The notary is defined by the GDPR as the data controller for all personal data that he collects in the context of notarial acts. This legal qualification entails specific obligations: appointment of a Data Protection Officer (DPO), keeping a register of processing operations, and implementation of appropriate security measures. The decree of November 26, 1971 also requires the retention of notarial minutes for 75 years, which creates a specific legal framework, distinct from the general rules of the GDPR. Understanding this connection is the first condition for real compliance.
What personal and sensitive data appear in notarial documents?
Notarial acts concentrate an exceptional density of personal data. A single real estate sale deed can contain the complete civil status of the parties, their marital status, their tax regime, the composition of their assets and information on their potential heirs. This diversity requires each study to precisely map the data it processes.
The most frequent categories in the acts are as follows:
- Marital status and identity: surname, first name, date and place of birth, nationality, identity document number.
- Asset data: value of assets, declared income, debts, composition of real estate and movable assets.
- Tax data: tax number, situation with regard to real estate wealth tax, capital gains.
- Inheritance data: family ties, status of heir, available portions, previous donations.
- Supporting documents: copies of passport, proof of address, marriage or divorce certificates.
Some of this data falls into the category of sensitive data within the meaning of article 9 of the GDPR, the processing of which is in principle prohibited except for strict exceptions. A deed of donation may, for example, mention a disability or serious illness justifying a special clause. In this case, the notary must identify the precise legal basis authorizing this processing and document it in his register.
The volume processed by a medium-sized study is considerable. Each file uses several dozen distinct pieces of data, and an active study can manage several hundred files per year. This reality makes systematic management essential, not just recommended.

What are the GDPR obligations of notarial firms?
GDPR compliance in the notarial profession is based on six concrete obligations, some of which are often underestimated in their practical scope.
1. Designate a DPO. Article 37 of the GDPR requires the appointment of a Data Protection Officer. For small-scale firms, this designation can be shared, in particular via the ADSN (Association for the Development of Notarial Services). The DPO is the central contact for all requests to exercise rights and for exchanges with the CNIL.
2. Keep a register of processing operations. The article 30 of the GDPR requires a register documenting each processing operation: purpose, categories of data, retention period, recipients and security measures. This register is the first document requested during a CNIL inspection.
3. Carry out impact analyzes (AIPD). For processing operations presenting a high risk for the rights of individuals, in particular the processing of large-scale heritage data, a Data Protection Impact Analysis is mandatory. It must be documented and updated.
4. Implement security measures. The recommended technical measures include encryption of data at rest and in transit, access control by personal authorization, and traceability of consultations. Each access to a folder must be logged.
5. Notify data breaches. Any breach must be reported to the CNIL within 72 hours of its detection. This deadline is imperative and failure to respect increases the sanctions.
6. Respect the retention periods. The legal retention of 75 years of minutes takes precedence over the right to erasure. This duration constitutes the legal basis for notarial processing and must appear explicitly in the register.
Pro Tip: Document each treatment decision at the time it is made, not after the fact. A register updated in real time is infinitely better than a document reconstituted during an inspection.
How to secure dematerialized notarial documents?

