ChatGPT in a funding application: why it breaches § 203 StGB

Compliance & Recht · 19.04.2026 · 13 minutes

Tax advisers, lawyers and auditors risk breaching § 203 StGB when they use ChatGPT. What the DSK held in 2024 and what stays lawful.

The sentence is now routine in law firms, tax practices and audit offices: "I'll just get ChatGPT to word that." What looks harmless with a pitch deck or a generic email is, with a funding application in German or European research and innovation funding management, not a question of efficiency but a criminal offence. Funding applications regularly contain client, project and financial data protected by section 203 of the Criminal Code (StGB)[1]. Entering them into a publicly operated language model amounts — on the Data Protection Conference's (DSK) determination of May 2024 — to "disclosing" another person's secret within the meaning of the offence[2].

This article takes the legal position apart step by step: who is actually bound, what exactly section 203 prohibits, what the DSK put on record in 2024, how data moves through OpenAI's infrastructure, and which arrangements remain legally workable. The audience: professionals bound by confidentiality who draft, review or approve funding applications.

Who is bound to confidentiality by professional law

Section 203(1) StGB lists the professions bound to secrecy exhaustively. Relevant to funding practice are above all lawyers (no. 3), patent attorneys (no. 3), tax advisers (no. 3) and auditors (no. 3)[1]. These groups are treated together in the offence as so-called "inherent" holders of secrets. Their duty of confidentiality does not arise by agreement but by operation of law — as soon as the engagement is established.

The duty is not limited to the professionals named. Since the redraft of 30 October 2017, section 203(4) StGB has also drawn "participating persons" and external service providers into the offence[12]. An assistant, a tax clerk, an IT service provider or a cloud platform that gains access to client data in the course of handling the engagement is covered by the criminal provision as soon as it is brought into the professional's working process. The legislature thereby addressed the scenario of technical outsourcing explicitly — and did not declare it permissible, but placed it under the same obligations.

The professional chambers have taken this tightening up in their guidance. In its guide to the use of AI (as at 12/2024), the Federal Bar Association records that any form of external AI use by lawyers requires the participating service providers to be brought in under section 203(3) sentence 2 StGB, and therefore has to be secured contractually, technically and organisationally[7]. The Federal Chamber of Tax Advisers and the Chamber of Public Accountants refer to the same framework in their professional guidance[8][9].

What section 203 StGB actually prohibits

The offence reads, at its core:

Whoever, without authorisation, discloses another person's secret — in particular a secret belonging to the personal sphere of life, or a trade or business secret — that has been entrusted to them or otherwise become known to them in their capacity as […] a lawyer, patent attorney, […] tax adviser or auditor […] shall be punished by imprisonment for up to one year or a fine. (Section 203(1) StGB)[1]

Four elements of the offence are decisive for the AI question. First, another person's secret: protected is any information that is not in the public domain and in whose confidentiality the person concerned has a recognisable interest. That covers the project content of a funding application, the cost plan, the shape of the consortium, the company's financing structure, personal research work — practically everything that comes together in an application. Second, entrustment or becoming known: protection applies as soon as the information comes to notice in the course of the engagement, regardless of whether the client expressly marked it as confidential.

Third, disclosure: any act that gives a third party the opportunity to learn the secret suffices. The prevailing view in case law and the literature specifically does not require the third party actually to take note of the information; making it possible is enough. Fourth, lack of authorisation: disclosure is unauthorised as long as there is no consent from the person concerned, no statutory permission and no effective inclusion of the third party under section 203(3) sentence 2 StGB.

The Federal Court of Justice set out the line on passing on engagement-related data early. In its ruling of 11 November 2004 on the assignment of lawyers' fee claims (IX ZR 240/03), the Ninth Civil Senate held that passing engagement-related information to a third party without the client's consent fulfils the objective elements of section 203(1) no. 3 StGB and that the assignment concerned is void under section 134 of the Civil Code, because disclosure of the information needed to enforce the claim is unauthorised[4]. The decision is the reference point for any form of technical or organisational outsourcing, cloud and AI services included: without consent or the inclusion provided for in professional law, passing data on fulfils the offence.

Moreover, it is not only the person who does the typing who is liable. Anyone in a law or tax practice who orders, tolerates or, knowing of it, fails to stop the use of an AI service that has not been brought in properly can be liable as a principal or as a participant. In professional law, organisational responsibility falls on the practice or its management additionally, independently of the individual act. The offence is a genuine special offence — only a holder of the secret can commit it — but inclusion under subsection 4 and the participation rules in sections 26 and 27 StGB widen the circle of people covered appreciably.

The DSK's 2024 determination on AI chatbots

The Conference of the Independent Federal and State Data Protection Supervisory Authorities — the DSK — published version 1.0 of its "Guidance on artificial intelligence and data protection" on 6 May 2024[2]. The document is not a source of law in the formal sense, but it bundles the shared supervisory interpretation of all state data protection commissioners and the BfDI and carries corresponding weight: anyone not following the requirements described there has to expect a supervisory review.

Four core statements are central for the use of AI by professionals bound to confidentiality. First, the DSK classifies publicly accessible AI chatbots whose providers may use inputs to improve the model as fundamentally impermissible under data protection law for processing personal data or data subject to a duty of secrecy. Second, the DSK stresses that using an AI provider regularly constitutes processing on behalf of a controller under Article 28 GDPR — and this regardless of whether the provider accepts that role contractually. Without an effective processing agreement, the use is already unlawful under data protection law, before the criminal provision even applies[11].

Third, the DSK addresses the third-country problem explicitly: if processing takes place outside the EU — which is the norm with US providers — Chapter V of the GDPR (Articles 44 et seq.) applies. An adequacy decision (currently the EU-US Data Privacy Framework) or standard contractual clauses with supplementary measures are a precondition. Fourth, the DSK records that professionals bound to confidentiality must additionally comply with the criminally enforced duty under section 203 StGB, and points expressly to section 203(3) sentence 2 StGB as the minimum requirement for bringing in AI service providers[2].

In parallel, the Federal Data Protection Commissioner (BfDI) reaffirmed the same principle in his position paper on AI standardisation: cloud-based AI systems shift processing risks onto the controller, and those risks cannot be dispelled by the provider's terms of use[3]. The burden of proving that no impermissible disclosure took place lies with the professional bound to confidentiality.

The ChatGPT data flow and OpenAI's terms

To understand why the DSK's position rules out ChatGPT in its standard configuration, it is worth looking at the actual data flow and the contractual framework. OpenAI offers ChatGPT in three product variants that have to be assessed differently under data protection law: the free and Plus variant (consumer), ChatGPT Team and Enterprise (business), and direct API access.

Under OpenAI's current business terms, inputs from Team and Enterprise customers and via the API are in principle not used for training; for consumer accounts that exception does not apply automatically but only on a manual opt-out[6]. All variants share two structural properties, though: processing takes place in OpenAI's infrastructure, server locations are configured differently by product, and as a US company OpenAI is in principle subject to US access laws.

OpenAI offers a data processing addendum (the EU DPA) that business and API customers can conclude electronically[5]. The EU DPA incorporates standard contractual clauses under Article 46 GDPR and names OpenAI Ireland Ltd. as the contracting party. Formally, then, a processing agreement is possible. What the EU DPA does not do: it does not replace inclusion under section 203(3) sentence 2 StGB. The GDPR processing agreement and the criminal-law inclusion of the participating person are two separate legal acts. A GDPR-compliant contract alone does not entitle a tax adviser to pass on client data.

Then there is the AI Act. Regulation (EU) 2024/1689 classifies generative models such as GPT-4 as "general-purpose AI models" and obliges providers to meet transparency, documentation and risk assessment requirements (Articles 52 et seq.)[10]. For use in sensitive contexts — and funding applications with financial, research and personnel data are among them — the requirements on the controller tighten further. Obligations on providers do not release users from responsibility; they shift it.

