller obligations on lawful basis, purpose limitation, security, and cross-border transfer. Its Executive Regulations have still not been issued, so the federal penalty machinery is not yet fully switched on — which is not at all the same as the obligations not existing. For many dispute practices the regime that actually bites is a free-zone one: the DIFC has its own Data Protection Law No. 5 of 2020 and the ADGM its Data Protection Regulations 2021. Both are GDPR-shaped, both have active regulators, and neither is covered by the federal law.

Qatar

Law No. 13 of 2016 on Personal Data Privacy Protection was the first national data privacy law in the Gulf, with penalties running from QAR 1,000,000 to QAR 5,000,000. Entities inside the Qatar Financial Centre sit under a separate regime instead — the QFC Data Protection Regulations 2021, which follow the GDPR closely.

Bahrain

Law No. 30 of 2018 restricts transfers out of the Kingdom at Article 19: the destination must appear on the Authority's adequacy list, or the transfer must rest on approved safeguards or a specific authorisation. The Personal Data Protection Authority sits under the Ministry of Justice and Islamic Affairs. If your AI vendor's servers are outside Bahrain, Article 19 is the provision to read first.

Oman

The Personal Data Protection Law issued by Royal Decree No. 6/2022, with Executive Regulations under Ministerial Decision No. 34/2024, is now fully enforceable — the transition period ended on 5 February 2026. It requires explicit consent, clear privacy notices, a designated data protection officer, controls on cross-border transfer, and prompt breach notification. Oman is the jurisdiction where “we will get to it” most recently stopped being an available answer.

Kuwait

Kuwait has no comprehensive general data protection statute. CITRA's Data Privacy Protection Regulation, amended by Decision No. 26 of 2024 and effective from 19 February 2024, is addressed to CITRA-licensed telecommunications and internet service providers rather than to law firms as such. In practice a Kuwaiti practice is constrained by professional secrecy, by its contractual undertakings, and — the moment the file concerns people in the EU — by the GDPR.

The GDPR, wherever your firm sits

The GDPR is not only a European firm's problem. It reaches the processing of personal data about people in the EU and EEA regardless of where the processing happens, which covers a large share of the cross-border commercial disputes run out of the Gulf. What it adds on top of the regional regimes:

  • Articles 5(1)(f) and 32 — integrity, confidentiality, and security appropriate to the risk. A dispute file is high-risk on any reading.
  • Article 28 — you may not hand personal data to a processor without a written contract meeting specified terms. Accepting consumer terms of service is not that contract.
  • Articles 9 and 10 — case files routinely carry health data and data about criminal offences or allegations. Both attract stricter conditions than ordinary personal data.
  • Chapter V (Articles 44–49) — transfers outside the EEA need an adequacy decision, standard contractual clauses, or another listed mechanism.
  • Article 33 — a personal data breach must reach the supervisory authority within 72 hours. You cannot meet that deadline through a vendor with no contractual duty to tell you promptly.

Note

Two things fall out of all of this. The questions to ask are identical in every one of these jurisdictions — what is retained, for how long, who can see it, where does it sit, and what does the written agreement say — even though the governing statute changes at each border. And a tool that is properly contracted, hosted, and documented answers all five at once, which is why the choice of tool matters far more than the choice of prompt.

The four things that actually go wrong

01

The input is retained

Consumer chat products commonly store conversation history by default, and history is a copy of the client document sitting on infrastructure you do not control, under a retention schedule you did not set. Retention is what turns a one-off paste into a standing exposure.

02

The input trains the model

Several consumer tiers use conversations to improve the underlying models unless a setting is changed. Business and enterprise tiers generally do not. The distinction is a contractual term rather than a property of “AI”, it is the single term most worth checking before anything confidential is typed, and because vendors revise these terms it is worth checking against the current version rather than what was true last year.

