Knowledge base

Using AI safely in the notarial profession

Safe AI use in the notarial profession is achievable when four frameworks are in place: the duty of confidentiality under article 22 Wna, the GDPR, the EU AI Act and the KNB AI-Weegschaal. In practice this means personal data is anonymised before processing, data stays within your own EU environment, no models are trained on client data, every action is traceable and the notary reviews and signs. A supplier that meets these requirements can prove it through verifiable certifications such as ISO/IEC 27001:2022.

What does the duty of confidentiality under article 22 Wna require?

Article 22 of the Dutch Notaries Act (Wna) imposes a duty of confidentiality on the notary covering everything that comes to their knowledge in the exercise of their office. That duty also binds everyone working under their responsibility, allows exceptions only where statute provides for them, and does not lapse with the client's consent. This makes professional secrecy the strictest of the four frameworks: it leaves no room for a balancing of interests.

For AI use, this means the core question is not whether a tool is convenient, but where file information ends up. As soon as confidential data reaches an environment the office does not control, such as a public chatbot that processes input outside the EU, professional secrecy is at stake. Safe AI use therefore starts with an architecture in which privacy-sensitive data never leaves your own environment.

The KNB has additionally set out the security requirements for offices in the Gedragscode Informatiebeveiliging Notariaat, its information security code of conduct. Any office planning to deploy AI would be wise to measure every application against that yardstick too: the code sets concrete requirements for, among other things, annual staff awareness training, continuity planning and periodic technical security scans.

What do the GDPR and the EU AI Act ask of you?

The GDPR sets requirements that apply directly to AI. Every processing of personal data needs a legal basis. Data minimisation applies: process no more data than the purpose requires. A data processing agreement is mandatory with every supplier that processes personal data. And transfers outside the European Economic Area require additional safeguards. Add to this the accountability principle: you must be able to demonstrate who processes which data and why.

The EU AI Act, Regulation (EU) 2024/1689, adds a risk-based layer on top. For notarial offices, article 4 is the most immediately tangible: since 2 February 2025, organisations deploying AI must ensure sufficient AI literacy among the staff who work with it. They must understand what the system does, what it is good at and where it can fail.

In practical terms: take stock of which AI applications are in use at the office, including the informal ones, record for each application which data goes in and who reviews the output, and provide short, repeated training. Whoever records this can also demonstrate it later; which is exactly what both the GDPR and the AI Act ask of you.

What does the KNB AI-Weegschaal weigh?

The KNB AI-Weegschaal is the assessment framework the professional body offers offices to determine, per AI application, whether its use is responsible. The framework does not prohibit AI; it forces a structured weighing of benefits against risks, per application and per type of data.

Its principles can be summarised in three questions. Is the operation transparent: do you know what the system does with your data? Is the outcome traceable: can you trace every passage back to its source? And is human oversight preserved: does an authorised member of staff review every outcome before it enters the file? An application that fails to give a satisfactory answer to any of these questions does not belong in the case flow of a notarial office.

What does privacy-friendly mean technically?

Privacy-friendly is not a feeling but a verifiable set of architectural properties. At aiNotaris there are five, and they apply to all digital colleagues, from aiAssistant to aiExpert.

  • Anonymisation before processing: the Data Shield locally replaces names, addresses, citizen service numbers, IBANs and other identifying data with fictitious counterparts before any AI model sees a thing. Privacy-sensitive data never leaves your own environment.
  • EU hosting: the environment runs 100% privately on infrastructure within the EU, with encryption in transit and at rest.
  • No training on client data: your documents are never used to train AI models. This is safeguarded both technically and contractually.
  • Audit trail: every action is logged, so it can be verified afterwards who or what performed which action and when.
  • Human oversight: the software proposes, the notary reviews and signs. Essential steps are never executed without approval.

These five properties reinforce one another. EU hosting without anonymisation does not protect professional secrecy; anonymisation without an audit trail makes verification after the fact impossible. You can read exactly how the replacement of identities works on our confidentiality page.

Which assurances can you verify?

Promises about security are only worth something once you can check them. aiNotaris is certified to ISO/IEC 27001:2022; the certificate is publicly verifiable via IAF CertSearch, the international register of accredited certifications.

It is only fair to state what that certification does and does not prove. It proves that an information security management system is in place and is periodically audited by an external auditor: risk analyses, access management, encryption, incident procedures and supplier assessment. It does not prove that every individual AI outcome is correct; for that, traceability and human oversight remain indispensable.

Two further assessments are in progress: SOC 2 Type II and ISO/IEC 42001, the standard for AI management systems. Once completed, we will make those demonstrable too: the certificate in the public register, the report on request. Until then we do not claim them, and you may apply that same standard to every supplier: a logo on a website is not a certificate.

Checklist: how to assess any AI supplier

With the four frameworks and the five technical properties, any AI supplier can be assessed in a single conversation. The following questions align with the principles of the KNB AI-Weegschaal: transparency, traceability and human oversight.

  • Where is the data processed, and does privacy-sensitive data leave your own environment?
  • Is personal data replaced or masked before an AI model processes it?
  • Is it contractually ruled out that your data is used to train models?
  • Does all processing stay within the EU, including sub-processors, and is there a data processing agreement?
  • Is every outcome traceable to its source, so that review can be targeted rather than exhaustive?
  • Is human oversight anchored in the design: does the software propose and does your staff member review?
  • Is every action recorded in an audit trail the office itself can inspect?
  • Are certifications verifiable in a public register such as IAF CertSearch, with scope and validity period?

A supplier that answers these questions promptly and concretely has its architecture in order. A supplier that retreats into generalities has answered them too.

Frequently asked questions about safe AI use

With pseudonymisation, identifying data is replaced by a counterpart and a key exists to translate it back; with anonymisation, re-identification is no longer possible. The Data Shield replaces personal data locally before processing, and the translation table never leaves your environment. For the AI model the data is therefore effectively anonymous: at no point does it hold data that can be traced to a person.

Yes. Article 4 of Regulation (EU) 2024/1689 has applied since 2 February 2025 to every organisation deploying AI systems, regardless of size. Staff working with AI must sufficiently understand what the system does, what it can do and where it can fail. A short internal training session and clear working agreements are usually the first step.

No. EU hosting is necessary but not sufficient. It says nothing about whether personal data is anonymised before processing, whether models are trained on your data, whether outcomes are traceable and whether human oversight is preserved. Always assess a supplier on the full interplay of those properties.

Ask for the certificate number and the certification body, and look the certificate up in the public register IAF CertSearch. A valid certificate states its scope and validity period. The ISO/IEC 27001:2022 certificate of aiNotaris is verifiable there; SOC 2 Type II and ISO/IEC 42001 are in progress at our end and we will only claim them once completed.

See the security in practice

In a thirty-minute demo we show you how the Data Shield works, using a file from your own practice.