April 24, 2026
Confidentiality Across Jurisdictions: A Basic Awareness Firms Need
Confidentiality obligations are not identical everywhere, and neither are the answers to questions about where data is processed. A firm working across jurisdictions should know the basics before assuming one vendor agreement covers every client relationship.
Why location can matter
Different jurisdictions have different rules about cross-border data transfer, and some client engagements, particularly government-adjacent or regulated-industry work, carry specific contractual or regulatory requirements about where data can be processed and stored. A vendor's standard terms may not address a specific client's actual requirement.
The practical question to ask before onboarding a client matter
Does this specific client relationship carry any contractual or regulatory data-location requirement, and if so, does the AI tool's actual infrastructure meet it? This is a matter-by-matter question, not a one-time firm-wide policy decision, because client requirements vary.
Keeping this manageable
Most firm work does not carry unusual data-location requirements, and treating every matter as if it does would be needless overhead. The efficient approach is a short intake checklist that flags the minority of matters, regulated industries, government contracts, certain international clients, where this question needs a specific answer before any AI tool touches the matter.
A short example of why this is not hypothetical
A firm working with a government-adjacent client may find that client's own compliance requirements specify where data can be processed, independent of what any AI vendor's general terms say. Discovering this after a matter is already underway, rather than at intake, creates an awkward and sometimes costly scramble to either change tools mid-engagement or explain a compliance gap to the client. A five-minute intake question avoids the scramble entirely.
Building the intake question into an existing form
Rather than creating a new, separate step, add a single question to whatever intake or engagement-setup form a firm already uses: does this matter carry any specific data-location or processing requirement. Embedding the question into an existing, already-mandatory step is far more reliable than hoping staff remember to ask it separately, because it removes the chance of it simply being forgotten under deadline pressure.
Where this leaves a firm
None of this is complicated in principle, which is exactly why it gets skipped under deadline pressure. The question worth returning to before treating handling client data and AI risk with real discipline as settled is what a careful reader would actually notice if the firm got it right. On the point raised above under “why location can matter,” the answer is usually specific rather than clever: cross-border data-location rules and client-specific requirements can vary meaningfully by matter. Firms that build this expectation into how they train new associates find it easier to sustain once experienced staff move on, because the standard lives in a documented habit rather than in one person's memory. The gap between a firm that talks about handling client data and AI risk with real discipline and a firm that actually practices it shows up over several quarters, not in any single engagement, and it tends to show up most clearly in the small, unglamorous checks that a client never sees directly but benefits from anyway.
It also helps to name, plainly, who is responsible for keeping this working once the novelty of a new tool wears off. Someone should own the point raised under “the practical question to ask before onboarding a client matter,” check it periodically rather than assume it stays true on its own, and be the person a colleague asks when a new situation does not fit the pattern described here. Put simply: a short flagging checklist keeps this manageable without adding overhead to routine matters. That kind of ownership, named and specific, is a small addition to a firm's process, and it is usually the difference between a good idea that is followed for a month and a standard that actually holds up over a year of real client work.
None of this needs to be elaborate to be effective. A short, dated note in a shared file, reviewed at the next quarterly check-in, is usually enough to keep the responsibility from quietly disappearing when the person who first cared about it moves on to something else.
Key takeaways
- Cross-border data-location rules and client-specific requirements can vary meaningfully by matter.
- A vendor's standard terms do not automatically satisfy every client's specific requirement.
- Ask the data-location question at matter intake, not as a blanket firm-wide assumption.
- A short flagging checklist keeps this manageable without adding overhead to routine matters.