Skip to content
Novot AI
NLBook a call
← Back to knowledge base

AI and client contact at a law firm: the duty of confidentiality

On top of the privacy rules, a law firm is bound by the duty of confidentiality in article 11a of the Dutch Advocates Act: everything you learn in your profession is secret, even when no personal data is involved. If you use AI for client contact, the question is not only whether you have a legal basis, but whether your supplier sits inside your circle of confidentiality. Logistical messages such as appointments can be automated; anything touching the client's legal position belongs with a human. Record it in your engagement letter and agree confidentiality separately with your supplier.

Published on

Why is a law firm a different case from an ordinary business?

Most business owners who put AI into their customer contact have one set of rules to keep in mind: data protection law. At a law firm or a legal practice there is a second layer on top of that, and that layer is older, stricter and more personal. It is the duty of confidentiality.

That duty is set out in article 11a of the Dutch Advocates Act. The core of it: unless otherwise provided by law, the advocate is bound to secrecy in respect of everything he learns of in the exercise of his profession as such. Note what it says. Not "personal data". Not "sensitive information". Everything you learn in the exercise of your profession. The fact that the client came to see you is already secret. The subject of the matter is secret. The existence of the matter is secret.

That same provision extends the duty to the advocate's associates and staff, and to other persons involved in the exercise of the profession. That last part is exactly what is at stake the moment a supplier's software enters the picture.

Article 10a of the Advocates Act sets out what all of this is for. It lists the core values of the profession: independent in relation to the client, third parties and the matters in which the advocate acts, partisan in serving the client's legitimate interests, and a person of trust. "Person of trust" is not a nice phrase for the brochure. It is the reason someone dares to tell you things he tells no one else.

Why does the duty of confidentiality go further than the privacy rules?

You need a legal basis for any processing of personal data anyway, and that does not change here. But the duty of confidentiality works differently, and it is stricter on four points.

  • It is not only about people. An acquisition file for a company without a single natural person in it falls outside the privacy rules, but sits squarely inside your professional secrecy.
  • There is no balancing test. Under data protection law you can base a processing operation on an interest you weigh against the interests of the person concerned. The duty of confidentiality has no such dial. You stay silent, unless the law itself provides otherwise.
  • Criminal law sits behind it. Article 272 of the Dutch Criminal Code makes it an offence when someone who knows or ought reasonably to suspect that he is bound to keep a secret by virtue of his office, profession or a statutory provision, or a former office or profession, intentionally breaches that secret. That is not an administrative fine for the firm. It is a criminal offence aimed at a person.
  • There is disciplinary law. Alongside the statute, the disciplinary tribunal tests your conduct against the core values. A privacy regulator looks at the data processing; the disciplinary tribunal looks at the profession.

The counterpart of the duty of confidentiality is legal professional privilege: the right to say nothing as a witness, and the right that documents covered by your secrecy stay out of reach of the authorities. Neither works without the other. If you had to speak after all, staying silent would be pointless. That is why the privilege is not yours personally but the client's, and you merely administer it. That is the sentence to keep in your head with every technical decision: you are the custodian of someone else's secret.

What does it mean when client information passes through a third party's system?

An AI that reads your email, answers your WhatsApp or writes up your phone calls always does the same thing: it moves text. From your environment to a processing environment and back again. The moment that text contains a client name, a matter number or a subject line, you are moving a secret.

The question then is not whether that is allowed, but whether the party on the other end sits inside or outside your circle of confidentiality. The Advocates Act itself provides the hook: the duty also applies to other persons involved in the exercise of the profession. A supplier processing messages on your behalf can therefore be brought inside that circle. But that does not happen by itself, and not with a standard contract.

Three things matter here, and they are often confused with one another.

  1. A data processing agreement is not a confidentiality arrangement. It is a privacy instrument. It governs how a party processes personal data on your behalf. It says nothing about your professional secrecy, and it does not make a third party a party to that secret. You need both, and the second one is usually not in there.
  2. The label decides nothing; the practice does. The Dutch Data Protection Authority puts it this way: the organisation that actually determines the purposes and the means of the processing is the controller, regardless of what the processing agreement says. Translate that to your own situation. If your supplier decides for itself what happens to the text, for instance because it improves models with it, then it is not an extension of your firm. Then it is a third party reading your files.
  3. Sub-processors count. Your supplier has suppliers of its own. Every link that can see the text sits inside or outside your circle. Without a list of those links you do not know where your secret ends up.

In practice this means that "where is my data stored" is not the most important question. The most important question is: who may reach it, under what arrangement, and what may they do with it.

This is where the reasoning most often goes wrong, because two questions have been folded into one.

The first question is the privacy question: may you process this personal data? You answer that with a legal basis, and consent is rarely the most practical choice there.

The second question is the confidentiality question: may you share this information with a party outside your firm? A legal basis is not enough for that. The secret belongs to the client. Only he can release you from it, and only if he understands what he is agreeing to.

Two nuances you should not skip. First: if your supplier genuinely sits inside your circle of confidentiality, then strictly speaking you are not sharing the secret with an outsider, just as you are not sharing it with your own secretary. In that case a release is not required, but setting up that circle is your responsibility, and you have to be able to demonstrate it. Second: even with the client's release, you remain the one who judges whether it is wise. Consent from a client who cannot assess the risk he is running is not cover. The core value of independence in article 10a also means: independent in relation to your client.

In practice it comes down to this. For an assistant that only provides general information and never touches the substance of a matter, informing the client is enough. For anything that touches the substance, you want it arranged explicitly, and preferably in writing, in the engagement.

What do you record in your client engagement letter?

The engagement letter is where this belongs, not a cookie banner or a line at the bottom of your website. Your client is entering into an agreement with you as a person of trust. So it should state who else is reading along.

Six points that make the difference:

  • That automated tools are used, and for what. Describe the function, not the brand name: taking in first messages, producing a call summary, searching a file.
  • Where the information is kept and stays. Inside the European Economic Area or not. For your client that is a concrete question, certainly in a matter with an opposing party abroad.
  • That the supplier is bound by the same confidentiality. Refer to the duty the statute extends to persons involved in the exercise of the profession.
  • That the information is not used to train models. This is the one sentence your client will genuinely remember, and rightly so.
  • What a human always does. State that advice, litigation decisions and deadline monitoring rest with the advocate handling the matter. That is precisely the reassurance that counts.
  • How he opts out. A client who would rather have no automated tool anywhere near his matter must be able to say so without it becoming a hassle. Record whom he tells.

Also put a confidentiality clause into the contract with your own supplier, separate from the privacy arrangements, with a ban on sub-contracting without your agreement. That clause is your only real handle when something goes wrong.

Which messages do you never let an AI handle?

The dividing line does not run between easy and hard, but between messages that touch the matter and messages that do not. Logistics may be automated. Legal position may not.

Types of client message at a legal practice and whether an AI may handle them
Type of messageHandled by an AI?Why
Opening hours, directions, how an intake worksYesNo substance and no client relationship needed; this is public information.
Rescheduling an appointment with an existing clientYes, calendar onlyOnly time and place. Do not let the system state what the appointment is about.
Invoice or payment questionYes, limitedFinancial administration can stand apart from the substance, provided the system does not look into the file.
First message from someone who is not yet a clientIntake onlyThe conflict check has not been done. Recording and passing on is fine, answering on the merits is not.
"What is the status of my case?"NoRequires file access and interpretation. A badly phrased status update is advice.
Substantive legal questionNoThis is the core of the profession. Advice belongs with an advocate who is liable for its content.
Message containing a deadlineNoObjection, appeal, limitation. A missed deadline cannot be repaired and goes straight to liability.
Message from the opposing party or its lawyerNoPosition-sensitive. Any reply can be read as a position, and there is a conflict of interest in play.
Message from the police, the public prosecutor or a courtNoTouches on legal professional privilege and on case documents. Belongs with a human who knows the matter.
Signal that may touch money laundering or terrorist financingNoCalls for an assessment the law places on the institution itself, with its own rules around the report.
Message about threats, violence or a crisisNoA badly timed automatic reply does real damage here. This goes straight to a human.
Request for the file or for copiesNoRequires identity verification and a judgement on what may and may not be released.

