Skip to content
Back to Setup Guides
Essential

Safe Setup Guide: ChatGPT for Legal Work

How to configure ChatGPT before using it for legal work in England and Wales: training and memory settings, what not to paste, and how to check output

Setup time: 10 minutes
By Rory CollinsLast updated: 29 September 2026

Privacy & Professional Conduct Notice

This guide helps you configure ChatGPT safely, but you remain responsible for complying with the SRA Standards and Regulations. Never input confidential client information without proper safeguards.

Overview

ChatGPT is made by OpenAI. On a personal plan, OpenAI may use your conversations to train its models unless you turn that off. On a Business or Enterprise workspace it does not, by default. This guide covers the settings to change, what to keep out of the tool, and how to check what it produces.

Every vendor fact below was checked against OpenAI's own pages on 29 September 2026. The pages are listed under "Sources checked" at the end of this guide. Settings and prices change, so follow the links before you rely on them.

Setup time: about 10 minutes Suitable for: sole practitioners and firms of any size, within the limits set out below


Plans and prices

PlanPrice OpenAI publishesNotes
FreeNo chargePersonal plan
Plus$20 a monthPersonal plan. OpenAI's help centre gives the price in US dollars. No annual billing
BusinessStandard seat: $25 per user a month billed monthly, or $20 billed annuallyMinimum of two seats. Formerly called ChatGPT Team
EnterpriseNot captured on the pages checkedSold through OpenAI's sales team

Pounds. Viewed from the UK on 29 September 2026, OpenAI's business pricing page showed £15 a month for a Business Standard seat and £75 a month for a Premium seat, above a line giving the US dollar prices. The page did not say whether the pound figure is the annual or monthly rate, or whether it includes VAT. Confirm the amount at checkout. No pound price for Plus could be confirmed.


What OpenAI says about your data

Free, Go, Plus, Pro (personal)BusinessEnterprise
Used to train modelsYes, while "Improve the model for everyone" is onNot by defaultNot by default
Deleted conversationsNot stated on the pages checkedRemoved within 30 days, unless longer retention is required by law or to protect the serviceRemoved within 30 days, unless OpenAI is legally required to keep them
Retention periodChats stay in history until you delete themWorkspace admins can control itWorkspace admins control it
Who at your firm can see chatsNot applicable: there is no workspaceWorkspace admins can view, export and delete members' conversationsAdmins can reach an audit log through the Enterprise Compliance API
Data processing addendumNot mentioned on the pages checkedAvailableAvailable
Storage in the UKNot statedNot listed as eligibleAvailable to eligible new workspaces

Two points that are easy to miss:

  • Feedback overrides the opt-out. OpenAI's help page says that if you press thumbs up or thumbs down on a response, the whole conversation may be used for training, even after you have opted out.
  • UK data residency covers storage only. OpenAI lists the United Kingdom as a region for storing content at rest. Its separate commitment to run the model in-region ("inference residency") is listed for Europe, the United States and the United Arab Emirates, and not for the UK. Workspace names, billing information and user logins may be stored outside the chosen region.

Step 1: Use a work account

  1. Create the account with your work email address, not a personal one.
  2. Keep client work out of any personal ChatGPT account.

If your firm has a Business or Enterprise workspace, use that and skip to Step 3. The workspace settings are controlled by your administrator.


Step 2: Turn off model training (personal plans)

On the web, signed in:

  1. Open your account menu.
  2. Select Settings.
  3. Select Data controls.
  4. Select Improve the model for everyone, turn it off, and select Done.

On iOS and Android: open the sidebar, select your profile icon to open Settings, select Data controls, and turn off Improve the model for everyone.

OpenAI says the setting applies to your account across devices when you are signed in, and that new conversations will not be used for training once it is off. It does not delete or hide existing chats.

Do not press the thumbs up or thumbs down buttons on a conversation you would not want used for training.


Step 3: Turn on multi-factor authentication

  1. Go to ChatGPT Settings.
  2. Select Security and login.
  3. Under Multi-factor authentication (MFA), choose a method and follow the setup steps.

OpenAI's help page says administrators cannot currently enforce MFA across a ChatGPT workspace, so each person has to turn it on.


Step 4: Decide what to do about Memory

Memory lets ChatGPT carry details from one conversation into another. For legal work that creates a risk of information from one matter appearing in another.

  1. Open Settings.
  2. Select Personalization.
  3. Select Memory.

Menu names in this guide are given in OpenAI's spelling.

OpenAI says the controls you see vary by plan, region and workspace. They may include Reference saved memories and Reference chat history. Turning Memory off does not delete past chats. Deleting a chat does not necessarily delete a saved memory created from it, so delete both.

In a workspace, owners and admins can manage memory settings for members.


Step 5: Use Temporary Chat for anything you do not want kept

OpenAI says a temporary chat:

  • does not appear in your chat history
  • does not create or update memories
  • is not used to improve OpenAI's models
  • may be retained for up to 30 days for safety purposes

Before the chat begins you can choose whether it uses your existing memories and custom instructions. A temporary chat is still sent to OpenAI and may be held for 30 days, so it is not a way to make confidential material safe to paste.


Step 6: Set custom instructions

On web and desktop: in Settings, select Personalization, make sure Enable customization is on, and enter your instructions in the Custom Instructions field.

OpenAI says information from custom instructions is also used to improve model performance unless you have opted out (Step 2). Do not put a client's name or matter details in them.

