AI Transcripts for Client Conversations: What Tax Advisory Firms Must Check Under Professional Law

AI transcripts in the tax advisory firm: what Section 203 StGB, Section 62a StBerG, and the GDPR require before using Teams Copilot or Otter.ai.

Hand-drawn sketch: a desk microphone beside a closed padlock resting on a thin stack of documents.

AI Transcripts for Client Conversations: What Tax Advisory Firms Must Check Under Professional Law

A client conversation lasts 45 minutes, and a clean write-up often takes just as long again. It is only natural, then, to think about letting Teams Copilot or Otter.ai take notes. But before AI transcripts for client conversations run in a tax advisory firm, the decisive review is not a technical one but a professional-law one: confidentiality, service provider contract, consent, and retention.

Important note in advance: This article classifies the legal situation and does not replace legal advice. Have the specific use case reviewed by your chamber of tax advisors or a law firm specialized in professional law before introducing it. The cited provisions are the starting point for this review, not its result.

Which Rules Apply to AI Transcripts in a Tax Advisory Firm?

For AI transcripts in a tax advisory firm, four sets of rules apply simultaneously, and none replaces another: criminal law, the professional law of the Tax Consultancy Act, data protection law, and, as soon as recording takes place, the protection of the spoken word.

  • Section 203(1) No. 3 StGB: Tax advisors and authorized tax agents are named there explicitly. Anyone who unlawfully discloses another person's secret faces up to one year of imprisonment or a fine, and up to two years if acting for payment (para. 6). Source: Section 203 StGB
  • Section 203(3) and (4) StGB: Disclosure to persons who assist in the professional activity is permitted to the extent necessary. An AI service provider can be such an assisting person, which is why an AI transcription tool is conceivable under professional law at all. However, anyone who fails to ensure that the provider has been bound to secrecy becomes criminally liable themselves under para. 4 sentence 2 no. 1.
  • Section 201(1) StGB: Anyone who unlawfully records another person's non-public spoken word faces imprisonment of up to three years or a fine. The sentencing range here is higher than under Section 203 StGB. Source: Section 201 StGB

Does an AI Conversation Transcript Require the Client's Consent?

As a rule, yes, for two independent reasons. Section 201 StGB requires the consent of all conversation participants to the recording, and Section 62a(5) StBerG requires the client's consent if the service directly serves an individual engagement.

The Federal Chamber of Tax Advisors is explicit in its FAQ catalog "AI in the Tax Advisory Profession" (as of January 27, 2026, legal status July 2025), in the section on dictation AI: recording non-public conversations is only permitted with the prior consent of all participants, and subsequent consent is not permissible. Source: BStBK, FAQ AI in the Tax Advisory Profession

Consent must therefore be given and documented before the start button is pressed, and it applies to all participants. The second hurdle is often overlooked: Section 62a(5) StBerG distinguishes between general firm infrastructure and services that directly serve an individual engagement. A transcript of a specific client conversation can hardly be classified as a "general work tool."

Is a Data Processing Agreement Under Art. 28 GDPR Sufficient?

No. Section 62a(3) StBerG requires a contract in text form with three mandatory contents that a standard data processing agreement does not automatically cover. Professional law and data protection law run in parallel, as Section 62a(8) StBerG makes explicitly clear.

  • Confidentiality obligation with instruction: The service provider must be bound to confidentiality and instructed about the criminal consequences (No. 1). The instruction is part of the obligation, not optional.
  • Limited access to information: Access to information only to the extent necessary for performance of the contract (No. 2).
  • Provisions on subcontractors: It must be determined whether further persons may be engaged. If so, the service provider must also bind them in text form (No. 3). Source: Section 62a StBerG
  • Selection and termination: Under Section 62a(2) StBerG, the service provider must be selected carefully and the cooperation must be terminated without delay if the requirements are no longer met. An ongoing obligation.
  • Services from abroad: Section 62a(4) StBerG only permits access if the level of secrecy protection there is comparable to that in Germany. In the case of processing outside the EU, this is the most demanding review step.

In parallel, Art. 28 GDPR remains applicable: a contract in written, including electronic, form, processing only on documented instructions, confidentiality, deletion or return after the end of the service, and approval requirements for sub-processors. Source: Art. 28 GDPR This gives rise to a very concrete question for every provider: is there a supplementary agreement under professional law pursuant to Section 62a(3) StBerG, or only the standard data processing agreement? To be answered based on the specific contract, for Otter.ai just as for Microsoft.

Where Does the Transcript End Up, and How Long Does It Stay There?

A Teams transcript is not a fleeting by-product but a file with a storage location and permissions. Microsoft documents that recordings and transcripts end up in OneDrive for Business or SharePoint and are subject to the same permission and retention rules as any other file. Source: Microsoft Learn

For Copilot in Teams meetings, Microsoft distinguishes two operating modes: retained transcripts, which are stored and remain discoverable, and temporary transcripts, which are generated only for Copilot and permanently removed after the meeting ends. Source: Microsoft Learn For a firm, this choice is a matter of professional law, not convenience.

Retention is governed by Section 66 StBerG: case files must be retained for ten years, calculated from the end of the calendar year in which the engagement ended, and under para. 4 this also applies in electronic form. Source: Section 66 StBerG The firm must determine whether an AI transcript is an internal working document or part of the case file. Otherwise, the tool's default deletion interval will make that decision silently.

From our Copilot enablement projects, the most frequent finding is not the AI model but the storage location: transcripts end up in the organizer's OneDrive and inherit its sharing permissions. Anyone who does not clean up permissions before the rollout also distributes access to the transcript along with it. More on this in Copilot Rollout and the Oversharing Risk described.

In What Order Should You Check This in Practice?

The review proceeds from the professional duty to the technology, not the other way around. Anyone who starts with the tool ends up building the justification around a decision that has already been made.

  • Clarify purpose and processing location: Internal file note, client transcript, or evaluation? Where is the transcription performed, where does the result end up, are there sub-processors? Without these answers, Section 62a(4) StBerG cannot be assessed.
  • Finalize the contractual situation: Supplementary agreement under Section 62a(3) StBerG in text form plus a data processing agreement under Art. 28 GDPR. Both, not just one of the two.
  • Operationalize consent: A fixed wording, stated and documented before the conversation begins, for all participants.
  • Define storage and deletion: Storage location, permissions, retention period, and deletion concept in writing, aligned with Section 66 StBerG.
  • Policy, training, approval: The BStBK recommends an AI policy with an approval process and corporate accounts instead of private logins. In addition, the AI competence obligation, see Article 4 EU AI Act. The pilot operation only starts after that.

Conclusion

AI transcripts are not prohibited in a tax advisory firm, but they come with conditions. The BStBK classifies dictation AI as permissible in principle, but ties this to consent, contractual arrangements, and confidentiality. Clarify the specific case with your chamber of tax advisors or a law firm specialized in professional law before the rollout. We support you in the implementation with our Automation for Tax Advisors. What DATEV itself already provides is shown in our article on DATEV Copilot 2026.

Frequently Asked Questions

May Tax Advisory Firms Use Teams Copilot or Otter.ai for Client Conversations?

There is no blanket ban. Use is only permissible if the prior consent of all conversation participants has been obtained (Section 201 StGB), the provider is bound to confidentiality in text form under Section 62a(3) StBerG, and a data processing agreement under Art. 28 GDPR exists.

Is the Provider's Standard Data Processing Agreement Sufficient?

No. The data processing agreement covers data protection law, not professional law. Section 62a(3) StBerG additionally requires a confidentiality obligation with instruction on the criminal consequences, a limitation of access to information, and a provision on subcontractors.

Is It Enough to Ask the Client for Consent After the Conversation?

No. Consent to the recording of the non-public spoken word must be obtained beforehand. The Federal Chamber of Tax Advisors states in its AI FAQ that subsequent consent is not permissible.

How Long Must an AI Conversation Transcript Be Retained?

That depends on whether it forms part of the case file. Under Section 66(1) StBerG, case files must be retained for ten years, calculated from the end of the calendar year in which the engagement ended, and under para. 4 this also applies in electronic form. The firm itself must make and document this classification.

Is a Provider Outside the EU Excluded?

Not automatically, but the bar is higher. Section 62a(4) StBerG only permits access if the level of secrecy protection there is comparable to that in Germany, and the third-country transfer must be secured under data protection law.

Simon Glowik, founder of NordFlux
About the author

Founder of NordFlux. Spent four years automating processes at enterprise scale at Dräger, and now brings that depth to the mid-market — pragmatic and with full data sovereignty.

Certifications

  • Microsoft certified — PL-900 and AZ-900
  • UiPath certified — Automation Developer Associate
  • UiPath zertifiziert — Automation Developer Associate
All articles
Free initial analysis

Concrete questions about automation or AI?

In a free initial analysis we discuss your case directly. No strings attached.

Reviewing AI Transcripts in the Firm Under Professional Law