AI in consulting: working under a non-disclosure agreement
Which rules apply to consultancies using AI?
The legal position is simpler than for the chambered professions — and for exactly that reason it is often underestimated.
- The non-disclosure agreement. It is the actual yardstick. NDAs regularly contain a clause permitting disclosure to employees, advisers and service providers, provided they are engaged on a need-to-know basis and bound to equivalent confidentiality. Where no such clause exists, or where it is drawn narrowly, every use of a service provider requires consent — including the use of an AI tool.
- § 2 no. 1 lit. b GeschGehG. Information is a trade secret only if it is "subject to reasonable steps under the circumstances, by the person lawfully in control of the information, to keep it secret". This is not a formality: absent those steps the protected status falls away — and with it the claims for injunctive relief, destruction and damages under §§ 6 et seq. GeschGehG. The loss lands on your client, and the question about its cause lands on you.
- The GDPR. Consulting projects almost always contain personal data: staff lists, org charts, salary bands, candidate profiles, customer records. That requires a legal basis (Art. 6), a data processing agreement with every provider engaged (Art. 28), and, with US providers, a solution to the third-country problem (Art. 44 et seq., Schrems II).
- No criminal law. Consultants are not professionals bound by secrecy under § 203 StGB. There is no chamber, no instruction requirement, no personal criminal liability. That is a genuine structural advantage over law firms and medical practices — the requirements are contractual, and therefore solvable by contract.
Why are public chatbots particularly delicate here?
The usual objection is: "it's only a summary." But consulting material is rarely harmless. A due-diligence extract, a restructuring plan, a price list, a competitive analysis, a post-acquisition integration concept — these are the documents whose premature disclosure derails transactions and destroys negotiating positions.
With the consumer and free versions of the major chatbots the default is: inputs are stored and may be used for training unless you actively object; processing is predominantly in the United States, where the CLOUD Act permits authority access even to data on European servers held by US providers. It was precisely this tension that brought down the Privacy Shield in Schrems II (C-311/18).
For a consultancy the consequence is twofold. First, the breach of contract towards the client. Second — and harder to repair — the question whether the information concerned was still subject to "reasonable steps to keep it secret" at all. A provider that stores inputs and uses them for training is hard to defend as a reasonable step.
The practical risk here too is shadow AI: project teams use private chatbot accounts because there is no official, approved tool. A compliant channel removes the reason for that — and is itself evidence of your confidentiality measures.
What is AI actually worth in consulting?
- Analysis and synthesis: condense interview notes, workshop minutes and free-text responses into themes; reduce market reports and competitive material to what matters for the project.
- Deliverables: management summaries from technical notes, storylines for presentations, chapter drafts for reports — the structure stands in minutes, the judgement stays with you.
- Proposals and tenders: structure responses to statements of work, adapt reference texts, formulate queries to the client.
- Project operations: status reports, risk registers, action plans, onboarding material for new team members.
- Translations for international engagements — without project material leaving the house or the EU.
- Knowledge work: methodology write-ups, checklists, training material, FAQs for recurring client questions.
What remains essential: the professional judgement, the recommendation and the responsibility towards the client stay with you. AI supplies structure and a first draft, not consulting work — and figures taken from AI responses must always be checked against the source.
How PrivatAI meets the requirements
PrivatAI stores nothing: inputs and responses are processed and discarded — not logged, never used for training. One exception: in the event of system errors or detected misuse, the inference data centre may temporarily retain a single request in order to analyse the cause; this is contractually limited and disclosed in the DPA (§ 4 no. 2). Even then there is no use for training and no access by model providers.
We are contractually bound to confidentiality towards you. As a processor under Art. 28 GDPR we ensure that all persons authorised to process data are bound to confidentiality (DPA § 4 no. 3, Art. 28(3)(b), Art. 29 GDPR). The same requirement applies to the sub-processors engaged. Whether your particular non-disclosure agreement permits the use of service providers follows from its wording — usually it does, where the provider is placed under equivalent obligations.
Processing exclusively within the EU: the application runs in Germany (Hetzner), the AI processing in France (Scaleway). No US parent company, no CLOUD Act access. The technical and organisational measures are documented and the sub-processor chain is public — both are precisely the material with which you evidence reasonable confidentiality measures to your client.
Ready immediately: browser chat for everyday work, OpenAI-compatible API for connecting your own tools and knowledge bases.
PrivatAI supplies the technical and contractual prerequisites for compliant use. Whether a particular use is compatible with your non-disclosure agreement is a question you answer from its wording — no provider can certify that for you.
PrivatAI (privatai.com) — AI chat & API from Germany. No content logs*, no training on your data, GDPR-compliant.
PrivatAI compared (default settings)
| Criterion | PrivatAI | Public US chatbots (default) |
|---|---|---|
| Storage of inputs in normal operation | None — processed and discarded | Yes, conversations are stored |
| Training on project data | Never | Frequently by default (opt-out required) |
| Place of processing | EU (DE/FR) | Predominantly USA |
| CLOUD Act access | No (EU provider) | Possible |
| DPA (Art. 28 GDPR) | Yes (DPA) | Business plans only |
| Contractual confidentiality | Yes (DPA § 4 no. 3) | Varies |
| Evidence of confidentiality measures | DPA, TOM, sub-processors public | Hard to establish |
All figures describe normal operation. The one narrow exception — temporary retention of individual requests on system errors or detected misuse — is disclosed in full in the DPA (§ 4 no. 2).
* In normal operation. The one narrow exception — temporary retention of individual requests on system errors or detected misuse — is disclosed in full in the DPA (§ 4 no. 2).