GDPR and Legal AI: What every law firm must know in 2026
Using AI in a law firm without violating GDPR or professional secrecy: checklist, pitfalls to avoid, and criteria for choosing a compliant tool.

Consumer AI tools (ChatGPT, Claude, Gemini) are not suitable for processing data covered by professional secrecy. Here is how to frame the use of AI in your firm without sacrificing the productivity it provides.
The stakes are not theoretical: several European bars have begun to sanction failures related to the unmanaged use of AI tools. And CNIL/DPA case law is tightening every quarter.
The double framework: GDPR + Professional Secrecy
The lawyer is a data controller within the meaning of the GDPR and is bound by professional secrecy by ethics. Any tool that processes client data must respect both regimes — which are cumulative, not alternative. GDPR compliance never exempts one from secrecy, and vice versa.
In concrete terms, this requires: a clear legal basis for each processing operation, rigorous minimization of data sent to the AI, traceability of access, and a contractual guarantee that the provider will never exploit this data for other purposes.
The 5 criteria for a compliant AI tool
- Hosting exclusively in the European Union, without transfer to the United States or China.
- Contractual guarantee that your data is never used to train public models.
- End-to-end encryption at rest and in transit (AES-256, TLS 1.3 minimum).
- Strict data partitioning by firm (verifiable logical multi-tenancy).
- Provider subject to European law, not exposed to the American Cloud Act.
In addition to these five central criteria are often overlooked elements: the ability to configure the retention period of prompts, logging of admin access, and the ability to export or delete all data from a file in one click — a direct requirement of Article 17 of the GDPR.
The pitfalls to absolutely avoid
Pasting a file into ChatGPT
A seemingly harmless gesture, but in reality a characterized violation of professional secrecy and an unmanaged transfer of data outside the EU. The disciplinary risk is real, and the reputational risk is even more significant: a single public incident can destroy years of positioning.
Believing that an "opt-out training" option is enough
Disabling training does not erase the international transfer of data or the risk of requisition by a foreign authority. This is only one part of the equation. An opt-out training does not change the legal sovereignty of the provider.
Relying on a generic, non-negotiated "DPA"
Many providers offer a standard DPA that refers to incomplete standard contractual clauses. Have it audited by a competent DPO or IT lawyer before signing.
The checklist before signing an AI contract
- Request a signed DPA (Data Processing Agreement).
- Demand the list of subcontractors and their location.
- Verify ISO 27001 certification or equivalent.
- Read the reversibility and data export clause.
- Test the tool on a fictional file before deployment.
- Verify the existence of a PIA (Privacy Impact Assessment) from the provider.
- Ensure notification within 72 hours in the event of a breach.
Internal Governance: The firm's AI policy
No compliant tool replaces a clear internal policy. Every firm deploying AI should formalize: who can use which tools, on which types of cases, with what traceability, and which behaviors are strictly prohibited (copy-pasting into unapproved tools at the top of the list).
This policy must be annexed to the internal regulations, signed by all employees, and reviewed annually. It is also a commercial differentiator for demanding clients.
The KAIUS approach
KAIUS is published by a Belgian company, hosts all data in Europe, does not share any information with public models, and provides a signed DPA to each client firm. This discipline allows sensitive firms to adopt it with peace of mind, including for cases covered by reinforced confidentiality agreements.