GDPR-compliant AI for tax advisors: mask the client, keep the draft
Kanzlei staff paste client files into consumer AI tools every day. Why that breaks GDPR and § 57 StBerG, and how masking values before the model fixes it.

- Pasting a client letter into a consumer AI tool is a third-country transfer and a § 57 StBerG problem, even when nobody meant harm.
- Masking swaps names, tax IDs and IBANs for placeholders before the model sees them and restores them only in your view.
- You still want a DPA, a public subprocessor list and EU-hosted or local models. FlowSentric ships all three.
Ask around any German tax firm and you'll hear a version of this story. It's late afternoon, a Steuerbescheid has landed that needs a reply, and somebody opens a consumer AI chat, pastes the whole letter in and asks for a draft. Thirty seconds later they have one. It's decent. Nobody meant any harm.
Two legal problems were just created, quietly, and the draft is the only thing anyone will remember.
Problem one: that was a third-country transfer
Most consumer AI tools process prompts on US infrastructure. The moment a client's name, Steuernummer, IBAN or address goes into the box, personal data has left the EU. Under Chapter V of the GDPR that transfer needs a legal basis, typically Standard Contractual Clauses or an adequacy decision. A consumer account rarely comes with a data processing agreement you could point to. So in practice you point to nothing.
Problem two: § 57 StBerG doesn't care how convenient it was
Tax advisors are bound to confidentiality by professional law, not only by data protection rules. Handing client facts to a service that may retain them, or train on them, is very hard to square with that duty. And "the intern did it" is not a line anyone wants to use in front of the Steuerberaterkammer.
The usual reaction is a ban. We have yet to see one work, because the productivity gain is real and people route around bans. The better move is to take the sensitive values out of the prompt before it leaves the building, and let people keep the tool.
What "masked before the model" means in practice
Privacy Guard, the masking layer in FlowSentric, runs over every message before it gets anywhere near a model. It works in several layers:
- Pattern rules catch the structured stuff: IBANs, card numbers, phone numbers, emails, IP addresses, and the German tax identifiers, both the USt-IdNr (DE plus nine digits) and the Steuernummer and Steuer-ID in the ways people actually write them.
- Industry-standard recognisers cover the everyday categories of personal data.
- Name recognition that speaks German. "Anna Weber" in a German letter is spotted as a person, not only in English text. Sounds obvious. It's the part most tools get wrong.
Each value becomes a placeholder like [NAME_1] or [TAX_ID_1]. That's what the model sees. When the answer streams back, the placeholders are swapped for the real values again, but only in your browser, from a mapping that exists in memory for that one request.
Why the lawyers relax a little
A prompt that says "Please draft a reply to [NAME_1] about the assessment for [TAX_ID_1]" no longer identifies a natural person. The model can still do the job, because the shape of the text is intact. It drafts, summarises, translates, checks. What crosses the border is a template, not a client file.
To be clear, masking doesn't replace the paperwork. You still want a data processing agreement, a published subprocessor list, and ideally models that run in the EU. We provide all three. The DPA is ready to sign, the subprocessor list is public, and 26 models in the picker are routed through an EU gateway and carry an "(EU)" label. If you'd rather keep everything on your own hardware, local models are an option too.
What a Kanzlei actually does with it
- Upload the client's documents into a knowledge folder. Scanned Bescheide work; the OCR reads German, umlauts included.
- Ask questions in chat with Privacy Guard switched on. Answers cite the document and the page.
- Turn the recurring stuff into an agent. "Summarise new client mail and draft a first reply" is a typical one. Agents have Privacy Guard on by default and can run on a schedule.
- Put a widget on your website that answers routine questions from your public FAQ, with masking on for whatever visitors type.
What we don't claim
Masking is a strong control, not magic. "The dentist from Altona with the blue Porsche" identifies someone without containing a single detectable identifier. We also don't say your data "never leaves the EU". You pick the model, and the picker tells you where it runs. The full list of controls is on the security page, including the things we deliberately don't promise.
If you want to watch Privacy Guard work through one of your own documents, book a 30-minute walkthrough. Or just try it: the Free plan includes Privacy Guard and doesn't ask for a card.

