Legal Data Tech

§ 43e BRAO · Confidentiality

Confidentiality doesn't end at the firm's door.

Any law firm using cloud software, AI or external IT hands client secrets to a third party. § 43e BRAO sets out the conditions under which that is permitted — and establishes four concrete obligations. This guide explains them and shows how to recognize a provider that actually meets them.

By Tim Platner, attorney & managing director · As of: July 2026

4

statutory obligations for every service provider you engage

Written form

required for the undertaking & notice — not just verbal

§ 203 StGB

a criminally enforced duty of confidentiality that must be passed down the chain

The legal framework

A provision that makes legal tech possible in the first place.

Attorneys are subject to a criminally enforced duty of confidentiality. Violating it is a criminal offense under § 203 StGB. For a long time it was therefore disputed whether a law firm could engage external IT service providers at all without committing an offense — since the mere possibility of the provider becoming aware of the information is enough.

The legislature resolved this: first, the 2017 reform of § 203 StGB clarified that "participating persons" — explicitly including external IT service providers — may be engaged if they are bound to confidentiality. The major 2022 BRAO reform then added § 43e BRAO, which spells out the professional-conduct requirements for the law firm.

In short: cloud, AI and external IT are permitted for law firms — but only under the conditions of § 43e BRAO. These conditions are not a formality; they are the line between permissible outsourcing and criminal breach of secrecy.

What this means for law firms

Every tool with data access is affected.

The obligations don't only apply to "outsourcing" in the classic sense. They apply as soon as an external service provider can become aware of client data — whether as practice-management software, a dictation or OCR service, cloud storage or an AI assistant. For the law firm, this leads to an uncomfortable truth:

The responsibility stays with you

§ 43e obligates the law firm, not the provider. Whether the service provider complies is something you must verify — and, if in doubt, demonstrate.

The chain matters

A provider that itself uses US cloud services or external AI APIs passes your client secrets further along. Without a subcontractor list, you won't see this.

Proof is mandatory

Both the bar association and your clients are entitled to expect that you can present documented proof of selection, undertaking and notice.

The four obligations in detail

What § 43e BRAO specifically requires.

01§ 43e Abs. 2 BRAO

Careful selection

The service provider must be selected carefully. What matters is their professional suitability and – especially for IT and AI – their technical and organizational security level. The selection decision should be documented so it can be demonstrated to the bar association and to clients.

02§ 43e Abs. 3 BRAO

Written-form confidentiality undertaking

The service provider must be expressly bound to confidentiality — and in written form (Textform). A GDPR data processing agreement under Art. 28 GDPR does not automatically suffice: it satisfies data protection law but does not replace the professional-conduct obligation, which is independent of it.

03§ 43e Abs. 3 BRAO

Notice under § 203 StGB

Part of the undertaking is an explicit notice that the engaged individual is personally subject to criminal liability under § 203 StGB for breach of confidentiality. Only this notice carries the attorney's duty of confidentiality seamlessly through into the technology being used.

04§ 43e Abs. 4 BRAO

Binding & controlling subcontractors

If the service provider in turn engages further providers (hosting, subprocessors, AI components), it must be ensured that they too are bound to confidentiality. To exercise selection and control, the firm needs a complete, up-to-date list of subcontractors.

For service providers outside the EU/EEA, § 43e BRAO imposes additional requirements — one more reason to insist on a European processing chain.

How DEPLAW meets § 43e

The entire chain — documented down to the last subcontractor.

We supply the building blocks § 43e BRAO requires instead of leaving them to the law firm. All of these points are part of the data processing agreement and can be demonstrated on request.

