Skip to content

Sector guidance

Privacy for professional services

Client confidentiality, document-heavy estates and rapid AI adoption — a sector where unstructured data is the whole privacy problem.

In professional services, the personal data that matters usually belongs to someone else's customers, employees or counterparties. It arrives by email, sits in shared drives and matter folders, and outlives the engagement that justified it.

This is the sector where AI assistants deliver the fastest visible benefit and create the fastest exposure, because assistants surface whatever the underlying permissions already allow.

Where personal data flows

Client engagement data
Datasets, documents and system access provided to deliver an engagement, often under a processor role.
Unstructured estates
Mailboxes, shared drives, collaboration sites and matter folders holding the majority of personal data by volume.
Business development
Contact databases, pitch materials and marketing lists, controller-side and subject to marketing rules.
Subcontractors
Associates, offshore delivery teams and specialist providers with access to client material.
AI assistants
Copilots and assistants operating across mail, documents and chat, inheriting existing permissions.

Priority risks

Permission sprawl
Sites and drives shared broadly years ago, invisible until an assistant starts surfacing their contents.
Engagement data retention
Client data retained indefinitely after closure because deletion is nobody's task and the contract is silent.
Email as a data store
Attachments containing personal data living in mailboxes outside any inventory or retention control.
Unsanctioned AI use
Client material pasted into consumer AI tools, often in breach of the engagement terms rather than only privacy law.
Subcontractor gaps
Associates and offshore teams engaged without flow-down terms or access restrictions.

Practical controls

  • Run permission remediation on collaboration platforms before enabling AI assistants, then keep it as a recurring control.
  • Define an engagement closure procedure that includes return or deletion of client data and records the outcome.
  • Give staff an approved AI tool and a clear boundary on what may be entered, since prohibition alone drives shadow use.
  • Apply sensitivity labelling to matter folders and enforce sharing restrictions based on the label.
  • Hold flow-down terms with every subcontractor and restrict access to the specific matter.
  • Run targeted sensitive-data discovery on mailboxes and drives, prioritised by exposure rather than volume.
  • Address leaver accounts and dormant sites explicitly, as they are the most common unmanaged store.

Worth measuring

  • Number of collaboration sites shared organisation-wide or externally without an owner review.
  • Engagements closed in the period with a recorded data disposal outcome.
  • Share of staff using the approved AI tool versus detected use of unapproved tools.

Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.