strafsachen.at
Appeals

Seized lawyer data in the cloud: inspection and sealing in Austria

Seized lawyer data in the cloud: sections 112 StPO and 9 RAO, inspection, sealing and remedies in Austrian criminal proceedings.

Your personal attorney

Mag. Christopher Angerer, Rechtsanwalt

Your lawyer for criminal defence

Criminal proceedings are a matter of trust. One lawyer who walks with you from the first consultation through to the trial, everything from one hand.

13 September 2026, Mag. Christopher Angerer, Rechtsanwalt

Cloud data held by a lawyer can be evidence in criminal proceedings while also containing protected mandate communications. The first response matters: identify the data set, raise professional secrecy, request sealing and preserve a reliable record of every later inspection.

Section 112 StPO protects items whose seizure is prohibited because of statutory professional secrecy. Section 9 of the Austrian Lawyers Act, RAO, requires lawyers to maintain confidentiality. This article explains the specific issues raised by stored emails, documents and messages in a cloud. General file access, a search of the suspect premises and data protection complaints are outside its scope.

Quick assessment

Which review matters first for cloud data?

Choose the situation closest to yours. You will receive an initial orientation and a list of documents useful for the next review.

Would you like to discuss your situation? Go straight to the enquiry form.

01 Question 1

What has happened to the cloud data?

The next step depends on whether an authority wants to inspect the data, has already sealed it or has asked the cloud provider to disclose it directly.

All paths at a glance

Overview of all answers.

01

Check professional secrecy and sealing before any inspection.

If an authority accesses cloud data containing lawyer communications, the affected person should immediately raise professional secrecy. Section 112 StPO provides special protection for items whose seizure is prohibited because of professional secrecy. Ask for the objection and the affected data set to be recorded in the minutes.

The exact classification may require technical assistance. Preserve the order, account name, period and folder structure. Do not open the files yourself if doing so could change their state or make the scope of the communications unclear.

About controlled inspection →
02

Leave sealed data unchanged and prepare for the court decision.

Sealed data should not simply be opened or analysed before the decision on whether the seizure is lawful. Sealing protects the dispute over whether the material is covered by professional secrecy. The key facts are who entrusted the communication, which period it concerns and why it belongs to the legal mandate.

Review the court decision and its reasons after service. Depending on the procedural stage, applications and remedies may be available. Keep the material together with the service date and minutes.

About remedies against analysis →
03

Review the production request, data type and professional secrecy separately.

A request to a cloud provider is procedurally different from seizure within the law firm account. First identify the data category, account and period named in the request. If the request concerns lawyer communications, the authority must take professional secrecy into account. Storage by a service provider does not automatically remove that protection.

Preserve the notice, sender details and timestamps. Do not delete or restructure the account in haste. The technical environment should be documented in its original state.

About the special features of cloud storage →
04

Clarify the scope by comparing the order, account and period.

An unclear description makes it difficult to review proportionality and professional secrecy. Record which cloud, user account, folders and period are named. If these details are missing, the objection to the scope should be recorded expressly.

The order, seizure minutes, provider notice and affected mandate relationship are important for legal review. They allow a more reliable assessment than an isolated screenshot.

About the next legal steps →

Professional secrecy under section 112 StPO and section 9 RAO

Section 112 StPO is connected with protected professional communications. It must be read together with section 157(1) numbers 2 to 5 StPO. Those provisions concern persons who may refuse to give evidence because of professional confidentiality. Lawyers and defence counsel are covered within the scope of their professional work. The specific data set must therefore be linked to the person who entrusted the information, the professional relationship in which it arose and its content.

Section 9 RAO requires lawyers to keep confidential matters entrusted to them or learned in their professional capacity. The duty protects the relationship of trust with the client. It commonly covers advice, defence material, documents supplied by the client and communication about a mandate. A file is not automatically protected merely because it is stored in a law firm account. The connection to the mandate must be identifiable.

The review therefore starts with origin and function. A private note with no mandate connection must be assessed differently from a client email containing defence documents. In a mixed account, the material must be separated on a traceable basis.

Why cloud storage does not decide the legal issue

Technical storage by a cloud provider does not automatically change the professional relationship between lawyer and client. The relevant factors are the data itself, the circumstances in which it was created and the purpose of the communication. An authority must distinguish protected mandate data from other data even where both are kept in one online account.

