AI in a tax firm is legal when two conditions hold at the same time: the provider is bound to professional secrecy as an assisting person under section 203(3) and (4) of the German Criminal Code (StGB), and the processing of client data meets the GDPR, including a data processing agreement and, for payroll and health-related data, Article 9. A private ChatGPT account meets neither. A platform with EU hosting, a signed confidentiality obligation, a data processing agreement and permissions per client file meets both.

This guide is written for the 53,932 tax practices in Germany and their Austrian counterparts under the Wirtschaftstreuhandberufsgesetz. It explains what the 2017 reform of section 203 actually allows, where the GDPR adds duties the criminal code does not, which five questions settle any vendor conversation, which use cases pay off first, and how DATEV, ChatGPT, Copilot and a dedicated platform compare when the client is a Berufsgeheimnisträger.

53,932tax practices in Germany, 67% of them sole practices (BStBK Berufsstatistik 2025)
60%of German companies name data protection as a reason against AI, ahead of cost at 32% ([Destatis](https://www.destatis.de/DE/Themen/Branchen-Unternehmen/Unternehmen/IKT-in-Unternehmen-IKT-Branche/Tabellen/ikti-gegen-nutzung-kuenstliche-intelligenz.html))
28%of knowledge-intensive service firms in the Mittelstand use AI, the highest of any sector (KfW 2026)
1 yearmaximum prison sentence under section 203(4) StGB for an assisting person who discloses a secret

Section 203 StGB and AI: what is allowed once the provider is an assisting person

Since the reform of 9 November 2017, a tax adviser may disclose client secrets to other assisting persons to the extent necessary for their work, and the legislature named the operation, maintenance and external storage of IT systems as exactly such work. That sentence is what makes cloud software, and with it cloud AI, legally possible for a Berufsgeheimnisträger. The condition sits one paragraph later: the assisting person must be bound to secrecy, and a provider who then discloses a secret faces up to one year in prison under section 203(4). If you never bound the provider, the criminal exposure is yours, not theirs, a point the innFactory analysis of section 203 and public cloud makes with the phrase that this is no trivial offence.

Three consequences follow for AI tools. First, the confidentiality obligation is a separate document from the GDPR data processing agreement; the DPA checklist covers Article 28, not section 203. Second, every link in the chain counts: if your platform sends prompts to a model provider, that provider is also an assisting person and must be bound as well, which is why a platform that can show you its sub-processor list and their obligations is worth more than one that cannot. Third, necessity is a real test. Uploading a full client file to draft a two-line e-mail is not necessary; a platform that lets you scope what the model sees per task keeps you on the right side of that word.

A private ChatGPT account used for client work fails section 203 twice: there is no confidentiality obligation with OpenAI, and the consumer terms allow training on your inputs unless you opt out. It also fails the GDPR: no data processing agreement, no EU residency, no deletion control. The DStV published a model AI usage policy for practices in April 2026 for exactly this reason. Put the rule in writing before the next Mandant asks whether you use AI.

GDPR in the practice: Article 9, the DPA and client data in prompts

The GDPR adds three duties the criminal code does not know. A data processing agreement under Article 28 with every AI provider, with a sub-processor list you can actually read. A legal basis for special categories under Article 9 wherever payroll runs through the tool: sickness days, religious affiliation for church tax, disability status and union membership are all special-category data and appear in ordinary payroll files. And a data protection impact assessment under Article 35 when you process client data at scale with a new technology, which an AI platform over your whole client base is. The DPIA template is built for that case.

The practical trap is not the contract, it is the prompt. Staff paste a client name, a tax number and a bank statement into a chat window because that is the fastest way to get an answer. A platform that resolves those references itself from a connected system, with permissions per client file, means the person never has to paste anything, and the audit log shows which file the model read. That is the difference between a policy and a control.

Your officer will run the same twelve questions as for any other AI tool; the data protection officer checklist lists them with the proving documents. For the most common starting point, ChatGPT Business and the GDPR shows tier by tier where residency and the DPA stop.

