DATEV and Microsoft 365: the unresolved data protection dilemma for law firms

DATEV deems Microsoft 365 fundamentally possible in law firms and shifts the burden of proof to the user. What this means for your law firm.

Hand-drawn sketch: two document folders side by side, connected by a thin line, with an open padlock resting on the line.

Almost every tax law firm works with two systems in parallel: DATEV for business applications, Microsoft 365 for email, files and meetings. In data protection between DATEV and Microsoft 365, a gap emerges that hardly anyone notices in law firm everyday life: DATEV is the processor, the law firm is responsible. And DATEV explicitly requires the user—you—to provide proof of GDPR compliance for Microsoft 365.

In short

DATEV deems Microsoft 365 fundamentally possible in tax law firms but places the responsibility for documenting GDPR compliance with the user. Anyone using both systems therefore requires their own written proof. The data processing agreement with Microsoft does not replace it.

Who is responsible for data protection at DATEV?

The law firm, not DATEV, is responsible under the GDPR. In their FAQs on GDPR and Data Processing (as of 28.01.2025) DATEV describes the allocation of roles itself: The data processing agreement takes into account "your interests as the client and data protection controller and DATEV's interests as the processor" equally. And more clearly: even with a designated data protection officer, responsibility for GDPR compliance lies "exclusively with the controller, i.e., the law firm owner".

This allocation of roles is legally correct. But it has one consequence that gets lost in law firm everyday life: in the same document, DATEV states that the majority of GDPR measures must be implemented "independently of DATEV programs" such as the inventory of processing activities and the review of legal bases. If you understand law firm software as a comprehensive data protection package, this statement says otherwise.

What does DATEV itself say about Microsoft 365 in the law firm?

DATEV deems Microsoft 365 permissible in tax law firms but completely shifts the burden of proof to the user. In the Statement on the Use of Microsoft 365 Cloud Services (as of 04/2024) it says that use is for tax and accounting professionals "fundamentally possible". The next sentence is the crucial one: "However, it is incumbent on users to document, based on information provided by Microsoft, that all GDPR requirements with regard to Microsoft 365 use are met."

On the older page DATEV and Microsoft it still says today that the use of Microsoft 365 lies "in the area of responsibility of the respective users". The tone has shifted between 2022 and 2024, the responsibility never.

Our position: This is not negligence on DATEV's part, but the only statement a processor is permitted to make. The dilemma remains unresolved because the shift disappears in law firm everyday life. It sits in a PDF that no one reads until the regulatory authority or a client asks.

Why is the data processing agreement with Microsoft not sufficient?

A data processing agreement regulates cooperation but does not prove the legality of processing. DATEV formulates this sharply in the same statement: "The controller must maintain independent proof of the legality of its processing activities. The processor has no obligation in this regard." The basis is the accountability requirement under Article 5(2) in conjunction with Article 24 GDPR. Article 28 GDPR additionally requires working only with processors that provide sufficient safeguards.

In practice, usually it is not the contract that is missing, but the accompanying documentation:

  • Record of Processing Activities: Microsoft 365 is often missing as a separate entry, even though Article 30 GDPR requires categories of recipients and transfers to third countries.
  • System separation: Which client data lives in DATEV, which in Exchange, SharePoint and Teams? Without this separation, no level of protection can be justified.
  • Professional supplemental agreement: According to DATEV, Microsoft provides a template confidentiality agreement for privileged professionals that meets the statutory requirements. Not every law firm has signed it yet.
  • Technical specifications: Which services are deliberately disabled, who is allowed to use external AI functions?

Is Microsoft 365 in the law firm permitted under the DSK ruling?

The ruling by the Data Protection Conference of 24.11.2022 is not a usage ban, but a statement about verifiability. In the wording of the ruling it says that proof of compliant operation of Microsoft 365 based on the data protection addendum of 15.09.2022 "cannot be provided". DATEV explicitly criticizes that the ruling is "frequently misquoted" and equated with a ban; its wording does not support this interpretation.

Since then, the situation has moved forward without the ruling being formally repealed. The European Data Protection Supervisor closed its proceedings against the EU Commission on Microsoft 365 on 11.07.2025 after the identified violations were remedied. The Hessian Commissioner for Data Protection and Freedom of Information considers compliant operation in the report of 15.11.2025 as possible regarding the seven DSK criticism points. Both findings have limitations: the EDPS reviewed Regulation 2018/1725 for EU bodies, not the GDPR, and the contractual framework negotiated by the HBDI concerns public authorities. A tax law firm is not one.

What applies professionally in addition to the GDPR?

Professional rules and data protection rules apply side by side, not alternatively. Section 62a of the German Tax Adviser Act permits tax advisers to grant service providers access to client secrets to the extent necessary. The provision requires careful selection, a written contract, a confidentiality obligation with instruction on criminal penalties, and at foreign involvement a level of protection comparable to the domestic. Paragraph 8 makes clear: the provisions on the protection of personal data remain unaffected.

In addition, there is Section 203 of the German Criminal Code. Paragraph 3 permits disclosure to participating persons to the extent necessary. But Paragraph 4 makes it a criminal offense if you failed to ensure that a participating person was obligated to maintain confidentiality. A simple GDPR data processing agreement does not automatically satisfy this. DATEV itself notes that professional and criminal law were not addressed by the DSK at all.

This article reflects the documented state of affairs and is not legal advice. Whether your specific situation is sound should be reviewed by your data protection officer and, on professional law matters, through individual legal counsel.

What should law firms do now specifically?

The most effective first step is a data map, not a contract review. In our automation projects with law firms and accounting departments, every initiative starts by writing down which system sees which data: receipts in the client mailbox, storage in SharePoint, transfer to DATEV Unternehmen online, notifications in Teams. The technical implementation requires this documentation anyway, and it is at the same time the foundation for the processing register under Article 30 GDPR. It is common to find client documents in three locations simultaneously, of which only one was documented.

Three other points are worthwhile independent of any project:

  • Deliberately enable or disable external AI functions. DATEV points out with its own DATEV Copilot that with internet search enabled, only "Microsoft's data protection provisions" apply, "which contain no special confidentiality standards for privileged professionals" (DATEV, accessed 08/2026). What already applies to DATEV's own product applies even more to every purchased AI tool.
  • Complete professional supplemental agreements. With every service provider with access to client data, including your own IT department.
  • Maintain proof in writing. A plausible explanation in conversation is not proof under Article 5(2) GDPR. Two pages naming the systems, settings and contracts are.

The affected group is large: at the end of the 2025 financial year, DATEV had approximately 927,900 customers and 40,296 cooperative members (DATEV press release, 27.03.2026). Documentation obligations lie in each firm individually.

How to automate workflows around DATEV without letting client data roam uncontrolled, we describe under Automation for Tax Advisers. What DATEV's own AI assistant does is described in the article on DATEV Copilot in MyDATEV.

Frequently Asked Questions

Is DATEV a processor or controller?

DATEV is a processor, the law firm is the controller. So DATEV presents the roles in the FAQs on GDPR and Data Processing (as of 28.01.2025). A data processing agreement is required for every customer with a direct contractual relationship to DATEV.

May a tax law firm use Microsoft 365?

According to DATEV's statement of 04/2024, use is fundamentally possible. The prerequisite is that the law firm itself documents that all GDPR requirements are met, and that the agreements under Section 62a of the German Tax Adviser Act are in place. There is no blanket authorization.

Does the contract with Microsoft serve as proof of data protection compliance?

No. It regulates the relationship but does not replace independent proof of legality. DATEV puts it this way: the controller must provide this proof and the processor has no role in it. The basis is Article 5(2) in conjunction with Article 24 GDPR.

Does the DSK ruling of 2022 prohibit Microsoft 365?

No. It establishes that proof of compliant operation based on the data protection addendum of 15.09.2022 cannot be provided. It does not impose a usage ban. Formally, it has not been repealed to date.

Simon Glowik, founder of NordFlux
About the author

Founder of NordFlux. Spent four years automating processes at enterprise scale at Dräger, and now brings that depth to the mid-market — pragmatic and with full data sovereignty.

Certifications

  • Microsoft certified — PL-900 and AZ-900
  • UiPath certified — Automation Developer Associate
  • UiPath zertifiziert — Automation Developer Associate
All articles
Free initial analysis

Concrete questions about automation or AI?

In a free initial analysis we discuss your case directly. No strings attached.