- Tools
- Artificial intelligence
The firm's AI tools register
One entry per AI tool, the points to check flagged as you answer, a proposed level of data allowed, and a register to export to CSV, PDF or Word.
What the rule says
Rules verified on 07/10/2026
The OVB and AVOCATS.BE guidelines ask the lawyer to read each tool's terms of use before using it: training, transfer and storage of the data, further use by the provider, where the data is processed, open or closed system, liability, intellectual property. The CCBE guides list the questions to put to the provider.
Each tool that processes personal data is also a processing activity for the GDPR register (art. 30) and may call for a DPIA before first use. The register lists what to fix or decide, in plain words with its source; it never gives a score.
- OVB and AVOCATS.BE, Guidelines for lawyers on the use of artificial intelligence (January 2025)
- CCBE, technical guide on the use of AI tools and models by lawyers (27 March 2026)
- CCBE, guidelines on the use of cloud computing by lawyers (27 February 2025)
- CCBE, guide on the use of generative AI by lawyers (2 October 2025)
- Charter for the responsible use of AI tools, proposed model (OFABB, March 2026)
- Regulation (EU) 2016/679 (GDPR)
- Regulation (EU) 2024/1689 on artificial intelligence (AI Act)
- EDPB, Opinion 28/2024 on certain data protection aspects related to AI models (17 December 2024)
Encrypted vault
Your data stays on this device.
Keep your registers in an encrypted vault in this browser: a firm feature, free with a verified e-mail address. Without it, everything works for this session and every export stays available.
Your register appears here
Describe a tool on the left: its points to check appear as you answer, and the register is ready to export.
Three AI tools: one hosted in the EU, one in the United States, one keeping prompts.
How it works
How the tool works
- The entry. For each tool, six sections: the tool (product tier, deployment, account, uses, most sensitive data entered), the provider and hosting (parent company, model used, where the data is processed, transfers, sub-processors), the contract and the data (role under the GDPR, processing agreement, training, retention, staff access, authorities' requests, intellectual property, governing law, exit), security (certifications, authentication, logs, memory), the AI Act and the GDPR (the firm's role, DPIA, reference in the GDPR register), and the decision (authorisation, level of data, review).
- The points to check. With each answer, the tool shows what to fix, justify or decide, in plain words, with its source: consumer version, training on inputs, prompts kept, no processing agreement, processing outside the European Economic Area, access by foreign authorities, memory shared across matters, high-risk or prohibited uses, terms not read for a year. Each point carries a word: "blocks personal data", "decision to record", "to fix or justify", "reminder". Never a mark or a score.
- The proposed level. Public information only, pseudonymised data only, personal data allowed, or secret information allowed. The firm may choose another level by recording its reason. For an online service, the "secret" level needs an explicit decision: the bar guidelines require absolute certainty that the environment is closed.
- The register. The list of tools, to export to CSV (Excel), PDF and Word, in the language chosen.
Without a verified address, the list lasts for the session: export it before closing the tab. With a verified address, it is kept in the encrypted vault of this browser, where the GDPR register and the DPIA tool can read it.
What the texts say
- OVB and AVOCATS.BE guidelines (January 2025). Before using a tool, the lawyer reads its terms of use, in particular on training, transfer and storage of the data, its reuse, where it is processed, whether the system is open or closed, liability and intellectual property.
- CCBE guides (generative AI, October 2025; technical guide, March 2026; cloud computing, February 2025): access by the provider's staff and by authorities, retention and backups, governing law, the chain of model providers, separation of client data, certifications.
- GDPR: processing agreement (art. 28), record of processing activities (art. 30), impact assessment (art. 35), transfers (arts 44 to 46). EDPB Opinion 28/2024: the deployer checks whether the model was developed lawfully.
- AI Act: prohibited practices (art. 5), high-risk uses (Annex III), transparency (art. 50).
Points to watch
- The proposed level is a starting point: it follows from the answers recorded, not from an audit of the provider.
- An "unknown" answer is treated with caution: it brings up the point to check.
- AI features built into other software (translation, word processing, PDF readers) are tools like any other: record them too.
- ISO/IEC 42001 is not listed: the CCBE does not mention it.
What the tool does not do
- It does not contact any provider or check its statements.
- It sends nothing: the list stays in this tab or in this browser's encrypted vault.
Verification
The sources were verified on 7 October 2026. The tool assists the lawyer, who remains responsible for the decision to authorise a tool.
Updated on 7 October 2026
Frequently asked questions
Why keep a register of AI tools?
The OVB and AVOCATS.BE guidelines ask the lawyer to read each tool's terms of use before using it. The register records that review, the provider's safeguards and the firm's decision. It also feeds the GDPR register, the DPIA and the list of authorised tools in the AI policy.
Which points does the register check?
About thirty points drawn from the bar guidelines, the CCBE guides, the GDPR and the AI Act: consumer version, training on inputs, retention, processing agreement, place of processing and transfers, access by the provider's staff and by authorities, certifications, authentication, shared memory, intellectual property, high-risk or prohibited uses, review of the terms.
Does the register give a compliance score?
No. For each point, it says what to fix, justify or decide, with its source. A tool cannot know whether your use meets the rules: that is for the firm to judge.
Where is my data kept?
In this tab, for the session, without a verified address. With a verified address, in this browser's encrypted vault, protected by your passphrase. Nothing is sent to Normalex or to Avlex.
Can a tool hosted in the United States be used?
Yes, if there is a transfer mechanism: the adequacy decision for companies listed under the Data Privacy Framework, or standard contractual clauses. The register flags the transfer and any exposure to requests from foreign authorities, and recommends storage in the EU.
How is the register exported?
To CSV for Excel, to PDF or to Word, in the language chosen, independently of the site's language. The document gives an overview, then each tool's entry and its points to check.