Professional secrecy and AI: what law firms, practices and tax advisers need to know
Breaching professional secrecy is a criminal offence throughout the DACH region: Section 203 of the German Criminal Code, Section 121 of the Austrian Criminal Code together with the professional codes of conduct, and Art. 321 of the Swiss Criminal Code. Those covered include lawyers, doctors, pharmacists, tax advisers and notaries – and, expressly, their auxiliary staff.
For AI this raises a question data protection law does not answer: is entering client or patient data into an AI tool already a disclosure to a third party? The answer depends on how the provider is contractually engaged – not on whether the tool is marketed as secure.
This article sets out the position in Germany, Austria and Switzerland, explains the difference between the data protection layer and the secrecy layer, and names the measures that let holders of professional secrets use AI.
Who is bound by professional secrecy
The catalogues in the three countries are similar. Section 203 of the German Criminal Code covers doctors, dentists, pharmacists, lawyers, notaries, tax advisers, auditors and professional psychologists, among others. Art. 321 of the Swiss Criminal Code names clergy, lawyers, defence counsel, notaries, auditors, doctors, dentists, pharmacists, midwives, psychologists and nursing professionals. In Austria, Section 121 of the Criminal Code supplements the professional duties in Section 9 RAO for lawyers and Section 54 ÄrzteG for doctors.
One commonality matters most for AI: all three legal systems extend the duty of confidentiality to auxiliary staff. Reception, bookkeeping, IT support and interns are bound just as the professional is. An internal AI policy that addresses only the professionals themselves falls short.
The three countries compared
The differences lie less in the scope of protection than in how external service providers are engaged.
| Germany | Austria | Switzerland | |
|---|---|---|---|
| Core provision | Section 203 StGB | Section 121 StGB, supplemented by professional law (Section 9 RAO, Section 54 ÄrzteG) | Art. 321 StGB; for lawyers additionally Art. 13 BGFA |
| Maximum penalty | Up to one year imprisonment or a fine | Up to six months imprisonment or a fine | Up to three years imprisonment or a fine |
| Auxiliary staff covered | Yes, expressly | Yes, via criminal and professional law | Yes, expressly |
| External service providers | Expressly regulated since the 2017 reform: disclosure to contributing persons is permitted where necessary for their activity | Via contractual confidentiality undertakings and professional law | Not expressly regulated; engagement runs through the concept of the auxiliary person |
| Release from the duty | Consent of the person concerned | Consent of the person concerned | Consent of the entitled person or authorisation by the supervisory body |
When AI use becomes a disclosure
Disclosure means making a secret accessible to a third party. What is critical is therefore not the use of AI as such, but passing information to a third party who has not been engaged.
A public AI tool that uses inputs for training and is under no contractual confidentiality obligation is exactly that: an uncontrolled third party. Entering identifiable client or patient data into such a system is the classic problem case – however good the output is.
The position differs where the provider is contractually engaged as a processor, has been placed under a confidentiality undertaking, the data stays in the EU or Switzerland, inputs are not used for training, and technical and organisational measures secure confidentiality. Then the use is not inherently at odds with the duty of secrecy. The final assessment stays with the professional and turns on the individual case.
The German route: contributing persons
Germany addressed the question expressly in 2017. Since then Section 203 StGB permits disclosure to persons who contribute to the professional activity of the secrecy holder – including external service providers – to the extent necessary for their activity.
The permission comes with conditions: the professional must select the contributing person carefully and place them under a confidentiality obligation. Where those duties are breached, criminal liability remains. In practice this means documented provider selection and an express confidentiality undertaking are not formalities but the precondition of the permission.
Austria and Switzerland have no identically worded provision. There, engagement runs through the status of auxiliary person and through professional law – with similar requirements on selection, undertaking and oversight, but without the express statutory anchor.
Why a DPA alone is not enough
Data protection and professional secrecy are two separate legal layers with different objectives. A data processing agreement under Art. 28 GDPR, or a contract under Art. 9 FADP, governs the processing of personal data. It releases nobody from a criminally sanctioned duty of secrecy.
