The problem is already in your office

Ask your team honestly. Who has pasted a contract into ChatGPT to summarise it? Who has uploaded a client's tax return to Claude to check it? Who has asked Copilot to translate a deed?

The answer is almost certainly more people than you think, and most of them on personal accounts, free or paid out of their own pocket, because the firm has not offered anything better. This is often called shadow AI: AI used for firm work, outside the firm's knowledge and control.

Staff do this because AI saves time, not because they are careless. The trouble is what follows:

  • Copies of client documents sit in accounts the firm does not manage, under consumer terms.
  • There is no record of which documents were sent, by whom, or when.
  • When that person leaves, the history leaves with them.

Why this is a PDP Law question, not just an IT one

Under Indonesia's PDP Law, your firm is usually the controller of your clients' personal data. Shadow AI runs straight into several of its obligations:

  • Article 31: the controller must record all processing activities. Processing in a staff member's personal account never reaches your records.
  • Article 37: the controller must oversee everyone involved in processing under its control, including staff and the services they use.
  • Article 34: an impact assessment is required for high-risk processing, which includes using new technology and processing specific data such as personal financial data.
  • Article 56: if data is processed outside Indonesia, the cross-border transfer conditions apply.

On top of that sit your own professional duty of confidentiality and the confidentiality clauses in your client agreements.

Banning AI outright rarely works; people carry on, just more quietly. The realistic approach is to provide a safe, official route and then close the unsafe ones.

This guide is general information, not legal advice.

Four things to check before AI touches a client document

1. Account type: consumer or business

This is the biggest difference. Consumer accounts, free or on a personal subscription, are governed by terms for individuals. Business and enterprise accounts are governed by commercial terms, usually with a data processing agreement, and the provider acts as a processor on your instructions.

2. Whether your data trains the model

On consumer accounts, data is often used for training by default unless you switch it off. On business accounts, it generally is not.

3. How long data is kept

Providers keep conversations and uploaded files for a set period, sometimes after you have deleted them from view. Ask for the number.

4. Where data is processed

Many global AI services process data outside Indonesia. Ask where. If it is abroad, Article 56 applies: you must make sure the recipient country offers equal or higher protection, or that adequate and binding safeguards are in place, or that the individual has consented.

What the three big providers say, as of September 2026

The summary below comes from each provider's official pages at the time of review. These policies change often, so check them again before you decide.

Service Consumer accounts Business or enterprise accounts
ChatGPT Free, Plus and Pro: used for training by default, can be switched off Business, Enterprise, Edu and API: not used for training by default
Claude Free, Pro and Max: the user chooses; if allowed, data is kept for up to five years Team, Enterprise and API: not used for training by default; Anthropic acts as processor for Team and Enterprise
Microsoft Copilot Personal Microsoft account: used for training by default, can be switched off; kept for 18 months Entra ID work account: not used to train foundation models; Microsoft acts as processor

A few details worth knowing:

  • ChatGPT. On a personal account, training is switched off under Settings, Data Controls, "Improve the model for everyone". According to OpenAI, even with it off, a conversation you rate with a thumbs up or down may still be used for training. Temporary Chat is not used for training but may be kept for up to 30 days. For business accounts, see OpenAI's enterprise privacy page. OpenAI also offers data residency in a number of countries for certain plans; check whether the country you need is listed.
  • Claude. Since the consumer terms changed in August 2025, Free, Pro and Max users choose whether their data may be used for training. Those who decline keep the 30-day retention period. For commercial products, Anthropic says it does not train on inputs or outputs by default, and it acts as processor for Team and Enterprise accounts.
  • Microsoft Copilot. According to Microsoft's privacy FAQ, Microsoft does not train Copilot on data from users signed in with an organisational Entra ID account. Work accounts are covered by enterprise data protection under Microsoft's data protection addendum.

The lesson: a business account settles the training question. It does not by itself settle where data goes, who may send which documents, or whether there is a record. The AI still receives whatever your staff paste or upload.

A short AI policy template

A good policy fits on one page. Adapt this one:

  1. Client documents may only be processed with AI services the firm provides: [name the services and plans]. Personal accounts may not be used for client documents.
  2. Every firm AI account is on a business or enterprise plan, or has model training switched off and checked by [name].
  3. AI may only read folders approved for AI. Everything else stays closed.
  4. NIK, NPWP, passport and bank account numbers must be masked before a document goes to an AI.
  5. Health data, children's data and criminal records are not sent to an AI without the responsible partner's approval.
  6. AI output is always reviewed by the responsible professional before it goes to a client, a court or the tax office.
  7. Every use of AI on client documents is recorded, and the record is kept for [period].
  8. A misdirected document or suspected leak is reported to [name] the same day.
  9. This policy is reviewed every six months.

Consider mentioning your use of AI in engagement letters too. Corporate clients increasingly ask.

What a controlled setup looks like

Permissions per folder, not just per person

An associate may be allowed to open every matter in their team; that does not mean the AI they use should be. A good setup lets you choose which folders an AI may read, separately from the person's own access, and never lets the AI reach further than the person who authorised it.

An access record you can show

When a client or an auditor asks "has AI read our documents?", you need an answer you can show, not a guess. A useful record says which documents were searched or read, by which connection, when, and which requests were refused.

Mask identifiers on the way out

Nearly every deed, lease and tax document names its parties by NIK or NPWP. Withholding all of those from AI means not using AI at all. The middle path is that the AI still reads the document but receives the identity numbers masked, for example ••••••••••••0001.

Accounts the firm controls

The firm pays and the firm administers. When someone leaves, access is removed in one place and the history stays with the firm.

Where folders.id fits

folders.id is built for this kind of setup:

  • Connect the AI your team already uses, then choose which folders it may read. Access to a folder includes its subfolders, and an AI connection can never reach further than the person who authorised it.
  • Every search, every document read and every refused request is recorded in the activity log.
  • NIK, NPWP, passport and bank account numbers are masked before they reach any AI, on by default. The AI can still read the deed; your team still sees the numbers as normal.
  • If you use folders.id's built-in AI, answers come only from documents you are allowed to open, each claim linked to the passage it came from.

One thing still holds: content you allow is sent to the AI provider that asked for it, and from then on that provider's policies apply. That is why the choice of account type above still matters.

Your staff are already using AI. The job now is to make sure they do it through a route you can see and control.