Ten minutes to know where your practice stands

The free AI governance check scores policy, DPA coverage, permissions and audit readiness and returns a gap list you can hand to your data protection officer. Anonymous, EU-hosted.

Run the governance check

The five questions for every AI vendor

1

Will you sign a confidentiality obligation under section 203(4) StGB?

A yes means a written commitment that names the secrecy duty, the criminal consequences and the obligation to bind their own sub-contractors. A vendor who offers only a data processing agreement has not understood your profession.

2

Where is the data processed, and by whom, model provider included?

Ask for the sub-processor list with countries. A German platform that routes prompts to a US model without a bound sub-processor has an open link in the chain.

3

Is training on our data excluded in writing?

For every model behind the platform, not just the platform itself. Abuse-monitoring retention of prompts, such as the 30 days some cloud AI services keep for human review, must be disclosed and, for client data, switched off.

4

Can you show a user who is not allowed to see a client file asking about it?

The permission demo. If the answer comes anyway, the platform has one index for the whole practice and every trainee can read every Mandant.

5

What do we take with us when we leave?

Export of documents, prompts, assistants and audit logs, and a deletion confirmation. A practice changes software every few years; an AI platform without an exit is a second lock-in next to the practice software.

What a confidentiality obligation under section 203(4) must contain, in one paragraph: the provider acknowledges it acts as an assisting person for a Berufsgeheimnisträger, commits to keep all client secrets confidential beyond the end of the contract, binds every own employee and sub-contractor to the same duty, uses the data only as far as necessary for the contracted service, and has been informed of the criminal consequences of section 203(4). Date, signature, done. It is one page, and most vendors have never been asked for it.

Use cases that pay off

The best first use cases in a practice share two properties: the input is something the firm already holds in a system, and the output is checked by a professional before it leaves the building. Client questions about deadlines, a draft reply to a Finanzamt letter, a summary of a 40-page audit report and a searchable memory of every circular your association ever sent are all of that kind. Fully automated filing is not, and the AI Act will treat some HR-adjacent uses as high risk from December 2027.

The table sorts common use cases by the data class they touch and by the setup that makes them permissible. The time figures are deliberately absent where we have no source; the DStV whitepaper on AI assistants from February 2025 is the honest starting point for expectations.

Use caseData classPermissible withWho checks
Answer recurring client questions (deadlines, documents needed, VAT basics)No client data, practice knowledgeAny EU-hosted tool with a DPA; no section 203 issue if no secretsAssistant, spot checks
Draft a reply to a tax office letter for a named clientClient secretSection 203 obligation + DPA + permission per client fileProfessional, always
Summarise an audit report or a contractClient secret, possibly Art. 9As above, plus training exclusion for the modelProfessional
Payroll queries (sick days, church tax, disability)Art. 9 special categoriesAs above, plus DPIA and a documented legal basisPayroll specialist
Searchable memory of association circulars, BMF letters, internal templatesNo client data

Any EU-hosted knowledge base; see building an AI knowledge base

Nobody per query, curated quarterly
Receipt recognition and invoice automationClient financial dataPractice software with built-in AI (DATEV automation service) already inside the DATEV data centreBookkeeper
Employee evaluation or hiring support inside the practiceEmployee data, AI Act Annex IIIHigh-risk rules from 2 Dec 2027; human oversight, logging, works council where presentPractice owner

DATEV, ChatGPT, Copilot or a dedicated platform: the comparison for practices

Most practices will run two things: the AI that is already inside their practice software, and a general assistant for everything the practice software does not do. The first is DATEV's territory and it is the right answer for receipts and postings, because the data never leaves the DATEV data centre. The second is where the section 203 question actually arises, because it is where staff reach for ChatGPT.

The table compares the realistic options for that second layer. It is deliberately fair to DATEV and deliberately hard on us: Teamo AI is a managed platform, and a practice that requires air-gapped operation should look at self-hosting instead. For the broader vendor field see the ChatGPT alternatives for the Mittelstand and the six-component test in what an AI operating system for companies is.

