DeepScript
Privacy & compliance

Transcription in Law Firms: Privilege and GDPR in Practice

German professional secrecy makes law firm transcription a criminal-law question, not only a data protection one. What section 203 StGB demands of a vendor, and how to organise it so it holds up.

Julian KisselJulian KisselAugust 14, 2026Updated August 14, 20268 min read

Key takeaways

  • In Germany a transcription vendor handling client audio must be bound to secrecy in writing and told it can be prosecuted for a breach.
  • A GDPR processing agreement alone is not enough: it covers data protection, not the criminal-law duty under section 203 StGB.
  • Uploading a client recording to a free tool breaches professional rules, criminal law, the GDPR and most likely the firm's own insurance terms at once.
  • The vendor question that decides everything is where the machine doing the recognition physically stands.

Client interviews, witness statements, board meetings inside an internal investigation: law firms work daily with audio that ranks among the most sensitive material in the economy. A single carelessly uploaded file can endanger a mandate, trigger professional sanctions, expose an individual lawyer to criminal prosecution, and draw a GDPR fine of up to four per cent of annual turnover.

It still happens ad hoc. A junior drops the interview recording into a US cloud service because it has to be done by this evening.

This article is written from the German position, which is the strictest in Europe and therefore the useful benchmark: if a setup satisfies German professional secrecy law, it satisfies privilege rules in jurisdictions that stop at civil liability. If your firm has a German office, instructs German counsel, or handles EU client data, the analysis below applies to you directly.

Section 43a BRAO: confidentiality as a fundamental duty

Der Rechtsanwalt ist zur Verschwiegenheit verpflichtet. Diese Pflicht bezieht sich auf alles, was ihm in Ausübung seines Berufes bekanntgeworden ist.
Section 43a (2) BRAO · abgerufen 2026-08-13

The German Federal Lawyers' Act obliges every lawyer to secrecy about everything learned in the exercise of the profession. The duty is comprehensive, unlimited in time, and not restricted to what the client says: it covers every piece of information gathered under the mandate, so witness statements, recordings of interviews, calls with opposing counsel and internal case discussions are all inside it.

Breaches are actionable twice over: through professional discipline, up to disbarment, and through criminal law under section 203 (1) no. 3 StGB, which carries up to one year of imprisonment or a fine.

Section 203 StGB and the duty-bound professional

Section 203 (1) no. 3 StGB makes the unauthorised disclosure of secrets by a lawyer a criminal offence. The part that matters for vendor selection came in a 2017 amendment: subsections 3 and 4 now expressly permit bringing in external service providers, but only on conditions.

  1. The provider must be bound to secrecy in writing.
  2. It must be told expressly that it can be prosecuted under section 203 (4) sentence 3 StGB.
  3. The provider thereby becomes a duty-bound party itself and can be prosecuted if it discloses the secret.

A transcription vendor processing a client interview falls squarely inside this. Uploading an MP3 to an online service that has signed no written undertaking and been given no such notice is not a compliance gap. It is an offence under section 203 (1) StGB, committed by the individual lawyer rather than by the firm.

This is the point that surprises foreign counsel most often. In most common-law jurisdictions, using an inadequate vendor is a professional-conduct and negligence problem. In Germany it is prosecutable, and the exposure is personal.

Article 9 GDPR: special categories

Many client matters carry data under Article 9 (1): health data in medical liability work, ethnic origin in asylum cases, criminal convictions in defence work, sexual life in family matters. Processing is prohibited unless an exception in Article 9 (2) applies; for legal work the relevant one is Article 9 (2)(f), processing for the establishment, exercise or defence of legal claims.

That basis carries the processing the mandate needs. It does not carry a transfer to a US provider without adequate safeguards, and it certainly does not carry the use of the material to train a speech model.

Article 28 GDPR: the processing agreement

Engaging an external transcription service is processing on your behalf. The agreement must contain everything Article 28 (3) requires and be concluded before the first transfer. Firms should insist on one thing beyond the standard template: the agreement must acknowledge the professional-law position, specifically the provider's undertaking under section 203 (4) StGB. A standard DPA does not contain it, because data protection law and criminal secrecy law are different regimes with different consequences.

Where firms get burned

Schrems II and the US cloud trap

Several popular transcription services, Otter, Fireflies and Rev among them, are US companies. Even where they offer EU endpoints, the CLOUD Act reaches the parent: a US authority can order production regardless of where the data physically sits. In Schrems II (C-311/18) the Court of Justice held that US law does not offer protection comparable to Articles 7 and 8 of the Charter.

For legal data that bites twice. On the professional side, section 43a BRAO demands active protection of the secret, which is hard to reconcile with transferring it into a jurisdiction where state bodies can compel access. On the data protection side, transfers to the US require standard contractual clauses plus supplementary technical measures, and for audio carrying privileged content there is no measure that sufficiently reduces the risk, because the provider needs the audio in cleartext to transcribe it.

