25.06.2026
Local AI for Law Firms: §203, Case Data and RAG
How local RAG systems unlock case knowledge, cite sources and preserve matter-level permissions in every answer.
Case-law research, draft pleadings and case knowledge are sensitive. We set up a local AI platform with controlled data sources, roles and documented access paths.
Companies worldwide trust WZ-IT
Client emails, pleadings and research cost hours - but putting case data into ChatGPT or Copilot lacks what §43e BRAO requires of a service provider: a written obligation, instruction on the consequences, careful selection and oversight.
A DPA alone does not define how client separation, source permissions and the §203 framework are implemented technically.
With external AI services, providers, subprocessors, storage locations and possible third-country transfers must be assessed. A locally configured platform can reduce those external data paths.
We configure and operate AI Cube for the agreed GDPR and Section 203 scope. This includes controlled data paths, limited permissions, documented maintenance, the appropriate DPA and written secrecy obligations for the people involved. Legal evaluation of the specific use remains with the controller and its advisers.
§203 StGB protects confidential information entrusted by clients, patients and other parties. The necessary involvement of contributing persons is permitted. What matters is that access is limited to what is necessary, the people involved are bound to secrecy and the complete data and maintenance path is controlled.
With public AI services, inputs and documents leave your own infrastructure. Whether a service is suitable in a specific case therefore depends not only on a DPA, but also on data flows, subprocessors, access permissions and the actual use.
On-premises inference, local vector search and internally operated interfaces keep technical processing in your controlled environment. This reduces external data paths and subprocessors and allows access to be limited precisely.
When we provide setup or operations as a contributing person, the people involved accept a written secrecy obligation and are instructed about the criminal consequences. Where personal data is involved, this is combined with a DPA, limited administrative rights and documented maintenance paths.
These technical and contractual building blocks form part of the agreed §203 scope:
Data-protection layer
Secrecy and instruction on criminal consequences
necessary rights, logging and controlled paths
This content is general information and not legal or tax advice. The specific implementation under §203 must be reviewed professionally on a case-by-case basis.
AI Cube provides chat, local models and dedicated knowledge areas within the firm network. DMS connections, automated RAG pipelines and client separation are implemented separately after reviewing the existing systems.

Delivered ready to use within 10 working days
€6,490 excl. VAT one-time
Device, setup, briefing and shipping
€349.90 excl. VAT / month
AI Cube Care · first year accompanied, then cancellable monthly
RAG, data sources, integrations, secure connectivity and custom workflows are scoped separately.
AI Cube Care keeps the device running: a monthly maintenance window, tested model updates with a rollback path, round-the-clock monitoring, ticket support and warranty handling. For confidentiality professionals we add a data processing agreement under Art. 28 GDPR and the written secrecy obligation under Section 203 (4) of the German Criminal Code, including instruction on the criminal consequences; on request remote access stays switched off by default.
These examples describe possible workflows. Data sources, permissions and professional review are defined for the concrete use case.
Sovereign AI is a lifecycle, not a device purchase - and everything stays on your infrastructure.
Workshop, sizing, data classification and §203 contract framework. We understand your stack, professional software and compliance requirements before we recommend.
On-premise build on your hardware, RAG on your documents with access control, integration into your professional software, secrecy obligation + DPA.
Updates, monitoring, model upgrades and RAG maintenance as a service contract - or you operate fully yourself. Handover and knowledge transfer included.
From hardware and inference through RAG and integration to operations and security - no interface ping-pong between advice, build and operations.
Enquiry
Describe the workflow and data that should be processed locally or in a controlled environment.
From local AI integration to architecture, data sovereignty and ongoing operations.
“WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.”

Steve Kirchner
Managing Director, nextGYM GmbH

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”