A starting point you can adapt:

I am a solicitor practising in England and Wales in [PRACTICE AREA].

- Apply the law of England and Wales unless I say otherwise.
- Never invent a case, statute, rule number or quotation.
- If you are not certain an authority exists, say so and mark it "UNVERIFIED".
- Cite cases with their neutral citation where there is one.
- Ask me a question if my instructions are unclear.
- Set out counter-arguments as well as the argument I asked for.

An instruction not to invent authorities reduces the problem. It does not remove it. You still check every authority (see below).


Your professional duties

This section summarises published rules and guidance. It is not legal advice, and it has not yet been reviewed by a solicitor.

  • Confidentiality. Paragraph 6.3 of the SRA Code of Conduct for Solicitors, RELs, RFLs and RSLs requires you to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.
  • Competence. Paragraph 3.2 requires the service you provide to be competent, and paragraph 3.3 requires you to keep your professional knowledge and skills up to date.
  • Supervision. Under paragraph 3.5, where you supervise or manage others you remain accountable for the work carried out through them.
  • Not misleading anyone. Paragraph 1.4 says you do not mislead or attempt to mislead your clients, the court or others.
  • Responsibility for output. The SRA's Risk Outlook report on AI (20 November 2023) says you "remain responsible and accountable for the outputs from AI you are using".
  • Law Society guidance. "Generative AI – the essentials" says that if you are using a free, online generative AI service where you have no operational relationship with the vendor other than use, you should not put any confidential data into the tool. It also advises carrying out due diligence on the supplier, and being able to say where data is processed, who processes it, how and where it is stored, and who has access to it.
  • Data protection. Where a prompt contains personal data, the UK GDPR and the Data Protection Act 2018 are relevant. The Information Commissioner's Office says a restricted transfer of personal data outside the UK must be covered by UK adequacy regulations, appropriate safeguards or an exception. OpenAI's pages do not say where personal-plan content is stored.

Follow your firm's own AI and information security policy where it is stricter than this guide.


What not to put into ChatGPT

On a personal plan, treat ChatGPT as a tool with which you have no contract beyond its terms of use. Do not enter:

  • client names, or facts that would identify a client or matter
  • privileged communications or advice
  • personal data about anyone, including health information and financial details
  • National Insurance numbers, passport numbers or bank account details
  • the terms of a confidential settlement
  • anything covered by a confidentiality agreement or undertaking

Use placeholders instead:

  • Identifying: "Jane Smith issued a claim against XYZ Ltd on 15 March 2026 for breach of a supply agreement"
  • Safer: "A claimant has issued a breach of contract claim against a technology company"

On a Business or Enterprise workspace, what may go in is a decision for your firm, made after due diligence on the contract and the data processing addendum.


Checking output

ChatGPT can produce authorities that do not exist and misstate ones that do. Before relying on anything it produces:

  • Cases: find every case in a law report or on a service such as Westlaw UK, Lexis+ UK, BAILII or The National Archives' Find Case Law, and read it
  • Legislation: check the text and whether it is in force, for example on legislation.gov.uk
  • Jurisdiction: confirm the law is that of England and Wales, not Scotland, Northern Ireland or another country
  • Quotations: check every quotation against the source
  • Dates, names and figures: check each against your own documents
  • Currency: confirm the authority has not been overruled, amended or repealed

The Law Society's guidance says that for documents going to court you must review final versions to make sure all citations are verified, and that the court expects to impose severe sanctions for the misuse of AI in legal research or court documents other than in exceptional circumstances.

Asking ChatGPT whether a case is real is not a check. The SRA's report says not to trust an AI system to judge its own accuracy.


If client information goes in by mistake

  1. Delete the conversation, and any saved memory created from it.
  2. Tell the person your firm's policy names, usually the compliance officer for legal practice (COLP) or the data protection lead.
  3. Record what was entered, when, and on which plan.

The ICO says a notifiable personal data breach must be reported to it without undue delay and not later than 72 hours after you become aware of it. Whether an incident is notifiable is for your firm to assess. Paragraph 7.11 of the SRA Code requires you to be honest and open with clients if things go wrong.


Quick checklist

Before first use

  • Account created with a work email address
  • "Improve the model for everyone" turned off (personal plans)
  • Multi-factor authentication turned on
  • Memory reviewed and turned off, or limited
  • Custom instructions set, with no client details in them
  • Your firm's AI policy read

Every conversation

  • No client names, identifying facts or personal data
  • No thumbs up or thumbs down on sensitive conversations
  • Every authority checked against its source
  • Conversation deleted when no longer needed

Sources checked

All read on 29 September 2026.

OpenAI

Rules and guidance


Need help?

If you have a question about this guide, or find that a setting has moved, contact hello@counsel.directory.

Review status: this guide has not yet been reviewed by a solicitor.


Disclaimer: This guide is general information about configuring a software product. It is not legal advice and it is not advice on your professional obligations. You remain responsible for complying with the SRA Standards and Regulations, data protection law and your firm's policies. Check with your firm's compliance and IT teams before using a new tool for client work.

Tags

chatgptsetupprivacysecuritybeginner
Quick Reference
Tool
ChatGPT
Setup Time
10 minutes
Trains on Data
No (if configured)
Data Residency
UK storage on Enterprise only; not stated for other plans
Enterprise Option
Available
Priority
Essential