Two rules of thumb help when in doubt. First: if an error in the answer would change the client's legal position, the message goes to a human. Second: if the answer can only be given by looking into the file, the message goes to a human.

What does this mean for logs, transcripts and training data?

An automated assistant leaves traces, and those traces are themselves secret. A chat log in which someone asks about a criminal case, a call summary with the name of an opposing party, a list of subjects of incoming messages: these are all documents covered by your duty of confidentiality, and in principle you do not have to hand them over.

That has consequences an ordinary business never faces. Logs held at a supplier sit outside your walls. A support engineer who "takes a quick look" to fix a fault is looking at client information. A test environment with real messages in it is a copy of a file. And a system that uses messages to improve itself lets client information end up somewhere you can never get it out of again.

What you want to arrange here is small and concrete. How long logs are kept. Who can reach them. Whether anyone can look over your shoulder, and if so only with your approval each time. And whether messages are reused for training. That last one is a yes-or-no question. Do not settle for "we don't just use your data".

Think about the client's own side too. Someone who approaches you on WhatsApp about a divorce has those messages sitting on a phone his partner may be able to see. You cannot control that, but you can name it and offer a safer channel. That is classic lawyer's work, not a technical matter.

Where does confidentiality stop: anti-money-laundering rules and other exceptions

Article 11a opens with a reservation: unless otherwise provided by law. So there are statutory exceptions, and at a legal practice the best known is the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act.

That act provides that an institution carries out client due diligence in order to prevent money laundering and terrorist financing. And it provides that an institution reports an executed or intended unusual transaction to the Financial Intelligence Unit without delay, once the unusual character of the transaction has become known. For advocates this applies only to certain kinds of service, and specifically not to determining a client's legal position or representing a client in proceedings. That boundary is exactly why this work cannot be delegated to a machine: judging which side of the line a situation falls on is itself legal work.

For your AI setup, something down to earth follows from that. A system that takes in client messages is not a money-laundering detector and should not try to be one. What it can do is route a signal to the human who makes the assessment. So do not build an automatic conclusion; build a route.

The same goes for the identity verification the law prescribes for certain services. An automated assistant can request documents and put them ready. The verification itself, and the question of whether it adds up, remains work for people at the firm.

Where do you start at a firm that has done nothing about this yet?

A workable order, from cheap to expensive.

  1. List your channels. Where do messages come in: email, WhatsApp, phone, contact form? Which of these already carry substance today?
  2. Draw the line. Decide per type of message whether it is logistics or touches the matter. The table above is a starting point; your own practice decides the rest.
  3. Start with the most boring part. Appointments and general questions are the safest place to begin and immediately take pressure off the phone.
  4. Put your questions to the supplier on paper. Where is the data, who can reach it, is anything trained on it, who are the sub-processors, how long do logs stay, and will the supplier accept a confidentiality clause that goes beyond the privacy arrangements.
  5. Update your engagement letter. One paragraph, in plain language, covering the six points above.
  6. Write down the escalation route. What happens when a message falls outside the safe category, who gets it then, and within what time. Put that on paper, because that is what people actually act on.

The underlying principle is simple enough to explain to your whole firm. The client tells you something because he knows it stays with you. Every system you bring in has to be explainable as an extension of your own firm, not as a third party that happens to be reading along. If you cannot explain it that way, the information does not belong in it.

See what Novot AI can do for your business.

Book a call