In practice a provider can be impeccable in data protection terms and still fail the secrecy assessment – for instance because no express confidentiality undertaking was agreed, or because it stays unclear which individuals at the provider can access content.
The reverse holds too: solving the secrecy layer cleanly does not dispose of the data protection layer. The record of processing, the duty to inform and, where applicable, the impact assessment all remain. Both assessments have to run side by side.
Measures for permissible AI use
Holders of professional secrets should secure AI use on three levels. The order is deliberate: without the contractual level, the technical measures do not carry legally.
- Contractual: data processing agreement, express confidentiality undertaking by the provider and its sub-processors, contractual exclusion of training on inputs, documented provider selection.
- Technical: hosting in the EU or Switzerland, encryption in transit and at rest, role-based access control, audit logs, no provider access to content outside defined cases.
- Organisational: an internal policy with clear limits, confidentiality undertakings for all auxiliary staff, anonymisation where possible, regular training, and a named contact for borderline cases.
Use cases sorted by risk
Sensible first use cases are those with high benefit and manageable risk. Sorting them helps teams start without tackling the most sensitive matters first.
| Risk | Examples | Precondition |
|---|---|---|
| Low | Searching internal templates and guidance notes, general research with no case reference, drafting help for unproblematic correspondence | Internal policy and training |
| Medium | Summarising your own files, drafting client and patient correspondence, analysing your own templates | Contractual engagement, hosting in the EU or Switzerland, no training on inputs |
| High | Analysis of highly sensitive mandates, health data of individual patients, ongoing criminal or supervisory proceedings | Case-by-case assessment, consent of the person concerned where appropriate, documented decision |
What anonymisation achieves – and what it does not
Anonymisation lowers the risk but does not dissolve it. Removing names is not enough when the constellation of facts, the date, the location and the procedural stage make a person identifiable. In small firms, practices and municipalities the pool of possible individuals is small.
As a sole measure it therefore does not carry. It is worthwhile as an additional layer alongside contractual engagement and a clarified processing location – and as a habit that limits the damage when something does go wrong.
Frequently asked questions
May lawyers use ChatGPT for client work?
For identifiable client data, consumer versions are unsuitable: there is no contractual confidentiality, the processing location cannot be steered, and the training setting sits with the individual user. Use becomes defensible only with a contractually engaged provider, a clarified location and training excluded. The final assessment stays with the firm.
Does anonymising inputs help?
It lowers the risk but is not sufficient on its own. What matters is whether the person remains identifiable despite the removal of names – through the constellation of facts, the date, the location or the procedural stage. In small units that is frequently the case.
Does professional secrecy extend to reception staff?
Yes. All three legal systems expressly extend the duty to auxiliary staff. Reception, bookkeeping, IT support and interns are bound. An AI policy therefore has to apply to everyone with access to client or patient data.
Is a data processing agreement enough?
No. The DPA governs the data protection layer, not the duty of secrecy. Professional secrecy additionally requires an express confidentiality undertaking from the provider and its sub-processors, plus careful and documented selection.
What applies to firms with offices in several countries?
The law that applies is the law of the place where the profession is practised, not the law of the server location. Firms operating in Germany, Austria and Switzerland have to meet the strictest requirements among the systems involved and know how each treats the engagement of service providers.
Can the person concerned consent to AI use?
Yes. Consent from the entitled person releases the professional from the duty in all three countries. It has to be informed and tied to the specific use. As a routine model for everyday work it is impractical, but for individual sensitive matters it is a viable route.
Sources
- Section 203 StGB – breach of private secrets · Gesetze im Internet (German Federal Ministry of Justice)
- Austrian Criminal Code (StGB), Section 121 · RIS – Austrian Legal Information System
- Swiss Criminal Code (StGB, SR 311.0), Art. 320/321 · Fedlex – Swiss Federal Chancellery
Related reading
Bring AI into your company securely.
Try Custodos with your team – and see how quickly secure AI becomes productive.
- Try it with the whole team
- Set up in minutes
- Productive from day one
