Professional secrecy is a technical requirement.
This profession is not governed by NIS2 but by criminal and professional law. They require that every service provider who could gain access is placed under an undertaking in text form, that nobody sees more than necessary, and that this can be evidenced. We build access, archives and AI use so that the evidence exists.
NIS2 is being sold to law firms. Wrongly.
German law firms have been offered NIS2 audits for months. A look at Annex 1 and Annex 2 of the BSI Act settles it: legal advice, tax advice, auditing and notarial services do not appear there — in neither annex, as neither an essential nor an important entity. In scope would be anyone providing managed IT services on the market, and a law firm does not.
Whoever works as a supplier to a regulated business receives that business's supplier requirements through the contract. That is a different thing from an obligation of your own, and it follows a different timetable.
This profession's duties are written elsewhere. They are older, they are sharper, and criminal law stands at the end of them.
What we find
Access over VPN and remote desktop. Client documents by unencrypted email, at best a ZIP with a password — whose file names stay unencrypted and give away the engagement anyway. Everything is PDF, Word and Excel. Digital documents are printed and scanned back in. What comes out of that sits in the "digital archive". When a server dies, the local IT provider comes and restores the disks. Backups run to tape.
This is not the extreme case, it is the normal case. Whatever does not sit inside DATEV is effectively unprotected.
And the most common route by which client data reaches the wrong hands is not an attack. It is a process run by hand: access rights that have grown over years and were never taken back, documents assigned and sent manually, and no log from which anyone could reconstruct afterwards who accessed what and when. Where everyone can see everything and nobody keeps a record, a mix-up is not an exception but a matter of time.
What the law requires
Since the 2017 reform, § 203 of the German Criminal Code addresses the external service provider explicitly. Subsection 3 permits disclosure to contributing persons to the extent necessary for their work. Subsection 4 draws the consequence, and it does so in both directions: it punishes the contributing person who discloses a secret — and, under number 1, the professional secret holder who failed to ensure that this person was placed under an undertaking of confidentiality. On the wording, the missing undertaking becomes an offence only once the contributing person actually discloses something. The charge therefore does not arise on the day of the inspection but on the day of the incident — and then retrospectively.
§ 43e BRAO and, in identical wording, § 62a StBerG say what that undertaking must look like: text form under § 126b BGB, meaning a readable declaration on a durable medium such as an email, with no signature required; instruction about the criminal consequences; restriction of knowledge to what is necessary to perform the contract, and an explicit rule on whether the provider may involve further persons, who must then be placed under the same undertaking in text form. Subsection 4 requires that with a provider abroad, the protection there is comparable to domestic protection.
According to the German Federal Bar's guidance, the mere possibility of access is enough to constitute disclosure. Nobody has to have actually looked. An IT provider's remote access is therefore already the act the law governs — not its abuse. A standard remote-maintenance contract does not, as a rule, meet the three requirements of § 43e subsection 3.
Data protection runs alongside this, not inside it: a processing agreement under Article 28 GDPR does not replace the professional-law undertaking. § 43e subsection 8 BRAO states this expressly.
And then came AI
Recently everything that needs checking goes through a language model. Numerous document management systems now ship the feature, and the vendors assure everyone it is done properly. Those vendors are systems integrators and DMS makers — not security providers. The question rarely asked is not whether the model works well, but where the document goes.
Because the law already covers this case. Anyone who hands client data to a provider discloses it to a contributing person — with everything § 43e BRAO and § 62a StBerG require for that. An account with an American provider does not satisfy it, and the DMS maker's assurance does not replace the check.
We run models in the EU, in Germany or on your own premises, and we log which document went to which model and when. That is not a restriction on using AI, it is the precondition for it.
How to get out of it
Access gets a name and an end. Every remote session runs through a controlled path: approval per assignment, a fixed time window, session recording, no permanently stored credentials. That turns the undertaking in text form into evidence that holds when it is needed.
Rights are taken back. Who may see which engagement is decided once and reviewed continuously. Grown permissions are the actual finding in almost every firm.
The archive outlives the vendor. § 147 of the German Fiscal Code requires six to ten years of retention, the period does not expire while the assessment period is still open, and the tax authority may access the data even where it sits with a third party. An archive strategy has to stay readable, migratable and exportable across a decade — a change of vendor must not break that chain.
AI gets a path instead of a ban. A model in the EU or on site, an approval per document class, a log of every handover.
Where it pays to start
A survey of the access paths and the service-provider contracts, before anything is procured. In this order: who enters the firm from outside today and by which route; which of those providers is under an undertaking in text form and with what instruction; where documents go when they pass through an AI feature; and whether it can be reconstructed, for the last twelve months, who accessed what.
