Solution · Professional secrecy (§ 203 German Criminal Code)

For lawyers, doctors, tax advisors & notaries

Client events, patient trainings, chamber seminars: for you, the guest list itself is a professional secret. ticketYoo brings the operating mode, the chain of confidentiality obligations and the evidence that § 203 of the German Criminal Code demands — and is honest about what remains your responsibility.

Get in touch Read the documentation
Professional-secrecy mode Team: Musterstadt law firm · active since 1 Sep active Two-factor login Mandatory for all 6 team members enforced AI assistant · WhatsApp · Google Analytics US services touching guest data blocked Google Wallet · push · Stripe · PayPal only with the administrator’s logged consent consent required Attendee list switched on Disclosure confirmed · Dr Muster · 3 Sep, 10:12 logged The team’s security log — operator access appears here as well.

The yardstick is § 203 StGB — not just the GDPR

The guest list is the secret

Anyone attending your patient training or client event thereby reveals that they are your patient or client. Your guest list is therefore not an ordinary data set but a professional secret. § 203 (3) and (4) of the German Criminal Code allow you to involve service providers as “participating persons” — but only if you bind them to secrecy. The Art. 28 GDPR data processing agreement does not cover this. For lawyers, tax advisors and notaries, § 43e BRAO, § 62a StBerG and § 26a BNotO additionally require a contract in text form with defined content, including passing the obligations on to subcontractors.

What ticketYoo brings to the table

A dedicated operating mode, a closed chain of confidentiality obligations and evidence your data protection officer can verify.

Operated entirely in Germany

Application, database, file storage, search and virus scanning run on servers in Germany. No US cloud services in core operations; fonts and scripts are served by us, nothing is loaded from third-party servers. Email is sent via Code Piraten GmbH’s own mail server — no third-party email provider.

Professional-secrecy mode

A dedicated operating mode — per team or for a whole installation — blocks US services that touch guest data: the AI assistant, WhatsApp and US tracking such as Google Analytics or Meta Pixel. Google Wallet, push notifications, Stripe, PayPal and Microsoft 365 work only after your team administrator’s explicit, logged consent. EU alternatives such as Mollie, wallee and Matomo remain freely usable.

Deliberate disclosure instead of accidental

Features that make guests visible to each other or to third parties — attendee list, contact exchange, matchmaking, roommate finder, social wall, live Q&A, shared guest lists — require an explicit confirmation when switched on. Every decision is recorded with name, time and event as evidence; the file export of shared guest lists is off by default.

Encryption, mandatory 2FA, key rotation

Uploaded files — uploads, signatures, evidence — are stored encrypted with AES-256-GCM. In professional-secrecy mode, two-factor login is mandatory for all team members and enforced, including for existing sessions. A documented, rehearsed rotation procedure exists for the encryption key.

Transparency about operator access

If a platform administrator accesses your team data, that access appears in your own security log — you can see when the operator accessed it. Switching the mode on or off and every disclosure confirmation are recorded there too, with person and time.

Deletion concept & data-subject rights

Retention periods, automatic clean-up, data-subject access (Art. 15/20 GDPR) as an encrypted package and erasure on request (Art. 17) are built in. Details under security & privacy.

Related: security & privacy, EU hosting, public sector

What the operator sees

Team members yes — guest data no

Through the administration interface, Code Piraten GmbH’s platform administrators see only the names and email addresses of your team members — no guest data. We only have access to your events and guests if you explicitly invite us as a user into your team. Technical maintenance access at server level exists — as with every operator — and is secured by the written confidentiality obligation of all employees under § 203 (4) of the German Criminal Code.

Honest limits

What we do not promise

  • Guest names and email addresses are not field-encrypted in the database — necessary for search and sorting. Compensated by access control, strict tenant isolation, encrypted backups and the chain of confidentiality obligations.
  • Emails to your guests naturally carry names and the event reference — they run through a contractually bound mail server in Germany.
  • Payment providers connected before the mode was switched on (Stripe, PayPal) are not disconnected automatically — it is the new connection that is tied to consent.
  • The mode enforces the confirmation, not the decision: whatever networking features you switch on disclose attendance.

What remains with you

Four things no software can take off your hands

  1. Signing the § 203 service-provider agreement with us before we activate the mode.
  2. For events with a health context — e.g. patient trainings with allergy or diagnosis details in form fields — a data protection impact assessment. We support you with a checklist.
  3. Handling networking features deliberately: whatever you switch on discloses attendance.
  4. Binding your own staff who work with the guest list to confidentiality.

How to get started

Four steps to an activated team

  1. Get in touch — we sign the service-provider agreement under § 203 StGB / § 43e BRAO with you in text form.
  2. We activate professional-secrecy mode for your team; the activation is logged and reported to you.
  3. Your team members set up two-factor login (enforced) and you decide, with documentation, on features that require consent.
  4. For health data: a data protection impact assessment based on our checklist. For chambers, associations or large practices we run a dedicated installation on request, in which every team automatically works in professional-secrecy mode.

FAQ

Common questions from law firms and practices

Is the Art. 28 GDPR data processing agreement enough?

No. § 203 StGB additionally requires you to bind the service provider to secrecy; for lawyers, tax advisors and notaries, § 43e BRAO, § 62a StBerG and § 26a BNotO prescribe a contract in text form with defined content. We provide this service-provider agreement — it is the prerequisite for activation.

Who switches professional-secrecy mode on?

Only we as the operator, after the agreement has been signed — per team or for an entire installation. In a dedicated installation all teams, including those created later, are covered automatically. The activation is recorded in your security log.

Can we still use networking features such as the attendee list or social wall?

Yes — deliberately. When switching a feature on, a team administrator explicitly confirms that it discloses your guests’ attendance; the confirmation is logged with name, time and event. The mode does not replace your decision, it makes it verifiable.

What applies to health data, e.g. in a patient training?

Allergy or diagnosis details in form fields are Art. 9 GDPR data. The data protection impact assessment rests with the controller — that is, with you; we provide a checklist for it and answer the technical questions it raises.

Is there a dedicated installation for our chamber or association?

Yes, on request. In a dedicated installation every team automatically works in professional-secrecy mode — without having to be activated team by team. Get in touch with us.

Events that keep professional secrets

We sign the service-provider agreement with you and activate the mode for your team.