03

Human reviewers can see it

Trust-and-safety and abuse-monitoring pipelines mean a subset of conversations may be reviewed by people. That is a reasonable safety design for a consumer product. It is a poor fit for privileged material.

04

You cannot account for what you disclosed

Every regime above assumes you can account for your own processing — what left the firm, when, and on what basis. A chat history scattered across individual personal accounts will not produce that account. Firms discover this at exactly the wrong moment: during a client security questionnaire, an insurer's review, or a regulator's enquiry after an incident.

The account matters more than the brand

“We use ChatGPT” describes almost nothing. A free personal account and a contracted enterprise deployment of the same model differ on retention, training, human review, regional hosting, and whether any agreement exists at all. Firm policy should be written about accounts and contracts, not about product names.

Anonymising the document is weaker than it looks

The instinct is to strip the names and paste the rest. It helps, and it is better than nothing, but do not over-trust it. Case documents are dense with re-identifying detail that survives a find-and-replace: contract values, project names, hearing dates, site locations, the specific sequence of a variation order. In a market where a limited number of parties are running a limited number of large disputes, that residue is often enough.

There is also a quieter cost. Redaction to a level that genuinely defeats re-identification tends to remove the exact specifics that made the analysis useful, so you end up doing more work to get a worse answer.

The phrase is doing a lot of marketing work in this market, so it is worth reducing to things you can verify. When assessing any AI tool that will touch case material, these are the properties that matter:

  • Encryption in transit and at rest, with server-side encryption keys managed separately from the storage layer — so the party holding the files is not the same party holding the keys.
  • Tenant isolation: your workspace's data is segregated from every other customer's, with access scoped per account.
  • No training on customer content, stated contractually rather than in a help-centre article that can be edited.
  • Defined retention and deletion: how long material is held, what deletion actually removes, and how long backups persist.
  • Breach notification terms, in the contract: how fast you are told, in writing. The GDPR gives you 72 hours to notify a supervisory authority — you cannot meet that if your vendor takes a month to reach you.
  • Data residency and sub-processors: which region the data sits in, and the named list of downstream vendors that can touch it.
  • Purpose limitation in the product itself: a tool built to extract and structure facts has far less reason to retain and reuse content than one built to be a general assistant.

Ask for those seven in writing. A vendor that cannot answer them quickly is telling you something useful.

A workable firm position

Blanket bans tend to fail, because the pressure that produced the shortcut is still there at 6pm. The policies that hold up in practice route the work rather than forbidding it:

  1. 01Draw one bright line: no client material in personal accounts of any consumer AI product, no exceptions, no anonymisation carve-out.
  2. 02Provide a sanctioned tool for the work people were already trying to do, so the shortcut has somewhere legitimate to go.
  3. 03Keep a short approved-tools list with the contract terms recorded next to each entry — retention, training, residency, sub-processors.
  4. 04Train on the distinction between accounts and tiers, which is where most well-intentioned mistakes happen.
  5. 05Decide the client-disclosure question deliberately: some engagement letters and outside-counsel guidelines already require notice or consent before AI processing.
  6. 06Keep the paperwork. The written processing agreement, the retention terms, and the transfer basis are exactly what a client, an insurer, or a regulator will ask for — and far easier to collect before you need them.

The underlying point is not that AI is unsafe for legal work. It is that general AI products are built for a general audience, with defaults tuned for that audience — and case files are not a general-audience input. Once the tool is chosen deliberately, with terms you have read, the shortcut stops being a risk and starts being an ordinary part of the workflow.

If the reason people are pasting documents into a chat window is that reading them takes too long, that is a workflow problem worth solving directly. Five ways to cut case file review time covers the practical side.

This article is general information about professional practice and technology, not legal advice. Data protection and professional conduct rules differ by jurisdiction and change often — the position described here is as at August 2026. Check the rules that bind you, and your firm's own policies, before changing how you handle client material.

Client confidentialityGenerative AIGDPRGCC data protectionLegal ethics

Keep reading