Skip to main content
LexLogik LogoLexLogik

Insights for law firms

German § 43e BRAO and cloud tools: practical checks for firms

By Clemens Jonathan Schmid

What to clarify before third-party IT touches client papers - calmly, with documentation you can defend.

For lawyers in Germany, involving third parties with client data is not a side issue. Section 43e of the Federal Lawyers’ Act (BRAO) frames the use of service providers - alongside GDPR and professional secrecy. Cloud OCR or PDF tools enter that analysis as soon as matter content is processed.

Core of the review

The questions are whether the provider was chosen carefully, bound adequately, and whether the firm keeps the insight and control it needs. “Free and convenient” does not replace that review. Nor does brochure language without contractual and technical substance.

Short internal notes help: tool purpose, data types, location, DPA in place, support access, deletion, who approved. That is not bureaucracy for its own sake - it is the trail you need when questions come.

Checks before rollout

  • Narrow purpose: which steps, which matter types?
  • Contractual cover (DPA, secrecy, sub-processors).
  • Technical and organisational measures described clearly?
  • Day-to-day instruction and control realistic?
  • Exit: export and deletion clear?
  • Training: who may upload what?

Relationship to GDPR

BRAO duties and data protection run in parallel. A solid DPA is necessary but not automatically enough for the professional-law assessment. Conversely, professional care does not replace a legal basis or TOMs. Bring both lenses into one decision - ideally with a named owner (compliance / IT / partner).

LexLogik targets firms with hosting in Germany and short processing windows; professional-law clearance remains each firm’s task and advice.

Internal IT and external providers

Section 43e BRAO is not only about SaaS. Classic IT providers, hosting and support access sit in the same diligence logic. One checklist for third-party IT touching matters prevents double standards.

When unsure, seek chamber guidance or professional advice before rollout. Documentation may be short if it exists and can be found.

Avoid shadow IT

Bans without alternatives drive private cloud accounts. Better: a few approved tools with clear boundaries - no permanent storage, no matter-chat uploads.

Usability in daily work

Bans without alternatives drive shadow IT (private cloud accounts, messenger conversions). Better: a few approved tools with clear boundaries (“no permanent storage”, “no matter-chat uploads”). Section 43e then stays manageable rather than abstractly threatening.

Approval note before rollout

Before a cloud tool touches matters, record purpose, data types, location, processor agreement and who approved on one page. On client or regulator questions you then have a trail - not only spoken assurances.

Include sub-processors in the review

Check not only the main contract but the sub-processor list and change notices. A tool can host in Germany and still outsource critical processing steps. Fix who in the firm reviews those lists yearly. Otherwise the professional-rules review stops at the brochure and falls short in practice.

Professional rules on service providers (such as § 43e BRAO for German counsel) demand careful selection and control - including OCR and PDF tools that process matter content. Narrow purpose, reviewed contracts and governed support access make the duty practical. “Handy and cheap” does not replace that review.

10 days free

Try LexLogik in your practice

All features unlocked. No credit card. No automatic subscription.