Skip to main content

AI in tax advisory firms: what is permitted with client data

Client data is subject to fixed rules from professional law, criminal law and data protection law. Many tasks need no client data at all.

8 min read

Tax adviser working on a laptop in front of a bookshelf

Key points

  • Client data belongs only in tools covered by a contract under § 62a StBerG and, where personal data is involved, by a data processing agreement under the GDPR.
  • If the use directly serves a single engagement, the client's consent is also required.
  • In the view of the Federal Chamber of Tax Advisers, private AI accounts are not permitted for firm work, and tools that have not been approved may only receive anonymised information.

May a firm enter client data into an AI tool? That depends on the specific access: the contract with the provider, the account used for the work and whether the task needs the data at all.

The firm checks this once for each tool and records the result as a rule. After that, a few questions before each prompt are enough in daily work. The legal assessment of the individual case is for your firm to make.

What § 62a StBerG requires

Tax advisers may give service providers, including AI providers, access to information protected by client confidentiality, to the extent this is necessary for the service (§ 62a(1) StBerG, the German Tax Advisory Act). The provider must be selected with care (subsection 2). The contract must be in text form (email is enough). It obliges the provider to maintain confidentiality and informs it of the consequences of a breach under criminal law, limits its knowledge to what is necessary and states whether it may involve other persons (subsection 3). If the service is performed abroad, the protection of secrets there must be comparable to that in Germany (subsection 4).

If the use directly serves a single engagement, the client's consent is also required (subsection 5). Whether an AI tool falls under this has not yet been conclusively settled. The Federal Chamber of Tax Advisers (BStBK) advises obtaining consent before entering sensitive information.

Data protection law remains unaffected (subsection 8): where personal data is processed, a data processing agreement (DPA) under Article 28 GDPR is needed as well. In addition, professional secrets are protected under criminal law by § 203 StGB (German Criminal Code).

The duty of confidentiality covers everything that has become known in the course of professional practice (§ 57(1) StBerG). It therefore also covers information about companies, which the GDPR as such does not protect. Articles of association or a balance sheet can thus fall under confidentiality even if they name no individual.

For your own team, § 62 StBerG applies: employees must be bound to confidentiality in text form and informed of the consequences under criminal law. A firm rule for AI also sets out in which tools this confidentiality is maintained.

What the chamber and the AI Forum recommend

The Federal Chamber of Tax Advisers sees AI as an amplifier of tax expertise, not a replacement for it. Responsibility stays with the qualified tax adviser, and AI results must be checked. The chamber recommends an internal set of rules for AI and providers based in the EU or with data centres in the EU. The location of the servers alone is not sufficient. It considers private AI accounts for work purposes to be impermissible. New tools should be checked and approved before they are introduced, for example by firm management, the data protection officer or a person responsible for IT.

Unless the conditions of § 62a are met, only anonymised data belongs in an AI tool. The BStBK FAQ still refers to anonymisation or pseudonymisation. The guidance paper prepared for the AI Forum run jointly by the chambers (KI-Forum, as of 28 July 2026) makes it clear: pseudonymised data generally remains personal data and a professional secret. The paper does not represent a binding position of the chambers. The legal assessment of the individual case is for your firm to make.

The guidance paper names two further points for practice. Removing the name and tax number is often not enough to anonymise data: sector, location, amounts, unusual circumstances or file metadata can make a person identifiable again. And a business or enterprise plan is a sign of better controls. The review under § 62a StBerG, § 203 StGB and the GDPR for the specific configuration is still necessary.

Questions for the provider before approval

Before a tool is approved for client data, the firm needs answers from the provider. The following list summarises what § 62a StBerG and Article 28 GDPR require and what the guidance paper recommends for vetting providers. You can send it as it is to the provider or your software partner and file the answers with the approval.

  • Who is our contracting party, and which product, plan and features does the contract cover?
  • Do you commit to confidentiality in text form, with notice of the consequences under criminal law, as required by § 62a(3) StBerG?
  • Do your employees access our data only to the extent necessary to perform the contract, including in support?
  • Which other service providers do you use, and do you bind them to confidentiality in text form?
  • Where are prompts processed and stored, including logs, backups and support access?
  • Are our prompts used for training or product improvement, and can this be excluded by contract?
  • How long do you store prompts and responses, and how do you prove deletion?
  • Will you conclude a data processing agreement with us under Article 28 GDPR?

A label such as “GDPR-compliant” or “hosted in the EU” answers only part of these questions. The guidance paper also recommends limiting each approval in time and reassessing it at least once a year or whenever something changes.

Decision guide before every prompt

Once a tool has been checked, the task decides in daily work. These rules fit on one page that can sit next to your screen.

  • If the task needs no reference to a client, then work in the approved tool and check the result as usual.
  • If the task needs client data and the tool is approved for it, then use the firm account and enter only what the task requires.
  • If the use directly serves a single engagement and involves sensitive information, then obtain the client's consent first.
  • If the tool is not approved for client data, then only anonymised information goes in. Replacing names is not enough.
  • If it is a private account, then no firm work goes into it.
  • If you are unsure, then ask the responsible person in the firm before you enter anything.

Many tasks need no client data at all:

  • summarising circulars and BMF letters (guidance from the Federal Ministry of Finance)
  • drafting checklists and template letters
  • preparing internal processes and minutes without any client reference, in a tool approved by the firm
  • answering team questions from the firm manual

Example: explaining a tax assessment notice

A tax assistant needs to explain to a client why the income tax assessment notice differs from the return. She wants the AI to produce a draft in plain language.

