GuCoIA Logo
·
AI Security Legal GDPR

German Legal Ethics and AI: What Lawyers Need to Know About §43a BRAO

ChatGPT in law firms creates professional liability risks. We explain what §43a BRAO means for AI use and how firms can protect client data.

ChatGPT and similar AI tools have arrived in German law firms. Many lawyers use them daily — often without realizing they may be violating professional ethics rules. §43a BRAO is unambiguous. The question is whether your AI infrastructure is too.

AI adoption in German law firms is growing rapidly. Lawyers use ChatGPT for drafting briefs, contract analysis, and legal research. It saves time and increases productivity — as long as no one asks where client data goes in the process.

That is exactly the problem.

Every request sent to ChatGPT or similar services leaves the firm’s network. It is transmitted over the public internet to servers operated by OpenAI — a US company — where it is processed and temporarily stored. Client names, contract contents, litigation strategy, witness lists: whatever enters the prompt leaves the firm’s control.

This is not a theoretical risk. It is a professional liability issue.

What §43a BRAO Requires

§43a paragraph 2 of the German Federal Lawyers’ Act (BRAO) requires every lawyer to maintain confidentiality over everything entrusted to or known to them in the exercise of their profession. This duty is absolute — toward clients, courts, and the public.

Confidentiality is not a recommendation. It is a professional obligation, the violation of which can result in disciplinary proceedings and — in serious cases — loss of license.

Critically: the duty of confidentiality does not apply only to the lawyer personally. It extends to all technical tools and third-party providers that process client data. Anyone who passes client data to a US cloud service — even for an AI query — must ensure that data is protected there as it would be in their own office.

Standard AI services do not provide this protection.

The CLOUD Act Problem

OpenAI is a US company subject to the US Clarifying Lawful Overseas Use of Data Act (CLOUD Act). This law allows US law enforcement to compel disclosure of data stored on US servers — even if that data belongs to foreign users and was collected in Europe.

In practice: client data your firm sends to OpenAI can be disclosed in the context of a US investigation without notifying your firm.

Whether OpenAI’s own privacy policy excludes this is irrelevant — US federal law supersedes contractual data protection commitments.

What the GDPR Additionally Requires

Beyond professional ethics, the GDPR applies. Anyone who passes client data to a third-party provider needs a legal basis — typically a data processing agreement (DPA) under Art. 28 GDPR.

OpenAI offers a DPA for API users. However, this does not apply by default to ChatGPT users without their own API integration. And even with a DPA, the third-country problem remains: data transfers to the US require additional safeguards under Art. 46 GDPR — such as standard contractual clauses.

These are legally vulnerable since the ECJ’s Schrems rulings established that US intelligence agencies have access to data that is incompatible with European fundamental rights.

The Technical Solution: A Gateway

The alternative to banning AI use is controllability.

A security gateway — a gateway that sits between your firm’s IT and the AI service — solves several problems at once:

Data sovereignty: The gateway runs in your own infrastructure (on-premises). Requests are filtered and classified there before leaving the firm’s network. Client data identified as confidential can be blocked or masked.

Audit trail: Every request is logged with timestamp, user, model used, and token count — with a SHA-256 hash chain for tamper evidence. You have complete documentation for data protection inquiries or professional ethics reviews.

Policy enforcement: You define which data may reach which models. Firm policy is enforced technically — not just as a PDF document.

Cost control: Intelligent routing cuts AI costs by up to 85% by directing simple requests to cheaper models.

First Steps

  1. Inventory: Which AI tools are your staff currently using — with and without IT knowledge?
  2. Legal basis review: Does a DPA exist with every provider in use?
  3. Risk assessment: What categories of data typically appear in AI prompts?
  4. Technical measures: Evaluate an on-premises gateway as an infrastructure measure.

Banning AI does not protect your firm — it merely shifts the problem to informal use on personal devices. Controllable AI use is safer than uncontrolled AI use.


Questions about technical implementation? GuCoIA offers a free 30-minute demo for law firms — no sales pitch, concrete answers for your infrastructure.

Request demo →