flowsulting.
[00/Guide · Privacy & law]

Is AI automation GDPR-compliant? With § 203 German Criminal Code for tax advisors, doctors and lawyers

Last updated: 2026-07-11 · by Florian Zitzmann, flowsulting

Short answer

Yes — AI automation is GDPR-compliant when five requirements are met: data processing in the EU, a data processing agreement with every service, human final decisions, access plus source code owned by the client — and, for professionals bound to secrecy (tax advisors, doctors, lawyers), the provider's written confidentiality obligation under § 203 German Criminal Code before the project starts.

The five requirements at a glance

RequirementWhyHow it's done in practice
Data processing in the EUArt. 44 ff. GDPR — third-country transfers need their own legal basisChoose AI models and hosting with EU processing; no customer data to US endpoints without a legal basis
Data processing agreement (DPA)Art. 28 GDPR — mandatory as soon as a provider processes personal dataDPA with every integrated service; the client receives the list of sub-processors
§ 203 German Criminal Code (professional secrecy)Tax advisors, doctors and lawyers may only share client or patient data with formally obligated providersWritten confidentiality obligation of the provider before the project starts (§ 203 (4) German Criminal Code)
Human final decisionArt. 22 GDPR — no purely automated decision with legal effectAI prepares (drafts, sorting, extracts); approval and decisions stay with people
Access & source code with the clientAccountability (Art. 5 (2) GDPR) and control over your own processingAll accounts belong to the business; workflows and source code belong to the client, not the consultant

In short: GDPR compliance is not a property of the AI, but of the project. The same technology can be used compliantly or not — the difference lies in contracts, data flows and responsibilities.

§ 203 German Criminal Code: the extra hurdle for tax advisors, doctors and lawyers

For professionals bound to secrecy, the GDPR alone is not enough. Client and patient data are additionally protected under criminal law by § 203 German Criminal Code. The good news: in 2017 the legislator clarified that external providers may be involved — under one clear condition. The provider must be obligated to confidentiality in writing before first accessing protected data (§ 203 (4)) and then becomes personally liable under criminal law for breaches.

In practice this means: the confidentiality obligation and DPA are signed before any system is connected. flowsulting does this by default at project start — not on request. For firms and practices there is one more principle: the AI only prepares. It sorts documents, drafts replies, prepares appointments. The professional judgement and every outbound approval stays with the professional.

And the EU AI Act?

The EU AI Act classifies AI applications by risk. The typical office workflows — email drafts, document matching, quote and appointment preparation — sit in the minimal-risk category. What matters is transparency (staff know where AI is used) and human oversight, which a clean setup includes anyway. High-risk applications such as automated candidate screening are a different field and not part of such projects.

Note: this article explains the practice from an automation provider's perspective and does not replace legal advice. For a legal assessment of your individual case, talk to your data protection officer or a specialist lawyer.

Frequently asked questions about GDPR and AI automation

Is AI automation GDPR-compliant?

Yes, if set up correctly: data processing in the EU, a data processing agreement with every integrated service, human final decisions on anything with external effect, and full client control over access and source code. It is not the AI tool that determines compliance, but the implementation.

May tax advisors, doctors and lawyers use AI automation (§ 203 German Criminal Code)?

Yes. Since the reform of § 203 German Criminal Code, professionals bound to secrecy may involve external providers if those providers are obligated to confidentiality in writing before accessing protected data (§ 203 (4)) and a data processing agreement is in place. This obligation must happen before the project starts, not afterwards.

Does AI automation transfer data to the US?

Not necessarily. For most business processes there are AI models and hosting options that process data in the EU. flowsulting selects services so personal data stays in the EU; where that is not possible, the workflow is built so that no personal data leaves the system.

What does the EU AI Act mean for AI automation in businesses?

Typical office automations — email drafts, document sorting, appointment preparation — fall into the minimal-risk category and are mainly subject to transparency duties. High-risk applications (such as automated hiring or credit decisions) are a different field and not part of such projects. What matters: people keep the final decision.

Read on

Want to know which of your processes can be automated in a GDPR-compliant way? The free AI scan shows you in a few minutes — or book the free audit directly, 30 minutes, no sales pitch.

Take the AI scan first