← Back to blog

Can You Keep Client Documents and Meeting Notes Together in an AI Tool?

Usually yes. On a business account with a data processing agreement, model training switched off and access limited to the people who work on that client, keeping a client's documents and meeting notes together where an AI tool can work across them is ordinary processing. The risk sits in what happens next. The workspace quietly becomes a second client file, with its own copies, its own retention and its own access list, and nobody manages it as one.

We have covered which data may go into which kind of tool in Is It Safe to Put Client Data into ChatGPT?, and what changes when the data arrives as a file in Can You Upload a Client Document to an AI Tool?. This post takes the next step. Once a firm uses AI every day, where should client material live, and how do you keep it together without losing control of it?

Why would a firm want it all in one place?

Because that is where the value is. An assistant that can read a client's documents and the notes of every meeting can prepare a review in minutes, brief a colleague taking over the relationship, and answer "what did we agree last March?" without anyone searching three systems. Clients notice when the person across the table already knows their history. The time saved is real too, and firms that set this up well can offer a closer, more responsive service than firms still working from scattered folders.

The typical set-ups are an AI notetaker producing meeting summaries, a project or workspace inside an AI assistant holding a client's files, and a practice-management system that has added AI features. The questions below apply to all three.

When is it fine to keep them together?

When four things are true. The tool is on a business account under a data processing agreement, because under Article 28 of GDPR the provider is your processor and needs a contract to match. Training on your content is switched off. Access is limited to the people who work on that client. And the material sits in the right tier of the routing framework from our earlier post: client names and circumstances are tier three, and health or other sensitive material is tier four, which needs its own decision.

Check the terms attached to the plan your firm actually pays for, on the day, in writing. Vendor terms change, and no blog post, this one included, can tell you what yours say today.

Where does it go wrong?

Six places, and most firms meet at least two of them in the first year.

The workspace becomes a second client file

A firm already has a client file, in a practice-management or document system, with a retention schedule and an owner. A workspace in an AI tool starts as a convenience and ends up holding copies of the fact find, last year's review, three meeting summaries and an email thread somebody pasted in. Nobody decided it would be a record. It is one anyway, and it drifts out of step with the real file the first time a document is updated in one place and not the other.

Notes outlive your retention schedule

GDPR requires personal data to be kept no longer than is necessary for the purpose (Article 5(1)(e)). Your retention schedule says how long that is for client files. An AI workspace or notetaker has its own retention setting, and its default is often to keep everything until someone deletes it. The Data Protection Commission puts it plainly: without a retention schedule and the processes behind it, an organisation risks breaching the storage limitation principle. Your processing agreement also has to say what happens to the data when you stop using the service, because Article 28(3)(g) requires the processor to delete or return it at your choice.

The notetaker records people who are not your client

A notetaker captures everyone on the call. That can include a client's spouse, an accountant joining for ten minutes, or a colleague from another firm. Where you collect personal data from the person directly, Article 13 says they must be told at the time it is obtained, which for a recording means at the start of the meeting. People who are discussed but not present, such as a dependant or a business partner, are covered by Article 14. Telling everyone at the start, and keeping the summary while discarding the recording where the recording is not needed, deals with most of this. Minimisation (Article 5(1)(c)) points the same way.

One client's material answers another client's question

If one workspace holds several clients, the assistant will draw on all of them. Ask it to draft a letter for one client and it may borrow a figure, a phrase or a circumstance from another. That is a confidentiality failure, and GDPR treats confidentiality as a core principle (Article 5(1)(f)) and expects security measures that protect it (Article 32). It is also, for most professional firms, a breach of a duty owed to the client regardless of data protection. Separation by client prevents it.

Access and deletion requests have to reach the AI tool

A client who asks for their data is entitled to all of it (Article 15), and a request to erase it, where it applies, covers every copy (Article 17). You have one month to respond (Article 12(3)). The European Data Protection Board's guidance on the right of access says that where a controller uses a processor, the search has to extend to the data the processor holds. So the AI workspace, the notetaker's archive and any summaries are in scope. The Data Protection Commission frames the question every firm should be able to answer: if someone asks for access to their data, or asks you to delete it, within the AI system, can you do it? Article 28(3)(e) requires your processor to help you. The agreement should say how.

Health and other sensitive details end up in notes

Protection, pensions, mortgages and many legal matters involve conversations about health. Data concerning health is special category data under Article 9 of GDPR, and processing it is prohibited unless one of the listed conditions applies. A notetaker records it whether or not anyone meant it to. Decide in advance whether meetings that touch on health may be recorded at all, and whether the summary should leave those details out. Where the processing is likely to result in a high risk to the people concerned, Article 35 requires a data protection impact assessment before it starts.

What structure should a firm adopt?

Five decisions, most of which fit on one page.

  1. One system of record. The client file stays where it is today, in the practice-management or document system that already has your retention schedule and access rules. Anything that matters for the client's record ends up there.
  2. The AI tool as a working layer. It reads from the record, or holds working copies for a task. Finished outputs, such as an agreed meeting summary, are filed back to the record. Working copies are cleared on a schedule.
  3. A retention rule for the AI layer. Set the tool's retention no longer than the record's, and shorter where you can. Recordings are the first candidate for deletion once the summary is filed.
  4. Separation by client. One workspace, project or permission group per client, open only to the people on that client. No shared pool of client files.
  5. A short register of which AI tools hold client data. For each one: what data it holds, which tier, its retention setting, who owns it, and how an access or deletion request reaches it. Article 30 already expects most firms to keep a record of processing, because the exemption for organisations under 250 staff does not apply where processing is regular, likely to result in a risk, or includes special category data. The AI register can be a few lines in that record.

Add one rule for notetakers. Tell everyone at the start of the call, and have a named person check the summary before it goes on the client file.

What do we do when we build this for a client?

We start from where the client record sits today and map every other place client material already lives, including AI features already switched on inside software the firm pays for. That map usually finds more copies than anyone expected.

From there we apply the data-routing framework we design for regulated organisations: a classification register that decides, tier by tier, what data may go to which AI system, pseudonymisation patterns for the work that does not need identifiers, and written triggers for when a formal impact assessment is required. We set out the workspace structure per client, the retention settings and the path an access or deletion request takes through each tool, and we check that path works before anything goes live. The full method is on our how we build page.

Where to start

Firms that settle this early get more from it than a tidy compliance file. Their people walk into every meeting with the client's history to hand, clients feel known, and the firm can adopt the next useful tool quickly because the rules for where client material lives are already written.

If you want an honest picture of where your firm stands before committing to anything, our free AI Readiness Self-Assessment takes ten minutes. A dploy.ai AI Operations Assessment covers this ground properly and maps where AI pays back for your business, for a fixed fee agreed before we start. Or book a short call and talk it through first.

This is practical guidance and not legal advice. A firm with a genuinely difficult question, particularly about health data or recordings, should take its own.

Want to know where AI fits in your business?

We run a structured assessment that identifies your highest-value AI opportunities. Fixed price, agreed before we start, delivered within ten working days.

Book a free 15-minute call