Skip to main content

§ 31 · For lawyers

Section 43a BRAO and AI: What Attorney-Client Confidentiality Requires From AI Tools

Section 43a BRAO doesn't ban AI — but it sets conditions. Which contracts, server locations, and controls attorney-client confidentiality requires for AI tools, and how to recognise a provider that's clean under professional-conduct rules.

4 minFor lawyers
An open statute book showing Section 43a BRAO next to a laptop whose screen displays an AI data-protection query — a symbol for attorney-client confidentiality with AI tools.

In one sentence

Section 43a(2) BRAO doesn't prohibit the use of AI — it requires that case data only reaches service providers who are contractually bound to confidentiality, don't train on your data, and process it in the EU in a traceable way.

The legal framework, sorted out clearly

Three provisions interlock. Section 43a(2) BRAO establishes attorney-client confidentiality, Section 2 BORA gives it concrete professional-conduct form, and Section 203 StGB makes the disclosure of private secrets a criminal offence. The decisive question is: does entering case data into an AI service already amount to disclosure? It does, as soon as the data reaches a third party who isn't properly secured. Section 43e BRAO, however, explicitly permits engaging service providers — provided the provider is contractually bound to confidentiality and the processing stays within the necessary scope. That answers the question "may a lawyer use ChatGPT" by itself: a private consumer account with no contract and no training opt-out doesn't satisfy Section 43e.

What the BRAK and DAV require

The guardrails set by the BRAK (Federal Bar) and DAV (German Bar Association) on AI use are, at their core, clear — even as they keep evolving with the technology. Three things are expected: a data processing agreement (DPA) under the GDPR, a contractually guaranteed training opt-out for case data, and ideally hosting within the EU. If any of these elements is missing, the use is open to challenge under professional-conduct rules — regardless of how well the tool actually works.

Three questions to ask yourself — and seven for the provider

Before using any tool, ask yourself three questions: who processes the data? Where, and for how long? Is training done on case data? Anyone who can't clearly answer these three shouldn't touch a case file.

Ask every legal AI provider seven questions:

  • Is there a data processing agreement (DPA) in place under the GDPR?
  • Are all subprocessors publicly listed?
  • Exactly where are the servers located?
  • How long are inputs stored?
  • Is the exclusion of training on your data contractually guaranteed?
  • What technical safeguards (encryption, access control) are in place?
  • How are you informed about changes to the subprocessors?

Liability stays with you

No contract takes the outgoing review off your hands. AI systems invent citations; courts have repeatedly clarified that checking AI output is part of a lawyer's duty of care (see our report on the Berlin Court of Appeal (KG Berlin)). Every citation, every deadline, every reference to the case file needs to be verified — and that verification needs to be documented. Since 2 August 2026, the transparency obligations under Art. 50 of the EU AI Act also apply; violations of the AI Act can be punished with fines of up to 35 million euros or 7% of worldwide annual turnover.

How SmartLegalPro meets these criteria

SmartLegalPro is built for exactly this framework: EU hosting, no training on case data, and a public subprocessors list you can check at any time. Premium models outside the EU (the Fable add-on) are locked by default and can only be unlocked after an explicit firm-level opt-in, with EU pinning wherever possible. How we process data is set out openly in our AI transparency page. For handling real names, the Anwaltsportal offers PII masking and PDF redaction. You'll find details for law firms at /fuer-anwaelte — read why a consumer chatbot isn't enough for this under Why Not ChatGPT.

A model firm policy in seven points

  • Name approved tools on a whitelist; everything else is blocked.
  • No consumer account is ever used with case data — never.
  • Check and file the DPA and training opt-out before enabling a tool.
  • Mask personal data wherever the use case allows it.
  • Document the outgoing review and citation check as mandatory steps.
  • Set rules for client information; obtain consent when in doubt.
  • Review subprocessors and contracts annually.

Frequently asked questions

May a lawyer use ChatGPT? Only with a data processing agreement and a contractual training opt-out. A private account doesn't satisfy Section 43e BRAO.

Is a DPA alone enough? No. Without a training opt-out and a traceable server location, the use remains open to challenge.

Does the client have to consent? That depends on the individual case. This overview doesn't replace legal advice — set out information and consent in your firm's own policy.

Lexi, digitale Rechts-Assistenz

Ready to clarify your matter?

{n} credits free. No credit card required. Ready in 2 minutes.

Start free now

No credit card required · GDPR-compliant · Start for free

Start free
No credit card
Get started