Skip to main content

With the increasing use of tools based on artificial intelligence (AI) technology in law firms, bar associations have launched initiatives to ensure their proper use by members.

One particularly important aspect concerns the requirement to anonymise personal data when using these systems and, in particular, generative AI (GenAI) tools.

The CCBE (“Council of Bars and Law Societies of Europe”), in its Guide on the use of generative artificial intelligence by lawyers dated 2 October 2025, highlighted the risks associated with entering personal data into GenAI system prompts.

Among these risks is the fact that GenAI system providers may use input data for the purpose of training their machine learning models. This would expose personal data - including, where applicable, data falling within categories requiring enhanced protection (such as ‘sensitive data’ and ‘judicial data’) - to processing that could be unlawful. Furthermore, providers may have access to both the input data and the data generated in the outputs.

Given the confidentiality obligations incumbent upon lawyers, the CCBE has emphasised their responsibility regarding the information entered into AI systems, not limited to that constituting “personal data”. Among the rules governing the use of such tools, it has been stipulated that lawyers must avoid entering personal, confidential or otherwise client-related data into the user interface of a GenAI tool, unless adequate safeguards are in place. Such safeguards could take the form of contractual obligations on the GenAI provider to process the data as confidential, or the conclusion of a data protection agreement in line with Regulation (EU) 2016/679, stipulating that the data entered is to be used exclusively for the purposes of the law firm.

The “BrevIArio normativo sull’uso dell’IA” (Regulatory Guide on the Use of AI) published by the Turin Bar Association also highlights the risks associated with the potential storage and subsequent use of input data by AI system providers for training purposes. On this point, it emphasises the need to verify that the provider offers guarantees that this will not occur, possibly subject to additional conditions beyond those of the standard public licence. It also highlights the risk of “regurgitation” of personal data, where information entered as input by a specific user is provided as output in response to another user’s prompts, thereby constituting unlawful processing of personal data. In this regard, the handbook stipulates that lawyers must not include confidential information in their prompts.

Even more explicit is the “Breve vademecum per avvocati sull’utilizzo dell’intelligenza artificiale” (Brief Guide for Lawyers on the Use of Artificial Intelligence) published by the Rome Bar Association, which, amongst its practical guidelines on the use of AI tools, recommends anonymising data by removing names and other identifying details, as well as avoiding the use of “public” chatbots for texts containing confidential data.

To prevent the input of personal data, it is therefore essential to adopt appropriate anonymisation measures, in compliance with the requirements emerging from supranational and domestic legislation on the protection of personal data.

Such measures, which are both technical and organisational in nature, must be implemented whilst ensuring compliance with all data protection obligations, which require the data controller (in this case, the lawyer) to make a continuous effort, given the purely ‘relative’ nature of anonymisation processing, as recently confirmed by the Court of Justice of the EU in the case of SRB v EDPS (judgment of 4 September 2025, C-413-23 P), concerning the relationship between the concept of ‘personal data’ and ‘pseudonymisation’.

The failure to design anonymisation measures, or their improper design, may expose the lawyer to multiple levels of liability, starting with disciplinary liability.