Back to all blog articles

THE LEDGER BLACK BLOG / FOR ADVISERS

Where Does Your Clients' Data Go When You Use AI?

Every time a financial adviser uses an AI tool with client information, that data takes a journey most advisers have never considered. With the NZ regulatory landscape tightening around offshore data and AI accountability, it is time to start asking where that journey ends.

AI Privacy · Data Sovereignty · Financial Advisers · New Zealand · Privacy Act 2020 · FMA Compliance

The Scenario Every Adviser Recognises

You finish a client meeting. You recorded it. Good practice. You run the recording through an AI tool to get a summary. The summary mentions your client has a history of depression, earns $185,000, has an existing AIA policy, and their partner is pregnant with their second child.

That summary is useful. It saves you an hour of note taking. But there is a question worth pausing on.

Where did all of that just go?

For most advisers, the honest answer is: you don't know. The audio likely went to a server in the United States. The transcription was processed by an American AI company. The summary containing your client's medical history, financial position, and deeply personal circumstances passed through infrastructure governed by US law, not New Zealand law.

And under most AI providers' terms of service, that data may be retained, logged, or used to improve their models.

You would never post your client's medical history on social media. But the data journey you just triggered may not be all that different in terms of who can potentially access it.

This is not about fear. It is about understanding a risk that the industry has largely ignored because the tools made it easy and nobody raised the question.

Until now.

What Is Actually Changing

The regulatory landscape in New Zealand is shifting, and the pace is accelerating.

The Privacy Act 2020 and Offshore Disclosure

The Privacy Act 2020 has always required care around offshore data disclosure. Information Privacy Principle 12 sets conditions on when personal information can be disclosed to overseas recipients. The disclosing party must have reasonable grounds to believe the overseas recipient will protect the information in a manner consistent with New Zealand's Information Privacy Principles.

For many years, this was treated as a box ticking exercise. A data processing agreement with a US cloud provider was considered sufficient. But the enforcement environment in 2026 is different. The Office of the Privacy Commissioner is increasingly focused on how organisations handle personal information in the context of AI and automated decision making. The question is no longer just "is your data encrypted in transit?" It is "where does it go, who processes it, under whose laws, and can you prove the recipient provides comparable protection?"

When the AI provider is a US company subject to the CLOUD Act, which allows US government agencies to compel disclosure of data held by US companies regardless of where the data is stored, the "reasonable belief" threshold becomes significantly harder to satisfy.

FMA Cyber Resilience

The Financial Markets Authority has been steadily raising expectations around how licensed financial advice providers manage technology risk. The FMA's cyber resilience guidance makes it clear that technology governance is not a separate concern from advice governance. It is the same thing.

For advisers and FAPs, this means understanding and being able to articulate the risks associated with your technology stack. "We use an overseas CRM and public AI tools" was an unremarkable answer two years ago. It is becoming increasingly difficult to defend when a regulator asks you to describe your data governance framework and how you manage the risk of client information being processed offshore.

The Global Direction

This is not unique to New Zealand. Australia's Privacy Act reform is moving in the same direction. The EU AI Act is already in force and sets explicit requirements around transparency, accountability, and data governance for AI systems. The global trend is toward data localisation and AI accountability.

New Zealand tends to follow these trends. The only question is how quickly the enforcement environment catches up. The advisers who are prepared before it does will have a genuine advantage over those scrambling to react.

What the Industry Is Actually Doing

Let's be honest about current practice in the New Zealand financial advice sector.

Advisers paste client fact finds into ChatGPT to help draft Statements of Advice. Client meeting recordings are transcribed by offshore AI services. CRM platforms store client data in US or EU data centres and call it "secure" because the connection is encrypted. AI meeting assistants join calls and send full audio to servers in jurisdictions the adviser has never thought about.

None of this makes advisers bad people. The tools made it easy. Nobody flagged the risk. And until recently, nobody was asking the hard questions about where the data actually ends up.

But those questions are now being asked. By regulators, by compliance teams, and increasingly by clients who are paying attention to how their information is handled in an age of AI.

"I didn't think about it" has never been an acceptable answer to a regulator. And it is becoming an even less acceptable answer when the tools exist to do it properly.

The Data Journey Most Advisers Have Never Seen

To make this concrete, here is the typical data journey when an adviser uses a mainstream AI tool with client information.

Step 1. The adviser enters client data into the AI tool, either by pasting text, uploading a document, or connecting a meeting recording.

Step 2. That data leaves the adviser's device and travels to the AI provider's servers. For most providers, these servers are in the United States.

Step 3. The AI model processes the data. This typically involves the full content being sent through the provider's infrastructure, potentially across multiple services and data centres.

Step 4. The AI generates a response. The original data may be logged, cached, or retained for quality assurance and model improvement, depending on the provider's terms.

Step 5. The response is sent back to the adviser.

