MatterLayer / Field note

Security and privacy diligence

Can a law firm put client data into AI tools?

There is no responsible yes-or-no answer at product level. A firm must assess the particular client information, purpose, provider, contractual and technical controls, applicable obligations and matter-specific risk before approving a workflow.

01

Classify the information and purpose

Begin with what the proposed workflow actually sends. Client data may include personal information, sensitive information, confidential communications, privileged material, identity documents, commercial information or court material. The legal and professional treatment depends on the circumstances; these labels are not interchangeable. Record the minimum fields or documents required and ask whether the same outcome can be achieved with less information or without AI. For organisations subject to the Privacy Act, the APPs may regulate collection, use, disclosure and other handling of personal information. The OAIC recommends caution and due diligence for commercially available AI, including attention to necessity, intended use, access and human oversight. That analysis does not replace confidentiality, privilege, contractual or court requirements. The approving person should understand the actual matter context and not rely on a generic vendor category such as 'enterprise' or 'private'.

02

Interrogate the provider and service chain

Ask where data is processed and stored, who can access it, whether inputs or outputs are used to train models, how long they are retained and which subprocessors participate. Review authentication, tenant separation, encryption, logging, incident notification, deletion, export and support-access controls. Examine how terms can change and which commitments are contractual. Australian hosting may be relevant to a firm's risk decision, but it is not a universal legal requirement and does not by itself answer questions about remote access, ownership, subcontractors or lawful demands. Conversely, an offshore component is not automatically impermissible in every circumstance. The firm needs a documented, proportionate decision for the information and obligations at issue. Professional guidance in Victoria and Queensland gives practitioners further jurisdiction-specific prompts about public tools, confidentiality, terms, training use and provider access.

03

Apply shared responsibility in practice

A secure provider does not configure the firm's users, choose appropriate data or verify legal outputs. The Australian Signals Directorate's cloud shared-responsibility guidance explains that provider and customer responsibilities vary by service model and should be understood. Translate that into named controls: the provider may protect infrastructure, while the firm manages identity, authorised use, device security, data selection, matter permissions and response procedures. Test whether access follows real matter restrictions, including ethical walls and departed users. Decide which logs the firm will review and who owns incident triage. A cyber event, a policy exception and a notifiable data breach are different classifications; do not label every anomaly as a reportable breach without the required assessment. The operating plan should say who preserves evidence, who assesses impact and when legal, privacy, security or client teams are involved.

04

State the Pilot boundary so users can follow it

A safe Pilot does not say simply 'approved for client data'. It identifies the permitted matter cohort, data categories, workflow, users, provider configuration, retention setting and prohibited inputs. Start with the least sensitive data that can test the decision. Use read-only integration where possible, prevent the service from taking consequential action and place review before any output leaves the approved environment. Show the boundary at the point of use and train participants with examples of allowed and excluded material. Record deviations and stop if the control cannot be operated consistently. The Pilot should also test revocation and deletion. Success means the firm can explain what was processed, why, by whom, under which controls and with what review. It does not establish that every later client, matter or AI feature is approved.

Source file

Primary reading

  1. 01
    Guidance on privacy and the use of commercially available AI products

    Office of the Australian Information Commissioner

  2. 02
  3. 03
  4. 04
    Guidelines for procurement and outsourcing

    Australian Signals Directorate

Closed beta / October 2026

Test one decision with your own matter evidence.

MatterLayer starts with a bounded question, a clear data scope and a responsible reviewer. Source systems stay authoritative throughout the Pilot.