Chapter 04

Client Data Does Not Stop Being Sensitive When It Becomes a Prompt

“No model training” is not a complete confidentiality analysis.

A legal AI workflow can create multiple copies, embeddings, logs, summaries and derived inferences. Governance must follow the whole data lifecycle, not only the uploaded document.

Map the data path

For every tool, record the input categories, storage locations, transfer routes, subprocessors, access roles, retention periods, deletion method and whether data is used for product improvement. Include telemetry and generated output, not only source files.

Purpose and legal basis

Client instructions do not automatically authorise every form of personal-data processing. Purpose limitation and data minimisation should be assessed separately. Kazakhstan's updated personal-data framework limits processing to specific, predetermined and lawful purposes and restricts solely automated processing that changes rights or legal interests, subject to consent or statutory grounds.

Cross-border processing

Regional firms often use foreign cloud and model providers. That can engage national rules on cross-border transfer, localisation, confidentiality and government access. A contract with the visible vendor is insufficient if the technical chain includes model hosts, observability providers, vector databases or support systems.

Privilege is not the same as cybersecurity

Encryption and access control reduce security risk but do not by themselves preserve legal professional privilege. Firms should examine whether disclosure to a provider is necessary, contractually restricted, consistent with the applicable privilege doctrine and documented as part of legal service delivery.

Minimum controls

  • Prohibit consumer-grade tools for client-confidential information unless specifically approved.
  • Separate public, internal, confidential and highly restricted datasets.
  • Use matter-level access and least privilege.
  • Disable training and unnecessary retention where technically available.
  • Test deletion, export and incident-notification obligations.
  • Maintain a fallback process if the provider becomes unavailable or changes terms.
QuestionEvidence required
Where is data processed?Architecture and transfer map
Who can access it?Role matrix and subprocessor list
What survives deletion?Retention and backup statement; tested deletion
Can the system create new sensitive inferences?Output classification and logging policy
What happens after an incident?Notification timeline, evidence preservation and client response plan