In Germany, Pasting a Patient Note Into a Chatbot Is a Crime
Your vendor’s data processing agreement is not the protection you think it is. German law puts a second barrier in front of patient data, and that one sits in the criminal code.
A German pharmacist who knowingly pastes an identifiable patient note into an unapproved AI chatbot risks committing a criminal offence under section 203 of the German Criminal Code, unless valid consent or strict statutory exceptions apply.
Section 203 requires intent. Negligence alone is not an offence under the statute. The criminal risk arises only when a professional knowingly uses an unvetted service without consent or the required statutory safeguards.
The problem surfaces when healthcare buyers ask software vendors where data is held. A vendor typically explains that servers sit in Frankfurt and provides a standard European data processing agreement. That answers data privacy law, but it leaves professional secrecy law untouched.
German law puts two separate barriers between a health professional and a cloud service. Clearing one does nothing for the other.
Why standard privacy forms fail here
German lawyers call this the two-barrier principle. Data protection rules and professional secrecy statutes run side by side, independently.
The first barrier is the General Data Protection Regulation (GDPR, the European Union privacy law). Article 9 classifies health data as a special category requiring strict safeguards. A standard Data Processing Agreement (DPA, a contract setting how personal data is handled) addresses this rule.
The second barrier is section 203 of the German Criminal Code. It makes unauthorised disclosure of client secrets by named professionals an offence punishable by fine or imprisonment. Pharmacists appear on the statutory list alongside doctors, psychotherapists, and lawyers.
A standard privacy contract cannot satisfy a criminal statute on its own. Section 203 punishes unauthorised disclosure, meaning a healthcare worker must obtain explicit patient consent or configure the technology to meet specific legal exceptions before sharing confidential records.

How modern AI triggers the criminal code

Legal commentary on section 203 holds that making protected information accessible to an unauthorised third party constitutes disclosure. An outsider does not need to read the text; commentary indicates that the realistic possibility of access is sufficient.
This rule creates problems when using consumer-tier AI tools. Free or standard commercial chatbots frequently retain user prompts for abuse monitoring and system training, occasionally allowing human staff to review logs. Even if staff never open the file, permitting that external visibility can break the professional secret.
Enterprise AI platforms and private application programming interfaces (APIs, tools allowing two computer systems to connect) present a different proposition. Many enterprise tiers offer zero data retention, use strict encryption, and turn off human logging. That technical difference determines whether an AI setup complies with the law.
Both the buyer and the vendor share the legal risk

Section 203 does not end with the medical worker. A statutory reform enacted on 9 November 2017 updated the code to accommodate modern computing while creating shared legal obligations.
Before this change, sharing patient data with an external IT provider risked breaching the statute outright. Under legal commentary on the 2017 reform, criminal liability can extend to external service providers and their personnel if they improperly disclose secrets encountered during support work.
To bring an external technology provider into a clinical workflow legally without patient consent, the setup must meet two core statutory conditions:
- The involvement of the external provider must be strictly necessary to deliver the service.
- The provider and its staff must be bound by a formal, written secrecy obligation under section 203.
Where the technology vendor operates outside Germany, the law adds a third condition. The professional must verify that the foreign jurisdiction provides comparable legal secrecy protections and equivalent criminal sanctions.
Three architectures that survive the question
Healthcare teams and technology developers can solve this challenge through three technical approaches.

- Run the model locally. The text never leaves the practice or pharmacy network. Because no third party can access the data, no disclosure occurs. This makes on-premises model deployment a standard commercial solution in German healthcare.
- Anonymise the data before sending it. Simply stripping names and phone numbers is rarely enough; combining medical details with birthdates or unusual diagnoses often allows re-identification. True anonymisation requires removing all identifiers so that no individual can be identified from the text.
- Use locked-down enterprise services. The healthcare buyer holds the encryption keys. The vendor signs a formal section 203 secrecy pledge alongside the data processing agreement, and configures the system to disable human review and log retention.

What the major cloud providers built
Cloud providers have introduced infrastructure designed to meet European secrecy and governance standards.
On 15 January 2026, Amazon Web Services launched its European Sovereign Cloud with an initial region in Brandenburg. AWS stated the infrastructure is physically and logically separate from its global regions, operated exclusively by EU residents under a German legal entity, and built so that customer data and metadata remain inside the EU. Reported investment was 7.8 billion euros at launch, though this figure was not independently verified.
Microsoft created the EU Data Boundary and established regional joint ventures. Delos Cloud, an SAP subsidiary, operates Microsoft Azure for the German public sector and entered active use in January 2026.
European software companies argue that American parent companies remain subject to foreign disclosure orders regardless of server location. That debate sustains domestic providers such as Schwarz Digits, OVHcloud, and T-Systems.
Three things sovereign can mean
The word sovereign is used across the market to describe three different technical models.
| Claim | What it means | What it answers |
|---|---|---|
| Data residency | The data sits in a given country | Satisfies basic GDPR requirements. Resolves nothing for section 203. |
| Operational sovereignty | Only staff within that jurisdiction can access systems and support | Addresses section 203 by limiting who could reach the data. |
| Jurisdictional sovereignty | The operating entity cannot be compelled by a foreign government | Addresses foreign legal exposure. Hardest to verify. |


Four questions buyers should send in writing
- Which employee roles can access this data, and from which countries?
- Does your service operate on an enterprise tier with zero data retention and no human review of prompts?
- Will you sign a formal obligation of secrecy under section 203 of the German Criminal Code, separate from a data processing agreement?
- If our data were encrypted with a key we hold, would your product still work?
A vendor that can document clear answers to these questions has done the work most vendors have not.
If you are the one selling
Two commercial conclusions follow for technology companies entering the German market.
Being able to answer the four questions above, plainly and in writing, is a practical advantage. When a buyer is evaluating competing products, having section 203 documentation ready sets your company apart from vendors who have never reviewed the statute.
Addressing professional secrecy openly also builds trust. A pharmacy buyer who has to raise section 203 themselves will assume the vendor either does not know German healthcare law or chose not to mention it. Raising the requirements early shows that your team understands the regulatory environment.
Editor’s note
The two-barrier principle, the scope of section 203, the 2017 reform and its conditions are drawn from German legal commentary and practitioner guidance. This is a summary for a general readership and it simplifies. Anyone acting on it should take German legal advice, because these are questions of criminal law.
Cloud provider details come from provider announcements and reporting from January 2026 onward. The 7.8 billion euro figure is as reported at launch and we have not independently verified it. We have not assessed whether any particular provider satisfies section 203, because that depends on contract terms we have not seen.
This article reports the legal framework as it stands. It is not legal advice.
Sources
- German Criminal Code, section 203: https://www.gesetze-im-internet.de/englisch_stgb/englisch_stgb.html
- Regulation (EU) 2016/679, Article 9: https://eur-lex.europa.eu/eli/reg/2016/679/oj
- AWS European Sovereign Cloud launch: https://press.aboutamazon.com/aws/2026/1/aws-launches-aws-european-sovereign-cloud-and-announces-expansion-across-europe