The dematerialization of documents creates specific risks which are added to the general obligations of the GDPR. A poorly protected digital document can be intercepted, modified or hosted on servers outside the European Union, which invalidates its probative value and exposes the study to sanctions.
The minimum technical requirements for a compliant dematerialized act are:
- Qualified electronic signature compliant with eIDAS regulation. It is the only signature that guarantees the legal value equivalent to the handwritten signature.
- Certified timestamp by a qualified trust service provider. The timestamp proves the anteriority of the act and its integrity on a given date.
- SecNumCloud certified hosting located in France or the European Union. Sovereign hosting is essential to avoid data transfers outside the EU, which are prohibited without specific contractual guarantees.
- End-to-end encryption for all document exchanges between the study, clients and institutional partners.
| Criterion | Minimum requirement |
|---|---|
| Electronic signature | eIDAS level 3 qualified |
| Accommodation | SecNumCloud Certified, EU only |
| Encryption | AES-256 at rest, TLS 1.3 in transit |
| Traceability | Named and time-stamped access log |
Pro tip: Before choosing an AI automation tool for processing procedures, always check that the service provider has a contractual commitment not to reuse your data for model training purposes. This clause must appear in the DPA (Data Processing Agreement).
AI automation in the processing of documents must respect these same sovereign accommodation requirements. An AI tool hosted in the United States processes your data under the jurisdiction of the US Cloud Act, which is incompatible with the GDPR.
What are the risks and sanctions in the event of non-compliance?
GDPR non-compliance in the notarial profession is not a theoretical question. The CNIL has extensive control powers and the sanctions are dissuasive.
- Financial sanctions: fines can reach 4% of global annual turnover. For a notarial firm, this ceiling represents an existential threat.
- Corrective measures: the CNIL may impose a limitation or temporary suspension of processing, which paralyzes the activity of the study.
- Civil liability: the protection of notarial data is an extension of professional secrecy. A violation entails the civil and disciplinary liability of the notary in a personal capacity.
- Reputation damage: a leak of asset or inheritance data destroys customer trust in a lasting manner.
“GDPR compliance in the notarial profession is not an additional administrative constraint. It is the digital translation of professional secrecy, which engages the personal liability of the notary in the same way as an instrumental fault. »
Proactive management concretely reduces these risks. An up-to-date treatment register, an identified DPO and a documented violation notification procedure make it possible to demonstrate the good faith of the study in the event of an audit, which directly influences the severity of possible sanctions.
What are the rights of clients over their notarial data?
Clients whose data appears in notarial documents benefit from the fundamental rights of the GDPR, but their exercise is governed by the legal specificities of the profession.
- Right of access: any client can request to know the data concerning them processed by the study. The DPO is the designated contact to process this request within one month.
- Right of rectification: an error in a document can be corrected by notarial rectification. The GDPR reinforces this already existing obligation.
- Right of opposition: the customer may object to certain processing, in particular for commercial prospecting purposes through the study.
- Right to erasure: this right is limited by the legal obligation of conservation. A client cannot demand the deletion of an authentic instrument whose retention for 75 years is required by law.
The balance between private life and evidential preservation is one of the most delicate tensions in contemporary notarial law. The right to erasure is limited by the historical necessity to preserve the original documents, which constitutes an explicit legal basis within the meaning of Article 6 of the GDPR. The DPO plays a central role in explaining these limits to customers and in documenting reasoned refusals of erasure.
The pseudonymization of data in internal working documents, distinct from the original minutes, offers a practical route to reduce the exposure of personal data without compromising the legal value of the acts.
Key points
GDPR compliance in notarial acts is based on six specific obligations, including the designation of a DPO, the keeping of a register of processing and certified sovereign hosting SecNumCloud.
| Point | Details |
|---|---|
| Designation of the DPO | Mandatory under Article 37 GDPR; can be shared via ADSN for small studies. |
| Treatment register | Document each processing with purpose, duration and security measures according to Article 30 GDPR. |
| Legal preservation | Minutes are kept for 75 years; this obligation takes precedence over customers’ right to erasure. |
| Security of digital acts | Qualified eIDAS signature, SecNumCloud hosting and end-to-end encryption are required. |
| CNIL sanctions | Non-compliance can result in fines of up to 4% of global annual turnover. |
What GDPR compliance taught me about notaries
After having supported several notarial studies in their compliance, I noticed that the main obstacle is not technical. It's cultural. Notaries are trained in procedural rigor, but the logic of the GDPR, which requires processing decisions to be documented before a problem arises, is foreign to their usual practice.
The point that surprises professionals the most is the tension between professional secrecy and GDPR transparency. The GDPR requires customers to be informed about the processing of their data. Professional secrecy requires not disclosing certain information. These two obligations coexist without contradicting each other, but their articulation requires careful wording of information notices, which many studies still neglect.
I have also observed that studies which appoint an experienced DPO, and not simply an administrative collaborator designated by default, progress twice as quickly in their compliance. The DPO provides a transversal reading of the risks that internal teams do not have the perspective to carry out on their own.
Finally, digitalization without prior audit is the most underestimated risk. Adopting an AI tool for drafting documents without checking its hosting architecture creates a potential violation even before having signed the first digital document. Compliance is designed upstream, not in repair.
- Jacques
Safe-doc supports notarial studies in their GDPR compliance
Notarial studies deal with some of the most sensitive data in the legal sector. Safe-doc offers a concrete layer of protection for professionals who use AI tools in their daily work on confidential documents and files.

Safe-doc pseudonymizes sensitive data before they reach an AI model, without ever storing the processed documents. This architecture guarantees that your clients' asset, tax and inheritance information does not leave your scope of control. For studies that want to use AI without compromising their GDPR compliance, Safe-doc offers a framework suitable for legal departments and compliance officers. Processing traceability is integrated by design, which directly facilitates the keeping of the register required by Article 30 of the GDPR.
Frequently asked questions
Is the notary obliged to appoint a DPO?
Yes. Article 37 of the GDPR requires the designation of a DPO on notaries as those responsible for large-scale data processing. This designation can be shared between several studies via the ADSN.
Can the client request the deletion of his data in a notarial deed?
No, not for the original minutes. The legal obligation of retention for 75 years constitutes a legal basis which takes precedence over the right to erasure provided for by the GDPR.
What sanctions does a notary office that does not comply with the GDPR risk?
The CNIL can impose fines of up to 4% of global annual turnover, and can impose a temporary suspension of processing. The civil and disciplinary liability of the notary is also incurred.
What is pseudonymization in the notarial context?
Pseudonymization consists of replacing identifying data with codes in internal working documents, while keeping the original documents intact. It reduces the exposure of personal data during routine processing without affecting the legal value of the actions.
Can an AI tool process notarial acts in compliance with the GDPR?
Yes, provided that the tool respects SecNumCloud certified sovereign hosting, contractually undertakes not to reuse the data, and that the data is pseudonymized before any sending to the model. A treatment of sensitive acts without data storage is the safest configuration.