Skip to content
biwak

Guides

Law & privacy

May a law firm use an AI tool?

Professional secrecy and AI: what § 203 StGB, § 43e BRAO and § 39c PAO require, what BRAK, DAV, epi and DPMA say, and how to check the processing chain.

Responsible:

Published

Updated 13 min read

Two assessments, not one

The most common mistake in law firms is to treat the question as a data protection question. Data protection is one assessment: legal basis, processing on behalf, third-country transfer, deletion. Professional secrecy is the other, and it is stricter, because it is backed by criminal law and turns not on a balancing of interests but on access.

A provider can meet every data protection commitment, such as no retention, no training, a European region, and still fail the professional-law assessment. And vice versa.

What the law requires

  • § 203(3) and (4) StGB permits secrets to be disclosed to other persons involved in the work, insofar as this is necessary for their activity. An offence is committed by anyone who fails to ensure that such a person has been bound to secrecy, if that person then discloses the secret without authorisation.
  • § 43e BRAO governs the use of service providers: a contract in text form with a confidentiality obligation and instruction on the consequences under criminal law (para. 3), comparable protection of secrets for services provided abroad (para. 4), and the client's consent if the service directly serves a single client matter (para. 5).
  • § 39c PAO for patent attorneys and § 62a StBerG (German Tax Advisers Act) for tax advisers are structured the same way.
  • § 31 PatG (German Patent Act) governs inspection of files. Under para. 2, inspection is open to anyone if the applicant consents and has named the inventor, or if eighteen months have passed since the filing or priority date and the notice under § 32(5) has been published. Until then, the content of an application is not public.
The service provider provisions compared
LawyersPatent attorneysTax advisers
Provision§ 43e BRAO§ 39c PAO§ 62a StBerG
Contract in text formPara. 3: confidentiality with instruction, knowledge only as far as necessary, rule for further personsPara. 3, identical wordingPara. 3, identical wording
Services abroadPara. 4: only with comparable protection of secretsPara. 4, identical wordingPara. 4, identical wording
Service for a single client matterPara. 5: only with the client's consentPara. 5, identical wordingPara. 5, identical wording

The sentence that matters

“It is sufficient … that they have the possibility to do so.”
BRAK, Guidance on the use of artificial intelligence, as of December 2024, p. 4

This refers to AI providers: for access to client secrets, it does not matter whether they actually read anything. That removes the most popular line of defence. “The provider doesn't even look at it” is no answer to the question of whether it could. Commitments such as no retention, no training or an access log do not change the access; they promise not to use it.

A practical consequence that is easily overlooked: as soon as remote maintenance, screen sharing or content-related telemetry comes into play, the possibility of access arises after all, and it does so with the first support case. A tool whose maker has to “take a quick look” when something goes wrong is a person involved in your work, on call.

What the Bar and professional associations say

The BRAK recommends choosing providers with servers in Germany or Europe where possible, because it has not been settled whether the protection offered by foreign providers satisfies § 43e(4) BRAO. It considers transmitting client secrets to language models such as ChatGPT unnecessary at the state of the art at the time, at least for freely accessible models, because the tools can also be used without them; in its view, merely removing names and addresses is usually not enough if client information can be inferred from the context.

“If there is doubt that confidentiality will be maintained … the AI model in question should not be used.”
epi, Guidelines on the use of generative AI, adopted by the Council on 16 November 2024, guideline 2a

Under guideline 4, epi members clarify the client's wishes before using generative AI; the explanatory note recommends recording the request and the response. Guideline 8 allows the set-up of and training on AI tools, their subscription fees and the review of AI-generated work to be charged at a level that appropriately reflects difficulty and scope.

On 23 February 2026, the Federal Association of German Patent Attorneys urged caution when data goes to externally hosted AI systems: if it becomes public, it destroys the novelty of the application, and anonymisation is not enough because the technical core of the invention is the secret. It recommends an agreement with the provider covering professionals bound by confidentiality, an agreement without data retention, and the exclusion of training; for anyone for whom that is not enough, there are local models. Biwak does not run a local model; the tools run on your computer, while the model computes at the provider.

Where the DAV weighs things differently from the BRAK

In its own-initiative statement no. 32/2025 of July 2025, the German Bar Association (DAV) considers the use of AI and cloud services permissible under professional law, subject to conditions. On access, it agrees with the BRAK at the outset: the mere possibility of gaining knowledge is also access. But it draws a different conclusion. In its view, the fact that data is temporarily decrypted at the provider for processing, or viewed during maintenance under strict organisational rules, is “necessary” within the meaning of § 43e(1) BRAO and § 203(3) StGB and therefore permitted. It rejects an obligation to use encryption that makes any access by the provider impossible if this would make the service practically unusable. The firm must nevertheless limit what the provider can learn to what is necessary, using reasonable measures. According to the DAV, the client's consent under § 43e(5) BRAO is only needed if a tool directly serves a single client matter, not for one used generally across the firm.

