Blog

Digital bar confidentiality obligations: 2026 guide

The lawyer's professional secrecy is defined as absolute by French law and covers all digital communications, with no possible exception outside the strict legal framework. The digital bar confidentiality obligations are not limited to paper exchanges: they extend to emails, collaborative platforms, artificial intelligence tools and any processing of customer data digitally. The National Bar Council (CNB), the Code of Ethics for Lawyers and the GDPR together form the normative base which governs these duties. Ignoring any of these sources exposes the lawyer to cumulative criminal, disciplinary and civil sanctions.

What are the key privacy requirements for lawyers using digital tools?

Attorney confidentiality duties do not stop at the door of the physical office. As soon as a digital tool processes customer data, the same ethical obligations apply with the same rigor.

A lawyer examines a file in his light-filled office.

The CNB has published a specific guide on ethics and artificial intelligence. This guide requires lawyers to carry out a risk assessment before adopting any AI tool, expressly excluding foreign platforms without guarantees equivalent to European law. This preliminary requirement is non-negotiable: the absence of an evaluation already constitutes an ethical violation.

The main obligations to respect are as follows:

  • European hosting required. The CNB and the CCBE require that the tools used be hosted under European jurisdiction, with contractual clauses complying with article 28 of the GDPR.
  • No retraining with customer data. Any AI tool that uses submitted data to improve its models violates professional secrecy, unless the customer has explicit and informed consent.
  • Explicit consent from the client. When personal data is processed by an AI, the client must be informed and give their consent, particularly in the engagement letter.
  • Access control and logging. Access to digital files must be traced, limited to authorized persons and auditable at any time.
  • Informing clients on digital risks. The duty to inform on the risks linked to the use of digital tools is an ethical obligation that is often neglected. The lawyer must warn his clients in the engagement letter.

Pro tip: Systematically include a specific clause on the use of AI tools in your mission letters. This clause must specify the tools used, their geographical location and the security measures applied.

Lawyer digital regulations are evolving rapidly. Regular monitoring of CNB publications remains essential to maintain compliance.

How does professional secrecy apply in the digital context?

The lawyer's professional secrecy is absolute according to French law. Article 66-5 of the law of December 31, 1971 and the Penal Code protect all communications between the lawyer and his client, whatever their form, including digital. This absolute protection only suffers from strictly regulated legal exceptions: the fight against money laundering, certain tax obligations, or the explicit consent of the client.

Since February 23, 2026, French law has established a specific “legal privilege” for in-house lawyers. This mechanism protects certain internal legal opinions, but remains more restricted than professional secrecy of the lawyer. The table below illustrates the basic differences.

Infographic: the essentials of digital confidentiality, between legal obligations and good practices

CriterionProfessional secrecy (lawyer)Legal privilege (corporate lawyer)
ScopeAbsolute, all communicationsLimited to written legal opinions
ExceptionsMoney laundering, customer consentCriminal, fiscal, competition law EU
OpposabilityFrench authorities and EUNot enforceable against EU authorities (competition)
Sanction in case of violationCriminal and disciplinaryMainly disciplinary
Mandatory mentionNot requiredYes, explicit mention required

The law of February 23, 2026 thus creates a new frontier between legal confidentiality and data protection within companies. It complicates the role of the data protection officer (DPD), who must now distinguish opinions covered by legal privilege from other internal communications.

Inadequate use of digital tools can constitute a violation of professional secrecy, even unintentional. Sending a client document via unencrypted general public messaging, or submitting a file to an AI without prior pseudonymization, exposes the lawyer to disciplinary proceedings before the Bar Council and to criminal sanctions.

What are the best practices to guarantee confidentiality on digital tools?

Legal data protection is based on concrete technical measures, not just declarations of intent. Here are the steps to implement in any firm dealing with customer data digitally.

1. Choose sovereign clouds. Consumer hosting solutions do not guarantee compliance with professional secrecy. Choose HDS or SecNumCloud certified clouds, hosted in France or the European Union.

2. Enable end-to-end encryption. Any communication containing customer data must be encrypted. The use of traditional emails without encryption is a frequent source of GDPR violations and ethics incidents.

3. Partition environments by file. Each client or business must have a separate digital space, with individualized access rights. This compartmentalization limits the spread in the event of an incident.

4. Appoint a DPO or DPD. A data protection delegate is recommended from 10 employees and mandatory from 50 members according to the CNB and the GDPR. The DPO coordinates governance, trains teams and manages the relationship with the CNIL.

5. Carry out an AIPD before any AI deployment. The data protection impact assessment (DPIA) is mandatory if the risk is high. It must precede any deployment of AI tools in a law firm.

The following table summarizes the risk levels associated with the main types of digital tools used in the office.

Tool TypeRisk levelPriority measure
Consumer messagingHighEnd-to-end encryption or replacement
Foreign cloud (non-EU)Very highMigration to EU hosting
General AI without pseudonymizationReviewMandatory prior pseudonymization
Certified Sovereign CloudLowLogging and access control
AI with integrated pseudonymizationMasteredRegular audit and AIPD

Pro tip: Anonymize only names is insufficient to protect professional secrecy in the face of an AI. The overall narrative context of the document may enable re-identification. Pseudonymize the entire context, including references to characteristic places, dates and situations, before any processing by an artificial intelligence tool.

