[{"data":1,"prerenderedAt":417},["ShallowReactive",2],{"navigation-docs_en":3,"/en/blog/microsoft-365-copilot-law-firms-tax-advisors-professional-secrecy-2026-posts_en":51,"/en/blog/microsoft-365-copilot-law-firms-tax-advisors-professional-secrecy-2026-surround-posts_en":406},[4],{"title":5,"path":6,"stem":7,"children":8,"page":25},"En","/en","en",[9],{"title":10,"path":11,"stem":12,"children":13,"page":25},"Docs","/en/docs","en/1.docs",[14,26],{"title":15,"path":16,"stem":17,"children":18,"icon":25},"Getting Started","/en/docs/getting-started","en/1.docs/1.getting-started/1.index",[19,21],{"title":20,"path":16,"stem":17,"children":-1},"Introduction",{"title":22,"path":23,"stem":24,"children":-1},"Migration Roadmap","/en/docs/getting-started/migration-fahrplan","en/1.docs/1.getting-started/2.migration-fahrplan",false,{"title":27,"path":28,"stem":29,"children":30,"page":25},"Technologies","/en/docs/technologies","en/1.docs/2.technologies",[31,35,39,43,47],{"title":32,"path":33,"stem":34,"children":-1},"Nextcloud","/en/docs/technologies/nextcloud","en/1.docs/2.technologies/1.nextcloud",{"title":36,"path":37,"stem":38,"children":-1},"Matrix / Element","/en/docs/technologies/matrix","en/1.docs/2.technologies/2.matrix",{"title":40,"path":41,"stem":42,"children":-1},"ONLYOFFICE","/en/docs/technologies/onlyoffice","en/1.docs/2.technologies/3.onlyoffice",{"title":44,"path":45,"stem":46,"children":-1},"Ubuntu Linux","/en/docs/technologies/ubuntu","en/1.docs/2.technologies/4.ubuntu",{"title":48,"path":49,"stem":50,"children":-1},"Keycloak","/en/docs/technologies/keycloak","en/1.docs/2.technologies/5.keycloak",{"id":52,"title":53,"authors":54,"badge":60,"body":62,"date":356,"description":357,"extension":358,"faq":359,"howto":375,"image":398,"meta":400,"navigation":401,"path":402,"seo":403,"stem":404,"__hash__":405},"posts_en/en/3.blog/28.microsoft-365-copilot-law-firms-tax-advisors-professional-secrecy-2026.md","Microsoft 365 Copilot in law firms and tax advisory practices – why § 203 StGB and § 43e BRAO reopen the cloud question in autumn 2026",[55],{"name":56,"to":57,"avatar":58},"europioneer Team","/",{"src":59},"/favicon.svg",{"label":61},"Professional secrecy",{"type":63,"value":64,"toc":345},"minimark",[65,69,117,122,142,146,170,174,180,190,206,210,231,235,292,296,319,323],[66,67,53],"h1",{"id":68},"microsoft-365-copilot-in-law-firms-and-tax-advisory-practices-why-203-stgb-and-43e-brao-reopen-the-cloud-question-in-autumn-2026",[70,71,72,73,77,78,81,82,85,86,89,90,93,94,97,98,101,102,105,106,85,109,112,113,116],"p",{},"On ",[74,75,76],"strong",{},"8 September 2026"," Microsoft completed the rollout of the ",[74,79,80],{},"Copilot and Agent 365 Dashboard data export"," to European tenants. For ",[74,83,84],{},"law firms",", ",[74,87,88],{},"tax advisory practices"," and other ",[74,91,92],{},"professional secrecy holders"," that reopens a question many firms had considered settled: is running ",[74,95,96],{},"Microsoft 365"," productively in an environment subject to criminally sanctioned confidentiality still tenable? The German Federal Bar (",[74,99,100],{},"BRAK",") and the German Federal Chamber of Tax Advisors (",[74,103,104],{},"BStBK",") have visibly tightened their positions in the past six months. The core statutory provisions – ",[74,107,108],{},"§ 203 StGB",[74,110,111],{},"§ 43e BRAO"," and ",[74,114,115],{},"§ 62a StBerG"," – force firm principals and data protection officers into a fresh assessment in autumn 2026.",[118,119,121],"h2",{"id":120},"why-law-firms-and-tax-advisors-are-a-special-case","Why law firms and tax advisors are a special case",[70,123,124,125,128,129,131,132,135,136,138,139,141],{},"A ",[74,126,127],{},"professional secrecy holder"," in the sense of ",[74,130,108],{}," is a person who by profession has access to third-party secrets and whose disclosure is criminally sanctioned. Under § 203 paragraph 1 number 3 StGB the circle includes attorneys, tax advisors, chartered accountants, notaries, physicians, psychotherapists and further groups. Unlike a general GDPR violation, a breach of § 203 StGB is a ",[74,133,134],{},"criminal offence"," – punishable