BRAK and DAV compared, based on their publications of December 2024 and July 2025
QuestionBRAKDAV
Client secrets in a language modelNot necessary at the state of the art at the time, at least for freely accessible modelsNecessary and unobjectionable for externally operated AI systems, for example for briefs in mass proceedings
Providers abroad (§ 43e(4))Choose servers in Germany or Europe where possible; open whether foreign protection is sufficientComparable protection assumed in EU states; otherwise judged by data protection standards
Anonymising before inputAnonymise or encrypt if possible; removing names and addresses is usually not enoughHelps, but is not mandatory if the processing can be based on a legal basis under the GDPR
Informing clients about AIIn principle no professional obligation; openness and, in case of doubt, a contractual provision recommendedNo general professional obligation

Both papers are assessments by the Bar and an association, not laws and not case law. If you follow the BRAK's more cautious line, you do not put client secrets into a language model; if you follow the DAV's line, you can, provided the following points are met.

When an AI tool is defensible under § 203 StGB and § 43e BRAO
  • The provider is bound to confidentiality in a contract in text form and has been instructed on the consequences under criminal law (§ 43e(3) no. 1 BRAO).
  • It may only gain knowledge to the extent necessary for the contract (no. 2), and this is also implemented technically: encrypted transmission, access only for processing or in a support case.
  • The contract governs whether and how it involves further persons or subcontractors, and binds them in text form as well (no. 3).
  • Training on client data is excluded by contract; according to the DAV, it does not meet the threshold of necessity.
  • If the service is provided abroad, the protection of secrets there is comparable (para. 4).
  • If the tool directly serves a single client matter, the client has given consent (para. 5).
  • The lawyer reviews every result before it is used.

What the Patent Office itself says

With Notice No. 1/26 of 2 March 2026, the DPMA (German Patent and Trade Mark Office) allows its examining sections to use external electronic search sources for searches as well, where appropriate with AI applications, insofar as this is permitted within the Office. The notice itself advises applicants who want to avoid the associated residual risk to consider filing the search or examination request only after publication.

“From the DPMA's point of view, this is a merely theoretical residual risk. Not a single case is known in which confidential application data has reached third parties.”
DPMA, FAQ on Notice No. 1/26, as of 21 July 2026

For unpublished applications, the Office currently uses only internal AI applications. Asked whether it recommends waiting until publication, the FAQ answers: “No, not at all.” The note about the later request applies only as an extreme precaution for applicants who, owing to special circumstances of the individual case, do not consider the residual risk acceptable. It does not amount to approval of any particular tool for law firms.

What Biwak transmits and what is still open

Biwak works as a desktop app with files in a working folder on your computer. For every model task, your question, the conversation context needed and the file contents used go to the Biwak relay at Supabase in Frankfurt am Main and from there to Microsoft Azure. The contracting party is Microsoft Ireland Operations Limited in Dublin; processing happens in Azure's EU Data Zone, which according to Microsoft can also include EFTA states such as Norway and Switzerland, and stored data remains in Germany. Only if Azure rejects a task, for example because the quota is exhausted, does the same task go to PREM SA in Lugano, Switzerland. Prem does not compute itself but forwards to its compute partners Nebius and TensorX in the EU and the United Kingdom. Access to Prem runs over Cloudflare's network. The full chain is set out in section 14 of the privacy policy.

Open, as of 4 October 2026
  • Biwak's DPA is available at biwak.ai/avv, with a confidentiality undertaking in text form, including a notice of criminal liability, in Appendix V. Whether the model providers' confidentiality obligations are sufficient for § 43e(3) BRAO has not been settled; none of them has expressly committed itself under Section 203 StGB.
  • At Azure, according to Microsoft, inputs and outputs are accessible neither to other customers nor to the model makers and are not used for training. For abuse detection, however, suspicious requests may be stored and reviewed by humans; the storage is in Germany. Since the question is who could gain access, this belongs in your assessment.
  • Prem, which only steps in when Azure declines, names its compute partners Nebius and TensorX; the DPA with Prem has not yet been signed. For § 43e(3) no. 3 and (4) BRAO, however, you need to know who is involved and where.
  • Prem's commitment neither to store inputs nor to use them for training rests, by Prem's own account, on contract and operating procedures, not on technical safeguards. For legal documents, Prem recommends an encrypted mode that Biwak does not currently use.
  • Switzerland, where Prem is based and which according to Microsoft may be part of the EU Data Zone, is covered by an adequacy decision under Art. 45 GDPR. Whether the protection of secrets there is comparable within the meaning of § 43e(4) BRAO remains a separate assessment under professional law.

That is why client secrets should not currently go into Biwak without your own assessment. Things that can do without them include templates and model texts, analyses with no link to a client matter, and the firm's internal organisation.

Checking the processing chain

What remains to be done in each case
Model access via a service providerFull chain requiredProcessing on behalf under Art. 28 GDPR, a confidentiality obligation in text form with instruction, a rule for other persons involved, assessment of the foreign country under para. 4, and for services relating to a client matter, consent. Doable: it is work, not an impossibility.
Local toolsNo blanket exemptionLocal file storage limits where data is stored, but does not replace checking the context that goes to the model.
Traceability and reviewPrerequisite for useVisible steps, a log kept on your side, and professional review of every result by the lawyer.

