Logo

Can You Enter Personal Data, Client Information, or Contracts into Generative AI?

Decent Law Firm

Decent Law Firm

0
img

What Happens to Information You Enter into Generative AI?

When using a generative AI service, it may appear that you simply type a question or upload materials and receive an answer.

In reality, however, the information you enter is transmitted to the service provider's systems, where it may be stored as chat history or system logs for a certain period or potentially used for service improvement, depending on the provider.

Some AI services allow users to disable the use of input data for AI training, delete chat history, or manage data retention periods.

Before entering work-related materials into a generative AI service, you should confirm the following:

  • Whether your input data may be used for AI training
  • How long conversations and uploaded files are retained
  • Whether chat history and uploaded data can be deleted
  • In which country the data is processed and stored
  • What access permissions are granted to external applications or internal systems

The Personal Information Protection Commission (PIPC) of Korea also recommends checking whether user inputs are used for AI training, reviewing chat history storage and deletion settings, and granting only the minimum necessary permissions when connecting external services.

Is It No Longer Personal Information If You Remove the Name?

Simply deleting a client's name or contact information from a contract does not necessarily mean that the document no longer contains personal information.

Under Korean privacy law, personal information includes not only information that directly identifies an individual but also information that can identify a specific individual when combined with other available information.

For example, even if names are removed, an individual may still be identifiable if the document contains:

  • A company name together with a specific job title
  • The contract date and transaction amount
  • Department information and performance evaluations
  • Detailed consultation history and family relationships
  • Case numbers and the location of a dispute

Accordingly, rather than removing only names, businesses should eliminate unnecessary identifying information wherever possible and replace actual names of individuals and companies with fictitious or placeholder names.

Does Entering Client Information into Generative AI Automatically Violate Privacy Laws?

Entering client information into a generative AI service does not automatically constitute a violation of the Personal Information Protection Act (PIPA).

However, personal information collected by a company may only be used within the scope of the original purpose of collection and the applicable legal basis for processing.

Another important question is whether the AI service processes the information on behalf of the company (data processing/outsourcing) or whether the AI provider uses the information for its own purposes (third-party provision).

It is also necessary to determine whether personal information is transferred to servers located outside Korea, as the PIPA establishes different legal requirements for:

  • Collection and use of personal information
  • Provision to third parties
  • Entrusted processing
  • Cross-border transfer of personal information

In other words, the mere fact that information was entered into an AI service does not determine which legal rules apply. The applicable legal framework depends on the contractual arrangement and the actual data processing structure.

Contracts and Consultation Materials Involve More Than Personal Information

Contracts and client consultation materials often contain far more than personal information.

They may also include confidential business information such as pricing terms, commercial strategies, technical information, and litigation or dispute response strategies.

Entering such materials into an external generative AI service may create risks including:

  • Breach of contractual confidentiality obligations
  • Disclosure of trade secrets or confidential business information
  • Violation of confidentiality agreements with clients
  • Breach of internal corporate policies
  • External transmission of materials prepared for litigation or regulatory investigations

Accordingly, a company's generative AI policy should address not only personal information but also trade secrets and other confidential business materials.

Internal Guidelines Companies Should Establish for Generative AI

If employees are left to decide independently how to use generative AI, companies may have little visibility into what information has been entered into external AI services.

Rather than simply instructing employees not to enter personal information, organizations should establish practical internal policies.

For example, a company may define:

  • Approved generative AI services and authorized accounts
  • Categories of prohibited personal information and confidential business information
  • Approval procedures for high-risk documents such as contracts and HR materials
  • Standards for removing or replacing identifying information, including names, contact details, and company names
  • Required settings regarding AI training and chat history retention
  • Internal reporting procedures for accidental disclosure or erroneous input

Instead of uploading an entire contract, employees should submit only the relevant provisions after replacing actual client information with fictional or anonymized information whenever possible.

Effective Governance Is More Important Than Simply Prohibiting AI

Generative AI can significantly improve efficiency in contract review and document drafting.

However, businesses should not use AI services without first understanding where client information and internal business data are stored and how they may be processed or used.

Companies should establish practical governance frameworks tailored to their operations, including approved AI services, prohibited categories of information, anonymization standards, and incident response procedures.

The Corporate Practice Team at Decent Law Firm provides comprehensive legal reviews of companies' generative AI usage, including the structure of personal information processing, AI service terms of use, cross-border data transfers, and internal AI governance policies.

#AI#Data#Personal Data#Client Information

logo© SkalePlus 2026
SkalePLUS Co., Ltd.Business Registration: # 162-86-02464E-Commerce Permit: 제 2024-서울강남-02254호
Address602 Yeongdong-daero, Gangnam-gu,
Seoul, 06083, Rep. of Korea
Phone+82 10-5139 1156
Emailsales@skaleplus.com
AboutPricingContact
ServicesInsightsEvents
Privacy PolicyTerms of ServiceMembership Terms of Service
Follow us:
linkedininstagramlinkedin