In short
§203 of the German Criminal Code makes unauthorised disclosure of client or patient secrets by lawyers, tax advisers, doctors and similar professionals a criminal offence. Since 2017 they may use external IT providers under specific conditions, but a GDPR processing agreement alone does not cure the criminal-law question. Running AI on infrastructure the practice controls avoids disclosure in the first place.
Who §203 applies to
Section 203 of the German Criminal Code (StGB) protects secrets entrusted to professionals bound by confidentiality, including lawyers, tax advisers, auditors, doctors and their staff. Disclosing such a secret without authorisation is a criminal offence, separate from any GDPR fine.
The 2017 reform
Since 2017, secrecy-holders may involve external service providers, such as IT providers, if they are necessary for the work and are bound to secrecy. That opened the door to outsourcing, but with conditions: the provider must be obliged to confidentiality, and disclosure must be limited to what is needed.
Why a GDPR agreement isn't enough
A data processing agreement under GDPR governs how personal data is processed. It does not by itself satisfy the criminal-law requirements of §203. A cloud AI service that receives client files in prompts, keeps logs and uses sub-processors creates disclosure questions that a standard processing agreement does not answer.
What self-hosting changes
If the AI runs inside the practice's own infrastructure, client material is not handed to an AI vendor at all:
- Prompts, documents and answers stay on the firm's or clinic's systems.
- Logs remain under the practice's control and retention rules.
- Matter and patient permissions are enforced by the system.
Practical steps
- Inventory where client or patient material could reach an AI tool today, including staff using public chatbots.
- Choose a deployment where models and logs run on infrastructure you control.
- Carry matter-level permissions and ethical walls into the AI.
- Document the setup for your professional body or data protection officer.
For professional-secrecy holders, self-hosted AI is not a preference. It is the simplest way to stay on the right side of the law.
See also our Europe compliance page and legal industry page.
General information, not legal advice. Questions? Write to sales@deepvox.ai.