by up to one year of imprisonment or a fine. ",[74,137,111],{}," concretises the admissibility of involving service providers for attorneys, the parallel provision in ",[74,140,115],{}," does the same for tax advisors. Both provisions require a written confidentiality obligation of the service provider with an explicit reference to the criminal-law consequences – a standard Article 28 GDPR data processing agreement is not enough.",[118,143,145],{"id":144},"what-the-september-2026-copilot-data-export-actually-changes","What the September 2026 Copilot data export actually changes",[70,147,148,149,151,152,155,156,159,160,163,164,169],{},"Microsoft rolled out the ",[74,150,80],{}," in response to a compliance-customer request. The feature exports ",[74,153,154],{},"pseudonymised, row-level usage metrics"," – who uses which Copilot agent how often, with which data sources and in which contexts. For compliance officers in corporate groups this is a useful tool. For law firms it is a problem: ",[74,157,158],{},"metadata from matter processing"," – document titles, recipient circles, editing patterns – is secrecy-relevant under the case law of the German Federal Court (",[74,161,162],{},"BGH, 20 February 2019, 1 StR 626/17","). Pseudonymisation alone does not suffice under criminal law because analysis in the corporate context makes reattribution to matters possible. Firms that fail to disable the export explicitly and to include it in the professional-law assessment operate in a regulatory grey zone in 2026. The broader context of Copilot's data processing is documented in the ",[165,166,168],"a",{"href":167},"/en/blog/microsoft-copilot-flex-routing","Microsoft Copilot Flex Routing"," article.",[118,171,173],{"id":172},"the-three-most-common-misconceptions-in-law-firm-it","The three most common misconceptions in law firm IT",[70,175,176,179],{},[74,177,178],{},"Misconception 1: \"We have a data processing agreement, so we are GDPR-compliant and § 203 StGB is handled.\""," – Wrong. The DPA only covers the data protection side. § 203 StGB is an independent criminal provision with its own requirements for the written confidentiality obligation.",[70,181,182,185,186,189],{},[74,183,184],{},"Misconception 2: \"The BRAK has approved Microsoft 365.\""," – Inaccurate. In April 2022 the BRAK classified Microsoft's Professional Secrecy Holder Addendum as ",[74,187,188],{},"generally suitable",", but explicitly pointed to the individual firm's responsibility to assess it for the concrete deployment scenario. Copilot was not part of that assessment at the time.",[70,191,192,195,196,200,201,205],{},[74,193,194],{},"Misconception 3: \"The EU Data Boundary solves the problem.\""," – Only partly. The EU Data Boundary governs the geographic storage location. It does not solve the access logic of the US parent group under the ",[165,197,199],{"href":198},"/en/blog/cloud-act-2026","US CLOUD Act"," or the access possibilities of US authorities under FISA Section 702. The debate around ",[165,202,204],{"href":203},"/en/blog/sovereignty-washing-microsoft-365-local-municipalities-2026","Sovereignty Washing"," has made this gap visible.",[118,207,209],{"id":208},"what-brak-and-bstbk-actually-expect-in-2026","What BRAK and BStBK actually expect in 2026",[70,211,212,213,215,216,219,220,223,224,227,228,230],{},"In its spring 2026 position the ",[74,214,100],{}," laid down four requirements which are now visible in the audit notes of the regional bar associations. First the firm has to run a documented ",[74,217,218],{},"necessity analysis"," for the cloud involvement. Second every relevant role at Microsoft and its sub-contractors must be ",[74,221,222],{},"contractually bound to confidentiality"," in writing – not only the contractual counterparty. Third the firm has to hold the technical means to ",[74,225,226],{},"exclude access from outside the EU",". Fourth the use of AI assistants such as Copilot is only admissible with a signed AI addendum and with documented client information about the AI usage. The ",[74,229,104],{}," has adopted the same structure for tax advisors in its 05/2026 