Whitepaper · 12 pages · PDF

AI in the law firm. Legally compliant under § 43e BRAO & GDPR.

Innovation in line with professional secrecy and data protection: the whitepaper shows which rules apply to the use of AI in law firms, when it becomes a risk, and how to recognize a tool that complies with professional conduct rules.

Free · Instant PDF · No sales call

12 pagesBRAO · StGB · GDPR · EU AI Act5-point checklist
Free downloadCover of the whitepaper "AI in the Law Firm – Legally Compliant under § 43e BRAO & GDPR"
LexAEU hosting

Servers in Germany, ISO 27001-certified data centers

LexAConsent & DPA

Art. 28 GDPR integrated by default

The legal anchors in the whitepaper
§ 43e BRAOService-provider privilege
§ 203 StGBProhibition on disclosure
Art. 28 GDPRData processing on behalf of the controller
Art. 4 EU AI ActAI literacy (EU AI Act)
Download

Download the free whitepaper now

Sign up – the PDF is available immediately after you submit the form. No sales call, no obligation.

  • Free – 12 pages as a PDF
  • Available immediately – right after submitting
  • GDPR-compliant, hosted in Germany
  • No spam – newsletter only on request
Contents

What to expect in the whitepaper

Eleven compact chapters – from the tension between efficiency and confidentiality, through the legal framework, to the checklist for selecting your tool.

  1. 01
    IntroductionThe transformation of the legal industry
  2. 02
    The tensionEfficiency vs. attorney confidentiality
  3. 03
    The riskWhen does using AI become a risk?
  4. 04
    Legal framework IThe legal framework for using AI in the law firm
  5. 05
    Legal framework IIClient consent
  6. 06
    Legal framework IIIOverview of the legal requirements
  7. 07
    Checklist IThe 5 criteria for AI that complies with professional conduct rules
  8. 08
    Checklist IIThe 5 criteria: certified security & internal firm policies
  9. 09
    The solution for law firmsLexA: Uncompromising compliance meets AI power
  10. 10
    The solution for law firmsLexA: Fully integrated AI assistant & all-in-one platform
  11. 11
    ConclusionFull capability under the attorney's duty of confidentiality
Inside the whitepaper
Two lawyers working together at a laptop
Introduction

The transformation of the legal industry

Artificial intelligence is transforming legal work at a rapid pace. Law firms are under growing pressure to handle matters more efficiently and to optimize internal processes. Generative AI offers enormous potential here – from automated preparation of pleadings to case-file analysis. Yet the use of language models in law firms raises fundamental questions of professional conduct: how can innovation be reconciled with professional secrecy?

This whitepaper examines the legal framework and shows how law firms can use AI in compliance with the GDPR and the BRAO.

The tension

Efficiency vs. attorney confidentiality

The attorney's duty of confidentiality (§ 43a(2) BRAO) and the prohibition on disclosure backed by criminal penalties (§ 203 StGB) are the cornerstones of client trust. The challenge with standard AI tools – such as public versions of ChatGPT – lies in how they process data: these systems often host data on servers in the USA and use user input to further train their AI models.

The risk

When does using AI become a risk?

If unredacted client data is entered into such a system, confidentiality is potentially breached, since the AI provider gains the legal and technical ability to access it. Such a breach can lead to criminal consequences as well as disciplinary sanctions under professional conduct rules.

Public AI tools

Servers in the USA · Training on user input

§ 203 StGB

Disclosing client secrets is a criminal offense

Sanctions

Criminal and disciplinary consequences

Legal framework

Six guardrails for using AI in the law firm

The legislature and the German Federal Bar (BRAK) have set out clear guardrails for IT outsourcing. The whitepaper organizes them into three pairs – here is the overview.

Confidentiality & service providers
§ 43e BRAO

Service-provider privilege

In legal terms, AI providers qualify as IT service providers. Disclosing client secrets to such service providers is permissible provided that use of the service is necessary and a strictly regulated contract (at least in text form) is concluded that obliges the service provider to maintain confidentiality.

§ 43e(4) BRAO

Third-country transfers

If the AI provider's servers are located abroad (e.g. in the USA), the law firm must ensure that a level of data protection comparable to that in Germany applies there. AI solutions with servers located in Germany or the EU are always the safer and simpler route under professional conduct rules.

Client & data
§ 43e(5) BRAO

Client consent

If an AI service "directly serves an individual matter", the service provider's contractual obligation is no longer sufficient. In that case, the client's express consent to the release of data must be obtained in advance.

Art. 28 GDPR

Data processing on behalf of the controller

If the AI processes personal data, concluding a data processing agreement (DPA) under Art. 28 GDPR with the provider is mandatory.