In practice that means: even ChatGPT Enterprise with an EU DPA and a European data region does not by itself meet the requirements of section 203 StGB. It meets them only once the provider has additionally been brought in in writing under section 203(3) sentence 2 StGB, the client's consent has been obtained and documented, or — barely achievable in practice — the inputs have been anonymised far enough that no inference back to the protected information remains possible. The consumer variant is not cleared under any arrangement.

A worked example: a funding application handled by a tax adviser

To make the chain visible, take an everyday situation: a tax adviser is handling an application for the research allowance under section 7 FZulG for a mid-sized client. The client has sent over the project concept, the cost breakdown, the staffing plan and the link to an ongoing EU Horizon Europe project. To structure the project description, the adviser copies five paragraphs into ChatGPT — into the Plus version, not the business variant. The instruction: "Word this more precisely for a funding application."

From the point of view of the offence, every element of section 203(1) no. 3 StGB is present. Another person's secret: the research project, the cost structure, the identity of the staff involved. Entrusted: all the information became known to the adviser in the course of the engagement. Disclosure: by entering it into ChatGPT, OpenAI as a third party gains the technical possibility of taking note of the data — and, in the consumer variant, does so contractually as well, unless an opt-out has been set. Lack of authorisation: there is neither the client's consent, nor inclusion under section 203(3) sentence 2 StGB, nor any ground of justification.

The consequences run along several tracks. In criminal law, imprisonment for up to one year or a fine; where the act is committed commercially or for gain, up to two years[1]. In professional law, a reprimand or censure by the responsible chamber of tax advisers comes into play, and on repetition a fine of up to €50,000 or exclusion proceedings. In civil law, the client acquires a claim for damages; if a competitor publishes the funding application or the funding commitment is lost because of the disclosure, the heads of damage can exceed the fee many times over. Under data protection law, fines under Article 83 GDPR are in prospect[11].

The situation becomes particularly delicate as soon as the client has to set out, in a later audit or a dispute with the funding body, how their application dossier came about. Funding authorities such as the BSFZ, the AiF, the BLE or the Commission services require the handling of the application to be traceable in review procedures. If it becomes apparent there that parts went through an AI service that had not been properly brought in, the matter can reach several levels at once: criminally against the adviser, in administrative law against the client (duty to cooperate, lack of transparency), and in civil law against the adviser in liability.

In practice the burden of proof shifts quickly. Section 203 StGB is a public prosecution offence once the secret was entrusted professionally; the investigating authorities do not have to wait for the client to file a complaint if the facts surface in a funding review or in fine proceedings against the adviser. Add to that the fact that handling an application often brings together data from several clients at once — consortium partners, suppliers, universities. Every single input that touches information from another engagement is a separate act fulfilling the offence. The provision offers no bulk discount.

What is possible within the law

The legal position by no means prohibits all use of AI. It requires clean contractual, technical and procedural inclusion. For professionals bound to confidentiality who handle funding applications, four arrangements have proved workable.

First: consent. The client gives informed consent in writing to AI-assisted handling, including naming the specific provider, the purpose of processing, the categories of data and the third-country dimension. Model wordings from the BRAK and the BStBK presuppose that consent is freely given, specific and revocable[7][8]. A blanket clause in the practice's terms of business is not enough. In sensitive settings, defence or dual-use funding for example, consent will often not be given.

Second: inclusion under section 203(3) sentence 2 StGB. The AI provider is taken into the circle of participating persons by written agreement, bound to confidentiality and restricted by organisational measures to what the service requires. Those participants are then themselves subject to the criminal provision under section 203(4) StGB. In practice OpenAI offers no direct contractual building block for this; inclusion then has to be constructed via the processor as an intermediate layer, which is only workable in curated platform environments[12].

Third: on-premises or EU-hosted models with a processing agreement. Using open-weight models in an environment controlled by the controller — on German cloud infrastructure with an Azure German region, at the GWDG, or on dedicated on-premises hardware — reduces the third-country problem and makes it easier to bring the host in under section 203(3) sentence 2 StGB. In this arrangement, compliance with the DSK requirements and the AI Act obligations can be documented far more credibly[2][10].