practice guidance. The practical consequence: the compliance effort for a Microsoft 365 setup with Copilot in a law firm is now higher than the effort to migrate to a sovereign stack.",[118,232,234],{"id":233},"the-sovereign-target-stack-for-law-firms-and-tax-advisory-practices","The sovereign target stack for law firms and tax advisory practices",[70,236,237,238,240,241,244,245,248,249,252,253,248,256,259,260,248,263,265,266,269,270,85,273,85,276,85,279,282,283,287,288,169],{},"The professional-law-clean target stack is now production-ready and in productive use at several German commercial law firms and mid-sized tax advisory partnerships. ",[74,239,32],{}," with ",[74,242,243],{},"Collabora Online"," replaces SharePoint, OneDrive and Word/Excel for matter files – the end-to-end encryption of the Nextcloud Talk and Files components is now documented as § 203 StGB-compliant. ",[74,246,247],{},"Open-Xchange"," or ",[74,250,251],{},"Mailcow"," carry the email traffic, optionally with S/MIME certificates from the beA context. ",[74,254,255],{},"OpenTalk",[74,257,258],{},"Nextcloud Talk"," cover video communication. ",[74,261,262],{},"Univention Corporate Server",[74,264,48],{}," provide the identity backend. Hosting runs at ",[74,267,268],{},"IONOS SE",", at a BSI-certified German data centre or in on-premises infrastructure. Integration with the law-firm-specific applications – ",[74,271,272],{},"DATEV",[74,274,275],{},"RA-MICRO",[74,277,278],{},"AnNoText",[74,280,281],{},"LegalPro"," – is documented via the now-established interfaces. The categorised ",[165,284,286],{"href":285},"/en/alternativen","alternatives matrix"," is the fastest way to pick concrete operators. The parallel blueprint for the public sector is described in the ",[165,289,291],{"href":290},"/en/blog/schleswig-holstein-blueprint-libreoffice-migration-states-municipalities-2026","Schleswig-Holstein blueprint",[118,293,295],{"id":294},"cost-time-frame-and-typical-pitfalls","Cost, time frame and typical pitfalls",[70,297,298,299,302,303,306,307,310,311,314,315,318],{},"For a mid-size law firm with 20 to 120 fee-earners plus support staff the one-time cost of a clean migration typically falls between ",[74,300,301],{},"35,000 and 220,000 euros"," – including DATEV and RA-MICRO integration, data migration and professional-law documentation. Recurring operation of the core suite runs at ",[74,304,305],{},"8 to 14 euros per user per month",", well below the effective price of Microsoft 365 E3 plus Copilot plus Professional Secrecy Holder Addendum. The typical pitfalls are, first, the ",[74,308,309],{},"DATEV online connection",", which continues to run via the DATEV cloud and has to be cleanly separated from the sovereign stack; second, the ",[74,312,313],{},"beA integration",", which is now available as a standard module in Nextcloud; third, the ",[74,316,317],{},"client communication",", which has to be moved to encrypted portals step by step. The migration time frame is 90 to 150 days if the professional-law documentation is produced in parallel.",[118,320,322],{"id":321},"what-to-do-now","What to do now",[70,324,325,326,329,330,333,334,336,337,340,341,344],{},"We recommend three concrete steps for Q4 2026 for law firms and tax advisory practices. First a ",[74,327,328],{},"live analysis of the Microsoft 365 data flows"," via ",[165,331,332],{"href":332},"/en/microsoft"," – it makes the concrete gap under § 203 StGB visible. Second the selection of the right sovereign building blocks via the ",[165,335,286],{"href":285}," and a compact comparison via ",[165,338,339],{"href":339},"/en/pricing",". Third an initial conversation via ",[165,342,343],{"href":343},"/en/contact"," about migration planning and about preparing the professional-law documentation for the bar association or tax advisor chamber. Anyone who postpones the assessment of the Copilot data export and of the Professional Secrecy Holder Addendum until spring 2027 risks an audit finding at the next chamber inspection and, in the extreme case, a criminal-law assessment under § 203 StGB. Anyone who starts the move now still has time in 2026 to bring