Skip to content

The documents, before the conversation

Five of the seven sample instruments are open on the web - no registration, no form. So that what we claim can be checked before you speak to us, and so that the same grid can be run against any other provider.

A selection from over 5,000 projects in 25 years of software development

Airbus Volkswagen Shell Renault Evonik Vattenfall Philips KPMG

Why most of the kit is open

Anyone assessing an AI supply route under German professional secrecy runs into a procurement problem: the documents that decide the question usually arrive only once you are already inside a sales process. Here it is mostly the other way round. Five of the seven samples are open, so that the assessment can happen before the conversation - and so that it can be run against other providers too. Two building blocks carry supplier names in clear and are confidential for a reason of law rather than of marketing: § 203 Abs. 4 Satz 2 Nr. 1 StGB and § 43e BRAO require verifiability towards the firm before the engagement, not prior publication to the world.

Between them the blocks cover the links described in the eight-link chain: the criminal-law obligation under § 203 Abs. 4 StGB, the data processing agreement, the onward obligation of sub-contractors, third-country transfer, retention and client consent.

A note on language. The commentary on this page is English; the operative documents are German, and deliberately so. Each is an instrument of German law, drafted to be signed under German law and read by a German court or chamber if it is ever tested. An English operative text would be a second version whose wording has never been reviewed - and in a dispute the first question would be which version governs.

Status v0.11 (18 August 2026). Samples for case-by-case adaptation by a lawyer, without warranty; this does not constitute legal advice.

The seven building blocks

1. Secrecy addendum under § 203 Abs. 4 StGB

The centrepiece: the separate obligation of the assisting person to secrecy, in text form and with an express notice of that person's own criminal liability under § 203 Abs. 4 Satz 1 StGB. Precisely the document that a data processing agreement does not replace.

Open as PDF · Word version to adapt

2. DPA component under Art. 28 GDPR

The data protection part, with the Gosign self-undertaking, the rules for the gateway and mapping, and the undertakings on non-storage at the model provider.

Open as PDF · Word version to adapt

3. Sub-processor list

Who besides us is involved in the processing, with the status of each participant and the mechanics of how changes are notified. This is the link at which provider chains most often tear in practice. The list names names, which is why it is not open on the web - Art. 28 Abs. 2 GDPR directs this information to the controller, not to the public.

Request access

4. Third-country transfer component (Art. 44 et seq. GDPR)

The frame for the transfer impact assessment, the position on the Data Privacy Framework and the supplementary measures. Relevant wherever a group with a US connection remains in the chain. The open version is the shortened, supplier-free one; the full provider version with names and DPF status per provider is confidential for the same reason as the list above.

Open as PDF · Word version to adapt · Request the full version

5. DPIA template (Art. 35 GDPR)

The data protection impact assessment as a template, with the input components a processor has to contribute under Art. 28 Abs. 3 lit. f GDPR.

Open as PDF · Word version to adapt

6. Retention matrix, client consent and transparency notice

Retention and deletion periods as a matrix, together with the sample client consent (§ 43e Abs. 5 BRAO, § 62a Abs. 5 StBerG, § 50a Abs. 5 WPO), the parties' consent for notaries (§ 26a Abs. 4 BNotO) and the transparency notice under Art. 13 and 14 GDPR.

Open as PDF · Word version to adapt

7. Kit overview and disclaimer

A short description of every building block together with its version status in one file - the fastest way to get an overview.

Open as PDF · Word version to adapt

If you would rather not build the supply route yourself

The kit shows what the chain has to look like. Building it yourself means: finding a model provider that will sign a secrecy agreement under § 203 Abs. 4; carrying that contractual matter through to signature; applying for the technical exceptions that exclude access to your inputs; having the instruments drafted by counsel - and re-doing the work every time a provider changes something. That is a project measured in months, and it does not end, because the position keeps moving.

We can walk the chain against your setup - as a technical and organisational assessment, not as legal advice.

Questions about the kit

Why are the documents in German when this page is in English?

Because each one is an instrument of German law. They are drafted to be signed under German law and to be read by a German court or chamber if they are ever tested. Producing an English operative text would create a second version whose wording has never been reviewed - and in a dispute the question would be which version governs. This page explains in English what each document does, so that general counsel or procurement can assess the set before the German colleagues sign it.

Do we have to register to get the kit?

Partly. Five of the seven building blocks are open on the web and available without a form, an email address or a conversation. The sub-processor list and the full transfer assessment are confidential: Art. 28 Abs. 2 GDPR directs that information to the controller, not to the public. For those two an email address for confirmation is enough - after that the access is open.

Can we use the samples to assess a different provider?

They are cut so that the assessment logic transfers - obligation under § 203 Abs. 4 StGB, onward obligation of sub-contractors, third-country transfer, retention, consent. The Gosign-specific undertakings inside them are recognisable as such and would be replaced for another provider. Using them as a grid against other providers' assurances is an express purpose.

What is the legal status of the kit?

v0.11, dated 18 August 2026. These are samples for case-by-case adaptation by a lawyer, without warranty, and using them does not constitute legal advice.

Is the DPA component enough on its own?

No, which is why there are seven documents rather than one. The DPA under Art. 28 GDPR governs processing on instructions under data protection law. § 203 Abs. 4 Satz 2 Nr. 1 StGB additionally requires the assisting person to be obligated to secrecy, in text form and with an express notice of criminal liability. That is the addendum, building block 1.

Have the kit checked against your setup

We walk the building blocks against your planned or running AI deployment - as a technical and organisational assessment, not as legal advice.

Book a conversation