An installed app is one part of the chain, not its assessment. What matters is which content goes where and who could access it there.

How to check it in your own firm

  • Which data is transmitted? With Biwak, for each model task, it is the question, the conversation context needed and the file contents used.
  • Can the tool work without a network? Disconnect and give it a real task. Whatever still works afterwards really runs locally. In the Biwak desktop app, model tasks require a connection; files, conversations and checkpoints stay local.
  • Who can watch when something goes wrong? Ask about remote maintenance, screen sharing and content-related telemetry. Biwak does not report anything on its own; an error report is only created if you send it, and it then contains the transcript of the open conversation. The same applies to reporting an answer; it also includes the transcript of the conversation. The on-screen set-up in the Rope Team plan is a screen share.
  • Which agreements cover the use? Data protection and professional secrecy set different requirements. Check whether the relevant obligations have been agreed in full and in the required form; the law does not require a specific number of separate contract documents.
  • Where is the log kept? At the provider or with you. Only in the second case can you produce it in a dispute without having to ask anyone. With Biwak, the tool log is on your computer; usage data is in the Biwak account.

Changes to this article

  • 4 October 2026: Brought the processing chain at Biwak up to date: model tasks now run primarily at Microsoft Azure in the EU Data Zone, with Prem AI only as a fallback; added open points on abuse detection at Microsoft.
  • 24 September 2026: Added a section on DAV statement no. 32/2025, with a comparison with the BRAK and a checklist; all statements checked against the wording of the statement, the BRAK guidance and § 43e BRAO.
  • 23 September 2026: Added a section on the processing chain at Biwak; supported the associations' statements with references; deleted a statement about “black-box tools” whose source could not be confirmed; added § 62a StBerG. During re-checking on the same day: deleted the statement from epi Information 2/2026 because the source could not be retrieved; aligned the BRAK statement on freely accessible models and § 31 PatG with the wording.
  • 10 September 2026: Separated the text form requirement under professional law from § 203 StGB, corrected inspection of files under § 31 PatG, corrected the classification of the DPMA notice based on the FAQ, and withdrew the earlier statement that two separate contract documents are strictly required.

Frequently asked questions

Is a data processing agreement under Art. 28 GDPR enough?

No, on its own it does not show that the professional-law requirements are met. In addition, § 203 StGB and, depending on the profession, § 43e BRAO, § 39c PAO or § 62a StBerG need to be checked. The text form and the confidentiality obligation with instruction follow from professional law. What matters is the full content of the contracts, not the number of documents.

Does a provider with servers in the EU help?

Only to a limited extent under professional law. The BRAK recommends providers with servers in Germany or Europe because it is open whether foreign protection satisfies § 43e(4) BRAO. But access remains decisive: who could look inside, including from support or from a group company outside the EU? The article on US providers and third-country transfers explains the data protection side.

What about anonymisation or pseudonymisation before input?

A viable route, but rarely practical. With a draft contract or an invention disclosure, the content is precisely the secret, not the name; the Federal Association of German Patent Attorneys also points this out. If you replace names and send the rest, you have sent the secret. With plain personal data it is different; there, the check is worthwhile.

Do I have to tell clients that I use AI?

Neither the BRAK in its guidance of December 2024 nor the DAV in its statement of July 2025 sees a general professional obligation to do so. The BRAK nevertheless recommends being open about it and, in case of doubt, a provision in the engagement agreement. This is separate from consent under § 43e(5) BRAO when a tool directly serves a single client matter.

And if only the assistant uses the tool?

That changes nothing. § 203 StGB is linked to knowledge of other people's secrets, not to someone's position in the firm; employees are bound to confidentiality anyway. The question remains who outside the firm gains access.

Can we use Biwak for client data?

Only after your own assessment. Biwak's DPA at biwak.ai/avv contains, in Appendix V, a confidentiality undertaking in text form with a notice of criminal liability, and states which model providers are involved and to what extent they are bound to confidentiality. Whether that is sufficient for your client matters is for you to decide under § 43e BRAO. We answer questions at kontakt@biwak.ai.

Sources

  1. § 203 StGB (violation of private secrets)
  2. § 43e BRAO (use of service providers)
  3. § 39c PAO (use of service providers)
  4. § 62a StBerG (use of service providers)
  5. § 31 PatG (inspection of files)
  6. BRAK: Guidance on the use of artificial intelligence, as of December 2024 (PDF)
  7. DAV: own-initiative statement no. 32/2025 on the use of AI in the legal profession, July 2025
  8. epi: Guidelines on the use of generative AI, adopted on 16 November 2024
  9. BDPA: Artificial intelligence as a member of staff in the patent law firm, 23 February 2026
  10. DPMA: Notice No. 1/26 of the President of 2 March 2026
  11. DPMA: FAQ on Notice No. 1/26, as of 21 July 2026
  12. Biwak: Privacy policy, section 14 (requests to a language model)

This text is not legal advice. It is the groundwork we had to do for ourselves, with the legal references, so that your lawyer does not have to start from scratch. Where a question depends on your circumstances, the text says so.

Further reading

All articles