the sovereign stack into productive operation cleanly and without a chamber audit finding.",{"title":346,"searchDepth":347,"depth":347,"links":348},"",2,[349,350,351,352,353,354,355],{"id":120,"depth":347,"text":121},{"id":144,"depth":347,"text":145},{"id":172,"depth":347,"text":173},{"id":208,"depth":347,"text":209},{"id":233,"depth":347,"text":234},{"id":294,"depth":347,"text":295},{"id":321,"depth":347,"text":322},"2026-09-08T00:00:00.000Z","New Copilot data exports in September 2026 force law firms and tax advisors to reassess. What § 203 StGB, § 43e BRAO and § 62a StBerG really demand.","md",[360,363,366,369,372],{"q":361,"a":362},"Is a German law firm using Microsoft 365 automatically covered by § 203 StGB?","Yes. Attorneys are professional secrecy holders under § 203 paragraph 1 number 3 of the German Criminal Code (StGB). Even disclosing another person's secret to anyone who is not bound to confidentiality can be a criminal offence. Using a cloud service like Microsoft 365 has counted as involving a so-called cooperating person under § 203 paragraph 3 StGB since the 2017 amendment. It is only permissible if that cooperating person – Microsoft and every sub-processor – is contractually bound to confidentiality in writing, and if the involvement is necessary. § 43e BRAO adds specific rules for attorneys, § 62a StBerG for tax advisors.",{"q":364,"a":365},"Does the standard Article 28 GDPR data processing agreement cover this?","No. The Article 28 GDPR data processing agreement only regulates the data protection relationship. § 203 StGB and the professional law specialisations additionally require a written confidentiality obligation with an explicit reference to the criminal-law consequences. Microsoft offers a Professional Secrecy Holder Addendum which the German Federal Bar (BRAK) classified as generally suitable in 2022. That addendum does not automatically cover every Microsoft sub-processor and does not cover AI processing by Copilot. Anyone deploying Copilot has needed a separate AI addendum since June 2026 – still only in English and under US governing law.",{"q":367,"a":368},"What changed with the Copilot data export in September 2026?","Microsoft rolled out the Copilot and Agent 365 Dashboard data export in September 2026. It exports pseudonymised, row-level usage metrics from the Copilot dashboard. The export does not leave the European data boundary in its default configuration, but it is analysed inside the Microsoft group and can be fed into model improvement unless it is explicitly disabled. For professional secrecy holders that matters because even pseudonymised metadata – document titles, editing patterns, recipient circles – can be secrecy-relevant. The German Federal Court has held since its judgment of 20 February 2019 – 1 StR 626/17 – that metadata falls under the attorney-client privilege.",{"q":370,"a":371},"What does the BRAK currently expect from law firms in concrete terms?","In its spring 2026 positioning the BRAK laid out four requirements. First the firm has to document the necessity of the cloud involvement. Second every relevant role at Microsoft and its sub-processors must be bound in writing to confidentiality. Third the firm must have the technical means to exclude access from outside the EU – this drives the debate about data sovereignty and the [US CLOUD Act](/en/blog/cloud-act-2026). Fourth Copilot is only admissible with a signed AI addendum and with client-facing documentation of the AI usage.",{"q":373,"a":374},"Is there a sovereign stack that cleanly covers § 203 StGB, § 43e BRAO and § 62a StBerG?","Yes. Since 2024 productive setups have been running in German commercial law firms and mid-size tax advisory partnerships based on Nextcloud with Collabora Online for documents, Open-Xchange or Mailcow for email, OpenTalk or Nextcloud Talk for video, and Univention Corporate Server as the directory service. Hosting is typically at IONOS SE or in a BSI-certified German data centre. The combination meets the professional law requirements without additional addenda because the operator itself is based in Germany and is not part of a