Microsoft 365 Copilot in law firms and tax advisory practices – why § 203 StGB and § 43e BRAO reopen the cloud question in autumn 2026
Microsoft 365 Copilot in law firms and tax advisory practices – why § 203 StGB and § 43e BRAO reopen the cloud question in autumn 2026
On 8 September 2026 Microsoft completed the rollout of the Copilot and Agent 365 Dashboard data export to European tenants. For law firms, tax advisory practices and other professional secrecy holders that reopens a question many firms had considered settled: is running Microsoft 365 productively in an environment subject to criminally sanctioned confidentiality still tenable? The German Federal Bar (BRAK) and the German Federal Chamber of Tax Advisors (BStBK) have visibly tightened their positions in the past six months. The core statutory provisions – § 203 StGB, § 43e BRAO and § 62a StBerG – force firm principals and data protection officers into a fresh assessment in autumn 2026.
Why law firms and tax advisors are a special case
A professional secrecy holder in the sense of § 203 StGB is a person who by profession has access to third-party secrets and whose disclosure is criminally sanctioned. Under § 203 paragraph 1 number 3 StGB the circle includes attorneys, tax advisors, chartered accountants, notaries, physicians, psychotherapists and further groups. Unlike a general GDPR violation, a breach of § 203 StGB is a criminal offence – punishable by up to one year of imprisonment or a fine. § 43e BRAO concretises the admissibility of involving service providers for attorneys, the parallel provision in § 62a StBerG does the same for tax advisors. Both provisions require a written confidentiality obligation of the service provider with an explicit reference to the criminal-law consequences – a standard Article 28 GDPR data processing agreement is not enough.
What the September 2026 Copilot data export actually changes
Microsoft rolled out the Copilot and Agent 365 Dashboard data export in response to a compliance-customer request. The feature exports pseudonymised, row-level usage metrics – who uses which Copilot agent how often, with which data sources and in which contexts. For compliance officers in corporate groups this is a useful tool. For law firms it is a problem: metadata from matter processing – document titles, recipient circles, editing patterns – is secrecy-relevant under the case law of the German Federal Court (BGH, 20 February 2019, 1 StR 626/17). Pseudonymisation alone does not suffice under criminal law because analysis in the corporate context makes reattribution to matters possible. Firms that fail to disable the export explicitly and to include it in the professional-law assessment operate in a regulatory grey zone in 2026. The broader context of Copilot's data processing is documented in the Microsoft Copilot Flex Routing article.
The three most common misconceptions in law firm IT
Misconception 1: "We have a data processing agreement, so we are GDPR-compliant and § 203 StGB is handled." – Wrong. The DPA only covers the data protection side. § 203 StGB is an independent criminal provision with its own requirements for the written confidentiality obligation.
Misconception 2: "The BRAK has approved Microsoft 365." – Inaccurate. In April 2022 the BRAK classified Microsoft's Professional Secrecy Holder Addendum as generally suitable, but explicitly pointed to the individual firm's responsibility to assess it for the concrete deployment scenario. Copilot was not part of that assessment at the time.
Misconception 3: "The EU Data Boundary solves the problem." – Only partly. The EU Data Boundary governs the geographic storage location. It does not solve the access logic of the US parent group under the US CLOUD Act or the access possibilities of US authorities under FISA Section 702. The debate around Sovereignty Washing has made this gap visible.
What BRAK and BStBK actually expect in 2026
In its spring 2026 position the BRAK laid down four requirements which are now visible in the audit notes of the regional bar associations. First the firm has to run a documented necessity analysis for the cloud involvement. Second every relevant role at Microsoft and its sub-contractors must be contractually bound to confidentiality in writing – not only the contractual counterparty. Third the firm has to hold the technical means to exclude access from outside the EU. Fourth the use of AI assistants such as Copilot is only admissible with a signed AI addendum and with documented client information about the AI usage. The BStBK has adopted the same structure for tax advisors in its 05/2026 practice guidance. The practical consequence: the compliance effort for a Microsoft 365 setup with Copilot in a law firm is now higher than the effort to migrate to a sovereign stack.
The sovereign target stack for law firms and tax advisory practices
The professional-law-clean target stack is now production-ready and in productive use at several German commercial law firms and mid-sized tax advisory partnerships. Nextcloud with Collabora Online replaces SharePoint, OneDrive and Word/Excel for matter files – the end-to-end encryption of the Nextcloud Talk and Files components is now documented as § 203 StGB-compliant. Open-Xchange or Mailcow carry the email traffic, optionally with S/MIME certificates from the beA context. OpenTalk or Nextcloud Talk cover video communication. Univention Corporate Server or Keycloak provide the identity backend. Hosting runs at IONOS SE, at a BSI-certified German data centre or in on-premises infrastructure. Integration with the law-firm-specific applications – DATEV, RA-MICRO, AnNoText, LegalPro – is documented via the now-established interfaces. The categorised alternatives matrix is the fastest way to pick concrete operators. The parallel blueprint for the public sector is described in the Schleswig-Holstein blueprint article.
Cost, time frame and typical pitfalls
For a mid-size law firm with 20 to 120 fee-earners plus support staff the one-time cost of a clean migration typically falls between 35,000 and 220,000 euros – including DATEV and RA-MICRO integration, data migration and professional-law documentation. Recurring operation of the core suite runs at 8 to 14 euros per user per month, well below the effective price of Microsoft 365 E3 plus Copilot plus Professional Secrecy Holder Addendum. The typical pitfalls are, first, the DATEV online connection, which continues to run via the DATEV cloud and has to be cleanly separated from the sovereign stack; second, the beA integration, which is now available as a standard module in Nextcloud; third, the client communication, which has to be moved to encrypted portals step by step. The migration time frame is 90 to 150 days if the professional-law documentation is produced in parallel.
What to do now
We recommend three concrete steps for Q4 2026 for law firms and tax advisory practices. First a live analysis of the Microsoft 365 data flows via /en/microsoft – it makes the concrete gap under § 203 StGB visible. Second the selection of the right sovereign building blocks via the alternatives matrix and a compact comparison via /en/pricing. Third an initial conversation via /en/contact about migration planning and about preparing the professional-law documentation for the bar association or tax advisor chamber. Anyone who postpones the assessment of the Copilot data export and of the Professional Secrecy Holder Addendum until spring 2027 risks an audit finding at the next chamber inspection and, in the extreme case, a criminal-law assessment under § 203 StGB. Anyone who starts the move now still has time in 2026 to bring the sovereign stack into productive operation cleanly and without a chamber audit finding.
Energy sector under NIS2 – why municipal utilities and grid operators can no longer defer the Microsoft 365 question before the autumn 2026 audit
From autumn 2026 municipal utilities and grid operators count as essential NIS2 entities. What that means for Microsoft 365 in the energy sector, concretely.
EU Commission and gematik Adopt Matrix – What This Means for German SMEs
More and more European institutions are migrating to Matrix/Element for secure communication. A trend that should also guide German SMEs.