Compliance7 min read

What is a DPA and why every lawyer using AI needs one

Free and Plus accounts don't come with one. If you're putting client data into AI without a signed DPA, you're already in breach.

Minimal illustration of a signed contract document with a red redline mark, representing a data processing agreement for AI tools.
By The Redline Editors

A data processing agreement, or DPA, is the contract that makes it legal for an AI vendor to handle personal data on your firm's behalf. If you're a UK solicitor running client data through ChatGPT, Claude, or Copilot without one in place, you're in breach of UK GDPR Article 28 right now, not in some hypothetical future audit. The same gap exists for US firms handling EU or UK client data, and increasingly under US state privacy laws too. Most guidance on this topic explains what a DPA is in the abstract. Almost none of it tells you which AI tools actually give you one and which quietly don't.

Here's the part that catches firms out: the free and personal tiers of every major AI tool run on consumer terms, not commercial terms, and consumer terms don't include a DPA. ChatGPT Free and Plus, Claude Free and Pro, and the personal version of Copilot are all consumer products. Feed client data into any of them and there is no processor agreement governing that data at all, because you never signed one and the vendor never offered one.

What a DPA actually has to contain

UK GDPR Article 28 doesn't just say "have a contract." It specifies what has to be in it. The Information Commissioner's Office lays this out directly in its AI toolkit guidance: a written contract must cover the subject matter, duration, nature and purpose of the processing, the type of personal data involved, and the categories of people whose data it is. It also has to bind the processor to specific obligations. The processor must act only on the controller's documented instructions, keep staff under a duty of confidentiality, get written authorisation before bringing in any sub-processor, help the controller respond to data subject rights requests, and delete or return the data at the end of the contract.

The ICO is explicit about what happens without one: firms risk breaching "UK GDPR articles 28 and 5(2)." That's not a minor paperwork gap. Article 5(2) is the accountability principle, the requirement to be able to demonstrate compliance, not just claim it. A verbal understanding with a vendor, or an assumption that "they probably handle this properly," satisfies neither article.

Which AI tools actually give you a DPA, and which don't

OpenAI's current Data Processing Addendum, effective 1 January 2026, states plainly that it applies to business products, covering ChatGPT Team, Business, Enterprise, and API usage under the Services Agreement. It is not offered on Free or Plus, which run on OpenAI's consumer terms instead. Anthropic draws the same line: Claude Free, Pro, and Max are consumer plans under Anthropic's Consumer Terms, while the DPA is automatically incorporated only when a customer accepts Anthropic's Commercial Terms of Service, which cover Claude for Work and the API.

Microsoft follows the same pattern through its enterprise agreements. Copilot bundled into a personal Microsoft 365 subscription runs on consumer terms. Microsoft 365 Copilot licensed through a commercial tenant sits under Microsoft's Product Terms and Data Protection Addendum instead, which functions as the DPA.

The practical rule is blunt: if you're paying a personal credit card for a "Plus" or "Pro" subscription, you don't have a DPA, full stop. If your firm has a signed business or enterprise agreement, the DPA is either included automatically or available to download and countersign. Check which one you're actually on before you put a single client name into the tool.

Why "we trust them" isn't a defence

Lawyers who wouldn't dream of sending a client file to an unvetted outside contractor without an engagement letter routinely paste client facts into a chatbot with nothing signed at all. The instinct that a reputable vendor "probably" handles data responsibly doesn't hold up against Article 28, which requires a written, specific, signed instrument, not a general reputation for competence.

This also matters for the audit trail your own regulator or a client's general counsel might ask for. If a corporate client's procurement team sends you a security questionnaire, as we've covered before in relation to Microsoft Copilot's SharePoint permission risks, "we use a well-known AI vendor" is not an answer to "show us your Article 28 contract with that vendor." You need the document itself, and you need to have actually read what it says your data will be used for, who the sub-processors are, and how long data is retained.

The US side: DPAs aren't just a UK GDPR thing

US firms sometimes assume this is purely a UK or EU problem. It isn't, for two reasons. First, if your firm handles any matter touching an EU or UK data subject, GDPR's extraterritorial reach can apply regardless of where your office sits. Second, US state privacy laws increasingly require their own version of a processor contract. California's CCPA requires a written contract with any "service provider" that limits use of personal information to the specified business purpose, and several other state privacy statutes modeled on it carry similar contractual requirements. A firm handling California resident data through a consumer-tier AI tool with no service provider agreement in place has the same structural gap as a UK firm without an Article 28 contract, just under a different statute.

Our breakdown of what "do not train on my data" actually means covers the retention side of this. Training settings and contractual processor status are two separate questions, and both need answering before client data goes anywhere near a tool.

What to actually do this week

Pull up the account tier every AI tool in your firm runs on. If it's a personal or consumer plan, either upgrade to the commercial tier and get the DPA signed, or stop putting any client-identifying information into it. There's no third option that survives scrutiny. For the tools you keep, download the actual DPA document, not just the marketing page that says one exists, and confirm it covers the specific product you're using: API access and the chat product from the same vendor sometimes sit under different terms.

Keep a simple internal record: tool name, tier, DPA signed date, and a link to the document itself. That single record is what turns a claim of taking data protection seriously into something you can actually hand a regulator or a client's compliance team on request. We cover how to build that into a written policy in how to write an AI policy for a small law firm.

FAQ

Does a DPA mean the AI vendor won't train on our client data?

Not by itself. A DPA governs the legal terms of processing, but you need to separately confirm the product's data retention and training settings. OpenAI, Anthropic, and Microsoft all state that commercial and API tiers don't train on customer data by default, but that's a product configuration, not something the DPA text guarantees on its own. Check both.

Who signs the DPA, the firm or the individual lawyer?

The firm, as the data controller, signs with the vendor. Individual lawyers using a personal subscription paid on their own card are not covered by any firm-level DPA, even if the firm has one with the same vendor under a different account. This is a common gap: partners who already pay for ChatGPT Plus personally and assume that covers their firm work.

What happens if we've been using a consumer-tier tool for client work without a DPA?

Stop putting client data into it immediately, and move to a commercial tier with a signed DPA before resuming. Whether you need to notify anyone depends on what data was actually processed and under which regulatory framework, which is a question for your data protection officer or outside counsel, not something to self-diagnose from a blog post.

For the underlying rule text and a template to build your own AI policy from, see our free guide. For a vetted list of tools worth putting on your approved list in the first place, see the best AI tools for lawyers.

ShareX / TwitterLinkedIn
Was this useful?

Disclaimer · Educational content about software and productivity, not legal advice. AI tools and regulatory guidance change frequently, so always evaluate any tool against your own firm's obligations and your regulator's current guidance (e.g. the SRA in England & Wales, or your state bar / the ABA in the US) before using it with client data.

Free starter kit

Want the safe-tools shortlist as a PDF?

10 lawyer-safe AI tools, 12 ready-to-use prompts, and a client-confidentiality checklist for the SRA (UK) and ABA Rule 1.6 (US). Free, no spam.

Get the free Starter Kit →

Go deeper: The Lawyer's AI Toolkit (£29) →