Before: She copies the notice, with name, address, tax number and all amounts, into an AI account she uses privately. Information protected by client confidentiality thus reaches a provider with no contract under § 62a StBerG and no data processing agreement. In the view of the Federal Chamber of Tax Advisers, this is not permitted.

After: She works in the approved tool through the firm account. She describes only the discrepancy in general terms, without name, address, tax number or amounts. She adds personal details later, in the firm's practice software. The qualified tax adviser checks the substance before the letter is sent.

A sample prompt for this step:

“You are helping a tax advisory firm with a letter to a client. The income tax assessment notice differs from the return: [discrepancy in one sentence, without names, places or amounts]. Explain in plain language and in no more than five sentences what this means for the client. Leave placeholders such as [SALUTATION] and [AMOUNT] as they are. Mark every statement that needs a professional check before the letter is sent.”

The placeholders keep personal details out of the prompt. They do not replace the approval of the tool, because even a discrepancy without names can point to a client in context.

Template for your firm rule

The Federal Chamber of Tax Advisers recommends an internal set of rules for AI. The following text is a starting point for the section on client data. Adapt it to your firm and have it adopted by firm management.

  • “We enter client data only into tools that firm management has approved for this purpose. The list is kept at [location].”
  • “We work exclusively through firm accounts. We do not use private AI accounts for firm work.”
  • “We enter only the information the task requires.”
  • “Only public or anonymised information goes into tools that have not been approved. Replacing names does not count as anonymisation.”
  • “If the use directly serves a single engagement, we obtain the client's consent before entering sensitive information.”
  • “A person with the relevant expertise checks every result before it leaves the firm. Responsibility stays with the qualified tax adviser.”
  • “We report questions, errors and accidental entries immediately to [contact person].”

Also record which tool is used for what. The Federal Chamber of Tax Advisers suggests a lean AI register for this: one line per tool with purpose, type of data, documentation level and responsible person. There is no statutory form for it.

Firm management decides which tools are approved for client data.
Firm management decides which tools are approved for client data.

Next steps

  • Record which AI tools are used in your firm today, including those that were never officially introduced.
  • Send the list of questions to the providers of the tools that are to process client data.
  • Adopt the firm rule and name a contact person.
  • Go through the decision guide with the team using two or three typical tasks, with made-up data.

If you would like support with this: AI training for tax advisory firms is a half-day session for qualified tax advisers and firm management. It covers confidentiality, data protection and the EU AI Act in practice. You leave with review steps, a checklist for tools, a draft of your AI policy and a certificate of attendance for each person. The exercises use no real client data.

Which tools is your team already using today that have not been checked?

Frequently asked questions

May an AI assistant advise clients?

Not on its own. Only persons and associations authorised to do so, such as tax advisers, may provide assistance in tax matters on a professional basis (§§ 2 and 3 StBerG). A firm's assistant identifies itself as AI, provides information, collects documents and hands over to a person as soon as the individual case needs a legal review.

Do we need the client's consent for every use of AI?

No. § 62a StBerG permits the use of service providers without consent if its conditions are met. If the use directly serves a single engagement, consent is required. Whether an AI tool falls under this has not yet been conclusively settled, so the Federal Chamber of Tax Advisers advises obtaining consent before entering sensitive information.

Is it enough to remove names and tax numbers?

Often not. According to the guidance paper for the AI Forum, sector, location, amounts, unusual circumstances or file metadata can make a person identifiable again. Pseudonymised data generally remains personal data and a professional secret. Only anonymised information belongs in a tool that has not been approved.

Is a provider with servers in the EU enough?

No. The Federal Chamber of Tax Advisers recommends providers based in the EU or with data centres in the EU, and the server location alone is not sufficient. You also need the contract under § 62a StBerG and, for personal data, the data processing agreement.

Do we have to tell clients that we use AI?

According to the Federal Chamber of Tax Advisers, there is currently no explicit obligation to do so under professional law. If personal client data flows to an AI service, the firm's privacy notice should explain this. If you obtain consent under § 62a(5) StBerG, explain the specific use when you ask for it.

Does our firm have to provide AI training?

Under Article 4 of the EU AI Act, anyone who uses AI must take measures that support the development of AI literacy. Training with a certificate of attendance is an obvious measure that is easy to document.

Sources

  1. § 62a StBerG, German Tax Advisory Act (in German)
  2. GDPR, Article 28, EUR-Lex
  3. BStBK, FAQ on AI (January 2026) (in German)
  4. Guidance on AI in tax advice, KI-Forum (as of 28 July 2026) (in German)
  5. § 2 StBerG, German Tax Advisory Act (in German)
  6. § 3 StBerG, German Tax Advisory Act (in German)
  7. § 57 StBerG, German Tax Advisory Act (in German)
  8. § 62 StBerG, German Tax Advisory Act (in German)
  9. § 203 StGB, German Criminal Code (in German)
  10. EU AI Act (Regulation (EU) 2024/1689), Article 4, consolidated version of 27 July 2026, EUR-Lex

Updated: . This article is not legal advice.

AI training for tax advisory firmsProfessional secrecy, data protection and the EU AI Act in practice
See the training

Read next

Questions about your situation?

In a first call we discuss your questions and possible next steps. 30 minutes, no obligation, by phone or video.