Professionals bound by secrecySolution · Use AI for client, patient and case work without breaching confidentiality under § 203 StGB

AI for professionals bound by secrecy: § 203 StGB & confidentiality, done properly | meinGPT

How lawyers, tax advisers, auditors, doctors, notaries and psychotherapists use AI despite their duty of confidentiality: the 'contributing person under § 203 StGB' construction, EU hosting, a DPA, no training on input — with real workflows, an example prompt, clear limits and selection criteria.

For Lawyers, tax advisers, auditors, doctors, notaries, psychotherapists and consultants handling protected secrets.

Who it is for
Lawyers, tax advisers, auditors, doctors, notaries, psychotherapists and consultants handling protected secrets
Impact
Written preparation supported — every secrecy-relevant statement stays with the professional, and confidentiality is preserved
Task
Use AI for client, patient and case work without breaching confidentiality under § 203 StGB
Short answer

§ 203-compliant AI use for professionals bound by secrecy means using generative AI in a way that preserves the criminally sanctioned duty of confidentiality under § 203 StGB. Anyone processing third-party secrets as a lawyer, tax adviser, auditor, doctor, notary or psychotherapist may only use external IT and AI if the provider is legally involved as a 'contributing person under § 203 (3) StGB': the provider and the people it deploys must be bound to secrecy. Rights of information and inspection are not prescribed by § 203 StGB — they have to be agreed contractually (for lawyers and tax advisers, § 43e BRAO and § 62a StBerG set out what the service contract must contain). Technically, EU operation, a data processing agreement (DPA) and the contractual assurance that input is not used to train the models are added. meinGPT offers professionals bound by secrecy exactly this separate confidentiality undertaking under § 203 StGB: in it, SelectCode commits in writing to secrecy as a contributing person under § 203 (3) sentence 2 StGB. The AI handles the preparatory work — the professional reviews and owns every substantive statement.

How it works

From the task to productive AI use

Legally, the core question is not "is AI allowed at all?" but "is the provider involved as a contributing person?". Since the revision of § 203 StGB, the legislator expressly allows professionals bound by secrecy to make use of 'contributing persons' in exercising their profession — external IT and AI providers, for instance — provided their involvement is necessary and they are bound to secrecy. meinGPT reflects exactly that construction in a separate confidentiality undertaking under § 203 StGB — its own signable contract, not part of the standard terms: in it, SelectCode commits in writing to secrecy as a contributing person under § 203 (3) sentence 2 StGB, keeps entrusted third-party secrets confidential (continuing beyond the end of the contract), obtains only the knowledge necessary to perform the contract, and binds all deployed staff and any sub-contractors (and their staff) to confidentiality in writing in advance; the undertakings are to be produced to the professional on request. Disclosure occurs only where an official or judicial duty requires it — with prior notice where permissible. Technically this runs on a platform that bundles several models behind one interface with central permission management, is operated in the EU, provides for a DPA and does not use input for training. The professional therefore stays master of the secret: the AI prepares letters, research and documents; the substantive review and the responsibility stay with them.

Who it is for
Lawyers, tax advisers, auditors, doctors, notaries, psychotherapists and consultants handling protected secrets
Impact
Written preparation supported — every secrecy-relevant statement stays with the professional, and confidentiality is preserved
Task
Use AI for client, patient and case work without breaching confidentiality under § 203 StGB
Use cases

What Professionals bound by secrecy gets done with AI

Concrete, repeatable flows — from the first prompt to a dependable result.

01

Draft client and patient communication

From bullet-point input, the assistant drafts a letter to a client, patient or other party in the desired tone of voice. The professional checks the content and its legal or substantive accuracy and approves — the AI takes over the drafting, not the responsibility for the statement.

02

Pre-capture and structure documents and records

From uploaded pleadings, contracts, findings or receipts, the assistant extracts structured fields and summarises the key points. The pre-capture serves the overview; every detail relevant to a secret or a decision is checked against the original before it is used further.

03

Research with sources as preparation

As preparation, the assistant researches publicly available information and summarises it with source references. The result is a working basis, not binding legal, tax or medical advice — the assessment and the conclusion are made by the professional.

04

Knowledge management in a firm, practice or audit company

An assistant connected to internal precedents, guidelines and handbooks answers recurring questions (deadlines, procedures, internal standards) with a source reference — for the team, with permissions, without protected client or patient data leaving the organisational boundary.

05

Build an assistant with a fixed review rule

Without programming, the firm or practice assembles an assistant with its own templates and a fixed review reminder ('Draft — to be reviewed and owned by the professional') and releases it to the team. Human control is thereby anchored in the workflow rather than optional.

Open example

A real prompt, a real answer

Nothing hidden — you see the input and the result before you sign up.

Prompt

I am a professional bound by secrecy preparing a letter to a client/patient. From my bullet points, draft a polite, factual text and output it as a table per section: section, draft text, review note for me. Make no binding legal or substantive statement and flag every point where I need to check or add something professionally. Bullet points: appointment confirmation, documents needed, note on an open question.

