Guide7 min read

Is It Safe for Notaries in France to Use AI?

AI helps draft and summarise. But pasting deed data into a consumer AI exposes a French notary's professional secrecy to a third party.

By Pierre de ONYRI

The answer fits in one line. AI can help you draft or summarise, but never hand it your deed data. A party's identity. An estate amount. A family situation. Pasted into a consumer AI, these details leave your office. That is exposure to a third party. Yet a notary is a public officer, bound by general and absolute professional secrecy. And under the GDPR, you remain the data controller for your clients' data. There is a clean method: anonymise before any prompt, then restore the values locally.

The problem: deed data pasted into AI

The habit spreads fast in offices. You ask an AI to summarise an estate file. You have it rewrite a marriage-contract clause. You submit the draft of a gift deed. To save time, you paste the raw text. That text often holds the parties' real data. This is where the risk begins, not in the tool itself.

A notarial deed concentrates some of the most sensitive data there is. Here is what a poorly prepared prompt can expose.

  • The identity and contact details of the parties, and of third parties named.
  • The assets: real estate, accounts, amounts, estate values.
  • The family situation: marital regime, filiation, gifts, heirs.
  • The deed references and the documents attached to the file.

The stake: public officer, secrecy and the GDPR

A notary is not an ordinary provider. It is a public and ministerial officer, holding delegated public authority. The notary authenticates deeds, collects the parties' consent and keeps the originals. On that basis, the notary is bound by professional secrecy. This secrecy is described as general and absolute. Everything the notary learns on duty is covered by it. The office staff is bound too.

The sanction is not theoretical. Article 226-13 of the Criminal Code punishes disclosing secret information by a person entrusted with it. The penalty runs up to one year in prison and a 15,000-euro fine. The status itself is old and solid. It is set by Ordinance No. 45-2590 of 2 November 1945 on the status of the notarial profession.

Now a consumer AI provider is an unauthorised third party. Secrecy binds the notary and the staff, not an outside service. So pasting deed data into an AI means exposing secret-covered information to that third party. The content can be retained, reviewed or reused to train the model. Exposure alone is enough to be a problem, even without a public leak.

The GDPR adds to the secrecy duty. The notary is the data controller for clients' data. The CNIL, France's data protection authority, states that AI gets no exemption. As soon as an AI system processes personal data, the regulation applies fully. That covers training, the query and the output. Legal basis, minimisation, security, transparency: nothing is set aside.

Is AI banned for the notarial profession?

No. No rule forbids a notary from using AI. The tool can structure an argument, rewrite a clause or suggest an outline. What causes trouble is exposing the data, not using AI itself. So the question is not “should we give up AI?”. The question is “how do we use it without exposing deed data?”. The answer holds in one word: minimisation.

AssumptionThe reality
“Pasting a deed into the AI stays between us”It is exposure to an unauthorised third party, while secrecy is general and absolute
“The GDPR doesn't apply to AI”The CNIL states there is no exemption: the regulation applies fully
“AI is banned for notaries”No: it is exposing the data that is the problem, not the tool
“Notary or provider, same secrecy”A notary is a public officer; its secrecy is stricter, and an AI provider is a third party
The risk isn't using AI — it's the deed data you leave behind in the prompt.

The fix: anonymise before the prompt

The fix matches what the CNIL says. When personal data is not needed for the processing, you strip it upstream. This is minimisation applied to AI. The notary keeps the tool and saves time. The AI never sees the deed's real values. You stay in control of the secret, on your own machine.

Two-part diagram: at top, a document sealed by an abstract wax seal carries a data line in the clear (amber) that reaches an exposed AI card; at bottom, the same line is reduced to cobalt token chips followed by a checkmark, and the AI receives only these anonymized tokens.
After the Ministry of Justice's “Notaire” fact sheet (justice.fr) and the CNIL's AI and GDPR recommendations.

In practice, you proceed step by step. You spot each identifying element. You replace it with a token before sending. The AI reasons about the shape of the file, without ever reading identities or amounts. You then restore the real values, locally. Here is the order to follow.

  1. 1Spot the deed data: identities, assets, family situation, references.
  2. 2Replace them with reversible tokens, in the browser.
  3. 3Send only the anonymized text to the AI.
  4. 4Restore the real values in the reply, locally, then re-read the result.

That's what ONYRI Sanitize is for. The engine detects sensitive data — identities, contact details, amounts, references — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI finds only tokens, never your deed data. You get AI's help, while reducing the exposure that professional secrecy and the GDPR ask you to control.

Frequently asked questions

Can a notary use AI without breaching professional secrecy?
Yes, as long as deed data is not exposed. A notary is a public officer bound by general and absolute secrecy, whose breach is punished by Article 226-13 of the Criminal Code. Pasting identities or an estate into a consumer AI exposes that information to a third party. AI stays useful on anonymized text: strip the identifying data before any prompt.
Is AI banned for the notarial profession?
No. No rule forbids AI for notaries. It is exposing the data that is the problem, not the tool. The CNIL notes that the GDPR applies fully to any AI processing personal data, and cites upstream anonymisation as a lever. So the good practice is to anonymise deed data before submitting it.
Does anonymising before the prompt make me GDPR-compliant?
No, not on its own. Anonymising reduces risk and supports the minimisation principle the CNIL cites. But it does not make the office “compliant” and does not lift professional secrecy. It is one useful control among others. Your duties of legal basis, security and transparency remain in full.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next