Law Firms and IT Service Providers: Essential agreements before getting started

Law Firms and IT Service Providers: Essential agreements before getting started
IT service providers often receive extensive access rights when working with law firms or notaries. Their staff manage user accounts, handle support tickets, and may come into contact with emails, documents, or metadata during troubleshooting. Precisely because this access can be necessary for operations, the collaboration must not begin with a generic support contract. Before any administrative access is granted, it must be clearly defined which services will be provided, what data may become visible, and under what conditions the service provider, their employees, and any subcontractors will operate.
This coordination involves more than just data protection. Professional confidentiality, criminal law protections for secrets, and GDPR requirements are all intertwined. Addressing only one of these levels leaves gaps in actual operations.
The contract must reflect reality
It starts with a clear definition of services. Terms like "IT support" or "managed services" are insufficient if they do not specify which systems are being maintained and what interventions the service provider is authorized to perform. Whether workstations, servers, backups, firewalls, or Microsoft 365 are part of the scope directly determines the technical access rights required.
The scope of services dictates the distribution of responsibility. If it is not defined who creates new users, grants permissions, or activates additional cloud and AI features, the result is not just abstract jurisdictional issues, but concrete security risks. A former employee might retain access because no one initiated the deactivation. A new feature might be activated before its compliance with data protection and professional regulations has been verified.
Therefore, the contract must not only describe what the service provider does, but also when and to what extent they are permitted to access systems. Section 43e of the Federal Lawyers' Act (BRAO) and Section 26a of the Federal Notaries Act (BNotO) permit access to protected facts only to the extent necessary for the commissioned service. This leads to the principle of least privilege: someone maintaining printers does not need access to document management. Someone administering Microsoft 365 does not automatically require permanent access to all user mailboxes.
Data protection and confidentiality address different risks
If the IT service provider processes personal data on behalf of the law firm or notary, a data processing agreement (DPA) under Article 28 of the GDPR is required. It specifies which data is processed for what purpose, how long the processing lasts, and what obligations both parties assume.
However, this does not fully regulate the collaboration, as the DPA only covers the data protection aspect. Law firms and notaries also process information subject to professional confidentiality. Consequently, Section 43e BRAO and Section 26a BNotO impose a separate obligation of confidentiality on the service provider.
This duty does not end with the company as the contractual partner. Since actual access is usually performed by individual technicians, the employees involved must also be included. Under certain conditions, Section 203 of the German Criminal Code (StGB) covers individuals who become privy to third-party secrets in the course of their work. This necessitates documented obligations and training tailored to the specific assignment. A general confidentiality clause in an employment contract is insufficient if it remains unclear what specific duties apply when accessing law firm or notary data.
Subcontractors change the processing chain
Hardly any IT service provider performs all services entirely on their own. Cloud providers, data centers, security platforms, remote maintenance services, or manufacturer support may be involved in operations. As soon as such companies can gain access to personal or confidential information, they become part of the processing chain.
It follows that subcontractors must not only become visible in the event of a security incident. The agreement with the IT service provider must disclose which companies are used, what tasks they perform, where they are based, and whether processing outside the European Union is possible. Article 28 of the GDPR makes the use of further sub-processors subject to prior authorization by the controller.
This authorization can only be meaningfully granted if changes remain transparent. If the service provider switches their backup platform or introduces a new monitoring system, it may change not only the technology but also the circle of companies with access and the location of data processing. The information and approval process must therefore be an integral part of ongoing operations and not limited to the signing of the contract.
Security measures must be adjusted according to the risk
Technical and organizational measures describe how the service provider protects the confidentiality, integrity, availability, and resilience of systems. Article 32 of the GDPR requires a level of protection appropriate to the respective risk. For a law firm or notary, a blanket promise to work "GDPR-compliant" is therefore insufficient.
The necessary measures are determined by the actual access paths. If technicians administer systems remotely, these access points must be specially secured and logged. If individual accounts have extensive rights, separate administrator accounts and multi-factor authentication are necessary. If backups or cloud services are used, encryption, recovery, and the separation of different client environments must be regulated in a verifiable manner.
The documentation of these measures is not a formal appendix, but the basis for a joint acceptance. Especially with Microsoft 365, it must be traceable which administrator roles have been assigned, which external shares are permitted, and which logging functions have been activated. Only a documented initial state makes it possible to later determine whether security-relevant settings have been changed or whether operations still comply with the agreed security concept.
Security incidents require a coordinated response
In the event of a security incident, the quality of the technical analysis is not the only deciding factor. Equally important is how quickly the law firm or notary office receives reliable information. Article 33 of the GDPR generally requires that reportable data breaches be notified to the competent supervisory authority within 72 hours of becoming aware of them. It follows that the IT service provider must not wait until their investigation is complete before reporting the incident.
The coordination process must therefore define which events are to be reported immediately, who is to be reachable on both sides, and what information is to be provided initially. This includes the suspected time of the incident, the affected systems, the data that may have been exposed, and any security measures already initiated. If this information is missing, the responsible party cannot fulfill its own reporting and assessment obligations in a timely manner.
Evidence preservation must also be regulated in advance. If logs are overwritten, systems are reinstalled prematurely, or compromised accounts are modified without documentation, subsequent investigation can be hindered. A robust incident response process therefore combines technical containment, legal assessment, and clear communication.
Practical classification
Robust cooperation only exists when the contract, technical permissions, and actual operations are in alignment. The law firm or notary office must know which access rights are required, who is exercising them, and how they are monitored; the IT service provider must deliver its services in such a way that these boundaries are maintained both technically and organizationally. Only when this connection is established does a general support relationship become a controllable operation.

FAQ: Agreements between law firms and IT service providers
Is a data processing agreement (DPA) sufficient?
No. The DPA governs data processing under data protection law, whereas professional confidentiality must be agreed upon separately. It is crucial that both regulatory levels reflect the actual access the service provider has.
What access rights should the IT service provider have?
Only the rights necessary for the specifically agreed-upon service. Anyone managing a limited system area does not need blanket access to document management, mailboxes, or other confidential content.
Must subcontractors be disclosed in advance?
Yes. As soon as cloud providers, data centers, or other partners become part of the processing chain, their role must be transparent. Changes to this chain require a regulated information and approval process.
What belongs in a coordinated incident response process?
It must define which events are reported immediately, who is reachable on both sides, and what information is provided initially. Technical containment, legal assessment, and evidence preservation must be aligned.
How can it be verified that operations still match the agreed-upon status?
Through a documented baseline and a joint acceptance of security-relevant settings. This is the only way to track subsequent changes to roles, permissions, or logging functions.










