- Regulation (EU) 2016/679 — GDPR, Articles 27 and 28
- Professional secrecy rules in national law
- Directive (EU) 2015/849 for AML-regulated clients
- Regulation (EU) 2022/2554 — DORA where clients are financial entities
Who has to appoint one
Software providers outside the Union serving law firms, accountants and consultancies in the EU. Client data in these sectors is covered by professional secrecy rules that sit alongside the GDPR and are often stricter about disclosure and location.
Thresholds and exemptions
No threshold. Professional secrecy obligations apply regardless of the size of the firm.
What must appear on the label
Not physical. The representative in the privacy notice and in the processing terms, together with the data location and subprocessor information the firm needs for its own professional obligations.
Marketplace fields
Bar associations and professional bodies in several member states have issued guidance restricting cloud storage of client files outside the Union, which functions as a market access condition.
Documentation you must hold
Article 30(2) records, Article 28 terms addressing professional secrecy and confidentiality expressly, the Article 27 designation, subprocessor list with notification rights, transfer impact assessment, encryption and access control documentation, and audit rights.
Standards and testing
Security certifications and penetration testing are expected by professional buyers, and some bar associations require specific assurances about third-country access.
Language requirements
Documentation in the language of the firm's jurisdiction.
When it applies
The representative before processing begins.
How long records are kept
Client file retention follows professional rules, often ten years or more, which the processing terms must accommodate rather than override.
What happens if you do not comply
GDPR fines, and separately professional sanctions against the firm for breach of secrecy, which makes firms extremely risk-averse in procurement.
Who enforces it
Data protection authorities and professional regulatory bodies.
Where the boundary lies
Professional secrecy is not the same as data protection and can be stricter: some bar associations prohibit storing client files where a foreign authority could compel disclosure, which no processing agreement can cure.
Questions we are asked
- Is professional secrecy covered by our processing agreement?
- Not automatically. It is a separate obligation of the firm under national law, and the terms must address confidentiality and access explicitly.
- Does EU hosting satisfy bar association guidance?
- Often it is necessary but not sufficient, because the concern is compelled access by authorities in the vendor's home jurisdiction.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom