Skip to content
Normalex

Search a tool or a guide

The firm's AI tools register

One entry per AI tool, the points to check flagged as you answer, a proposed level of data allowed, and a register to export to CSV, PDF or Word.

What the rule says

Rules verified on 07/10/2026

The OVB and AVOCATS.BE guidelines ask the lawyer to read each tool's terms of use before using it: training, transfer and storage of the data, further use by the provider, where the data is processed, open or closed system, liability, intellectual property. The CCBE guides list the questions to put to the provider.

Each tool that processes personal data is also a processing activity for the GDPR register (art. 30) and may call for a DPIA before first use. The register lists what to fix or decide, in plain words with its source; it never gives a score.

Encrypted vault

Your data stays on this device.

Keep your registers in an encrypted vault in this browser: a firm feature, free with a verified e-mail address. Without it, everything works for this session and every export stays available.

New tool

Step 1 of 6The tool
Uses

The most sensitive data anyone enters into the tool.

Your register appears here

Describe a tool on the left: its points to check appear as you answer, and the register is ready to export.

Three AI tools: one hosted in the EU, one in the United States, one keeping prompts.

How it works

How the tool works

  1. The entry. For each tool, six sections: the tool (product tier, deployment, account, uses, most sensitive data entered), the provider and hosting (parent company, model used, where the data is processed, transfers, sub-processors), the contract and the data (role under the GDPR, processing agreement, training, retention, staff access, authorities' requests, intellectual property, governing law, exit), security (certifications, authentication, logs, memory), the AI Act and the GDPR (the firm's role, DPIA, reference in the GDPR register), and the decision (authorisation, level of data, review).
  2. The points to check. With each answer, the tool shows what to fix, justify or decide, in plain words, with its source: consumer version, training on inputs, prompts kept, no processing agreement, processing outside the European Economic Area, access by foreign authorities, memory shared across matters, high-risk or prohibited uses, terms not read for a year. Each point carries a word: "blocks personal data", "decision to record", "to fix or justify", "reminder". Never a mark or a score.
  3. The proposed level. Public information only, pseudonymised data only, personal data allowed, or secret information allowed. The firm may choose another level by recording its reason. For an online service, the "secret" level needs an explicit decision: the bar guidelines require absolute certainty that the environment is closed.
  4. The register. The list of tools, to export to CSV (Excel), PDF and Word, in the language chosen.

Without a verified address, the list lasts for the session: export it before closing the tab. With a verified address, it is kept in the encrypted vault of this browser, where the GDPR register and the DPIA tool can read it.

What the texts say

  • OVB and AVOCATS.BE guidelines (January 2025). Before using a tool, the lawyer reads its terms of use, in particular on training, transfer and storage of the data, its reuse, where it is processed, whether the system is open or closed, liability and intellectual property.
  • CCBE guides (generative AI, October 2025; technical guide, March 2026; cloud computing, February 2025): access by the provider's staff and by authorities, retention and backups, governing law, the chain of model providers, separation of client data, certifications.
  • GDPR: processing agreement (art. 28), record of processing activities (art. 30), impact assessment (art. 35), transfers (arts 44 to 46). EDPB Opinion 28/2024: the deployer checks whether the model was developed lawfully.
  • AI Act: prohibited practices (art. 5), high-risk uses (Annex III), transparency (art. 50).

Points to watch

  • The proposed level is a starting point: it follows from the answers recorded, not from an audit of the provider.
  • An "unknown" answer is treated with caution: it brings up the point to check.
  • AI features built into other software (translation, word processing, PDF readers) are tools like any other: record them too.
  • ISO/IEC 42001 is not listed: the CCBE does not mention it.

What the tool does not do

  • It does not contact any provider or check its statements.
  • It sends nothing: the list stays in this tab or in this browser's encrypted vault.

Verification

The sources were verified on 7 October 2026. The tool assists the lawyer, who remains responsible for the decision to authorise a tool.

Updated on 7 October 2026

Frequently asked questions

Why keep a register of AI tools?

The OVB and AVOCATS.BE guidelines ask the lawyer to read each tool's terms of use before using it. The register records that review, the provider's safeguards and the firm's decision. It also feeds the GDPR register, the DPIA and the list of authorised tools in the AI policy.

Which points does the register check?

About thirty points drawn from the bar guidelines, the CCBE guides, the GDPR and the AI Act: consumer version, training on inputs, retention, processing agreement, place of processing and transfers, access by the provider's staff and by authorities, certifications, authentication, shared memory, intellectual property, high-risk or prohibited uses, review of the terms.

Does the register give a compliance score?

No. For each point, it says what to fix, justify or decide, with its source. A tool cannot know whether your use meets the rules: that is for the firm to judge.

Where is my data kept?

In this tab, for the session, without a verified address. With a verified address, in this browser's encrypted vault, protected by your passphrase. Nothing is sent to Normalex or to Avlex.

Can a tool hosted in the United States be used?

Yes, if there is a transfer mechanism: the adequacy decision for companies listed under the Data Privacy Framework, or standard contractual clauses. The register flags the transfer and any exposure to requests from foreign authorities, and recommends storage in the EU.

How is the register exported?

To CSV for Excel, to PDF or to Word, in the language chosen, independently of the site's language. The document gives an overview, then each tool's entry and its points to check.

A drafting aid based on the sources cited. To be reviewed and adapted by the lawyer; it is neither advice nor a guarantee of compliance.