Skip to content

A chain, not a certificate

Eight links of contract and configuration carry a supply route under German professional secrecy. Each one is verifiable on its own - as a document, a configuration record or a named responsibility. If one is missing, the whole claim hangs in the air.

Why a chain - and not a certificate

Anyone wanting to test a provider claim such as "§ 203-compliant" needs a grid, not trust. This is that grid: eight links of contract and technology that together carry the supply route. Each is verifiable on its own. If one is missing, the whole statement hangs in the air. The overview page AI under German professional secrecy introduces the chain; this page takes it link by link, with the test question and the form of proof for each.

The doctrinal frame behind it, named openly: § 203 Abs. 3 Satz 2 StGB permits the involvement of assisting persons - which on the prevailing reading includes IT and AI service providers. § 203 Abs. 4 Satz 2 Nr. 1 StGB requires that those persons be obligated to secrecy. And the technical line of "no human plaintext access" addresses the element of "disclosure" in subsection 1: on the DAV reading (SN 32/2025), purely automated processing without a human taking cognisance does not amount to disclosure at all. That interpretation has not been conclusively settled by the courts. The BRAK is more conservative: on its AI guidance (as at 12/2024), the mere possibility of taking cognisance may suffice. The chain therefore runs both lines in parallel - contract and technology as a belt-and-braces risk argument, not as cumulative legal conditions.

Part of the criminal-law precision: § 203 StGB is an intent-only offence and, under § 205 StGB, prosecuted only on complaint. This chain is not about a threat scenario. It is about provability - to whom can a firm evidence that its supply route holds?

Sources: DAV opinion SN 32/2025 (anwaltverein.de), BRAK guidance on AI use, as at 12/2024 (brak.de); each retrieved 22 July 2026.

You know the links - now what?

The eight links are also available as a working document for provider conversations: eight questions, each with the form of proof and the usual trap. The instruments that carry them are set out in the contract kit.

Questions about the chain

Why eight links and not a certification?

Because there is nothing to certify against. No court has ruled on whether a cloud AI service is admissible under § 203 StGB, and the two professional-body positions differ. A certificate would have to assert a legal conclusion that nobody is in a position to issue. Eight verifiable artefacts do something a certificate cannot: they let you check each part yourself, and they let you run the same grid against any other provider.

What if a provider cannot evidence one of the links?

A missing piece of evidence is an open point, not a verdict - but it is precisely the point at which the assurance tears if the client, the chamber or a supervisory authority asks. The workable response is to request the missing evidence in writing and to document the answer. If the provider replies with a sentence rather than a document or a configuration record, you know where you stand.

Is the redaction layer what makes the setup compliant?

No, and any provider who tells you otherwise has the argument the wrong way round. Pseudonymisation before the model call and re-insertion afterwards are data minimisation and a second line of defence. They lower the residual risk under both readings of the law. What carries the legal line is the obligation under § 203 Abs. 4 StGB and the contract chain around it.

Hold the eight links against your own setup

We walk them against your planned or running deployment - supply route, contracts, deployment type. As a technical and organisational assessment, not as legal advice.

Book a conversation