The OVB/OBFG AI guidelines: pseudonymising in practice
The Belgian bars' AI guidelines fit on a few pages. Section 1.2 holds two distinct rules, one on personal data and one on professional secrecy. How to apply both to a real file.
Updated on 29 September 2026
On 20 January 2025 the Orde van Vlaamse Balies (OVB) and AVOCATS.BE, the association of the French- and German-speaking bars (Ordre des barreaux francophones et germanophone, OBFG), published joint guidelines for lawyers on the use of artificial intelligence, in Dutch and French. They neither forbid nor require AI: its use falls within the lawyer's own freedom and responsibility. They do set out what that responsibility involves.
This guide summarises the text, looks closely at section 1.2 on data protection and professional secrecy, and proposes a routine for a real file. The summaries below are ours; the Dutch and French texts are authoritative.
What the guidelines say
| Section | Rule (summarised) | What it means in practice |
|---|---|---|
| 1 | AI is neither forbidden nor mandatory | Your choice, and your responsibility |
| 1.1 | Know the basics of AI and large language models | Understand that a model predicts plausible text; it does not look up the law |
| 1.1 | The core duties of art. 455 of the Judicial Code and of the bar codes apply (art. 1 of the OVB Codex, art. 1.2 of the AVOCATS.BE code of conduct) | Competence, professional secrecy, independence, no conflicts of interest |
| 1.1 | Read the terms of use of the AI tool | Training, transfer and storage; further processing; location; open or closed system; liability; intellectual property |
| 1.1 | Check the output, including the sources cited | Verify that every statute, author and judgment cited exists |
| 1.1 | No general duty to tell the client that AI is used | As with other IT tools |
| 1.2 | Pseudonymise personal data; do not enter personal data into prompts, input or documents | The core of this guide |
| 1.2 | Where processing personal data is essential: be transparent and ask the data subject's consent; sometimes another legal basis applies | The example given is recording a meeting to generate minutes |
| 1.2 | Never enter documents or information covered by professional secrecy or a confidentiality obligation into an AI tool | Exception only if absolutely certain of a closed environment with adequate safeguards, for example within the firm's own perimeter, with nothing shared outside |
| 1.3 | Explain your chatbot | Users must know they are dealing with an automated system |
| 1.3 | The lawyer remains ultimately responsible for the AI's output | All liability principles continue to apply |
Two rules, not one
Section 1.2 combines two obligations that are easy to merge in the mind:
- A data protection rule: pseudonymise personal data before they reach an AI tool.
- A professional secrecy rule: do not enter information covered by professional secrecy or a confidentiality obligation, outside a closed environment with adequate safeguards.
Pseudonymisation answers the first rule. It helps with the second, because a text without names, addresses or identifiers reveals much less. It does not settle it. The facts of a case, a defence strategy or the content of a negotiation can remain covered by secrecy even when every name has been replaced. The GDPR protects natural persons only, but secrecy does not stop there: a company name can reveal who the client is.
Before pasting anything into an AI tool, three questions help:
- Does the AI need this passage at all, or only part of it?
- Once pseudonymised, could the text still disclose something covered by secrecy or by a confidentiality obligation?
- What kind of environment is the AI tool: open or closed, trained on your input or not, where is the data stored, under which contract?
The OFABB model charter
The French-speaking Brussels Bar (OFABB) has drafted a model charter for the responsible use of AI tools within a firm, published in La Tribune in 2026. It is a template for firms to adapt, and it goes further on organisation:
- Section 4: before submitting documents covered by secrecy, personal data (including sensitive or criminal data), data on clients, opposing parties, magistrates, third parties or firm members, or case documents, the user weighs whether to do so, limits the data or pseudonymises them, and refrains in the absence of adequate guarantees.
- Section 5: AI-assisted work is flagged internally, so the reviewer knows extra care is needed.
- Sections 6 and 7: no AI-assisted content leaves the firm without a thorough review by a competent lawyer; no copy-paste without verification.
- Section 8: using AI does not reduce the lawyer's professional, civil, disciplinary or criminal liability.
How to do it with Localex
A routine that follows both rules of section 1.2:
- Choose what the AI will see. Copy only the passage you need into the tool, or load the document and work on the relevant part.
- Pseudonymise locally. Choose the Before AI preset. All categories are ticked by default, including organisations and sensitive data (GDPR art. 9 and 10).
- Review. Check each finding, mask what was missed, and look for details that identify without a name: a small municipality, a rare profession, an exact amount, a unique event. The AI features, free after e-mail verification, include a re-identification risk analysis that flags them.
- Apply the secrecy test. Read the pseudonymised text as a stranger would. If it still discloses what secrecy protects, shorten or generalise it, or do not send it.
- Use the AI tool whose terms you have read, with Copy for AI, and keep the encrypted restore key on your computer.
- Restore and verify. Put the names back on the Restore page, then check the substance and every source before anything leaves the firm.
What Localex is designed to help with
Localex is designed following the OVB/OBFG AI guidelines. It assists the lawyer; it does not replace the lawyer's assessment.
- Pseudonymising personal data: checksum-validated Belgian identifiers, names, addresses, dates and sensitive data, all ticked by default, with a mandatory review before export.
- Keeping personal data out of prompts: Copy for AI copies only the pseudonymised text, and a leak scan checks every export for original values.
- Location of processing: documents are processed in the browser and never uploaded, including when the on-device AI features are used. You can check it with the network panel or offline mode.
- Checking the output: the restore report flags tokens the AI altered or dropped. The legal substance remains for you to verify.
The full mapping, requirement by requirement, is on the security page.
Honest limits
- The guidelines are guidance from the bar associations; this summary does not replace them, nor the codes of conduct they refer to.
- Detection is not exhaustive. The review, the secrecy test and the final responsibility remain the lawyer's.
- Pseudonymised data remain personal data under the GDPR; see pseudonymisation vs anonymisation.