Fourth: anonymisation before input. As long as the input no longer contains personal or engagement-identifiable information, section 203 StGB is not engaged, because no third party's secret is disclosed. In funding applications, though, the threshold is high: project descriptions often contain terms and combinations that can be attributed to the client even without naming them. On this the DSK points to the strict reconstruction test and requires documented anonymisation processes[2].

upsmart meets this situation as a platform, not as a consultant. Client and application documents are ingested in an environment hosted in Frankfurt with documented processing on behalf of the controller; AI components are integrated so that a chain of inclusion under section 203(3) sentence 2 StGB, between the professional bound to confidentiality, the platform operator and the sub-processor, is in place before any segment of a funding application's text leaves the professional's sphere of control. That does not replace the controller's own assessment under professional law — but it moves the entry point from an unclear consumer interface to a contractually tangible processing framework.

The core message stays simple all the same: in the professions bound to confidentiality, routinely reaching for ChatGPT to handle a funding application is, in the standard configuration, not an efficiency gain but an act that engages the criminal law. The DSK has set out what supervisors expect; the chambers have taken it into their guidance; the legislature has codified the duty of inclusion in section 203(3) sentence 2 StGB and the participants' own criminal liability in section 203(4) StGB; the AI Act tightens the requirements further. Anyone wanting to use AI in application work needs an architecture that serves all three levels at once — and does not sacrifice them to the appearance of productivity.

  • [1]Section 203 StGB — violation of private secretsFederal Ministry of Justice, gesetze-im-internet.de · 2024Open source
  • [2]Data Protection Conference guidance: artificial intelligence and data protection (version 1.0, 6 May 2024)Conference of the Independent Federal and State Data Protection Supervisory Authorities (DSK) · 2024Open source
  • [3]BfDI statement to the German Bundestag on generative artificial intelligenceThe Federal Commissioner for Data Protection and Freedom of Information (BfDI) · 2023Open source
  • [4]Federal Court of Justice, ruling of 11 November 2004 — IX ZR 240/03 (assignment of lawyers' fee claims and section 203(1) no. 3 StGB)Federal Court of Justice, Ninth Civil Senate · 2004Open source
  • [5]OpenAI Data Processing Addendum (EU, as at 2024)OpenAI Ireland Ltd. · 2024Open source
  • [6]OpenAI Business Terms (applying to the API and ChatGPT Team/Enterprise)OpenAI, L.L.C. · 2024Open source
  • [7]BRAK guide with notes on the use of artificial intelligence (AI), as at December 2024Federal Bar Association (BRAK) · 2024Open source
  • [8]FAQ on AI in the tax advisory professionFederal Chamber of Tax Advisers (BStBK) · 2026Open source
  • [9]Questions and answers on the use of artificial intelligence in audit practice (as at 21 July 2025)Chamber of Public Accountants (WPK) · 2025Open source
  • [10]Regulation (EU) 2024/1689 on artificial intelligence (AI Act), Art. 10, Art. 52Official Journal of the European Union, EUR-Lex · 2024Open source
  • [11]Regulation (EU) 2016/679 (GDPR), Art. 28 processing on behalf of a controller, Arts. 44 et seq. third-country transfersOfficial Journal of the European Union, EUR-Lex · 2016Open source
  • [12]Section 203(3) StGB — inclusion of participating persons (as redrafted by the Act of 30 October 2017)Federal Law Gazette I p. 3618, Federal Ministry of Justice · 2017Open source

The ten-year rule: audit obligations after the grant notice

In the ECA's sample of audited research transactions, one in four shows quantifiable errors. Staff costs are the number one source of error — and the biggest block of the budget.

The 20/80 asymmetry: why writing the application is the smallest part of the work

The FDP Faculty Burden Survey, the EC's Horizon Europe interim evaluation and the ECA error statistics show where the effort actually lies — and where classic consultants structurally cannot reach.

HITL in the application process: what the Dell'Acqua study at BCG measured

758 consultants, a pre-registered field experiment, +25.1% on speed and +40% on quality — and where the lever finds its limits.

From the analysis into the application.

We show the platform on a real case.