At no point in this journey was the data within New Zealand jurisdiction. At no point was the data subject to New Zealand privacy law. And at no point did the adviser have visibility into what happened to the data between Step 2 and Step 5.

Now consider what that data might contain. Medical history. Mental health conditions. Income and debt levels. Tax identifiers. Insurance policy details. Family circumstances. GP reports.

This is not metadata. This is the most confidential information a client will ever share with a professional. And for many advisers, it is routinely leaving the country without a second thought.

Five Questions to Ask Your Technology Provider

Regardless of which platform or tools you use, every financial adviser and practice owner in New Zealand should be asking their technology providers these five questions before the regulatory landscape tightens further.

1. Where is my client data stored at rest?

Which country? Which jurisdiction's laws govern access to it? "The cloud" is not an answer. A specific location and jurisdiction is.

2. When I use your AI features, where does the data go for processing?

Which company processes it? In which country? Is the data retained after processing? Under what terms?

3. Is sensitive information treated differently from general queries?

Does your platform distinguish between a question about policy wording and one that includes a client's medical history, tax identifier, or financial position? Or does everything go through the same pipeline regardless of sensitivity?

4. Can you provide an audit trail of AI interactions involving client data?

If the FMA asked you to demonstrate your data governance around AI, could you produce a log showing what data was processed, when, by which provider, and what protections were applied? Or would the answer be silence?

5. Are you subject to the US CLOUD Act or equivalent foreign data access legislation?

If a foreign government issued a lawful demand for data held by your technology provider, would New Zealand law protect your clients? Or would the provider be legally compelled to hand it over regardless of where the data originated?

If your provider cannot answer all five of these questions clearly, that is worth understanding now. Not after an FMA review. Not after a client complaint. Not after a data breach makes the news. Now.

The Standard the Profession Deserves

The financial advice profession in New Zealand is built on trust. Clients share their most sensitive personal, financial, and medical information with their adviser because they believe it will be handled with care.

That trust should extend to the technology the adviser uses.

The current state of the industry, where client data routinely leaves the country for AI processing without the adviser's full understanding of the journey, is not a technology problem. It is a governance problem. And it is one that the regulatory environment is rapidly moving to address.

The advisers and practice owners who recognise this early and take steps to understand and manage their data governance will be in a significantly stronger position than those who wait for a regulator or a client to force the conversation.

This is not about abandoning AI. Intelligent automation is transforming the advice process for the better, reducing admin, improving documentation, and freeing advisers to spend more time with their clients. The question is not whether to use AI. The question is whether to use it responsibly.

At Ledger Black, we believe that client data sovereignty, AI accountability, and regulatory readiness should be foundational to any platform serving New Zealand financial advisers. Not a premium feature. Not a future roadmap item. The foundation everything else is built on.

We would welcome the opportunity to show you how we approach these challenges. But regardless of which platform you use, we encourage every adviser in New Zealand to start asking these questions today.

The profession deserves better than the status quo. And the regulatory environment is about to demand it.

Frequently Asked Questions

Do NZ financial advisers need to worry about AI and client data privacy?

Yes. Every time an adviser uses an AI tool with client information, that data is typically sent to servers outside New Zealand for processing. Under the Privacy Act 2020 and its Information Privacy Principles around offshore data disclosure, advisers and their FAPs have obligations regarding where personal information is sent and how it is protected. With the FMA's increasing focus on cyber resilience, AI data governance is becoming a compliance question, not just a technology one.

Is it safe to use ChatGPT or other AI tools with client financial information?

Most public AI tools process data on servers in the United States. When an adviser pastes client details into these tools, that information leaves New Zealand jurisdiction and may be subject to the US CLOUD Act or other foreign data access legislation. The data may also be retained or used to improve the AI provider's models. Advisers should understand the data journey before using any AI tool with confidential client information.

What does the NZ Privacy Act 2020 say about sending data offshore for AI processing?

Information Privacy Principle 12 of the Privacy Act 2020 governs the disclosure of personal information to overseas recipients. It requires that the disclosing party has reasonable grounds to believe the overseas recipient will protect the information in a manner consistent with NZ privacy standards. For AI providers based in jurisdictions subject to foreign government data access laws, establishing this reasonable belief is increasingly difficult.

What should financial advisers ask their technology providers about AI and data?

Advisers should ask five key questions: Where is client data stored at rest and under which jurisdiction? Where does data go when AI features are used and which company processes it? Is sensitive information like medical history and tax identifiers treated differently from general queries? Can the provider produce an audit trail of AI interactions involving client data? And is the provider subject to the US CLOUD Act or equivalent foreign data access legislation?

What are the FMA's expectations around AI and cyber resilience for financial advisers?

The FMA's guidance on cyber resilience sets expectations for how licensed financial advice providers manage technology risk, including the use of AI tools. Advisers and FAPs are expected to understand and manage the risks associated with their technology stack, including where data is processed and stored. Relying on offshore AI tools without understanding the data governance implications is an area of increasing regulatory scrutiny.