Sources: § 203 StGB, § 43e BRAO, § 62a StBerG and § 147 AO in their statutory wording; the BSI Act, Annex 1 and Annex 2, as amended by the German NIS2 implementation act (BGBl. 2025 I no. 301); German Federal Bar guidance on the use of AI, December 2024.
What you can hand off
-
Survey of access paths
Who comes in from outside, by which route, with which rights — and how much of that is covered by contract.
-
Controlled remote maintenance
Approval per assignment, fixed time window, session recording, no permanently stored credentials.
-
Permissions per engagement
Decided once, reviewed continuously. Grown rights are taken back rather than carried forward.
-
Provable access
Logging that shows, for past months, who accessed what and when.
-
AI with a path instead of a ban
Models in the EU, in Germany or on site, approval per document class, a log of every handover.
-
An archive that outlasts the retention period
Readable, migratable and exportable across a decade — including through a change of vendor.
The four that actually bite
Four provisions decide what has to be done technically in a firm. NIS2 is expressly not among them: this profession does not appear in Annex 1 or Annex 2 of the BSI Act. Also relevant, depending on the practice: the professional code, the GoBD rules on digital bookkeeping, and the EU AI Act.
-
§ 203 StGBViolation of private secrets · subsections 3 and 4
Subsection 3 permits disclosure to contributing persons to the extent necessary for their work. Subsection 4 punishes the contributing person who discloses a secret — and, under number 1, the professional secret holder who failed to ensure that this person was placed under an undertaking of confidentiality. It requires that the contributing person did in fact disclose something; the missing undertaking is then the charge the professional faces.
-
§ 43e BRAOUse of service providers · lawyers
Requires text form for every service contract, an undertaking of confidentiality with instruction about the criminal consequences, restriction of knowledge to what is necessary to perform the contract, and a rule on subcontractors. With a provider abroad, the protection there must be comparable to domestic protection. A standard remote-maintenance contract does not, as a rule, meet this.
-
§ 62a StBerGUse of service providers · tax advisors
Identical in wording to § 43e BRAO, referring to § 57 subsection 1 StBerG. For mixed practices this does not mean two regimes but one exercise: one register of providers, one form of undertaking, one body of evidence — otherwise every review turns into a search.
-
§ 147 AORetention of records and data access
Six to ten years of retention, and the period does not expire while the assessment period is still open. In a tax audit the authority may access the stored data directly, even where it sits with a third party. An archive strategy therefore has to stay readable, migratable and exportable across a decade.
Sector facts
| Typical engagements | Law firms and tax practices · single office to several locations · usually a local IT provider in the background |
|---|---|
| Most common triggers | A document sent to the wrong client, a cyber insurer's requirement, the introduction of AI, a change of IT provider |
| Core regulation | § 203 StGB · § 43e BRAO · § 62a StBerG · § 147 AO |
| NIS2 | Not covered by sector · requirements arrive through clients as supplier obligations |
| What we touch first | Remote access, service-provider contracts, permissions that grew over years |
| AI operations | Models in the EU, in Germany or on site · a log of every handover |
| Archive | Readable, migratable and exportable across the full retention period |
| Operating levels | Manual, automated or by playbook — selectable per area |
Asked before the briefing
This page describes the state of the provisions named and does not replace legal advice in an individual case.
-
Does NIS2 apply to our firm?
Not by sector. Legal advice, tax advice, auditing and notarial services do not appear in Annex 1 or Annex 2 of the BSI Act. In scope would be anyone providing managed IT services on the market. What reaches you are the supplier requirements of your regulated clients — contractual, not a reporting duty of your own. -
Is a data processing agreement with our IT provider enough?
No. The agreement under Article 28 GDPR covers data protection, not professional law. § 43e subsection 8 BRAO states expressly that both apply side by side. The professional undertaking in text form, with instruction about the criminal consequences, is a separate document. -
May we use AI on client documents?
Yes, if the provider is treated like any other service provider: under an undertaking in text form, restricted to what is necessary, and with comparable protection where the provider is abroad. Where the analysis serves one individual mandate directly, § 43e(5) BRAO additionally requires the client's consent; § 62a(5) StBerG is identical in wording. In practice that means a model in the EU, in Germany or on your premises, an approval per document class, and a log of every handover. -
Do we have to leave DATEV?
No, and that would not be the lever anyway. The finding almost always sits outside it: in the documents that travel by email, in the archive beside DATEV, in the remote access paths, and in permissions that were never taken back.
Who enters your firm today?
The industry briefing surveys your access paths and service-provider contracts, checks where documents go through AI features, and shows what can actually be evidenced about access over the past months.