Skip to content

Freelancers and clients · Business essentials

Protecting Client Information in Freelance Work

Client information should move through a deliberate lifecycle: identify what is needed, collect less, share securely, restrict access, monitor changes, respond to incidents, and remove or retain records for a documented reason.

Freelancer and client responsibilitiesFTC-informed practicesAI permission and redaction boundary

01

Inventory information and minimize collection

The FTC emphasizes knowing what information a business has and keeping only what it needs. Begin with the project purpose, not with a request for every available file.

U.S. federal orientation

Client-information inventory questions
QuestionFreelancer actionClient action
What is needed?Request the minimum fields, files, examples, or system access required for the agreed work.Remove unrelated customer, employee, financial, health, credential, or confidential data before sharing.
Why is it needed?Tie each category to a deliverable, test, decision, or support obligation.Confirm the purpose and reject convenience-only collection.
Where will it go?Name approved devices, services, folders, subcontractors, and AI boundaries.Approve the channel and verify contractual or regulatory restrictions.
How long is it needed?Propose a review, return, deletion, or retention point.Identify legal, operational, dispute, or records reasons that control disposition.

02

Secure information in transit and storage

Email and casual messages may be convenient but inappropriate for credentials, regulated data, large confidential collections, or sensitive payment and identity records.

General practice

  • Agree which service handles files, formal decisions, access invitations, secrets, backups, and incident notices.
  • Use encryption and secure transfer appropriate to the sensitivity and applicable obligations.
  • Restrict folders and links to named people, disable unnecessary public access, and set expiration where supported.
  • Keep work devices and software updated, protected, and separated from untrusted users or applications.
  • Back up essential project and business records and test that authorized recovery works.
  • Verify unusual file, access, or payment requests through a second known channel before acting.

03

Use individual accounts and least privilege

Give each person only the access needed for the current work and only for as long as needed. A shared password hides accountability and makes close-out harder.

U.S. federal orientation

  • Create named accounts instead of sharing an owner's or employee's login where the system permits.
  • Use a secure invitation or secret-sharing method; never paste passwords, recovery codes, private keys, or one-time codes into ordinary project or AI messages.
  • Require multi-factor authentication where available, especially for email, administrative, financial, source-code, hosting, and customer systems.
  • Choose the lowest role that supports the task and separate production, billing, identity, and security administration where practical.
  • Maintain an access record with system, person, role, approval, date granted, change, and removal confirmation.

04

Do not supply client information to AI by default

Permission to use information for a project does not automatically authorize supplying it to a separate AI provider or using it for another purpose.

General practice

  • Check the agreement, confidentiality terms, client policies, privacy requirements, professional duties, and tool settings before using any AI service.
  • Ask for client authorization when the intended AI use is not already clearly permitted and necessary.
  • Prefer a fictional example, abstracted structure, or minimal redacted excerpt over a full document or dataset.
  • Remove names, contact details, identifiers, credentials, account data, customer records, private code, and unrelated confidential context.
  • Review output for inaccurate disclosure, hidden sensitive detail, unsafe instructions, and material that should not enter the project record.

Understand Lucy's specific boundary before entering project material.

  • PrivacyReview the site's current description of information handling and limitations.
  • How Lucy worksSee the request flow, appropriate uses, redaction guidance, and human decision boundary.

05

Agree retention, deletion, return, and handoff

Do not keep every copy forever or promise immediate destruction without checking legal, contract, backup, dispute, insurance, and operational needs.

General practice

Information disposition decisions
DecisionQuestions to resolveClose-out evidence
ReturnWhich originals, exports, keys, repositories, accounts, and physical items return to the client?Itemized transfer and receipt confirmation.
Client ownershipWhich accounts, domains, subscriptions, files, and licenses must be in the client's control?Owner and administrator verification.
RetentionWhich records remain, for what documented purpose, with what protection and review point?Retention category and next review.
DeletionWhich working copies, downloads, temporary files, backups, devices, and vendor copies can be securely removed?Deletion scope, method, exceptions, and confirmation.
Access removalWhich user, token, key, device, integration, and recovery route must be removed or rotated?Access checklist and client verification.

06

Know how to contain and escalate an information incident

A lost device, mistaken recipient, exposed link, reused password, malware alert, compromised vendor, or unauthorized AI upload may require fast containment and qualified assessment.

State and local follow-up

  • Stop ongoing exposure when safe: revoke links or sessions, disable affected access, isolate devices, rotate secrets, and preserve evidence.
  • Notify the named client and internal incident contact using the agreed route; do not conceal, speculate publicly, or make unsupported assurances.
  • Record what happened, information and systems involved, people affected, timing, containment actions, and unresolved questions.
  • Check contractual notice, cyber-insurance, legal, regulatory, professional, law-enforcement, and affected-person obligations promptly with qualified help.
  • Recover from trusted backups or clean systems, validate the fix, monitor for recurrence, and update access and process controls.

Source register

Official starting points for this guide

Reviewed September 22, 2026. These are federal starting points, not a substitute for state, local, profession-specific, contract, or current-year review.

Keep going

Freelancer pathway

Build a clear freelance process

Connect business administration with service definition, discovery, agreements, delivery, invoicing, and close-out.

Client pathway

Prepare and manage a freelance hire

Connect vendor administration with a usable brief, fair selection, project management, acceptance, and handoff.

Client administration

Hire and onboard freelancers

Build classification, tax-document, payment, records, access, and offboarding checks into the client process.

Project close-out

Use the final delivery checklist

Confirm deliverables, ownership, credentials, documentation, approval, payment, and access removal.