Sensitive data in customer files in law is defined by the GDPR as any information revealing a person's ethnic origin, health, political opinions, religious beliefs or sex life. For legal professionals, lawyers and notaries, this definition extends to the very content of the files: contact details, financial situations, criminal records and identity documents. Professional secrecy reinforces this protection by imposing absolute confidentiality, under penalty of criminal sanctions. The CNIL monitors compliance with these obligations and has sanctioning power of up to 4% of global turnover.
What are the legal obligations related to sensitive data in customer files?
The management of sensitive data in legal customer files obeys a precise regulatory framework, structured around the GDPR and national law. Three obligations structure the daily compliance of firms and studies.
Notification of violations to the CNIL

Any data breach must be investigated notification within 72 hours after discovery. This period begins as soon as the data controller becomes aware of the incident, even partial. A firm which discovers on Monday morning that a criminal file has been transmitted in error to a third party must notify the CNIL before Thursday morning. Failure to comply with this deadline constitutes an independent offense, regardless of the seriousness of the violation.
Individual customer information
When transferring funds or transferring customer files, individual information must be sent to each customer within a maximum of one month, in accordance with article 14.3 of the GDPR. This period begins to run as soon as the transfer is finalized. Good practice consists of anticipating this information from the letter of intent, before closing, to avoid any legal gap. A prior audit of the file must identify the nature of the data, the legal bases and the possible presence of data relating to minors.
Documentation and internal governance
Legal obligations include:
- Maintaining a processing register, a legal document attesting to control of all flows of personal data within the firm.
- The designation of a data protection officer (DPO) for structures processing sensitive data on a large scale.
- Systematic information of customers on the purposes of the processing, the retention period and their rights (access, rectification, erasure, portability).
- Documentation of the legal bases for each processing, in particular consent or legitimate interest.
Complete documentation of processing constitutes the basis of any defense in the event of a CNIL inspection. Without an up-to-date register, a firm cannot demonstrate its compliance, even if its practices are impeccable.
Pro tip: When transferring funds, begin the GDPR audit of the customer file as soon as the letter of intent is signed. Waiting for closing exposes the transferor to a violation of article 14.3 of the GDPR and to personal liability.

