Blog

Digital bar confidentiality obligations: 2026 guide

A decorative visual adds a graphic touch around the title of the article.

Attorney-client privilege is defined as absolute under French law and covers all digital communications, with no exceptions outside of strictly defined legal frameworks. Digital bar confidentiality obligations do not stop at paper exchanges: they extend to emails, collaborative platforms, artificial intelligence tools, and any digital processing of client data. The National Bar Council (CNB), the Code of Ethics for Lawyers, and the GDPR together form the regulatory foundation that governs these duties. Ignoring any of these sources exposes the attorney to cumulative criminal, disciplinary, and civil sanctions.

Table of contents

What are the key privacy requirements for lawyers using digital tools?

Attorney confidentiality duties do not stop at the door of the physical office. As soon as a digital tool processes client data, the same ethical obligations apply with equal rigor.

A lawyer examines a file in a light-filled office.

The CNB has published a specific guide on ethics and artificial intelligence. This guide requires lawyers to conduct a risk assessment before adopting any AI tool, expressly excluding foreign platforms without guarantees equivalent to European law. This preliminary requirement is non-negotiable: the absence of an assessment already constitutes an ethical violation.

The main obligations to comply with are as follows:

  • European hosting mandatory. The CNB and the CCBE require that tools used be hosted under European jurisdiction, with contractual clauses complying with Article 28 of the GDPR.
  • No retraining with client data. Any AI tool that uses submitted data to improve its models violates attorney-client privilege, unless the client provides explicit and informed consent.
  • Explicit client consent. When personal data is processed by an AI, the client must be informed and give consent, particularly in the engagement letter.
  • Access control and logging. Access to digital files must be traced, limited to authorized persons, and auditable at all times.
  • Informing clients of digital risks. The duty to inform clients about the risks linked to the use of digital tools is an ethical obligation that is often neglected. The lawyer must warn clients in the engagement letter.

Pro tip: Systematically include a specific clause on the use of AI tools in your engagement letters. This clause must specify the tools used, their geographic location, and the security measures applied.

Digital regulations for lawyers are evolving rapidly. Regular monitoring of CNB publications remains essential to maintain compliance.

How does attorney-client privilege apply in the digital context?

Attorney-client privilege is absolute under French law. Article 66-5 of the law of December 31, 1971, and the Penal Code protect all communications between the lawyer and the client, whatever their form, including digital. This absolute protection allows only strictly defined legal exceptions: the fight against money laundering, certain tax obligations, or the explicit consent of the client.

Since February 23, 2026, French law has established a specific "legal privilege" for in-house counsel. This mechanism protects certain internal legal opinions, but remains more restricted than attorney-client privilege. The table below illustrates the fundamental differences.

Infographic: the essentials of digital confidentiality, between legal obligations and best practices

CriterionAttorney-client privilege (lawyer)Legal privilege (in-house counsel)
---
ScopeAbsolute, all communicationsLimited to written legal opinions
ExceptionsMoney laundering, client consentCriminal, tax, EU competition law
EnforceabilityFrench authorities and EUNot enforceable against EU authorities (competition)
Sanction for violationCriminal and disciplinaryPrimarily disciplinary
Mandatory mentionNot requiredYes, explicit mention required

The law of February 23, 2026 thus creates a new boundary between legal confidentiality and data protection within companies. It complicates the role of the data protection officer (DPO), who must now distinguish opinions covered by legal privilege from other internal communications.

Inadequate use of digital tools can constitute a violation of attorney-client privilege, even if unintentional. Sending a client document via unencrypted consumer messaging, or submitting a file to an AI without prior pseudonymization, exposes the lawyer to disciplinary proceedings before the Bar Council and to criminal sanctions.

What are the best practices to guarantee confidentiality on digital tools?

Legal data protection is based on concrete technical measures, not just declarations of intent. Here are the steps to implement in any firm handling client data digitally.

1. Choose sovereign clouds. Consumer hosting solutions do not guarantee compliance with attorney-client privilege. Prioritize HDS or SecNumCloud certified clouds, hosted in France or the European Union.

2. Enable end-to-end encryption. Any communication containing client data must be encrypted. The use of traditional emails without encryption is a frequent source of GDPR violations and ethical incidents.

3. Segment environments by case. Each client or matter must have a separate digital space, with individualized access rights. This segmentation limits the spread in the event of an incident.

4. Appoint a DPO. A data protection officer is recommended from 10 employees and mandatory from 50 members according to the CNB and the GDPR. The DPO coordinates governance, trains teams, and manages the relationship with the CNIL.

5. Conduct a DPIA before any AI deployment. The data protection impact assessment (DPIA) is mandatory if the risk is high. It must precede any deployment of AI tools in a law firm.

The following table summarizes the risk levels associated with the main types of digital tools used in practice.

Tool TypeRisk levelPriority measure
---
Consumer messagingHighEnd-to-end encryption or replacement
Foreign cloud (outside EU)Very highMigration to EU hosting
General AI without pseudonymizationCriticalMandatory prior pseudonymization
Certified sovereign cloudLowLogging and access control
AI with integrated pseudonymizationControlledRegular audit and DPIA

Pro tip: [Anonymizing only names](https://aizenia.fr/professions-liberales-ia/secret-professionnel-avocat-outils-numeriques/) is insufficient to protect attorney-client privilege from an AI. The overall narrative context of the document can enable re-identification. Pseudonymize the entire context, including references to characteristic places, dates, and situations, before any processing by an artificial intelligence tool.

