AI in law firms: working with client data in a GDPR-compliant way
What exactly do § 203 StGB, the BRAO and the GDPR require?
Three layers apply to lawyers simultaneously:
- § 203 StGB (German Criminal Code) makes the unauthorised disclosure of private secrets a criminal offence — including disclosure to an AI provider. Since the 2017 reform, professionals bound by secrecy may engage service providers, but only to the extent that this is necessary and the provider has been bound to confidentiality.
- § 43e BRAO (Federal Lawyers' Act) sets out precisely that for lawyers: engaging external service providers requires an agreement in text form, a confidentiality undertaking from the provider, and formal instruction about the criminal-law consequences.
- The GDPR requires a legal basis for personal data in a matter (Art. 6), a data processing agreement (Art. 28), appropriate technical measures (Art. 32) — and, for transfers to third countries such as the USA, additional safeguards (Art. 44 et seq.). Infringements can be sanctioned under Art. 83 GDPR with up to €20 million or 4% of worldwide turnover; the German Data Protection Conference (DSK) set out its expectations for AI systems in its guidance on AI and data protection (2024).
In short: using AI is not the legal problem — where the data goes and what happens to it there is.
Why are public AI chatbots risky for client work?
With the consumer versions of the large US chatbots, the default is: inputs are stored and may be used to train the models unless you actively object. Processing regularly takes place outside the EU. US providers are also subject to the CLOUD Act, which gives US authorities access to data even when it sits on European servers — precisely the tension that led the CJEU to strike down the Privacy Shield in Schrems II (C-311/18). The Italian data protection authority temporarily blocked ChatGPT in 2023 — a foretaste of how supervisory authorities assess the issue.
For a law firm that means: copying pleadings or file extracts into a public chatbot discloses client secrets to a provider that is neither bound to confidentiality nor guarantees zero retention. The risk lies not in the technology but in the vendor model.
What can a law firm actually use AI for?
With a data protection compliant provider, assistance tasks are the productive ground today:
- Drafting pleadings and contracts — the AI supplies structure and a first version; substantive review remains the lawyer's task.
- Summarising large documents — condensing case bundles, expert opinions and long email threads to the essentials.
- Research preparation — structuring facts, collecting lines of argument. Important: always verify AI-generated citations. In the US case Mata v. Avianca (2023), lawyers were sanctioned for citing judgments invented by ChatGPT without checking them.
- Client communication — letters, explanations in plain language, translations.
- Internal organisation — structuring meeting notes, deadline checklists, knowledge documentation.
How PrivatAI meets the requirements
PrivatAI is built for exactly this scenario: inputs and responses are processed and discarded — not stored, not logged, never used for training. The application runs in Germany (Hetzner), the AI processing in France (Scaleway); matter data does not leave the EU. The professional-law side is covered contractually: a data processing agreement under Art. 28 GDPR with a professional-secrecy clause (§ 203 StGB, § 43e BRAO) and, on request, a separate undertaking on professional secrecy as an annex — including the instruction required by § 203 (4) StGB. For firms with elevated requirements there is an Enterprise setup with a contractual § 203 commitment across the entire processing chain and German inference hosting. The OpenAI-compatible API integrates PrivatAI into existing practice management software and workflows; for day-to-day work there is the browser chat.
Which plan covers what. Essential and Professional include the EU processing described above and the Art. 28 GDPR data processing agreement with its professional-secrecy clause — that clause binds PrivatAI. What the standard plans do not include is the § 203 obligation passed down across the entire sub-processor chain, AI inference in Germany, and assurances for seizure situations (§ 97 StPO). Those are part of the Enterprise setup only and are agreed separately. If your own risk assessment requires the whole chain to be bound, that is an Enterprise conversation rather than something the €30 or €60 plan settles.
PrivatAI supplies the technical and contractual prerequisites for a compliant setup. Whether a particular use is permissible under professional law in your specific case is a question for your Rechtsanwaltskammer or your own adviser — no provider can certify that on your behalf.
PrivatAI (privatai.com) — AI chat & API from Germany. No content logs, no training on your data, GDPR-compliant.
PrivatAI compared to US chatbots (default settings)
| Criterion | PrivatAI | Public US chatbots (default) |
|---|---|---|
| Storage of inputs | None — processed and discarded | Yes, conversations are stored |
| Training on your data | Never | Frequently by default (opt-out required) |
| Place of processing | Germany + France (EU) | Predominantly USA |
| CLOUD Act access | No (EU provider) | Possible |
| DPA (Art. 28 GDPR) | Yes (DPA) | Business plans only |
| Confidentiality § 43e BRAO | Yes (DPA § 10 + Annex 4); commitment across the full sub-processor chain with Enterprise | Unresolved |