AI in a tax firm is legal when two conditions hold at the same time: the provider is bound to professional secrecy as an assisting person under section 203(3) and (4) of the German Criminal Code (StGB), and the processing of client data meets the GDPR, including a data processing agreement and, for payroll and health-related data, Article 9. A private ChatGPT account meets neither. A platform with EU hosting, a signed confidentiality obligation, a data processing agreement and permissions per client file meets both.
This guide is written for the 53,932 tax practices in Germany and their Austrian counterparts under the Wirtschaftstreuhandberufsgesetz. It explains what the 2017 reform of section 203 actually allows, where the GDPR adds duties the criminal code does not, which five questions settle any vendor conversation, which use cases pay off first, and how DATEV, ChatGPT, Copilot and a dedicated platform compare when the client is a Berufsgeheimnisträger.
Section 203 StGB and AI: what is allowed once the provider is an assisting person
Since the reform of 9 November 2017, a tax adviser may disclose client secrets to other assisting persons to the extent necessary for their work, and the legislature named the operation, maintenance and external storage of IT systems as exactly such work. That sentence is what makes cloud software, and with it cloud AI, legally possible for a Berufsgeheimnisträger. The condition sits one paragraph later: the assisting person must be bound to secrecy, and a provider who then discloses a secret faces up to one year in prison under section 203(4). If you never bound the provider, the criminal exposure is yours, not theirs, a point the innFactory analysis of section 203 and public cloud makes with the phrase that this is no trivial offence.
Three consequences follow for AI tools. First, the confidentiality obligation is a separate document from the GDPR data processing agreement; the DPA checklist covers Article 28, not section 203. Second, every link in the chain counts: if your platform sends prompts to a model provider, that provider is also an assisting person and must be bound as well, which is why a platform that can show you its sub-processor list and their obligations is worth more than one that cannot. Third, necessity is a real test. Uploading a full client file to draft a two-line e-mail is not necessary; a platform that lets you scope what the model sees per task keeps you on the right side of that word.
A private ChatGPT account used for client work fails section 203 twice: there is no confidentiality obligation with OpenAI, and the consumer terms allow training on your inputs unless you opt out. It also fails the GDPR: no data processing agreement, no EU residency, no deletion control. The DStV published a model AI usage policy for practices in April 2026 for exactly this reason. Put the rule in writing before the next Mandant asks whether you use AI.
GDPR in the practice: Article 9, the DPA and client data in prompts
The GDPR adds three duties the criminal code does not know. A data processing agreement under Article 28 with every AI provider, with a sub-processor list you can actually read. A legal basis for special categories under Article 9 wherever payroll runs through the tool: sickness days, religious affiliation for church tax, disability status and union membership are all special-category data and appear in ordinary payroll files. And a data protection impact assessment under Article 35 when you process client data at scale with a new technology, which an AI platform over your whole client base is. The DPIA template is built for that case.
The practical trap is not the contract, it is the prompt. Staff paste a client name, a tax number and a bank statement into a chat window because that is the fastest way to get an answer. A platform that resolves those references itself from a connected system, with permissions per client file, means the person never has to paste anything, and the audit log shows which file the model read. That is the difference between a policy and a control.
Your officer will run the same twelve questions as for any other AI tool; the data protection officer checklist lists them with the proving documents. For the most common starting point, ChatGPT Business and the GDPR shows tier by tier where residency and the DPA stop.
Ten minutes to know where your practice stands
The free AI governance check scores policy, DPA coverage, permissions and audit readiness and returns a gap list you can hand to your data protection officer. Anonymous, EU-hosted.
The five questions for every AI vendor
Will you sign a confidentiality obligation under section 203(4) StGB?
A yes means a written commitment that names the secrecy duty, the criminal consequences and the obligation to bind their own sub-contractors. A vendor who offers only a data processing agreement has not understood your profession.
Where is the data processed, and by whom, model provider included?
Ask for the sub-processor list with countries. A German platform that routes prompts to a US model without a bound sub-processor has an open link in the chain.
Is training on our data excluded in writing?
For every model behind the platform, not just the platform itself. Abuse-monitoring retention of prompts, such as the 30 days some cloud AI services keep for human review, must be disclosed and, for client data, switched off.
Can you show a user who is not allowed to see a client file asking about it?
The permission demo. If the answer comes anyway, the platform has one index for the whole practice and every trainee can read every Mandant.
What do we take with us when we leave?
Export of documents, prompts, assistants and audit logs, and a deletion confirmation. A practice changes software every few years; an AI platform without an exit is a second lock-in next to the practice software.
What a confidentiality obligation under section 203(4) must contain, in one paragraph: the provider acknowledges it acts as an assisting person for a Berufsgeheimnisträger, commits to keep all client secrets confidential beyond the end of the contract, binds every own employee and sub-contractor to the same duty, uses the data only as far as necessary for the contracted service, and has been informed of the criminal consequences of section 203(4). Date, signature, done. It is one page, and most vendors have never been asked for it.
Use cases that pay off
The best first use cases in a practice share two properties: the input is something the firm already holds in a system, and the output is checked by a professional before it leaves the building. Client questions about deadlines, a draft reply to a Finanzamt letter, a summary of a 40-page audit report and a searchable memory of every circular your association ever sent are all of that kind. Fully automated filing is not, and the AI Act will treat some HR-adjacent uses as high risk from December 2027.
The table sorts common use cases by the data class they touch and by the setup that makes them permissible. The time figures are deliberately absent where we have no source; the DStV whitepaper on AI assistants from February 2025 is the honest starting point for expectations.
| Use case | Data class | Permissible with | Who checks |
|---|---|---|---|
| Answer recurring client questions (deadlines, documents needed, VAT basics) | No client data, practice knowledge | Any EU-hosted tool with a DPA; no section 203 issue if no secrets | Assistant, spot checks |
| Draft a reply to a tax office letter for a named client | Client secret | Section 203 obligation + DPA + permission per client file | Professional, always |
| Summarise an audit report or a contract | Client secret, possibly Art. 9 | As above, plus training exclusion for the model | Professional |
| Payroll queries (sick days, church tax, disability) | Art. 9 special categories | As above, plus DPIA and a documented legal basis | Payroll specialist |
| Searchable memory of association circulars, BMF letters, internal templates | No client data | Any EU-hosted knowledge base; see building an AI knowledge base | Nobody per query, curated quarterly |
| Receipt recognition and invoice automation | Client financial data | Practice software with built-in AI (DATEV automation service) already inside the DATEV data centre | Bookkeeper |
| Employee evaluation or hiring support inside the practice | Employee data, AI Act Annex III | High-risk rules from 2 Dec 2027; human oversight, logging, works council where present | Practice owner |
DATEV, ChatGPT, Copilot or a dedicated platform: the comparison for practices
Most practices will run two things: the AI that is already inside their practice software, and a general assistant for everything the practice software does not do. The first is DATEV's territory and it is the right answer for receipts and postings, because the data never leaves the DATEV data centre. The second is where the section 203 question actually arises, because it is where staff reach for ChatGPT.
The table compares the realistic options for that second layer. It is deliberately fair to DATEV and deliberately hard on us: Teamo AI is a managed platform, and a practice that requires air-gapped operation should look at self-hosting instead. For the broader vendor field see the ChatGPT alternatives for the Mittelstand and the six-component test in what an AI operating system for companies is.