Diligence & competence
§ 43 BRAO

Conscientious professional practice

AI is an assistance system, not a substitute for a lawyer. AI systems are prone to so-called "hallucinations" (fabricated legal assertions). Every AI output must be reviewed by a qualified professional.

Art. 4 EU AI Act

AI literacy

The new EU AI Act requires the proactive development of "AI literacy" among staff – through training and clear approval processes for generated content.

The information provided is intended as professional guidance and does not replace individual legal advice.

Checklist

The 5 criteria for AI that complies with professional conduct rules

To use AI in a legally compliant way in everyday legal practice, law firms should assess every tool against these criteria.

Quick check: Which criteria does your current AI tool meet? Check them off.

  • Servers located in the European Union (ideally in Germany), so that the additional requirements of § 43e(4) BRAO do not apply in the first place.

    How LexA solves it:Operated in ISO 27001-certified German data centers (AWS Frankfurt).
  • The provider must contractually guarantee that client data will under no circumstances be used to train AI models.

    How LexA solves it:Closed ecosystem – no training takes place on client data.
  • A DPA under Art. 28 GDPR and a confidentiality agreement under § 203 StGB and § 43e BRAO must be in place.

    How LexA solves it:Confidentiality agreement and DPA are integrated directly and by default.
  • The provider should be able to demonstrate the highest IT security standards (e.g. ISO 27001).

    How LexA solves it:Hosting on ISO 27001-certified infrastructure, security architecture aligned with ISO/IEC 27001.
  • The law firm must train its staff in the use of the AI and define clear approval processes for generated content.

    How LexA solves it:Role and permission management plus clearly labeled AI output as the basis for your approval processes.
The solution for law firms

LexA: Uncompromising compliance meets AI power

Trying to make general-purpose AI models compliant with professional conduct rules through complex manual redaction costs valuable time. LexA is cloud-native, AI-based law firm software that was developed specifically for the German legal market and solves the compliance problem at its root.

01

Legally compliant infrastructure

LexA is operated in a GDPR-compliant manner in ISO 27001-certified German data centers (AWS Frankfurt). All required confidentiality agreements (§ 203 StGB / § 43e BRAO) and the DPA (Art. 28 GDPR) are integrated directly and by default.

Go to the Trust Center
app.lexatech.de
LexA data protection overview with record of processing activities and data subject access requests
02

Fully integrated AI assistant

LexA's AI operates in a closed ecosystem. No training takes place on client data. Law firms benefit from case-file research with source citations (RAG-based), intelligent case summaries, and automatic extraction of deadlines and data directly from incoming documents.

Explore the AI features
app.lexatech.de
LexAssistent answers a question about the case file with source citations
03

All-in-one platform

LexA is not just an AI tool – it brings together the whole of law firm management: full beA integration with electronic acknowledgement of receipt (eEB), service-disruption notices and active alerts if a beA message could not be delivered – plus AI-supported client intake (triage), collaborative word processing (OnlyOffice) and RVG-compliant e-invoicing (ZUGFeRD/XRechnung). Unlike standalone AI assistants without firm management or traditional law firm software without integrated AI, LexA unites everything in one platform – instead of fragmented point solutions.

All features
app.lexatech.de
beA mailbox directly in the LexA case file
Conclusion

Full capability under the attorney's duty of confidentiality

The question is no longer whether law firms should use AI, but how they do so in a legally compliant way.

Anyone who ignores the strict requirements of the BRAO and the GDPR puts their bar admission and the trust of their clients at risk. With specialized solutions like LexA, law firms don't have to compromise: they get the full capability of state-of-the-art AI technology – embedded in a system designed from the ground up to comply with the attorney's duty of confidentiality.

Portrait of the LexA team: attorney at law and founder

Frequently asked questions about the whitepaper

Is the whitepaper really free?

Yes. You receive the PDF immediately after submitting the form – at no cost, with no sales call and no obligation.

Who is the whitepaper for?

For lawyers, law-firm owners and those responsible for firm organization and IT who use or evaluate AI tools and want to know which professional-conduct and data-protection rules apply.

What happens to my data?

We use your details to provide you with the whitepaper. You will only receive emails about LexA, webinars and new expert content if you check the optional box – revocable at any time. You can find the details in our privacy policy.

Does the whitepaper replace legal advice?

No. It provides professional guidance on § 43e BRAO, § 203 StGB, the GDPR and the EU AI Act, but does not replace an individual legal review of your firm's processes.

Do I need LexA to use the whitepaper?

No. The legal framework and the checklist apply to any AI tool you use in your firm. Chapters 09 and 10 show how LexA implements the requirements.