group subject to the US CLOUD Act.",{"name":376,"description":377,"totalTime":378,"steps":379},"Reassess Microsoft 365 in a law firm or tax advisory practice under professional law","Six-step approach for firm principals and data protection officers in autumn 2026 – from the necessity analysis to the sovereign target picture.","P90D",[380,383,386,389,392,395],{"name":381,"text":382},"Document the necessity of the cloud involvement","Produce a written necessity analysis under § 203 paragraph 3 StGB. Catalogue every case-management and matter system that touches Microsoft 365. For each service assess whether an on-premises or EU-sovereign alternative would cover the same function. Since 2026 the BRAK and the BStBK expect a documented weighing, not a blanket appeal to economic efficiency.",{"name":384,"text":385},"Close the Professional Secrecy Holder Addendum and the AI addendum","Request the current Microsoft Professional Secrecy Holder Addendum and, for every Copilot deployment, the AI addendum. Check both against § 43e BRAO or § 62a StBerG. Watch the governing-law clause – US law is regularly not sufficient in the context of § 203 StGB. Without a signed addendum the operation is criminally risky.",{"name":387,"text":388},"Enumerate sub-processors and obtain written confidentiality obligations","Pull Microsoft's current sub-processor list. Check every listed sub-contractor for its seat and legal framework. For every sub-processor not covered by the addendum a separate written obligation is required – in practice this is barely solvable. This gap is one of the most common reasons for a negative GDPR audit in law firms in 2026.",{"name":390,"text":391},"Control metadata and Copilot usage firm-wide","Disable the Copilot data exports in the default configuration unless you are actively using the data boundary export feature. Restrict Copilot to explicitly approved matters. Introduce a firm-wide metadata classification that marks every matter-related document title, subject line and address book entry as secrecy-relevant.",{"name":393,"text":394},"Pilot the sovereign target stack","In parallel run a pilot on Nextcloud, Collabora Online and Open-Xchange in a BSI-certified German data centre. Migrate two to four practice groups or a single tax advisory team first. Verify integration with DATEV, RA-MICRO, AnNoText or LegalPro. Four to six weeks of pilot operation are mandatory before wider rollout.",{"name":396,"text":397},"Inform the regulator and clients transparently","Notify your bar association or the tax advisor chamber in writing about your AI usage and the planned migration. Update the client information under § 43e paragraph 2 BRAO. Document the timeline for the cloud change in the firm's internal data protection and professional law compliance manual. A clean transition in Q4 2026 avoids audit findings from the chamber in 2027.",{"src":399},"https://images.unsplash.com/photo-1589829545856-d10d557cf95f?w=1200&q=80",{},true,"/en/blog/microsoft-365-copilot-law-firms-tax-advisors-professional-secrecy-2026",{"title":53,"description":357},"en/3.blog/28.microsoft-365-copilot-law-firms-tax-advisors-professional-secrecy-2026","0FnaHS5zGiwzyMkFrH0-kJIX75wpzAj_hv7EyE2b7S0",[407,412],{"title":408,"path":409,"stem":410,"description":411,"children":-1},"Energy sector under NIS2 – why municipal utilities and grid operators can no longer defer the Microsoft 365 question before the autumn 2026 audit","/en/blog/municipal-utilities-nis2-energy-microsoft-365-sovereign-alternative-2026","en/3.blog/27.municipal-utilities-nis2-energy-microsoft-365-sovereign-alternative-2026","From autumn 2026 municipal utilities and grid operators count as essential NIS2 entities. What that means for Microsoft 365 in the energy sector, concretely.",{"title":413,"path":414,"stem":415,"description":416,"children":-1},"EU Commission and gematik Adopt Matrix – What This Means for German SMEs","/en/blog/eu-commission-matrix","en/3.blog/3.eu-commission-matrix","More and more European institutions are migrating to Matrix/Element for secure communication. A trend that should also guide German SMEs.",1788852143136]