Practices that already tried Langdock should read the Langdock alternative guide before renewing.

CriterionDATEV built-in AIChatGPT Team / BusinessMicrosoft 365 CopilotTeamo AI
Section 203 confidentiality obligationCovered within the DATEV contract frameworkNot offered on self-serve tiersMicrosoft added section 203 language to its DPA; marketplace models outside itOn request, signed per practice
Data locationDATEV data centre, GermanyUS company; EU residency only on Enterprise (about 150 seats)EU Data Boundary, US parentEU hosting, self-hosting optional
ScopeReceipts, postings, practice workflowsGeneral chat, files per userM365 documents and mailConnected systems (mail, calendar, Nextcloud, Notion, CRM) with permissions per record
Permissions per client fileInherits DATEV rightsWorkspace levelInherits M365 rights, oversharing riskSeven-ring model including per-row access
Model choiceDATEV decidesOpenAI onlyOpenAI via AzureSeveral EU and US providers, swappable per data class
Audit log a DSB can readDATEV loggingCompliance API on EnterprisePurview, extra licenceThree separate logs, six-month retention
Seat minimumDATEV membership2 seats; Enterprise about 150None, annualNone, 14-day trial

Use the practice software AI when

  • The task is receipts, postings or anything already inside the DATEV workflow

  • You want zero new contracts and the data must not leave the DATEV data centre

  • Your staff never need a general assistant

Add a dedicated platform when

  • Staff already use ChatGPT for mails, summaries and research (they do)

  • You want answers grounded in your own circulars, templates and mailboxes

  • You need permissions per client file and an audit log you can hand to the DSB

  • You want standing agents: deadline reminders, a Monday overview, a draft for every unanswered client mail

The AI Act in the practice: training duty now, high-risk rules in 2027

Two dates matter. Since 2 February 2025 every deployer must ensure AI literacy among staff under Article 4, which for a practice means a documented training that covers what may be entered, what must be checked and how to recognise a wrong answer; the Article 4 training guide has the curriculum. From 2 December 2027, after the postponement in the Digital Omnibus, AI used for hiring, promotion or evaluation of your own staff is high risk under Annex III, with human oversight and logging duties. Client-facing tax work is not high risk, but it remains a section 203 matter every single day.

All of this belongs in one document: a practice AI policy. The AI policy template for companies has the twelve clauses; for a practice, add the confidentiality obligation and the rule that client identifiers never enter a tool that is not bound under section 203. Austrian practices face the same structure under section 80 of the Wirtschaftstreuhandberufsgesetz 2017, which carries the confidentiality duty of Wirtschaftstreuhänder and their assistants.

Teamo AI: shared knowledge that never leaves Europe

Connect mail, calendar, Nextcloud, Notion and your CRM, set who may see which client, and start a deadline agent. EU-hosted, data processing agreement included, confidentiality obligation under section 203 on request, no seat minimum. 14 days free, no credit card, your team invited in minutes.

Start the free trial, no credit card

Conclusion: the question is not whether, but under which contract

Section 203 was rewritten in 2017 precisely so that professionals could use external IT without committing a crime. The price is one document most vendors have never seen and a discipline about what enters a prompt. Practices that settle both, and put the rule in a policy, get the productivity their staff are already taking from private accounts, minus the exposure.

Start with the two use cases that touch no client secret, the circular memory and the client FAQ. Bind the provider, sign the DPA, run the training. Then move client work onto the platform file by file, with the permission demo as your acceptance test.

AI in the tax practice in five sentences

AI is permissible in a tax practice when the provider is bound to secrecy under section 203(4) StGB and the GDPR is met with a DPA, an Article 9 basis for payroll data and a DPIA. A private ChatGPT account meets neither. Ask every vendor five questions: section 203 obligation, data location incl. model providers, training exclusion, permission demo, exit. Start with use cases that touch no client secret, keep the practice software AI for receipts, and add a platform with permissions per client file for everything else. Train staff now under Article 4 and expect high-risk rules for internal HR use from December 2027.