Managing partners and firm risk leads

An associate pasted a client file into ChatGPT: the next 48 hours

Sources verified Sanitized Ai Team

The short answer

Treat it as a possible confidentiality breach, not a training issue. In the first 48 hours, preserve the facts, find out exactly what was submitted and under which account, assess whether privacy law requires a report (PIPEDA or Quebec's private sector act), decide how the client will be told, and give your professional liability insurer prompt notice. Confirm each step with your law society's practice advisors and your insurer.

The situation

It is Tuesday afternoon. An associate mentions, almost in passing, that they pasted a draft share purchase agreement and the client's disclosure schedule into ChatGPT last week to tighten the indemnity language. The schedule lists employees by name, with salaries. The associate used a personal account on a firm laptop. Nobody else knew.

The supervision question is covered in what a partner owes when a student pastes a client file into AI. This guide covers the urgent one: what the firm does in the next 48 hours.

Hours 0 to 4: contain and preserve

  1. Stop further submissions. Ask the associate not to continue the conversation or upload anything else to that account.
  2. Preserve the facts before anything is deleted. Capture the conversation showing the date, the account, and exactly what was pasted or uploaded.
  3. Identify the account type. A personal account is governed by the individual's own settings. OpenAI says that, by default, it does not use content from ChatGPT Business or Enterprise workspaces to train its models (OpenAI data controls).
  4. Check the training setting. On a personal account, note whether "Improve the model for everyone" was on. OpenAI describes turning it off as applying to new conversations, so switch it off now and record what it was at the time of the incident.
  5. Then delete, once preserved. OpenAI states that a deleted chat leaves the account view immediately and is scheduled for permanent deletion within 30 days, unless it was already de-identified or OpenAI must keep it longer for security or legal reasons (OpenAI help centre). Deletion limits further exposure. It does not reverse the disclosure.

Hours 4 to 24: assess

Record what was submitted (documents, personal information, privileged advice, commercial terms), which client and matter, whose information was included, and when. This inventory drives every decision that follows.

Hours 24 to 48: decide and notify

Decide, with the right advisors, on the privacy report, the client conversation, and the insurer notice described below. Document each decision and the reasons for it.

What the rules actually say

Federal privacy law (PIPEDA). PIPEDA defines a breach of security safeguards to include the unauthorized disclosure of personal information resulting from a failure of the organization's safeguards. Under section 10.1, an organization must report a breach to the Privacy Commissioner, and notify affected individuals, if it is reasonable to believe the breach creates a real risk of significant harm. The factors include the sensitivity of the information and the probability it will be misused. Section 10.3 requires a record of every breach, whether or not it is reported, and the regulations set that retention at 24 months. See our PIPEDA overview for context.

Quebec. For firms subject to Quebec's private sector act, sections 3.5 to 3.8 apply to a "confidentiality incident", which includes communication of personal information not authorized by law. The firm must take reasonable measures to reduce the risk of injury. If the incident presents a risk of serious injury, it must promptly notify the Commission d'accès à l'information and the affected persons. The risk assessment weighs sensitivity, consequences, and likelihood of misuse, with input from the person in charge of protecting personal information. Every incident goes in the firm's register.

Informing the client (Ontario). The Law Society of Ontario's rule 7.8-1 applies when a lawyer discovers an error or omission that is or may be damaging to the client and cannot readily be fixed. The lawyer must promptly inform the client, recommend independent legal advice, and advise that the lawyer may no longer be able to act. The duty of honesty and candour in rule 3.2-2 points the same way. Whether a given AI disclosure crosses the 7.8-1 threshold is a judgment call. Make it with a practice advisor, not alone. The Federation of Law Societies Model Code contains the same rule; Quebec lawyers should confirm the equivalent obligations with the Barreau du Québec.

The insurer. Ontario's rule 7.8-2 requires prompt notice to the insurer of any circumstance that may give rise to a claim, and its commentary notes the policy requires this contractually too. LAWPRO asks lawyers to report real or possible mistakes immediately and cautions against trying to repair a potential claim on their own. If the firm also carries a separate cyber policy, check its notice clause.

British Columbia. The Law Society of BC's generative AI guidance points to Law Society Rule 10-4, which requires a lawyer to notify the Executive Director in writing immediately on reason to believe they have lost custody or control of practice records.

Why policies and bans fall short

Most firms that face this scenario already had a policy. The associate knew the rule and made a judgment under deadline pressure, on an account the firm could not see. That is the pattern: the incident surfaces only because someone volunteers it, days later.

Without a record, the firm relies on memory to answer what the regulator, the client, and the insurer will ask: what exactly was sent, when, and has it happened before. A policy tells people what not to do. It does not tell the firm when it happened, and it does not stop the submission.

What a practical control looks like

  1. Write the playbook down now. Assign an incident owner, list the steps above, and keep contact details for your practice advisor, insurer, and privacy officer in one place.
  2. Make self-reporting safe. An associate who reports within the hour gives you options. One who hides it for a month does not.
  3. Offer a sanctioned tool with business terms, configured and documented, so the fast option is also the approved one.
  4. Train on the specific risk: client names and identifiers, personal information, and deal terms, and why a submitted prompt cannot be recalled.
  5. Keep a register of AI incidents alongside your privacy breach records.
  6. Prepare a client communication template so the conversation, if needed, is prompt and measured.

Sanitized Ai is a browser extension that works at the point where this incident starts. When someone is about to submit client names, personal information, or deal terms to an AI assistant, it redacts or blocks the sensitive content before submission and explains in plain language what was flagged and why. The incident in this guide can become a near miss, and a lesson learned in the moment.

Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) without ever seeing prompt content. That record can help show the firm took reasonable safeguards, which is useful when a client or insurer asks. See how it fits law firms.

Frequently asked questions

Can we just delete the ChatGPT conversation and move on?

Deleting the chat, after preserving a record of it, is a sensible containment step, but it does not undo the disclosure. The firm's privacy assessment, client communication, and insurer notice still need to happen.

Is pasting client information into ChatGPT a privacy breach under PIPEDA?

It can be, because PIPEDA's definition of a breach of security safeguards includes unauthorized disclosure of personal information. A report to the Privacy Commissioner and notice to individuals are required only where there is a real risk of significant harm, but every breach must be recorded.

Do we have to tell the client?

It may be required. In Ontario, rule 7.8-1 requires prompt notice to the client of an error or omission that is or may be damaging and cannot readily be fixed. Whether a particular AI disclosure meets that threshold is a judgment call to make with your practice advisor and insurer.

Does it matter whether the associate used a personal or a business account?

Yes. OpenAI states that by default it does not use content from ChatGPT Business or Enterprise workspaces to train its models. A personal account is governed by the individual's own settings, which the firm does not control.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading