Skip to main content
11 min

Section 203 compliant AI platform: using AI safely despite professional secrecy

AI Compliance & Governance

Few professions benefit from AI as much as those bound by professional secrecy. Briefs, tax files, medical reports and expert opinions are text-heavy, repetitive and time-consuming. That is exactly the work AI takes off your plate. At the same time, few professions carry a higher risk when they pick the wrong tool: the data involved is protected by Section 203 of the German Criminal Code (StGB) under threat of criminal penalties.

The answer is not to avoid AI, but to use a platform built for professions bound by secrecy from day one. This article explains what Section 203 StGB requires from an AI provider, why GDPR compliance alone is not enough and how law firms, medical practices and consultancies can roll out AI safely.

Note: This article provides general information on AI use and professional secrecy. It does not replace legal advice in individual cases.

What Section 203 StGB regulates

Section 203 StGB makes it a criminal offence to disclose without authorisation a secret entrusted to a professional in their professional capacity. The list in paragraph 1 is long. It includes, among others:

  • Physicians, dentists, veterinarians, pharmacists and members of other healthcare professions
  • Psychologists with a state-recognised final examination
  • Lawyers, patent attorneys, notaries and defence counsel
  • Auditors, sworn accountants, tax advisors and tax agents
  • Marriage, family, parenting and youth counsellors as well as addiction counsellors
  • Social workers and social pedagogues in recognised counselling centres
  • Employees of private health, accident and life insurers and of medical billing offices

For all of these professions the rule is the same: anyone who passes on a client or patient secret without authorisation commits an offence. An AI tool that sends input to a provider is exactly such a disclosure. So the question is not whether AI and professional secrecy are compatible, but under which conditions.

The 2017 reform: contributing persons

Until 2017 the legal position for external service providers was unclear. A lawyer who hired an IT provider to run the firm's software operated in a grey area. The legislator resolved this explicitly with the "Act on the Reorganisation of the Protection of Secrets in the Involvement of Third Parties in the Professional Activities of Persons Bound by Secrecy".

Since then, Section 203 (3) StGB allows professionals bound by secrecy to involve "other contributing persons". These are persons or companies that contribute to the professional activity without being bound by secrecy themselves: data centres, cloud providers, typing services, IT support. And AI platforms.

The permission is tied to two conditions:

  1. Necessity. The disclosure must be necessary to use the service. The provider may only receive the data it needs for its task.
  2. Obligation to secrecy. Under Section 203 (4) StGB, the professional must oblige the contributing person to maintain secrecy. If they fail to do so and the person discloses a secret, the professional is liable themselves.

The professional codes were updated accordingly: Section 43e of the Federal Lawyers' Act (BRAO) regulates the use of service providers by lawyers, Section 62a of the Tax Advisory Act (StBerG) for tax advisors. Both require a written contract that obliges the provider to confidentiality, informs them about the criminal liability and restricts them to only accessing what is necessary for the service.

The same standard applies to AI platforms. What matters is not whether you use AI, but which provider you choose and what the contract looks like.

Why GDPR compliance alone is not enough

Many AI providers advertise "GDPR compliant". That matters, but for professions bound by secrecy it is only half the picture. GDPR and Section 203 StGB are two different legal regimes with different protective goals.

GDPRSection 203 StGB
Area of lawData protection (administrative law)Criminal law
Protected interestPersonal dataEntrusted secrets
AddresseeEvery controllerProfessionals bound by secrecy
Contractual basisData processing agreement (Art. 28)Confidentiality obligation (para. 4)
SanctionAdministrative fineImprisonment or criminal fine

An AI tool can have a clean data processing agreement under Art. 28 GDPR and still fail the requirements for contributing persons, for example because the provider does not enter into an explicit confidentiality obligation or because data flows to third countries where German criminal law has no effect. Professionals bound by secrecy therefore need both: the data processing agreement for data protection and the confidentiality obligation for professional secrecy.

What makes an AI platform Section 203 compliant

From Section 203 StGB, the professional codes and the GDPR, six concrete requirements can be derived. An AI platform for professions bound by secrecy has to meet all six.

1. Confidentiality obligation as a contributing person

The provider contractually commits to confidentiality, as required by Section 203 (4) StGB and the professional codes. The obligation includes the notice on criminal liability and restricts access to what is necessary. At innoGPT this obligation is a fixed part of the contract package.

2. Hosting in the EU

Processing takes place exclusively within the EU. innoGPT hosts in Berlin in an ISO 27001 certified data centre. Data does not leave the EU, not even for model requests.

3. No model training on your data

Inputs and documents are not used by the provider or its technology partners to train AI models. This is not just a line in the terms of use, it is contractually guaranteed.

4. Data processing agreement under Art. 28 GDPR

A data processing agreement with documented technical and organisational measures and individually configurable deletion periods. The contracting party is a German company, so German law applies and the place of jurisdiction is in Germany.

5. Roles and access control

Not everyone in the firm or practice may access everything. SAML SSO and role-based permissions define who may use which data, knowledge sources and models. This also satisfies the necessity requirement: access stays limited to what the task requires.

6. Encryption

Stored data is encrypted and transfers run over TLS. This applies by default to everything that happens on the platform, without anyone having to think about it.

The four questions to ask any AI provider

Four questions get you a long way when evaluating a provider. They separate suitable from unsuitable solutions faster than any data sheet.

  1. Where is the data processed? Does it stay in the EU, or are requests sent to servers outside Europe?
  2. Is input used for training? And is the waiver contractually guaranteed, or just a setting that can change at any time?
  3. Is there a real confidentiality obligation in addition to the data processing agreement? An explicit obligation as a contributing person under Section 203 (4) StGB, not just a general confidentiality clause?
  4. Can you control who accesses what? Are there roles, approvals and logs, or do all users have the same rights?

innoGPT answers all four with yes: EU hosting in Berlin, contractually guaranteed waiver of model training, confidentiality obligation as a contributing person and role-based access control.

Who the platform is built for

innoGPT covers the requirements of all professions named in Section 203 StGB. For individual sectors there are dedicated pages with concrete use cases.

  • Lawyers and law firms: review contracts, draft briefs, summarise case files, in line with Section 43e BRAO. See AI for lawyers.
  • Tax advisors and auditors: analyse tax assessments, prepare correspondence with the tax office, speed up client communication, in line with Section 62a StBerG. See AI for tax advisors.
  • Physicians and healthcare institutions: write medical letters, structure findings, simplify patient communication. For practices, medical centres and hospitals. See AI for doctors.
  • Other professions bound by secrecy: psychologists, counselling centres, insurers. The full list from Section 203 (1) StGB and the legal position in detail at AI for professions bound by secrecy.

Typical use cases in practice

The use cases are similar across all professions bound by secrecy. Almost always it is about text: reading, summarising, structuring, drafting.

  • Summarise documents. Reduce long files, expert opinions or medical reports to the essentials before the professional goes into detail.
  • Write first drafts. Generate briefs, objection statements, medical letters or opinions as a draft that the professional reviews and approves.
  • Work with your own knowledge. Store firm templates, practice guidelines or model contracts as a knowledge source so the AI answers in your context instead of generically.
  • Simplify communication. Translate technical texts into plain language for clients or patients, pre-draft follow-up questions, structure emails.
  • Speed up research. Organise facts, ask questions of a document, find contradictions in files.

What stays true in every case: AI delivers drafts and groundwork. Professional responsibility remains with the professional. That is exactly why roles, approvals and traceability are not a convenience feature but a prerequisite.

From uncontrolled individual use to a safe standard

In many law firms, practices and consultancies AI is already in use, just privately and without control. Staff paste text into free chatbots because it is fast. This shadow AI is the real risk: no contracts, no EU hosting, no control over what happens to the data.

The safe path runs through a structured rollout:

  1. One approved platform for everyone. Instead of ten private accounts, one central access with contract, roles and logs.
  2. Clear rules. What may be entered and what may not. Which models are approved. Who signs off on results.
  3. Short training sessions. Professionals and staff learn in a few hours how to work safely and productively.
  4. Measurable results. Usage, time savings and adoption become visible so the rollout can be adjusted.

innoGPT supports this path personally: with training, dedicated contacts and governance settings for data access, models and deletion periods. This turns shadow AI into enterprise AI that respects professional secrecy.

Checklist: rolling out Section 203 compliant AI

To close, the key points in a list you can use directly for vendor evaluation.

  • Confidentiality obligation as a contributing person under Section 203 (4) StGB is available in writing
  • Notice on criminal liability is part of the contract
  • Data processing agreement under Art. 28 GDPR with documented technical and organisational measures
  • Hosting and model processing exclusively in the EU
  • Waiver of model training contractually guaranteed
  • Contracting party is a company based in Germany or the EU
  • Role and permission concept in place, SSO possible
  • Deletion periods configurable
  • Encryption at rest and in transit
  • Internal usage rules and training planned

Frequently asked questions

Conclusion

Professional secrecy and AI are not mutually exclusive. In 2017 the legislator created the framework under which professionals bound by secrecy may use external service providers, and with them AI platforms. What matters is the right provider and the right contract: confidentiality obligation, EU hosting, no model training, data processing agreement and access control.

Anyone who meets these points can not only use AI in their firm, practice or consultancy, but roll it out safely and measurably. Book a demo or start a free trial.

Consultation

Request the § 203 licence

The § 203 licence is currently available on request only. Send us a short message and we'll get back to you within 24 hours.

Simon Bahlmann
Simon Bahlmann
AI Enabler at innoGPT

By submitting, you agree that we use your details to process your request. See our privacy policy for details.

Rather see the platform live?

  • 15 minutes
  • Use cases, pricing, data protection
  • No obligation
Request a slot
Free NewsletterEvery Tuesday

Weekly AI news in your inbox

New models, practical tips & expert insights — free for everyone.

By clicking "Subscribe" you agree to receive our weekly AI newsletter. Unsubscribe anytime. Privacy policy

Ready for enterprise AI?

See innoGPT in action and discover how AI transforms your work.

Book a demo