How meinGPT works on your task
meinGPT's answer
SectionDraft text (proposal)Review note
Salutation & reference"Dear …, thank you for your message of …"Check the date/reference
Appointment confirmation"I am glad to confirm our appointment on … at …."Check the appointment against the calendar
Documents needed"Please bring … so that we can discuss …."⚠ Check professionally: which documents are needed in this specific case
Open question"Regarding your question about …, I will come back to you separately after review."⚠ No binding information in the draft — to be answered by the professional
Closing"Kind regards"Sign-off by the professional before sending
Ready to use

Put it to work in your own company

In a short live demo we show how this solution runs in your company with meinGPT, GDPR-compliant — using your own use cases.

Book a live demo

Or download the AI for professionals bound by secrecy — the § 203 selection criteria (PDF, German) as a PDF:

AI for professionals bound by secrecy — the § 203 selection criteria (PDF, German)By email

A work email is enough — processed in line with the GDPR.

GDPR & security

Built for enterprise compliance

For professionals bound by secrecy, the central assurance is a separate confidentiality undertaking under § 203 StGB — its own signable contract, not part of the standard terms: in it, SelectCode commits in writing to secrecy as a contributing person under § 203 (3) sentence 2 StGB, keeps entrusted secrets confidential (including beyond the end of the contract) and obtains only the knowledge necessary to perform the contract. All deployed staff and any sub-contractors (and their staff) are likewise bound to confidentiality in writing in advance — a contractual commitment, not merely a statutory assumption; unauthorised disclosure by a contributing person is a criminal offence under § 203 (4) StGB. The undertakings are to be produced to the professional on request. Disclosure occurs only where an official or judicial duty requires it, with prior notice where permissible. Technically, operation takes place within the EU, a data processing agreement (DPA) is standard, and input is not used to train the models. Access follows the least-privilege principle through central permission management with SSO and is traceable through audit logs. meinGPT is operated by the ISO 27001 certified SelectCode GmbH, which has its security reviewed regularly through independent penetration tests (most recently SySS, 2025); the certificate and evidence are available through the Trust Center. Protected client and patient data therefore stays under control rather than being processed through private AI accounts (shadow AI).

What matters when choosing
  • § 203 StGB: Does the provider commit itself in writing to confidentiality as a contributing person (§ 203 (3) sentence 2 StGB) — and does it undertake contractually to bind its staff and any sub-contractors in writing too, with the undertakings to be produced to the professional on request?
  • Place of processing & sub-contracting: Is data processed within the EU, and are any sub-contractors (and their staff) likewise bound to confidentiality in writing?
  • DPA: Is there a data processing agreement under Art. 28 GDPR governing instruction-bound processing, technical and organisational measures and deletion duties?
  • No training on input: Is it contractually assured that prompts, uploads and client/patient data are not used to train the models?
  • Roles, permissions & logging: Is there central user and permission management, SSO, least-privilege access and audit logs to evidence access to protected material?
  • Client/patient separation: Can cases, matters or patient data be kept cleanly apart instead of being mixed in one shared, uncontrolled context?
  • Adoption & enablement: Is there training and are there champions, so the firm or practice uses AI correctly, with review and without detouring through private shadow AI?
Limits & failure modes

What this solution cannot (yet) do

Honesty is part of the solution. These limits are known — and therefore plannable.

01

AI is preparation, not legal, tax or medical advice: drafts, summaries and research are working materials; every substantive assessment and decision is made and owned by the professional.

02

Special categories of personal data (Art. 9 GDPR, health data in particular) and secrecy-protected client/patient data require additional care, narrow releases and, in case of doubt, a separate legal assessment of the individual case.

03

Confidentiality and the responsibility for preserving the secret always remain with the professional; contractually involving the provider as a contributing person does not relieve them of their own duty of care and review.

04

AI models can misrepresent or invent content; no draft and no summary may go out without review. A four-eyes or sign-off principle is strongly recommended.

05

This page does not replace legal advice. Whether and how AI may be used in a specific profession should be clarified with the competent professional chamber and/or legal counsel.

FAQ

Frequently asked questions

Yes — if the provider is legally involved as a contributing person under § 203 (3) StGB. § 203 StGB expressly allows professionals bound by secrecy to make use of contributing persons (external IT and AI providers, for instance) in exercising their profession, provided their involvement is necessary and they are bound to secrecy. At meinGPT this is reflected in a separate confidentiality undertaking under § 203 StGB — its own signable contract, not part of the standard terms: SelectCode commits in writing to secrecy as a contributing person under § 203 (3) sentence 2 StGB and binds all deployed staff and any sub-contractors in writing as well, contractually; the undertakings are to be produced to the professional on request. Unauthorised disclosure by a contributing person is a criminal offence under § 203 (4) StGB. The substantive responsibility and the duty of confidentiality stay with the professional.

Related solutions

AI in accounting & finance: receipts, invoices, reporting | meinGPTHow accounting and finance teams use AI GDPR-compliantly: pre-capture receipts and invoices, extract data, prepare reporting — with real workflows, an example prompt, strict review limits and selection criteria.Creating AI agents: build your own agents without code | meinGPTWhat an AI agent is (and how it differs from an assistant and a chatbot) and how companies build their own AI agents without programming: goal, instruction, knowledge (RAG), tools & actions, guardrails and approval — with a build guide, an example, governance, a checklist and GDPR.AI in customer service: enquiries, knowledge base, tickets | meinGPTHow customer service teams use AI GDPR-compliantly: answer enquiries faster, search the knowledge base, summarise tickets and reply consistently — with real workflows, an example prompt, honest limits and selection criteria.