Accountancy

ChatGPT and accountants: professional secrecy and client data

An accountancy firm handles FEC files, payslips and bank details every day. Before entrusting these documents to an AI assistant, two texts are worth rereading: the French 1945 ordinance on chartered accountants’ professional secrecy, and the GDPR.

Published on Updated on 7 min readBy the Tacite-IA editorial team

Contents
  1. The chartered accountant’s professional secrecy
  2. What the GDPR adds
  3. The data at stake: FEC, payroll, IBANs, NIR
  4. Personal account or business plan
  5. What the profession says
  6. Good practice for an accountancy firm
  7. Frequently asked questions
  8. Sources

Drafting a reminder letter, summarising a tax memo, preparing commentary on the annual accounts, understanding an unusual entry: generative AI has many uses in an accountancy firm, and they are often relevant. But a firm also handles, every day, some of its clients’ most sensitive data: detailed accounts, payroll, bank details, tax position. Before pasting a file into ChatGPT or another assistant, two legal frameworks overlap: the profession’s own professional secrecy, and the GDPR. This article looks at the situation of the expert-comptable, the chartered accountant regulated under French law; comparable professional secrecy rules exist in other countries, and readers elsewhere should check with their own professional body.

The chartered accountant’s professional secrecy

Ordinance No. 45-2138 of 19 September 1945, which organises the profession in France, provides that chartered accountants, trainee chartered accountants and certain employees of accountancy firms are bound by professional secrecy, under the conditions and penalties laid down in Article 226-13 of the French Criminal Code (Article 21).1 Article 226-13 of the Criminal Code punishes the disclosure of secret information by a person who holds it by virtue of their profession with one year’s imprisonment and a fine of 15,000 euros.2

The question raised by generative AI is therefore simple to put: is passing a client’s data to a third-party service, which processes and stores it on its servers, compatible with this secrecy? To our knowledge, there is no case law settling this point for AI assistants, and the answer depends on the actual conditions (contract, retention, access, type of data). What is certain is that data you do not send does not raise the question. Hence the value of minimisation, described below.

What the GDPR adds

Client files contain personal data: that of directors, of employees whose payroll the firm prepares, and of suppliers and customers who appear in the entries. Depending on the engagement, the firm may act as controller or as its client’s processor; each situation calls for its own analysis.

When it acts as a processor, for payroll for example, the GDPR prohibits it from engaging another processor without the prior specific or general written authorisation of the controller (Article 28(2)).3 An AI service that processes payslips on the firm’s behalf potentially falls within this framework. In all cases, the principles of data minimisation (Article 5) and security (Article 32) apply.3

For generative AI, France’s data protection authority, the CNIL, recommends governing use through a policy, involving the data protection officer and training users.6 We describe these steps in our article on ChatGPT and GDPR compliance for businesses.

The data at stake: FEC, payroll, IBANs, NIR

  • The FEC (fichier des écritures comptables, the French file of accounting entries): where the accounts are kept electronically, a business under tax audit hands a digital copy of it to the tax authorities (Article L47 A of the French Book of Tax Procedures).4 It contains every entry for the financial year, with descriptions and third-party accounts, often bearing names.
  • Payroll: salaries, bonuses, absences, attachments of earnings, and sometimes health-related information (sick leave) that falls within the special categories of Article 9 of the GDPR.3
  • The social security number (NIR), which employers use for payroll but whose use, the CNIL points out, is limited to very specific cases, most often related to social protection.5
  • Bank details: IBANs of clients, suppliers and employees, bank statements.
  • Strategic information: forecasts, planned sales of the business, financial difficulties, which are also covered by the client’s trade secrets.
payroll-extract.csvAnonymised version

employee no. ; employee ; NIR ; IBAN ; gross pay

0142 ; Ms Julie Garnier[NAME_1] ; 2 91 03 69 123 456 53[NIR_1] ; FR76 1820 6000 4512 3456 7890 189[IBAN_1] ; 2,850.00

0157 ; Mr Thomas Leroy[NAME_2] ; 1 88 11 13 055 789 08[NIR_2] ; FR76 3000 3035 4000 0501 2345 607[IBAN_2] ; 3,120.00

6 items replaced on the device
A payroll extract before and after anonymisation: the amounts remain usable for a consistency check, the identities and identifiers are not sent. Fictitious data.

Personal account or business plan

The type of account changes the contractual framework. For its consumer services, OpenAI states that it may use the content submitted to improve its models, unless the user turns this off.8 For ChatGPT Business, Enterprise and the API, the vendor states that it does not train its models on customer data by default, and offers a data processing addendum.7 Microsoft, Anthropic and Google also publish commitments for their business plans, including not training their models on customer data by default.10,11,12

Use to improve the models
Possible, can be disabledFor its consumer services, OpenAI states that it may use content to improve its models, unless the user turns this off.
Data processing agreement (GDPR)
NoneThe account belongs to the staff member: no agreement binds the firm to the vendor.
Professional secrecy
Not addressedNothing governs the confidentiality of client files with regard to the vendor.
What the type of account changes for a firm (sources 7 and 8). Switch between the tabs to compare.

A business plan is therefore a reasonable prerequisite. It does not remove the need to think about what is sent: a contract governs the vendor’s processing, it does not remove the transmission itself.

