The attachment is the standard method for sending confidential documents, and it is the only step in the process for which no one is responsible. Client correspondence, medical reports, credit files, personnel records: everything leaves the firm as a file attached to an email. Responsibility for it cannot be delegated, and it does not depend solely on whether something has already gone wrong.
Four industries, four legal frameworks, one common point: in an audit, what is usually in focus is not the damage that occurred but which safeguards were documented.
For law firms, tax advisors and auditors, confidentiality is not a duty of care, it is backed by criminal law. Section 203 of the German Criminal Code (§ 203 StGB) makes the unauthorised disclosure of another person's secret a criminal offence, and the professional obligation sits alongside it in § 43a(2) BRAO and § 57(1) StBerG. One distinction matters here: § 203 StGB requires intentional disclosure, so a misdirected email is not automatically a criminal offence. The professional duty of confidentiality and the obligations under Art. 32 GDPR, by contrast, do not depend on intent but on the protective measures in place.
Then there is retention: § 147 AO requires tax-relevant records to be kept, six to ten years depending on the type, and to remain available and readily legible at all times. The GoBD add the requirements of unchangeability and traceability. A sent-items folder is not evidence of who read a file, or when.
The practical core: a sent email cannot be recalled, it leaves no access log, and the attachment then sits permanently in a mailbox the firm does not control.
Health data is a special category of personal data under Article 9 GDPR, subject in principle to a prohibition with a narrow set of exceptions. Hospitals, medical centres and practices are also covered by § 203 StGB, and Article 32 GDPR requires safeguards appropriate to the risk. For findings, care documentation and admission data the risk is high, so the standard is high.
The fine tiers are worth separating: infringements of the processing principles, which include Art. 9 for health data, fall under Art. 83(5) GDPR in the upper tier of up to 20 million euros or 4 percent of total worldwide annual turnover, whichever is higher. Infringements of the security obligations under Art. 32 GDPR fall under Art. 83(4), up to 10 million euros or 2 percent. Supervisory reviews in practice focus above all on which measures are documented.
DigiG and KHZG add pressure from the other direction: more is transmitted electronically, and for the route outside KIM and the ePA usually nothing is defined. That is precisely where the email with the attachment lands.
In financial services, file exchange is not an IT topic, it is a supervisory one. § 25a KWG requires proper business organisation; MaRisk sets out the risk-management detail (currently BaFin Circular 06/2026 (BA)). For ICT risk management including third-party risk, DORA has applied directly as EU law since 17 January 2025. The BAIT have correspondingly fallen away for DORA subject institutions and remain in force only for a transitional group.
Three requirements follow that email structurally cannot meet: traceability at document level, control over the recipient group after sending, and the ability to demonstrate to a supervisor who had access and when. Missing encryption is only the most visible part. In practice, a review tends to start from missing traceability rather than from encryption alone.
For public authorities and municipal administrations, three layers meet: Article 32 GDPR for safeguards, the BSI IT-Grundschutz as the benchmark for what counts as appropriate,
and the German NIS2 implementation act with a significantly broader duty of risk management plus evidence and reporting obligations. Those duties are in force: the statutory registration deadline with the BSI has already passed, and the BSI is
calling on affected organisations to register without delay.
On top of that comes a requirement the private sector does not have: records management. A case file has to remain traceable. If part of it leaves the building as an attachment and exists only in one caseworker's sent items, it is neither part of the file nor auditable.
These four points are sector-independent, and they are why the problem cannot be solved by being careful:
The requirement is not "send it encrypted", it is keep access controllable and provable. Six criteria you can check with any provider:
With SecureCloud, data is stored AES-256 encrypted in German data centres; an additional encryption layer can be enabled per library, and its key never leaves the device. Share links carry password protection and an expiry date, logs are kept at file level, and Office and PDF documents can be edited simultaneously in the browser, including with external participants who have no account of their own. Alongside share links, external parties can also be added as their own users with granular permissions, in practice the more common route whenever collaboration runs longer than a single file transfer. The platform is GDPR-compliant, ISO 27001 and Trusted Cloud certified, and BSI C5 attested. It is operated by SecureCloud GmbH, headquartered with its data centres in Germany, with no US parent company.
The first step is smaller than the topic: pick one process where confidential attachments leave the building every week, and convert that one.
This article provides a general overview of typical regulatory requirements and does not constitute legal advice for an individual case. What applies is the version of each provision in force at the time and the circumstances of the specific case. As at: August 2026.
By ensuring the document never leaves the law firm as a copy. Instead of an attachment, the client receives a password-protected access link with an expiration date that can be revoked at any time, and every access is logged at the file level. This makes it possible to prove, in the event of a dispute, who had access and when, something an outbox cannot do. The retention requirements under Section 147 of the German Fiscal Code (AO) and the GoBD are covered by the version history. Data is stored with AES-256 encryption in German data centers; the platform is ISO 27001-certified and BSI C5 attested.
By sharing the document with limited validity rather than via an email attachment. The receiving practice does not need its own account; it sees only the shared document itself and not the surrounding folder, and access is logged. For health data under Article 9 of the GDPR, this is the difference between a documented security measure and one that cannot be verified. An additional layer of encryption can be enabled per library, and the encryption key never leaves the device.
Does SecureCloud meet the logging and audit trail requirements that MaRisk and DORA impose on the exchange of credit files?
SecureCloud logs access at the file level, assigns granular permissions per library, and maintains a version history, making it possible to demonstrate to the supervisory authority who had access to which document and when. Sharing permissions can be revoked after sending, ensuring that the recipient group remains controllable. Whether the specific implementation in an individual case meets the requirements of MaRisk and DORA is determined by the institution’s outsourcing and risk assessment; the platform provides the technical evidence to support this. The Advanced and Enterprise editions run as dedicated, isolated instances.
By keeping the document in one place and granting external parties access to it, rather than sending a copy as an attachment. Access is logged at the file level and thus remains part of the traceable document workflow, whereas an attachment in a case worker’s outbox lies outside the file. Permissions can be assigned on a per-library basis; sharing links include expiration dates and password protection. The BSI IT-Grundschutz serves as the benchmark for adequacy.
Yes. A sharing link can be revoked at any time, and access ends when the expiration date is reached even without intervention. This is the structural difference from an email attachment: a sent copy remains with the recipient, whereas a revoked sharing link does not. The access log also shows whether the document was opened before revocation, which is the decisive factor in assessing whether reporting is required.