News · Compliance · 21 July 2026

AI and client data: the legal risks of use without legal oversight.

By BoezioAI · Reading time: 8 minutes

Key points

  • ChatGPT, Claude and Gemini almost always enter firms and companies through the wrong door: an individual subscription activated with a credit card, outside any legal assessment.
  • The core principle: compliance is not a property of the model, but of the contractual and organisational configuration in which it is used. The very same tool can be perfectly lawful or seriously unlawful.
  • The risks of unstructured use: breach of professional secrecy (Art. 622 of the Italian Criminal Code), processing without the Art. 28 GDPR contract — with fines up to 20 million euros or 4% of turnover — data used to train models, extra-EU transfers without safeguards.
  • Italian Law 132/2025 requires professionals to inform clients about their use of AI; the Italian DPA has already fined OpenAI 15 million euros.
  • The answer is not to give up AI: it is to adopt it in a structured way — commercial plans with a DPA and transfer clauses, governed retention, internal policies, training.

Generative AI has entered professional firms and companies through the quietest door: individual initiative. The lawyer summarising a brief with ChatGPT, the finance manager having Claude analyse a supply contract, the marketing team feeding a client list to Gemini. Everyday actions, perceived as harmless, with one common trait: third-party data — clients, employees, counterparties — introduced into systems run by foreign providers, under contractual terms nobody has read and no function has vetted.

The phenomenon is aggravated by a widespread misconception: the idea that compliance is a property of the tool ("this platform is GDPR-compliant, that one is not"). Reality is more demanding — and it overturns the way most organisations are reasoning.

1. What matters is the configuration of use, not the model

The main platforms — ChatGPT, Claude, Gemini — all share the same commercial architecture: on one side the consumer plans, designed for individual users; on the other the commercial plans (team, enterprise, API), designed for organisations. The difference is not price or power: it is the legal status of the data.

Under consumer plans, as a rule, the provider does not act as a data processor, conversations may be used — depending on settings — to train the models, and data is stored on non-European servers without negotiated safeguards. Under commercial plans, use of data for training is contractually excluded and the relationship is backed by a Data Processing Agreement with standard contractual clauses for transfers. The real alternative is therefore not between one provider and another: it is between the unstructured and the structured use of the very same tool.

📌 The operational corollary: before feeding client or employee data into an AI platform you need to know which plan you are on, which clauses govern the data, where it is stored and for how long — and to document those checks. These are legal assessments before they are technical ones.

2. Professional secrecy: Art. 622 of the Criminal Code

For lawyers, accountants, labour consultants and doctors, the first safeguard at stake is professional secrecy: Art. 622 of the Italian Criminal Code punishes whoever discloses "without just cause" a secret learned through their profession. The confidentiality of lawyer-client communications is also a fundamental right according to the EU Court of Justice (Case C-694/20, Orde van Vlaamse Balies).

Where does entering client data into an AI platform sit within this framework? It depends — once again — on the configuration. If the provider is a data processor duly appointed under Art. 28 GDPR, bound by confidentiality and prohibited from using the data for its own purposes, it is not a "third party" to whom the secret is disclosed, but an auxiliary — just as is peacefully accepted for e-mail or practice-management systems. With a consumer plan, lacking that framework, handing over the client's documents and affairs to a party contractually free to store and use them revives the criminal and disciplinary risk. The same material conduct — pasting a document into a chat — changes its legal qualification depending on the contract underneath it.

3. GDPR: without a DPA the processing is exposed

Whoever uses AI on personal data of clients, employees or third parties is the data controller; the provider, where it processes that data on their behalf, must act as processor under Art. 28 GDPR, with a contract — the DPA — binding it to process data only on instruction, ensure security, regulate sub-processors and delete the data at the end.

Under commercial plans the DPA is generally incorporated into the contractual terms: it is not to be negotiated, but to be verified, downloaded and kept on file, with an entry in the record of processing activities. Under consumer plans it simply does not exist: feeding personal data into them amounts to a disclosure to third parties without the Art. 28 contractual basis, exposed to the fines of Art. 83 — up to 10 million euros or 2% of worldwide turnover for processor-related breaches, up to 20 million or 4% for breaches of the fundamental principles.

4. Training, retention, sensitive data

The most insidious issue — because it is irreversible — is the use of content to train the models: a confidential document that flows into training data leaves the controller's sphere of control for good. No deletion, no right to be forgotten will ever reach it again. On individual plans this may happen under settings the average user has never examined; on commercial plans it is contractually excluded.

The same goes for retention: from the standard terms of individual plans to the zero data retention options available in enterprise and API configurations. Retention policies are not to be presumed: they are to be verified contractually. And for special-category or judicial data under Arts. 9 and 10 GDPR — health, criminal matters, trade-union data — the bar rises further: either reinforced safeguards, or refraining from cloud AI altogether.

5. Extra-EU transfers: Schrems II and the Data Privacy Framework

The issue that most escapes perception is the geographical one: the major platforms belong to US providers, and feeding personal data into them entails a transfer to a third country subject to Arts. 44-49 GDPR. The Schrems II judgment of the Court of Justice (Case C-311/18) requires the exporter — that is, the firm or the company, not the provider — to verify in concrete terms the level of protection in the destination country and to adopt, where necessary, supplementary measures: this is the transfer impact assessment, the first document the Authority asks for in an inspection.

The 2023 adequacy decision on the EU-U.S. Data Privacy Framework has eased the picture, but only for providers certified in the U.S. Department of Commerce list — a certification to be checked case by case, for the specific contracting entity, bearing in mind that its predecessors (Safe Harbour, Privacy Shield) both fell in Luxembourg. Whoever uses a consumer plan has no negotiated instrument to govern the transfer; whoever uses a commercial plan has the standard contractual clauses incorporated in the DPA, but must complete them with the TIA and the DPF verification.

6. Law 132/2025, the AI Act and the OpenAI case

For intellectual professions, Art. 13 of Italian Law 132/2025 (in force since 10 October 2025) allows AI only in instrumental and support functions, requires the professional's intellectual contribution to prevail, and imposes a duty to inform the client in clear language; the Italian National Bar Council has already approved a model notice. The AI Act (Reg. (EU) 2024/1689) completes the framework with risk-graded obligations — we covered it in our guide to the AI Act and its sanctions.

As for enforcement, the signal is unambiguous: in December 2024 the Italian Data Protection Authority fined OpenAI 15 million euros for breaches concerning legal basis and transparency (enforcement later suspended by the Court of Rome in interim proceedings). The Authority's attention to generative AI is structural, not episodic.

7. The checklist: what to do, in order of priority

⚠️ What does not hold up is the organisational vacuum: extremely powerful tools left to individual initiative, with no ownership, no usage rules, no training. It is today's most common situation — and a stock of risk that builds up day after day, destined to surface at the worst moment: a dispute, a data breach, an inspection.

Frequently asked questions

Is my paid personal subscription enough?

No. The difference between consumer and commercial plans is not price: it is the legal status of the data. An individual subscription, however paid, as a rule does not include a DPA, does not exclude training and offers no safeguards on transfers.

Do I have to tell clients I use AI?

If you are an intellectual professional, yes: Art. 13 of Law 132/2025 requires you to inform the client in clear, simple and exhaustive language. Omitting it affects the fiduciary relationship and is relevant at the disciplinary level.

Where do you start?

With an audit of the tools already in use: which platforms, under which accounts, on which data. In our experience it is the step that brings the most surprises — and the one everything else follows from: account migration, DPA, notices, policies.

BoezioAI: AI adoption, with legal oversight built in

This is exactly the work we were born for: the team's AI engineers configure the tools and environments, the Legal Tech lawyers build the framework — audit of contractual plans, DPA and transfers, records and DPIA, client notices, usage policies and training. Because innovation, to be an advantage, must be defensible.

Let's talk: info@boezioai.com · +39 329 7413254

Adaptation, authorised by the author, of the article "Intelligenza artificiale e dati dei clienti: i rischi legali di un utilizzo senza presidio giuridico" by Avv. Dott. Comm. Dario Carta, published on cartaepartners.it. Key references: Art. 622 of the Italian Criminal Code; Arts. 9, 28, 30, 35, 44-49 and 83 Reg. (EU) 2016/679 (GDPR); Art. 13 of Italian Law 132/2025; Reg. (EU) 2024/1689 (AI Act); CJEU C-311/18 (Schrems II) and C-694/20; adequacy decision of 10 July 2023 (EU-U.S. Data Privacy Framework). This article is for information purposes only and does not constitute professional advice.

← All news