What the profession says

In 2024, the national council of the French order of chartered accountants (Conseil national de l’ordre des experts-comptables) published a practical guide for firms, “Comment utiliser ChatGPT ?” (How to use ChatGPT). It gives a blunt instruction: do not upload personal, sensitive or confidential data, “no client emails, FEC files, DSN [payroll declarations]… that have not been anonymised”, to websites the firm does not control, in order to respect the GDPR and professional secrecy.9

The instruction matches the legal analysis: the best-protected data is the data that is never sent. The profession’s recommendations evolve with the tools; before making any decision, it is worth consulting the latest publications of the Order and of the regional council to which the firm belongs.

Good practice for an accountancy firm

  1. Map current useWhich staff use which assistants, for which engagements.
  2. Choose tools under contractBusiness plan, GDPR addendum, verified storage location.
  3. Set the prohibited dataNamed FEC files, payroll, IBANs, NIR, employees’ health data.
  4. Anonymise by defaultTags instead of names, third-party accounts and contact details.
  5. Check engagement lettersInformation for clients and, where needed, authorisation for sub-processing.
  6. Train and keep recordsAwareness, record of processing, impact assessment where necessary.
A typical approach, built from the GDPR (Articles 5, 28, 30 and 35), the recommendations of the French CNIL and the Order’s guide (sources 3, 6 and 9).

The most effective measure is also the simplest: replace names, third-party accounts, IBANs and social security numbers with tags before sending. A review of entries, an explanation of a variance or commentary on the accounts can all be done perfectly well on pseudonymised data. We compare the possible methods in our guide to anonymising data before ChatGPT, and offer an AI policy template to adapt to your firm.

To support this rule with a tool, Tacite-IA detects on the computer, before anything is sent to AI assistants in Chrome and Edge, IBANs, social security numbers, email addresses, names preceded by a title, health data and other sensitive data, and offers an anonymised version. Excel, Word or PDF files are read on the computer: an anonymised text copy is sent instead of the original, and scanned PDFs, which cannot be read, are flagged as unverifiable. The analysis is carried out without AI and without sending the content to our servers. Desktop apps, such as the ChatGPT desktop app, are not covered.

Frequently asked questions

Can a chartered accountant use ChatGPT?

Nothing prohibits the tool as such, but in France the expert-comptable is bound by professional secrecy (Article 21 of the ordinance of 19 September 1945) and by the GDPR. The national council of the Order recommends not uploading personal or confidential data that has not been anonymised, such as FEC files, DSN or client emails.

Can you send an FEC file to ChatGPT?

An FEC file contains all the entries for the financial year, often with the names of customers, suppliers or employees. Sending it as it is passes on this data and information covered by professional secrecy. It is better to replace descriptions and named third-party accounts before any analysis.

Does the firm need its clients’ consent to use an AI?

When the firm acts as a processor within the meaning of the GDPR, for payroll for example, Article 28 requires it to obtain the client’s prior written authorisation before engaging another processor. Engagement letters and data processing agreements are worth rereading on this point.

What is the penalty for breaching professional secrecy?

Article 226-13 of the French Criminal Code provides for one year’s imprisonment and a fine of 15,000 euros for the disclosure of secret information by a person who holds it by virtue of their profession.

Sources

  1. Ordinance No. 45-2138 of 19 September 1945, Article 21 (professional secrecy of French chartered accountants). Légifrance (official French legal database). In French. Accessed on 8 October 2026.
  2. French Criminal Code (Code pénal), Article 226-13 (breach of professional secrecy). Légifrance (official French legal database). In French. Accessed on 8 October 2026.
  3. Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). EUR-Lex. Accessed on 5 October 2026.
  4. French Book of Tax Procedures (Livre des procédures fiscales), Article L47 A (file of accounting entries). Légifrance (official French legal database). In French. Accessed on 8 October 2026.
  5. Qui peut me demander mon numéro de sécurité sociale (NIR) ?. CNIL (French data protection authority). In French. Accessed on 8 October 2026.
  6. Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative. CNIL (French data protection authority), 18 July 2024. In French. Accessed on 5 October 2026.
  7. Enterprise privacy at OpenAI. OpenAI, page updated on 8 January 2026. Accessed on 5 October 2026.
  8. How OpenAI handles data in consumer services. OpenAI Help Center. Accessed on 5 October 2026.
  9. Comment utiliser ChatGPT ? Notice pour les cabinets d’expertise comptable. Conseil national de l’ordre des experts-comptables (national council of the French order of chartered accountants), 2024. In French. Accessed on 8 October 2026.
  10. Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat. Microsoft Learn. Accessed on 5 October 2026.
  11. Is my data used for model training?. Anthropic Privacy Center. Accessed on 5 October 2026.
  12. Generative AI in Google Workspace Privacy Hub. Google Workspace. Accessed on 5 October 2026.
One measure among others

Govern AI use without slowing your teams down

Tacite-IA detects sensitive data in messages and files before they are sent to AI assistants in Chrome and Edge, and in coding assistants (Claude Code, Cursor, Windsurf, Codex, Gemini CLI, Copilot CLI). Analysis runs 100% on the device, with no AI, and comes with an admin console and an audit mode. Desktop apps (the ChatGPT desktop app, the Chat tab in Claude Desktop, Copilot in Windows) are not covered.

€6 excl. VAT per user per month billed annually, €8 excl. VAT billed monthly. 3-month trial.

Further reading