Professional secrecy and AI: what law firms, practices and tax advisers need to know
Breaching professional secrecy is a criminal offence throughout the DACH region: § 203 of the German Criminal Code, § 121 of the Austrian Criminal Code together with professional confidentiality duties, and Art. 321 of the Swiss Criminal Code. Those covered include lawyers, doctors, pharmacists, tax advisers and their auxiliary staff. Disclosing client or patient data without authorisation risks a custodial or monetary penalty – including where the organisation was merely negligent.
The central question when deploying AI is therefore: does entering confidential data into an AI tool amount to unauthorised disclosure? The answer depends substantially on how the tool is operated.
Who is covered by professional secrecy
The lists are similar. § 203 of the German Criminal Code covers doctors, pharmacists, lawyers, tax advisers and auditors, along with their professional assistants. Art. 321 of the Swiss Criminal Code names clergy, lawyers, defence counsel, notaries, doctors, dentists, pharmacists and midwives together with their auxiliary staff; it does not apply directly to fiduciaries, though contractual and in part sector-specific confidentiality duties do. In Austria, § 121 of the Criminal Code applies to health professions, alongside professional confidentiality duties such as § 9 RAO for lawyers and § 54 of the Medical Act for doctors. Public officials are bound by official secrecy – § 353b of the German Criminal Code, Art. 20(3) of the Austrian Federal Constitution, Art. 320 of the Swiss Criminal Code.
When using AI becomes disclosure
What matters is passing data to third parties that are not engaged as auxiliaries. A public AI tool that uses inputs for training and is bound by no contractual confidentiality is exactly that: an uncontrolled third party. Entering identifying client or patient data into such tools is hard to reconcile with the duty of secrecy.
It looks different where the provider is contractually engaged as a processor, the data stays in the EU or Switzerland, it is not used for training, and technical and organisational measures secure confidentiality. The deployment then rests on a similar footing to established IT service providers – after all, your practice management software isn't kept in the filing cabinet either.
Measures for permissible AI use
Professionals bound by secrecy should secure their AI use on three levels:
- Contractually: a data processing agreement, confidentiality obligations, no training on inputs
- Technical: hosting in the EU or Switzerland, encryption, access control, audit logs
- Organisationally: an internal directive, anonymisation where possible, training for all auxiliary staff
Practical examples from law firms, practices and tax advisers
Sensible first use cases are those with high benefit and manageable risk: summarising your own files, drafting correspondence, querying internal templates and briefing notes. Delicate cases – analysing highly sensitive matters, for instance – belong on the platform only once the contract, the technology and the internal rules are in place.
Frequently asked questions
May lawyers use ChatGPT for client work?
With identifying client data in a consumer version: a clear risk of breaching the duty of secrecy – § 203 of the German Criminal Code, Art. 321 of the Swiss Criminal Code. It becomes permissible with an enterprise solution that is contractually bound as a processor, keeps data in the EU or Switzerland and does not use it for training.
Does anonymising inputs help?
Yes, consistent anonymisation reduces the risk considerably. In practice it is error-prone, though – contextual information can still allow conclusions to be drawn. It therefore complements a secure platform rather than replacing one.
Does professional secrecy apply to the secretariat too?
Yes. Auxiliary staff are equally bound by the duty of secrecy. AI rules and training therefore have to cover the whole team – not just the professionals themselves.
Related reading
Bring AI into your company securely.
Try Vidimas with your team – and see how quickly secure AI becomes productive.
- Try it with the whole team
- Set up in minutes
- Productive from day one