Written-form confidentiality undertaking
All individuals and systems with access to client and case data are demonstrably bound to confidentiality in written form — with explicit reference to § 43e BRAO, documented and part of the data processing agreement.
Documented notice under § 203 StGB
Bound individuals are expressly notified of the criminally enforced duty of confidentiality under § 203 StGB. The notice is documented and can be demonstrated on request.
Complete subcontractor list
You receive a complete, up-to-date list of all subcontractors used — with purpose, location (EU/Germany) and proof of their confidentiality undertaking. This lets you meet your selection and control obligation without follow-up questions.
Hosting & development in Germany
Operated on Deutsche Telekom servers (Open Telekom Cloud, ISO 27001 / SOC 2 Type II), development 100% in Germany. No critical components are outsourced to third countries — no need for costly third-country transfer assessments.
No data shared with external AI providers
Case data is not transmitted to external AI services (e.g. US APIs). AI processing takes place entirely within the controlled environment operated in Germany.
See the full security & compliance concept →

Checklist to take away

The § 43e check for any provider.

Seven questions you can use to check any legal tech, cloud or AI provider — not just DEPLAW. A provider that can substantiate all seven takes the § 43e documentation burden off your hands.

  • 01Is there a written-form confidentiality undertaking — with explicit reference to § 43e BRAO or § 203 StGB?
  • 02Have the individuals involved been notified of the criminally enforced duty of confidentiality under § 203 StGB?
  • 03Is there a complete, up-to-date subcontractor list (name, purpose, location)?
  • 04Are all subcontractors based in the EU/EEA — or are there guarantees under Art. 44 et seq. GDPR?
  • 05Is it ensured that subcontractors are themselves bound to confidentiality?
  • 06Is case data transferred to external AI services — and if so, on what legal basis?
  • 07Can selection and control be demonstrated with documentation (for the bar association and clients)?

Typical provider vs. DEPLAW

Where the difference actually lies.

"Typical provider" here stands for what the market usually delivers — without naming individual competitors. The point isn't that others do nothing, but that the § 43e chain is rarely fully documented and made available.

RequirementTypical ProviderDEPLAW
Confidentiality undertakingGDPR DPA (Art. 28), often without reference to § 43eDPA + separate written-form undertaking referencing § 43e
Notice under § 203 StGBusually not documentedexplicit and documented
Subcontractor liston request, sometimes incompletecomplete, with location & proof of undertaking
Hosting & developmentcloud, sometimes outside the EU100% Germany
AI processingexternal AI APIs (often US)no data shared with external AI providers

Frequently Asked Questions

§ 43e BRAO — briefly answered.

Yes. As soon as an external service provider has access to client data or the ability to become aware of it, the obligations under § 43e BRAO apply — regardless of whether the offering is labeled "software" or a "service." Cloud practice-management software, dictation and OCR services, and AI tools regularly fall under this.

No, not on its own. The DPA satisfies data protection law. § 43e BRAO is an independent professional-conduct obligation and additionally requires a written-form confidentiality undertaking as well as notice of the criminally enforced duty of confidentiality under § 203 StGB. Both should be expressly documented.

Possible consequences include professional sanctions (ranging from a reprimand to further measures by the bar association) as well as — at the core — potential criminal liability under § 203 StGB for breach of private secrets. Data protection risks may add to this.

Yes. To meet your selection and control obligation under § 43e Abs. 4 BRAO, you need to know who in the chain can access data. A reputable provider makes a complete, up-to-date subcontractor list available for this purpose.

Through a written-form undertaking referencing § 43e, documented notice under § 203 StGB, a complete subcontractor list (EU/Germany), hosting and development exclusively in Germany, and by not sharing case data with external AI providers.

No. The obligation applies to practically every law firm that uses external technology. What is rare is that providers fully document and actively make this compliance available — which is exactly where DEPLAW comes in.

Tim Platner

Tim Platner is an attorney and co-founder of Legal Data Technology GmbH. He advises law firms and insurers on the legally compliant introduction of AI-powered legal services.

View author profile →

This article provides general information about the professional-conduct framework and does not replace individual legal advice.

§ 43e documentation you can actually present.

In the demo we show the undertaking, the notice and the subcontractor list — and how DEPLAW keeps the entire chain in Germany.

Book a free demo