What are the legal retention periods for sensitive files and data?
Retention periods vary depending on the legal nature of the file. Applying a uniform duration to all files is a frequent and potentially punishable error. The table below summarizes the applicable legal durations according to the main types of files.
| Folder Type | Shelf life |
|---|---|
| KYC and anti-money laundering (LCB-FT) | 5 years after the end of the customer relationship |
| Lawyer's document (fee agreement, correspondence) | 25 years |
| Heavy criminal or real estate files | Up to 30 years |
| Billing data | 10 years (commercial prescription) |
These durations are not recommendations. They arise from distinct legal obligations: the monetary and financial code for KYC, the ethical rules of the bar for legal acts, and the criminal procedure code for criminal cases. Retaining data beyond the legal duration without a justified basis constitutes a violation of the GDPR principle of minimization. Conversely, premature destruction can deprive the firm of evidence in the event of litigation.
For files requiring prolonged retention beyond standard deadlines, an explicit contractual mention in the mission agreement or the general conditions is sufficient to create the necessary legal basis. This statement must specify the purpose, duration and methods of the customer's access to their data.
What technical measures effectively protect sensitive data?
Securing customer data in legal files is based on concrete technical choices, not on declarations of intent. Here are the essential measures for any firm dealing with confidential information.
- End-to-end encryption of exchanges. Exchanges of sensitive parts must pass through end-to-end encrypted channels. The RPVA (Virtual Private Network of Lawyers) is the reference for legal exchanges in France.
- Abandonment of standard email. The sending by unencrypted email of sensitive attachments is inadequate with regard to the GDPR. Expirable links and secure document spaces significantly reduce the risk of leaks.
- Sovereign platforms hosted in France. The solutions hosted in France guarantee that data does not pass outside European territory, a necessary condition to comply with GDPR requirements on international transfers.
- Fine management of authorizations. Each employee must only access files relating to their responsibilities. Access logs make it possible to trace any consultation and detect abnormal access.
- Pseudonymization of documents. Before any processing by a third-party tool, data allowing a customer to be directly identified must be replaced by neutral identifiers. This technique reduces the residual risk in the event of a leak.
Pro tip: Before using an artificial intelligence tool to analyze a file, always pseudonymize names, addresses and identification numbers. A pseudonymized document transmitted to an external tool does not constitute a data breach within the meaning of the GDPR, unlike a raw document.
Security by default is not an option reserved for large firms. It applies from the first criminal or family case processed, regardless of the size of the structure. For firms wishing to structure their governance of sensitive data, a documented and audited approach is the only one that resists a CNIL inspection.
How to reconcile professional secrecy, right to proof and transparency?
Professional secrecy is not an absolute obstacle to the production of evidence in court. Recent case law specifies the conditions under which its lifting is admissible.
1. Principle of proportionality. The lifting of professional secrecy must be proportionate to the issue at stake in the dispute, essential to the demonstration of proof, and limited to only the strictly necessary documents. The judge controls this criterion rigorously.
2. Anonymization and provisional sequestration. When an investigative measure concerns confidential documents, anonymization by a third party or provisional sequestration constitutes the guarantee expected by the courts. These mechanisms prevent the judge from retracting the measure and prevent sanctions.
3. Strict judicial control. The judge exercises a proportionality check between the right to proof and respect for private life. Requests that are too broad or poorly targeted are systematically rejected. A legal professional who formulates a request for the production of documents must anticipate this filter and construct his request accordingly.
4. Sanctions in the event of non-compliance. Violation of professional secrecy exposes you to criminal prosecution (article 226-13 of the penal code), disciplinary sanctions from the bar or the chamber of notaries, and civil damages. The CNIL may also sanction the data controller if the disclosure constitutes a data breach.
5. Obligation of transparency towards customers. The right to information of the persons concerned remains even in a contentious context. Hiding the identities of clients in legal documents produced in court, when their identity is not directly in question, protects both professional secrecy and the fundamental rights of third parties.
The tension between professional secrecy and the right to proof is resolved by precision. A targeted request, accompanied by appropriate procedural guarantees, succeeds where a general request fails.
Key points
The protection of sensitive data in legal client files is based on three inseparable pillars: documented regulatory compliance, technical measures adapted to the sensitivity of the files, and control of the tensions between professional secrecy and the right to proof.
| Point | Details |
|---|---|
| CNIL notification within 72 hours | Any data breach must be reported to the CNIL within 72 hours of its discovery. |
| Differentiated storage periods | The deadlines vary from 5 years (KYC) to 30 years (serious criminal) depending on the nature of the case. |
| Abandoning Standard Email | Sensitive documents must pass through encrypted channels or secure document spaces. |
| Pseudonymization before AI processing | Replacing direct identifiers before any external processing reduces the risk of GDPR violations. |
| Proportionality to lift secrecy | The lifting of professional secrecy requires a targeted request, limited to strictly necessary documents. |
What Fifteen Years of Legal Compliance Taught Me About Sensitive Data
Most of the firms I supported treated GDPR compliance as a one-off project. They would produce a treatment log, appoint a DPO, then move on. Two years later, the register was obsolete, authorizations had not been updated, and employees were still sending criminal cases by standard email.
The real problem is not ignorance of the rules. Legal professionals know the GDPR. The problem is the gap between written policy and daily practice. This gap widens silently, until control or incident occurs.
What I observed in the best protected offices was a different posture. Security by default is not an additional constraint. It is a reflex integrated into each stage of processing a file: pseudonymize before analyzing, encrypt before sending, check authorizations before sharing. These actions take thirty seconds. They avoid weeks of crisis management.
The professional secrecy and data protection are also levers of trust with customers. A firm that can demonstrate its documented compliance, its access logs and its pseudonymization policy stands out concretely from those who are satisfied with a declaration of principle. Sensitive clients, particularly in family or criminal matters, also choose their advice on this criterion.
- Jacques
Safe-doc, the layer of protection for your sensitive files
Legal professionals who use artificial intelligence tools to analyze files face a real risk if the documents transmitted contain raw data. Safe-doc solves this problem by automatically pseudonymizing identifying information before any external processing, without storing any documents.

Safe-doc integrates with existing workflows and allows you to continue using familiar AI tools while ensuring GDPR compliance. The GDPR compliant pseudonymization proposed by Safe-doc covers the needs of law firms, notaries and compliance managers who deal with high-sensitivity files. Zero storage architecture ensures that no customer data persists on the servers. To understand the technical operation, page security and architecture details the guarantees offered.
Frequently asked questions
What is sensitive data in a client file in law?
Sensitive data is any information revealing a person's ethnic origin, health, sex life, political opinions or criminal record, as defined by Article 9 of the GDPR. In legal files, this includes medical documents, criminal records and detailed asset situations.
What is the deadline for notifying the CNIL in the event of a data breach?
Notification must occur within a maximum of 72 hours after discovery of the violation. This deadline applies even if the full assessment of the incident has not been completed.
How long should a client file be kept in a law firm?
The duration varies depending on the nature of the file: 5 years for KYC data, 25 years for a lawyer's act, and up to 30 years for serious criminal or real estate files.
Is pseudonymization enough to protect sensitive data?
Pseudonymization significantly reduces the risk in the event of a leak or processing by a third-party tool, but it does not replace encryption or authorization management. It constitutes an additional measure recommended by the GDPR, in particular before any processing by artificial intelligence.
Can professional secrecy be lifted to produce evidence in court?
Yes, but under strict conditions: the lifting must be proportionate, limited to the necessary documents and often accompanied by anonymization or temporary sequestration. The judge systematically checks these criteria before authorizing production.