Consumer AI platforms cannot guarantee absolute compliance with professional secrecy. The risks of data transfer outside the EU or retraining without control remain real. Prior pseudonymization of documents constitutes the only technical measure allowing these tools to be used without compromising confidentiality. Safe-doc offers this layer of protection in real time, without storing the processed documents.

How to integrate confidentiality into internal policies and digital contracts?

Compliance with bar privacy standards is not limited to technical tools. It requires a structured internal organization and precise contractual commitments with each digital service provider.

The key points to cover in your internal policies are:

  • Draft a data processing agreement (DPA) with each AI service provider. This contract, provided for by Article 28 of the GDPR, must specify the purposes of the processing, the security measures, the location of the data and the deletion conditions.
  • Formalize a confidentiality commitment for each employee. Any member of the firm with access to customer data must sign a written commitment, updated whenever the tools used change.
  • Implement an incident management procedure. In the event of a data breach, notification to the CNIL within 72 hours is mandatory. This procedure must be documented, tested and known to all employees concerned.
  • Inform clients in the engagement letter. Lawyers must warn their clients of the risks associated with their own use of digital tools. This information must be explicitly included in the engagement letter, not just in the general conditions.
  • Ensure continuous regulatory monitoring. The GDPR, the CNB recommendations and European texts evolve regularly. A biannual review schedule for internal policies is a minimum practice. To improve the drafting of contractual clauses with AI service providers, the guide to AI contract confidentiality provides models adapted to firms.

The digital professional responsibility of the lawyer involves his personal responsibility. A firm that is well organized contractually and internally significantly reduces its exposure to disciplinary sanctions and client disputes.

Key points

Digital bar confidentiality obligations require absolute protection of customer data at every stage of digital processing, from messaging to artificial intelligence.

PointDetails
Absolute professional secrecyCovers all digital communications without exception outside the strict legal framework.
Prior risk assessmentAny AI tool adoption requires a risk analysis and AIPD if the risk is high.
Pseudonymization of the global contextAnonymizing only names is insufficient; the entire narrative context must be deidentified.
DPO mandatory from 50 membersRecommended from 10 employees, the DPO coordinates compliance and the relationship with the CNIL.
CNIL notification within 72 hoursAny data breach must be reported to the CNIL within this mandatory legal deadline.

What practice reveals about digital privacy in the office

Most of the confidentiality incidents I observe in firms do not stem from ignorance of the rules. They result from a gap between the stated policy and actual daily practices. A lawyer knows that professional secrecy is absolute. But the same lawyer submits a client memo to ChatGPT without pseudonymization because it's fast and no one controls.

What I have learned over the years is that digital compliance is not about having an internal charter. It comes down to friction. If the secure tool is more restrictive than the general public tool, employees will choose the general public tool. The solution is not to increase the number of bans, but to make the safe path as simple as the risky path.

The law of February 23, 2026 on legal privilege adds an additional layer of complexity for corporate legal departments. The DPO must now arbitrate between legal confidentiality and GDPR obligations on documents that fall under both regimes at the same time. This is a minefield that few firms have anticipated.

My conviction is that systematic pseudonymization before any AI processing is the only measure that truly reconciles productivity and compliance. It does not slow down work if it is integrated into the existing flow. And it protects the lawyer even if the AI ​​platform used has unknown flaws. Consult the guide on use of ChatGPT without violating professional secrecy for concrete implementation in your practice.

- Jacques

Safe-doc for digital compliance of law firms

Law firms that handle sensitive files with AI tools face a concrete risk: exposing client data to platforms that do not comply with professional secrecy. Safe-doc addresses this problem by pseudonymizing documents in real time, before sending them to an AI tool, without ever storing the processed files.

https://safe-doc.ai

Safe-doc integrates into existing workflows without requiring tool changes. Lawyers continue to use the AIs they know, with a layer of protection compliant with GDPR and CNB recommendations. The page dedicated to DPO and firms details the auditing, pseudonymization and compliance support functionalities available for legal structures of all sizes.


Frequently asked questions

Does professional secrecy cover exchanges by e-mail?

Yes. Professional secrecy applies to all digital communications, including emails. The absence of end-to-end encryption exposes the lawyer to an ethical risk and to an obligation to notify the CNIL in the event of a violation.

Can a lawyer use ChatGPT to handle client files?

A lawyer can use AI tools provided that the entire context of the document is pseudonymised before processing. Submitting a non-pseudonymized file to a general public platform constitutes a potential violation of professional secrecy.

What is the legal privilege introduced in 2026?

Legal privilege, created by the law of February 23, 2026, protects certain written legal opinions from in-house lawyers. It is more restricted than lawyer professional secrecy and does not apply in criminal, tax or European competition law matters.

At what threshold must a firm appoint a DPO?

A DPO is recommended from 10 employees and mandatory from 50 members according to the recommendations of the CNB and the rules of the GDPR. The DPO coordinates compliance, trains teams and manages relations with the CNIL.

What is an AIPD and when is it mandatory in the office?

The Data Protection Impact Assessment (DPIA) is a formal risk assessment relating to data processing. It is mandatory before any deployment of an AI tool presenting a high risk for the rights and freedoms of the people concerned.

Recommendation