Local AI for law firms: what Section 203 StGB and Section 43e BRAO allow
· 6 minute read
Law firms want to use AI to review files faster, check contracts and prepare briefs. The first question is almost always the same: may client data go into an AI system at all? The answer depends on where the AI runs. With cloud AI the provider must be bound to confidentiality under Section 43e BRAO, with local AI on your own premises no third party gets access. This guide explains what German professional law requires in detail.
What Section 203 StGB covers
Section 203 of the German Criminal Code (StGB) makes the violation of private secrets a criminal offence. It applies to professionals bound by secrecy, including lawyers, tax advisers, auditors and doctors. Anyone who discloses a secret entrusted to them in that capacity without authorisation faces up to one year in prison or a fine.
Disclosure does not only mean deliberately passing on information. Giving a third party the opportunity to learn the secret is enough. Uploading client files to a cloud service gives the provider exactly that opportunity.
Since 2017 service providers may be involved, under conditions
For a long time it was unclear whether law firms could involve external IT providers at all. The 2017 reform amended Section 203 (3) StGB: professionals bound by secrecy may disclose secrets to persons who contribute to their professional work, to the extent this is necessary for that work. This includes IT and cloud providers and therefore AI services.
The flip side is in Section 203 (4) StGB: anyone who fails to ensure that the contributing person has been bound to secrecy is also liable. For lawyers, Section 43e of the Federal Lawyers' Act (BRAO) spells out what this means in practice. For tax advisers Section 62a StBerG applies, for auditors Section 50a WPO.
What Section 43e BRAO requires of law firms
A firm that engages a provider with access to client secrets must above all ensure the following:
- The provider is selected with care.
- A contract in text form binds it to confidentiality and informs it of the criminal consequences of a breach.
- It may only learn as much as its service requires.
- It may only involve subcontractors if they are bound to confidentiality as well.
- For services abroad, the protection of secrets there must be comparable to the protection in Germany.
- If the service directly serves a single client matter, the client's consent is also required.
The GDPR adds to this: a data processing agreement under Art. 28 GDPR and, for providers outside the EU, an assessment of the third-country transfer.
Why cloud AI is difficult for law firms
With large AI vendors these duties hit practical limits. Standard contracts rarely include a confidentiality obligation under Section 43e BRAO, and small and mid-sized firms can hardly negotiate individual contracts. Many vendors are based in the US or use subcontractors there. Under the CLOUD Act, US authorities can also access data that US providers store in European data centers.
Then there is the question of what happens to the inputs: whether they are stored, reviewed by humans or used for training. The firm has to clarify and document each of these questions for every service.
Local AI: the data stays in the firm
Local AI runs on the firm's own hardware, for example on an AI server in the server room. Documents, queries and answers never leave the network. There is no AI vendor that could learn of client data, and therefore no provider that must be bound under Section 43e BRAO for the AI.
It still does not work entirely without an assessment. A firm that grants the hardware supplier remote access for maintenance involves a provider again, and the duties under Section 43e BRAO apply to that access. With an appliance without remote access the question does not arise.
The Sinabox is built for exactly this case: a preconfigured AI server that works without an internet connection after setup. Remote access by Sinabis only exists if the firm explicitly sets it up.
Checklist for using AI in a law firm
- Where are documents and queries processed: on your premises, in the EU or outside it?
- Does the provider have access to content, and is it bound to confidentiality under Section 43e BRAO?
- Is there a data processing agreement under Art. 28 GDPR?
- Are inputs stored or used for training?
- Which subcontractors are involved, and where are they based?
- Is it documented which client matters are handled with which system?
With local AI and no remote access, the first five questions have a one-sentence answer: the data does not leave the firm.
This guide gives an overview of the legal situation in Germany and does not replace legal advice in an individual case.