WZ-IT Logo

Local AI for professional secrecy holders (§203 StGB)

Timo WevelsiepTimo WevelsiepUpdated: 27.08.2026

Editorial note: Versions, commands and prices may change. Please verify critical steps independently before production use. This guide does not replace individual consulting.

Set up controlled AI for a firm, practice or advisory business? WZ-IT plans application, data flows, access and operations around the intended use and agreed technical scope. Explore the Section 203 Managed Cloud for AI software

For professional secrecy holders, AI touches not only data protection but criminally protected secrecy under Section 203 of the German Criminal Code. Cloud services are not prohibited across the board, and local systems are not automatically permitted. Disclosure, necessity, participants, contracts and technical safeguards are decisive. This is an assessment framework, not legal advice. As of August 2026.

Table of contents

What makes professional secrecy holders different

Certain professions are subject under §203 StGB (the German Criminal Code) to a criminally sanctioned duty of secrecy that goes beyond general data protection obligations. These include, among others, lawyers, doctors and dentists, pharmacists, psychotherapists, tax advisors, auditors and notaries - as well as their professional assistants.

Unauthorised disclosure can be a criminal offence. Data protection and professional secrecy remain separate reviews: a data processing agreement alone does not settle section 203, and a confidentiality obligation does not create a GDPR legal basis.

What section 203 means for external IT providers

Section 203(3) expressly permits disclosure to other persons contributing to the professional activity where necessary for their work. Subsection (4) also covers those contributing persons and requires, among other things, appropriate confidentiality commitments.

That does not make every external AI service acceptable. Assess necessity, the exact secrets exposed, provider staff and subprocessors, administration and support locations, technical access and export capabilities, plus GDPR and profession-specific requirements.

Why cloud AI needs particular scrutiny

A cloud service may receive prompts, answers, documents and metadata, and may involve subprocessors, international transfers, telemetry or support access. An EU region or a “no training” statement does not answer all of those questions. Cloud AI can suit anonymised, non-secret or explicitly approved tasks. Processing client, patient or tax secrets requires an assessment of the exact service and configuration.

What local AI improves and what it does not

Local AI can reduce the number of external recipients. Inference, embeddings and retrieval can stay inside a controlled boundary, supporting minimisation and potentially avoiding international transfers.

The model location is only one layer. Updates, telemetry, observability, backups, remote administration and connected OCR, speech or web services can still communicate externally. Knowledge permissions must also be enforced before retrieval. A prompt instruction is not access control; see RAG with real permissions.

The professions at a glance

The requirements are similar, the details differ by profession - from professional codes to sector-specific rules. For the individual professions we have prepared the AI use concretely:

Additional professional, chamber and sector rules vary by profession and use. They need to be assessed separately; architecture alone does not replace that work.

What a clean setup looks like

A dependable setup includes:

  • Data flow and data classes for prompts, answers, documents, embeddings, logs and backups.
  • Controlled model operation, local or dedicated, with only approved recipients.
  • SSO and rights management using existing users, roles and groups.
  • Technically enforced permissions for knowledge systems - not left to the model via a prompt.
  • Minimal logging with defined retention and separate evaluation rights.
  • Secured operations covering secrets, segmentation, patching, encrypted backups and tested restores.
  • Governed support access with named contributing persons and traceable approvals.
  • Matching documentation and contracts, including DPIA where required.

Operating models by protection need

Model Advantage Key assessment
Public AI API fast start disclosure, subprocessors, transfers, retention
Dedicated managed instance isolation and managed operations administrators, keys, support and export
Own data centre high technical control internal rights, patching, backup and physical security
On-premises appliance narrow local boundary updates, remote support, replacement and recovery

How WZ-IT supports the technical implementation

WZ-IT designs AI for professional secrecy holders from the trust boundary outward. The result may be an on-site AI Cube, a dedicated managed AI stack, a Section 203 Managed Cloud or integration with existing Proxmox, identity and network infrastructure.

We document data flows and administrative roles, implement SSO and permissions, restrict outbound traffic and establish monitoring, backup and recovery. The technical and contractual scope is aligned with the real processing arrangement and participating services. Approval of the target model for a particular purpose remains part of the organisation's professional, data-protection and, where required, legal assessment.

Sources

Rather have it operated?

You'd rather not run Local AI for Business yourself? WZ-IT handles setup, operations and maintenance - privacy-focused from Germany.

Enquiry

Assess local AI for your use case

Start with the AI Cube Pro or have us assess a custom AI platform, knowledge connection, or integration.

How should we get back to you?

Frequently Asked Questions

Answers to the most important questions

Yes. Section 203 StGB does not prohibit AI; it prohibits unauthorised disclosure of third-party secrets. Purpose, data, recipients, necessity and safeguards matter. Local or dedicated systems can reduce the disclosure surface but do not replace the assessment under section 203, GDPR and applicable professional rules.

Because an external provider and potentially subprocessors may gain access to protected information. Section 203(3) allows other contributing persons to be involved where disclosure is necessary for their work; subsection (4) includes confidentiality obligations. GDPR, professional law, contracts and technical access must be assessed separately.

Local AI can reduce external recipients and international transfers. It is not sufficient alone: local systems still require access, logging and deletion controls, secured administration, backups, updates and a review of connected services. The entire processing chain is decisive.

Among others lawyers, doctors and dentists, pharmacists, psychotherapists, tax advisors, auditors and notaries, as well as their professional assistants. They are subject to a criminally sanctioned duty of secrecy that goes beyond general data protection obligations - and that demands particular care in deploying AI.

No. Location and jurisdiction matter, but so do the contractual chain, necessity, subprocessors, administration and support access, encryption, key control and exports. A self-hosted system can also disclose data through telemetry or external add-ons.

A documented data flow and permissions design, controlled model and document processing, SSO and least privilege, matter or tenant isolation, data-minimised logs, encrypted backups, governed support access, and tested deletion and recovery. Contracts and records must match the actual technology.

Contact

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back — at the latest on the next business day.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/3 - Topic Selection33%

What is your inquiry about?

First select the service area that best matches your project.