Free online tools

The fastest and most dangerous route. Such services typically have no processing agreement, terms that grant a licence to use the content for model training, no stated processing location, and no way to evidence deletion. A single upload breaches section 43a BRAO, section 203 (1) StGB, Articles 6, 9, 28 and 44 GDPR, and in all likelihood the firm's professional indemnity terms simultaneously.

Bring-your-own-AI

Increasingly common: pasting client material into ChatGPT, Claude or a similar consumer front-end. Using the free interface breaches every duty listed above. Business tiers with a "no training on inputs" commitment solve part of the problem and leave the rest, because the data still lands on US infrastructure and the disclosure to a third party has already happened.

Three patterns from practice

Recorded client interview. A white-collar defence firm records first interviews with the client's consent to capture the facts completely. The file goes from an encrypted internal drive to a GDPR-compliant transcription service, and within hours the transcript with speaker separation sits in the matter folder. The original recording is deleted automatically after 30 days; the transcript stays part of the file. What carries it: the client's consent to recording, a processing agreement that includes the section 203 (4) undertaking, processing exclusively on servers in Germany, and complete deletion documentation.

Witness interviews in an internal investigation. Compliance investigations often mean dozens of employee interviews. The data protection requirements are stricter here, because those conversations regularly contain health data, statements about third parties, and material with employment-law consequences. A professional setup uses custom vocabulary for company terminology, speaker separation to keep the interviewer's contributions apart from the interviewee's, and a per-matter deletion plan agreed before the first interview.

Arbitration and mediation. International arbitration is transcribed verbatim. Counsel transcribing the daily sessions to prepare the next hearing is handling material that frequently touches corruption or antitrust allegations. Data residency is critical: a transfer to a US provider would compromise confidentiality towards the other parties to the arbitration, not only towards the client.

The vendor checklist

  • Processing location documented? Every step, upload, transcription, storage and backup, inside the EEA.
  • No US sub-processors? In particular no OpenAI, Google or AWS speech API in the backend. This is the one that hides best.
  • Article 28 agreement? Complete, in writing, before the first transfer.
  • Section 203 StGB undertaking included? Written commitment to secrecy plus express notice of criminal liability.
  • Encryption in transit and at rest? TLS 1.2 or higher, AES-256 at rest.
  • Evidence of deletion? Automated deletion after a configurable period, recorded in an audit log.
  • Certification? ISO 27001 at minimum for the hosting provider.
  • Staff undertakings? Written confidentiality commitments from every employee of the processor with access.
  • Insurance? The provider's own cover for data protection incidents.
  • Access and erasure workable? A practical path for when a client invokes Article 15 or 17.

The single question that decides most of this: where does the machine performing the speech recognition physically stand? Everything else follows from the answer.

How DeepScript fits a law firm

  • Servers in Germany. Hetzner data centres in Falkenstein and Nuremberg, ISO 27001 certified. No US owner, no US parent, no CLOUD Act exposure.
  • Own speech recognition. No API calls to OpenAI, Google or AWS. The whole chain runs on our infrastructure.
  • A processing agreement with the section 203 StGB clause. Our standard agreement contains the processor's undertaking under section 203 (4) StGB and the express notice of criminal liability. It is signable on the website.
  • Configurable deletion. You define when audio and transcript go. By default audio is deleted immediately after successful transcription.
  • Custom vocabulary. Firm terminology, client names, case references.
  • Speaker separation, included in every tier rather than sold as an upgrade.
  • Exports as TXT, SRT, VTT, JSON and DOCX, for dictation workflows, evidence records and electronic case files.

Conclusion

Transcription in a law firm is a professional and criminal-law question before it is a data protection one. The wrong vendor risks a fine; it also risks a prosecution of the individual lawyer and a professional sanction on top.

The answer is not to avoid transcription. It is a provider with EU processing, a processing agreement that carries the section 203 clause, and no US sub-contractor anywhere in the chain.

The full documentation, including the sub-processor list, is in the Trust Center; the sector page for firms is here. If the recordings come out of Zoom or Teams, the compliant pattern for that is this article.

law firmprivilegeprofessional secrecyGDPRsection 203 StGBcompliance

Sources

  1. [1]Section 203 StGB, violation of private secrets · Federal Office of Justice · 2026-08-13
  2. [2]Section 43a BRAO, fundamental duties of the lawyer · Federal Office of Justice · 2026-08-13
  3. [3]Regulation (EU) 2016/679 (GDPR) · EUR-Lex
Privacy & compliance

What GDPR, professional confidentiality and MiFID II actually require when you transcribe.

More in this topic

All articles on this topic

Related pages

Try it yourself?

Three transcriptions free, no credit card. Data stays in Germany.

Transcription in Law Firms: Privilege and GDPR in Practice | DeepScript