Protect Client Confidentiality When Using ChatGPT: A Lawyer's Guide
You can use ChatGPT for legal work without breaching confidentiality if client data never reaches it. That means redacting names, matters, addresses, account numbers and anything else identifying before you paste, not after. The practical way to do that is a browser extension that detects personal data as you type and replaces it with placeholders, so the AI works on [PERSON_A] and [COMPANY_B] while the real names stay on your machine. PiiBlocker does this for free on ChatGPT, Claude, Gemini, Perplexity, Grok, DeepSeek and Kimi. The rest of this guide covers what the rules require, what to redact, and a process that holds up.
What the rules actually require
Your duty of confidentiality does not stop at the chat window. The ABA's Formal Opinion 512 (July 2024) addresses generative AI directly: a lawyer must understand how a tool handles data before putting client information into it, and where the tool may retain or learn from inputs, informed client consent is required. The SRA's position for England and Wales is the same in substance. Confidential information stays confidential wherever it goes.
The consumer versions of ChatGPT, Gemini and Claude all store conversations on the provider's servers. Some use them for training unless you opt out. A privacy setting is not a confidentiality control, because the data has still left your firm. Redaction before sending is the only approach where the provider never holds the client's information at all, which is why it sits outside the consent question entirely.
What to redact
Anything that identifies a client, a counterparty, or a matter. In practice:
- Names of people and organisations, including opposing parties and witnesses
- Addresses, phone numbers, email addresses
- Case numbers, matter references, court file numbers
- Financial details: account numbers, sums that would identify a transaction
- Dates of birth, national insurance and social security numbers, passport numbers
- Medical or personal facts about a client
- Anything privileged, including your own work product on a live matter
The test is whether someone reading the prompt could work out who the client is or what the matter concerns. A contract clause with the parties' names removed is usually fine. A settlement figure alongside a company name is not.
A process that holds up
- Decide what the AI is for. Drafting a clause, summarising a judgment and rewriting a letter are safe uses with redaction. Uploading a full disclosure bundle is not, even redacted.
- Redact before you paste. Do it in the browser, at the point of sending, not by hand in a document. Manual redaction is where mistakes happen, and it is where the time goes.
- Check the placeholders. A good tool shows you what it found and lets you confirm before the message is sent. Anything it missed, you mask yourself.
- Keep the mapping local. The placeholder-to-name mapping should never leave your machine. When the AI answers with
[PERSON_A], the tool swaps the real name back on screen for you, and only for you. - Turn off training where you can. Redaction is the control. Provider settings are a backstop.
- Write it down. A one-page AI use policy that says what is allowed, what must be redacted, and which tool does it, is what a regulator or client will ask for.
How PiiBlocker fits
PiiBlocker is a free Chrome extension that runs steps 2 to 4 for you. As you type into ChatGPT or any of the other six supported sites, it detects names, addresses, numbers and other personal data and highlights them. Before the message is sent, a dialog shows what it found. Critical items such as card numbers and government IDs are redacted automatically; the rest you confirm with one click. The AI receives placeholders. The reply is unmasked on your screen.
Everything runs in your browser. The free version makes no network calls, has no account, and stores nothing on a server. That is the property that matters for confidentiality: there is no third party to trust, because nothing is sent to one.
For firms that need it, an enterprise version adds managed deployment through Group Policy and an admin dashboard, so the same protection applies to every fee earner without relying on individual installs.
Frequently asked questions
Is it a breach of confidentiality to use ChatGPT for client work? It depends on what you put in. If client-identifying information reaches the provider's servers, you need informed consent under ABA Opinion 512 and equivalent guidance elsewhere. If it is redacted before sending, the provider holds nothing confidential.
Does ChatGPT's "temporary chat" or training opt-out make it safe? No. Those settings change retention and training, not the fact that the data was transmitted to and processed by a third party. Redaction before sending is the control.
Can I just remove the names by hand? You can, but manual redaction misses things (a phone number in a signature block, a case reference in a quoted email) and it takes time. Automated detection at the point of sending catches what you skim past.
Does PiiBlocker work on legal AI tools like Harvey or Spellbook? Not currently. It supports the seven general chat interfaces listed above. Dedicated legal AI tools usually operate under a firm-level agreement with their own confidentiality terms.
Is PiiBlocker free for law firms? The core extension is free with no seat limit. The enterprise tier is for firms that want central deployment and reporting.
Install PiiBlocker free from the Chrome Web Store, or see the full list of supported sites and detected data types at piiblock.com.