A direct request to the provider also requires review of the procedural basis, the addressee of the order and the data category identified. Stored content, traffic data and basic account data can be governed by different rules. A production request should not use a broad technical description to bypass professional secrecy.

The account structure matters in practice. Law firm folders, private areas, shared project folders and automatic backups may contain different types of material. The defence should provide a factual classification instead of describing every file as protected without distinction.

Protection review

The first question for each type of cloud data

Technical form alone does not answer the legal question. Origin, mandate connection and the exact measure are decisive.

Cloud data and legal professional secrecy in criminal proceedings
Situation First key question Useful document
Client email Was it entrusted as part of a legal mandate? Email with sender, date and subject
Draft or legal opinion Does it serve advice or defence work? Document version and mandate link
Mixed cloud folder Which files have a concrete mandate connection? Folder overview with factual separation
Request to provider Are account, data type and period sufficiently specific? Order or notice in full

Inspection, sealing and judicial control

If protected data are found during a search or seizure, the objection to the measure should be raised immediately. The affected person should name professional secrecy expressly and ask for the affected files or data sets to be identified. The minutes should show when the objection was made and how the authority responded.

Sealing keeps the data set closed while the court decides whether seizure is lawful. The authority should not simply open or use sealed content for the investigation before that decision. The protection works only if the material remains unchanged. Deleting, sorting or editing it later can make classification more difficult.

A large account may require a technical copy. The record should then state who created it, how the data set was delimited and whether metadata were preserved. A traceable chain of handling helps determine whether the authority reached beyond the protected core.

Remedies against unlawful data inspection

The court decides whether protected items may be seized. It needs a clear description of the mandate, communication partners, period and data concerned. A general statement that all law firm data are confidential is not enough. At the same time, a technical collective label must not conceal a concrete mandate connection.

The appropriate response depends on the measure and its procedural stage. Review the seizure minutes, the order, any judicial decision and the date of service. Remedies against judicial decisions may be available under the applicable provisions. Legal review should address the data question and any procedural time limit together.

If the authority has already inspected the material, establish the scope of inspection as precisely as possible. Record search terms, opened folders, exported files and persons present where that information is available. This creates a basis for further applications and for assessing later use of the material.

What the lawyer and client should document immediately

The first record should preserve the original state. Save the order, minutes, cloud provider notices and every seizure confirmation. Note the time, authority, affected accounts and whether inspection has already begun.

Classify communications in a protected overview by mandate, communication partner, period and document type. The overview does not need to reproduce the content. It should explain why a data set falls within professional secrecy. This is particularly useful where an account contains different kinds of material.

Technical steps should be limited to preserving the state. Do not delete messages, move files or change access rights where that could affect the investigation or later evidence preservation. Have the technical record prepared by a qualified person and make every change traceable.

The mandate connection must be visible. For cloud data, the account name alone rarely resolves the issue. Communication partners, purpose, period and the link to a specific mandate are the useful points for separating protected data from other material.

Subscribe to legal updates. New posts and legal information from the firm are available through BRANDaktuellen Rechtsnews.

Frequently asked questions

Seized lawyer data in the cloud explained clearly.

Are cloud data in a law firm account automatically protected? +

No. Protection depends on the professional mandate connection and statutory confidentiality. Advice, defence material and client communications may be protected. Other data in the same account must be assessed separately.

What should I do if an authority wants to inspect lawyer communications? +

Raise professional secrecy expressly, ask for the affected data set to be identified and have the objection recorded in the minutes. The availability of sealing and the court decision on lawfulness must be reviewed.

May sealed data be opened? +

Sealing is intended to prevent the contents from being opened or used before the decision on lawfulness. Leave the material unchanged and review the judicial decision together with its service date.

Does professional secrecy apply against a cloud provider? +

The storage location does not automatically remove the mandate connection. In a request to the provider, data type, account, period and procedural basis must be reviewed. Protected mandate communications require separate legal classification.

Which documents are important for the review? +

The order, seizure or inspection minutes, the cloud provider notice, the affected accounts and a factual classification of the data by mandate and period are particularly important.

Topics
lawyer datacloudseizuresealinglegal professional secrecysection 112 StPOsection 9 RAOcriminal proceedings

Interview, house search, indictment?

In criminal matters every hour counts. Call us directly or send an email, callback within one business day, earlier in urgent cases.

Contact

A direct line to the firm.

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg