
Under the GDPR, notaries are classified as data controllers for all personal data they collect in the context of notarial acts. This legal classification entails specific obligations: designation of a Data Protection Officer (DPO), maintenance of a processing register, and implementation of appropriate security measures. The decree of 26 November 1971 further requires retention of notarial minutes for 75 years, creating a specific legal framework distinct from the GDPR's general rules. Understanding this relationship is the first prerequisite for genuine compliance.
Table of contents
- What personal and sensitive data appear in notarial acts?
- What are the GDPR obligations of notarial practices?
- How to secure dematerialized notarial acts?
- What are the risks and sanctions for non-compliance?
- What are clients' rights over their notarial data?
- Key points
- What GDPR compliance taught me about the notarial profession
- Safe-doc supports notarial practices in their GDPR compliance
- Frequently asked questions
- Further reading
What personal and sensitive data appear in notarial acts?
Notarial acts concentrate an exceptional density of personal data. A single real estate sale deed can contain the complete civil status of the parties, their marital status, their tax regime, the composition of their assets, and information on their potential heirs. This diversity requires each practice to map precisely the data it processes.
The most frequent categories in notarial acts include:
- Civil status and identity: surname, first name, date and place of birth, nationality, identity document number.
- Patrimonial data: value of assets, declared income, debts, composition of real estate and movable property.
- Tax data: tax identification number, real estate wealth tax status, capital gains.
- Succession data: family relationships, heir status, disposable portions, prior donations.
- Supporting documents: copies of passport, proof of address, marriage or divorce certificates.
Some of this data falls into the category of sensitive data within the meaning of Article 9 of the GDPR, the processing of which is in principle prohibited except under strict exceptions. A deed of donation may, for example, mention a disability or serious illness justifying a particular clause. In such cases, the notary must identify the precise legal basis authorizing this processing and document it in the register.
The volume processed by a medium-sized practice is considerable. Each file involves several dozen distinct data points, and an active practice may manage several hundred files per year. This reality makes systematic management indispensable, not merely recommended.

What are the GDPR obligations of notarial practices?
GDPR compliance in the notarial profession rests on six concrete obligations, some of which are often underestimated in their practical scope.
1. Designate a DPO. Article 37 of the GDPR requires the designation of a Data Protection Officer. For smaller practices, this designation may be shared, particularly through the ADSN (Association for the Development of Notarial Services). The DPO is the central point of contact for all rights requests and for exchanges with the CNIL.
2. Maintain a processing register. Article 30 of the GDPR requires a register documenting each processing activity: purpose, categories of data, retention period, recipients, and security measures. This register is the first document requested during a CNIL inspection.
3. Conduct impact assessments (DPIAs). For processing operations presenting a high risk to individuals' rights, particularly large-scale processing of patrimonial data, a Data Protection Impact Assessment is mandatory. It must be documented and kept up to date.
4. Implement security measures. Recommended technical measures include encryption of data at rest and in transit, access control by named authorization, and traceability of consultations. Each access to a file must be logged.
5. Notify data breaches. Any breach must be reported to the CNIL within 72 hours of detection. This deadline is imperative, and non-compliance aggravates potential sanctions.
6. Respect retention periods. The legal 75-year retention of minutes takes precedence over the right to erasure. This period constitutes the legal basis for notarial processing and must appear explicitly in the register.
Pro tip: Document each processing decision at the time it is made, not retrospectively. A register updated in real time is infinitely more valuable than a document reconstructed during an inspection.
How to secure dematerialized notarial acts?

The dematerialization of acts creates specific risks that supplement the general GDPR obligations. A poorly protected digital act can be intercepted, modified, or hosted on servers outside the European Union, invalidating its probative value and exposing the practice to sanctions.
The minimum technical requirements for a compliant dematerialized act are:
- Qualified electronic signature compliant with the eIDAS regulation. This is the only signature that guarantees legal value equivalent to a handwritten signature.
- Certified timestamp by a qualified trust service provider. Timestamping proves the anteriority of the act and its integrity at a given date.
- SecNumCloud-certified hosting located in France or the European Union. Sovereign hosting is essential to avoid data transfers outside the EU, which are prohibited without specific contractual safeguards.
- End-to-end encryption for all document exchanges between the practice, clients, and institutional partners.
| Criterion | Minimum requirement |
|---|---|
| Electronic signature | eIDAS level 3 qualified |
| Hosting | SecNumCloud certified, EU only |
| Encryption | AES-256 at rest, TLS 1.3 in transit |
| Traceability | Named and timestamped access log |
Pro tip: Before choosing an AI automation tool for processing acts, systematically verify that the provider contractually commits not to reuse your data for model training purposes. This clause must appear in the DPA (Data Processing Agreement).
AI automation in the processing of acts must comply with these same sovereign hosting requirements. An AI tool hosted in the United States processes your data under the jurisdiction of the US Cloud Act, which is incompatible with the GDPR.
What are the risks and sanctions for non-compliance?
GDPR non-compliance in the notarial profession is not a theoretical question. The CNIL has extensive enforcement powers, and sanctions are dissuasive.
- Financial penalties: fines can reach 4% of global annual turnover. For a notarial practice, this ceiling represents an existential threat.
- Corrective measures: the CNIL may impose a limitation or temporary suspension of processing activities, which paralyzes the practice's operations.
- Civil liability: the protection of notarial data is an extension of professional secrecy. A breach engages the personal civil and disciplinary liability of the notary.
- Reputational damage: a leak of patrimonial or succession data destroys client trust on a lasting basis.
"GDPR compliance in the notarial profession is not an additional administrative burden. It is the digital translation of professional secrecy, which engages the personal liability of the notary in the same way as an instrumental error."
Proactive management concretely reduces these risks. An up-to-date processing register, an identified DPO, and a documented breach notification procedure allow the practice to demonstrate good faith during an inspection, which directly influences the severity of any sanctions.
What are clients' rights over their notarial data?
Clients whose data appear in notarial acts benefit from the fundamental rights of the GDPR, but their exercise is governed by the specific legal requirements of the profession.
- Right of access: any client may request to know what data concerning them is processed by the practice. The DPO is the designated contact for processing this request within one month.
- Right of rectification: an error in an act can be corrected by notarial rectification. The GDPR reinforces this already existing obligation.
- Right to object: the client may object to certain processing activities, particularly for commercial prospecting purposes by the practice.
- Right to erasure: this right is limited by the legal obligation of retention. A client cannot demand deletion of an authentic instrument whose 75-year retention is required by law.
The balance between privacy and evidential preservation is one of the most delicate tensions in contemporary notarial law. The right to erasure is limited by the historical necessity to preserve original acts, which constitutes an explicit legal basis within the meaning of Article 6 of the GDPR. The DPO plays a central role in explaining these limitations to clients and in documenting reasoned refusals of erasure.
Pseudonymization of data in internal working documents, distinct from the original minutes, offers a practical way to reduce exposure of personal data without compromising the legal value of the acts.
Key points
GDPR compliance in notarial acts is based on six specific obligations, including designation of a DPO, maintenance of a processing register, and SecNumCloud-certified sovereign hosting.
| Point | Details |
|---|---|
| DPO designation | Mandatory under Article 37 GDPR; may be shared via ADSN for smaller practices. |
| Processing register | Document each processing activity with purpose, duration, and security measures under Article 30 GDPR. |
| Legal retention | Minutes are retained for 75 years; this obligation takes precedence over clients' right to erasure. |
| Digital act security | Qualified eIDAS signature, SecNumCloud hosting, and end-to-end encryption are required. |
| CNIL sanctions | Non-compliance exposes practices to fines of up to 4% of global annual turnover. |
What GDPR compliance taught me about the notarial profession
After supporting several notarial practices in their compliance efforts, I have found that the main obstacle is not technical. It is cultural. Notaries are trained in instrumental rigor, but the logic of the GDPR, which requires documenting processing decisions before a problem arises, is foreign to their usual practice.
The point that surprises professionals the most is the tension between professional secrecy and GDPR transparency. The GDPR requires informing clients about the processing of their data. Professional secrecy requires not disclosing certain information. These two obligations coexist without contradicting each other, but their articulation requires careful drafting of information notices, which many practices still neglect.
I have also observed that practices that designate an experienced DPO, rather than simply an administrative staff member designated by default, progress twice as quickly in their compliance. The DPO brings a cross-functional reading of risks that internal teams do not have the perspective to perform alone.
Finally, digitalization without prior audit is the most underestimated risk. Adopting an AI tool for drafting acts without verifying its hosting architecture creates a potential breach before signing the first digital act. Compliance is designed upstream, not as a repair.
- Jacques
Safe-doc supports notarial practices in their GDPR compliance
Notarial practices process some of the most sensitive data in the legal sector. Safe-doc offers a concrete layer of protection for professionals who use AI tools in their daily work on confidential acts and files.

Safe-doc pseudonymizes sensitive data before it reaches an AI model, without durably storing the processed documents. This architecture ensures that your clients' patrimonial, tax, and succession information never leaves your control perimeter. For practices that wish to use AI without compromising their GDPR compliance, Safe-doc offers a framework adapted to legal departments and compliance officers. Processing traceability is integrated by design, directly facilitating maintenance of the register required by Article 30 of the GDPR.
Frequently asked questions
Is the notary required to designate a DPO?
Yes. Article 37 of the GDPR requires the designation of a DPO for notaries as data controllers processing data on a large scale. This designation may be shared among several practices through the ADSN.
Can the client request deletion of their data in a notarial act?
No, not for the original minutes. The legal obligation to retain them for 75 years constitutes a legal basis that takes precedence over the right to erasure provided by the GDPR.
What sanctions does a notarial practice risk for GDPR non-compliance?
The CNIL may impose fines of up to 4% of global annual turnover and may impose a temporary suspension of processing activities. The civil and disciplinary liability of the notary is also engaged.
What is pseudonymization in the notarial context?
Pseudonymization consists of replacing identifying data with codes in internal working documents, while keeping the original acts intact. It reduces exposure of personal data during routine processing without affecting the legal value of the acts.
Can an AI tool process notarial acts in compliance with the GDPR?
Yes, provided the tool complies with SecNumCloud-certified sovereign hosting, contractually commits not to reuse the data, and the data is pseudonymized before being sent to the model. Processing sensitive acts without data storage is the safest configuration.