Consumer AI platforms cannot guarantee absolute compliance with attorney-client privilege. The risks of data transfer outside the EU or uncontrolled retraining remain real. Prior pseudonymization of documents constitutes the only technical measure allowing these tools to be used without compromising confidentiality. Safe-doc offers this layer of protection in real time, without storing the processed documents.

How to integrate confidentiality into internal policies and digital contracts?

Compliance with bar confidentiality standards is not limited to technical tools. It requires a structured internal organization and precise contractual commitments with each digital service provider.

The essential points to cover in your internal policies are as follows:

  • Draft a data processing agreement (DPA) with each AI service provider. This contract, required by Article 28 of the GDPR, must specify the purposes of the processing, the security measures, the location of the data, and the deletion conditions.
  • Formalize a confidentiality commitment for each employee. Any member of the firm with access to client data must sign a written commitment, updated whenever the tools used change.
  • Implement an incident management procedure. In the event of a data breach, notification to the CNIL within 72 hours is mandatory. This procedure must be documented, tested, and known to all employees concerned.
  • Inform clients in the engagement letter. Lawyers must warn their clients of the risks associated with their own use of digital tools. This information must be explicitly included in the engagement letter, not just in the general terms and conditions.
  • Ensure continuous regulatory monitoring. The GDPR, CNB recommendations, and European texts evolve regularly. A biannual review schedule for internal policies is a minimum practice. To improve the drafting of contractual clauses with AI service providers, the guide on AI contract confidentiality provides models adapted to law firms.

The digital professional responsibility of the lawyer engages personal liability. A firm that is well organized contractually and internally significantly reduces its exposure to disciplinary sanctions and client disputes.

Key points

Digital bar confidentiality obligations require absolute protection of client data at every stage of digital processing, from messaging to artificial intelligence.

PointDetails
--
Absolute attorney-client privilegeCovers all digital communications with no exceptions outside the strict legal framework.
Prior risk assessmentAny AI tool adoption requires a risk analysis and a DPIA if the risk is high.
Pseudonymization of the global contextAnonymizing only names is insufficient; the entire narrative context must be de-identified.
DPO mandatory from 50 membersRecommended from 10 employees, the DPO coordinates compliance and the relationship with the CNIL.
CNIL notification within 72 hoursAny data breach must be reported to the CNIL within this mandatory legal deadline.

What practice reveals about digital confidentiality in law firms

Most of the confidentiality incidents I observe in law firms do not stem from ignorance of the rules. They result from a gap between stated policy and actual daily practices. A lawyer knows that attorney-client privilege is absolute. But the same lawyer submits a client memo to ChatGPT without pseudonymization because it's fast and no one controls.

What I have learned over the years is that digital compliance does not depend on the existence of an internal charter. It depends on friction. If the secure tool is more restrictive than the consumer tool, employees will choose the consumer tool. The solution is not to multiply prohibitions, but to make the secure path as simple as the risky path.

The law of February 23, 2026, on legal privilege adds an additional layer of complexity for corporate legal departments. The DPO must now arbitrate between legal confidentiality and GDPR obligations on documents that fall under both regimes at the same time. This is a minefield that few firms have anticipated.

My conviction is that systematic pseudonymization before any AI processing is the only measure that truly reconciles productivity and compliance. It does not slow down work if it is integrated into the existing workflow. And it protects the lawyer even if the AI platform used has unknown flaws. Consult the guide on using ChatGPT without violating attorney-client privilege for concrete implementation in your practice.

- Jacques

Safe-doc for digital compliance of law firms

Law firms that handle sensitive files with AI tools face a concrete risk: exposing client data to platforms that do not comply with attorney-client privilege. Safe-doc addresses this problem by pseudonymizing documents in real time, before sending them to an AI tool, without durably storing the processed files.

https://safe-doc.ai

Safe-doc integrates into existing workflows without requiring tool changes. Lawyers continue to use the AI tools they know, with a layer of protection compliant with the GDPR and CNB recommendations. The page dedicated to DPOs and law firms details the auditing, pseudonymization, and compliance support functionalities available for legal structures of all sizes.


Frequently asked questions

Does attorney-client privilege cover exchanges by e-mail?

Yes. Attorney-client privilege applies to all digital communications, including emails. The absence of end-to-end encryption exposes the lawyer to an ethical risk and to an obligation to notify the CNIL in the event of a breach.

Can a lawyer use ChatGPT to handle client files?

A lawyer can use AI tools provided that the entire context of the document is pseudonymized before processing. Submitting a non-pseudonymized file to a consumer platform constitutes a potential violation of attorney-client privilege.

Legal privilege, created by the law of February 23, 2026, protects certain written legal opinions from in-house counsel. It is more restricted than attorney-client privilege and does not apply in criminal, tax, or European competition law matters.

At what threshold must a firm appoint a DPO?

A DPO is recommended from 10 employees and mandatory from 50 members according to the recommendations of the CNB and the rules of the GDPR. The DPO coordinates compliance, trains teams, and manages relations with the CNIL.

What is a DPIA and when is it mandatory in a law firm?

The data protection impact assessment (DPIA) is a formal risk assessment relating to data processing. It is mandatory before any deployment of an AI tool presenting a high risk to the rights and freedoms of the people concerned.

Recommendation