Practices that already tried Langdock should read the Langdock alternative guide before renewing.
| Criterion | DATEV built-in AI | ChatGPT Team / Business | Microsoft 365 Copilot | Teamo AI |
|---|---|---|---|---|
| Section 203 confidentiality obligation | Covered within the DATEV contract framework | Not offered on self-serve tiers | Microsoft added section 203 language to its DPA; marketplace models outside it | On request, signed per practice |
| Data location | DATEV data centre, Germany | US company; EU residency only on Enterprise (about 150 seats) | EU Data Boundary, US parent | EU hosting, self-hosting optional |
| Scope | Receipts, postings, practice workflows | General chat, files per user | M365 documents and mail | Connected systems (mail, calendar, Nextcloud, Notion, CRM) with permissions per record |
| Permissions per client file | Inherits DATEV rights | Workspace level | Inherits M365 rights, oversharing risk | Seven-ring model including per-row access |
| Model choice | DATEV decides | OpenAI only | OpenAI via Azure | Several EU and US providers, swappable per data class |
| Audit log a DSB can read | DATEV logging | Compliance API on Enterprise | Purview, extra licence | Three separate logs, six-month retention |
| Seat minimum | DATEV membership | 2 seats; Enterprise about 150 | None, annual | None, 14-day trial |
Use the practice software AI when
The task is receipts, postings or anything already inside the DATEV workflow
You want zero new contracts and the data must not leave the DATEV data centre
Your staff never need a general assistant
Add a dedicated platform when
Staff already use ChatGPT for mails, summaries and research (they do)
You want answers grounded in your own circulars, templates and mailboxes
You need permissions per client file and an audit log you can hand to the DSB
You want standing agents: deadline reminders, a Monday overview, a draft for every unanswered client mail
The AI Act in the practice: training duty now, high-risk rules in 2027
Two dates matter. Since 2 February 2025 every deployer must ensure AI literacy among staff under Article 4, which for a practice means a documented training that covers what may be entered, what must be checked and how to recognise a wrong answer; the Article 4 training guide has the curriculum. From 2 December 2027, after the postponement in the Digital Omnibus, AI used for hiring, promotion or evaluation of your own staff is high risk under Annex III, with human oversight and logging duties. Client-facing tax work is not high risk, but it remains a section 203 matter every single day.
All of this belongs in one document: a practice AI policy. The AI policy template for companies has the twelve clauses; for a practice, add the confidentiality obligation and the rule that client identifiers never enter a tool that is not bound under section 203. Austrian practices face the same structure under section 80 of the Wirtschaftstreuhandberufsgesetz 2017, which carries the confidentiality duty of Wirtschaftstreuhänder and their assistants.
Teamo AI: shared knowledge that never leaves Europe
Connect mail, calendar, Nextcloud, Notion and your CRM, set who may see which client, and start a deadline agent. EU-hosted, data processing agreement included, confidentiality obligation under section 203 on request, no seat minimum. 14 days free, no credit card, your team invited in minutes.
Conclusion: the question is not whether, but under which contract
Section 203 was rewritten in 2017 precisely so that professionals could use external IT without committing a crime. The price is one document most vendors have never seen and a discipline about what enters a prompt. Practices that settle both, and put the rule in a policy, get the productivity their staff are already taking from private accounts, minus the exposure.
Start with the two use cases that touch no client secret, the circular memory and the client FAQ. Bind the provider, sign the DPA, run the training. Then move client work onto the platform file by file, with the permission demo as your acceptance test.
AI in the tax practice in five sentences
AI is permissible in a tax practice when the provider is bound to secrecy under section 203(4) StGB and the GDPR is met with a DPA, an Article 9 basis for payroll data and a DPIA. A private ChatGPT account meets neither. Ask every vendor five questions: section 203 obligation, data location incl. model providers, training exclusion, permission demo, exit. Start with use cases that touch no client secret, keep the practice software AI for receipts, and add a platform with permissions per client file for everything else. Train staff now under Article 4 and expect high-risk rules for internal HR use from December 2027.





![European AI for Teams: Why 'EU Region' on US Clouds Is Not Enough [2026]](https://www.teamazing.com/wp-content/uploads/2026/04/EU-AI-Usage.jpg)
![OpenClaw at Work: 5 Reasons Your Security Team Will Say No [2026]](https://www.teamazing.com/wp-content/uploads/2026/03/openclaw-in-companies.jpg)