
§ 203(3) and (4) StGB: a medical practice's IT provider is itself criminally liable if it discloses a secret, and the practice is liable if it never bound the provider to secrecy
Since the recast of § 203 of the German Criminal Code, professionals bound by secrecy may disclose secrets to „sonstigen mitwirkenden Personen“ – other participating persons – „soweit dies für die Inanspruchnahme der Tätigkeit … erforderlich ist“, in so far as necessary to use their services. In return, subsection 4 sentence 1 makes the participating person itself an offender, and subsection 4 sentence 2 no. 1 punishes the professional who did not ensure that it „zur Geheimhaltung verpflichtet wurde“ – was bound to secrecy. What that means for software and cloud providers in healthcare, for law firms and for tax advisers, verbatim.
Key takeaways
- Professionals bound by secrecy are the persons named in § 203(1) StGB, among them „Arzt, Zahnarzt, Tierarzt, Apotheker oder Angehörigen eines anderen Heilberufs“ – physicians, dentists, veterinarians, pharmacists and members of other regulated healing professions (no. 1), „Rechtsanwalt, … Notar, … Wirtschaftsprüfer, … Steuerberater“ – lawyers, notaries, auditors, tax advisers (no. 3) and „Angehörigen eines Unternehmens der privaten Kranken-, Unfall- oder Lebensversicherung“ – staff of private health, accident or life insurers (no. 7). Whoever runs IT for them participates in their activity.
- § 203(3) sentence 2 StGB is the permission: disclosure to participating persons is allowed, but only „soweit dies für die Inanspruchnahme der Tätigkeit der sonstigen mitwirkenden Personen erforderlich ist“ – to the extent necessary. Access beyond what is necessary is not covered by the permission.
- The permission extends down the chain: sentence 2 second half applies „für sonstige mitwirkende Personen, wenn diese sich weiterer Personen bedienen“ – to participating persons who in turn use further persons. The IT provider's subcontractor is covered.
- § 203(4) sentence 1 StGB makes the participating person itself liable: „Freiheitsstrafe bis zu einem Jahr oder … Geldstrafe“ for the unauthorised disclosure of a secret that came to its knowledge „bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit“. The same applies to the data protection officer working for a professional bound by secrecy.
- § 203(4) sentence 2 no. 1 StGB reaches the principal: liable is anyone who „als in den Absätzen 1 und 2 genannte Person nicht dafür Sorge getragen hat, dass eine sonstige mitwirkende Person, die unbefugt ein fremdes … Geheimnis offenbart, zur Geheimhaltung verpflichtet wurde“ – as a professional did not ensure that a participating person who then discloses a secret was bound to secrecy. No. 2 extends this duty to the provider vis-à-vis its own subcontractors.
- § 203(6) StGB raises the range to „Freiheitsstrafe bis zu zwei Jahren oder Geldstrafe“ – up to two years – where the offender acts „gegen Entgelt oder in der Absicht, sich oder einen anderen zu bereichern oder einen anderen zu schädigen“ – for payment or with intent to enrich or to harm.
- The secrecy obligation is no substitute for the contract under Article 28 GDPR and the latter no substitute for it; § 203 StGB protects the secret, the GDPR protects personal data. Both have to be met side by side.
Two subsections that reach the provider and its customer at once
Anyone operating software or cloud services for medical practices, hospitals, law firms or tax advisers works with secrets that § 203 StGB protects. Until the provision was recast it was disputed whether a professional bound by secrecy could grant such providers access at all. The current version resolves this with an exchange: subsection 3 sentence 2 permits disclosure to „sonstigen mitwirkenden Personen“, and subsection 4 in return draws two new groups of offenders into the offence, the provider itself and the professional who did not bind it. Both sides of a software contract in healthcare have carried their own criminal exposure ever since.
This article reproduces § 203(1), (3), (4) and (6) StGB as made available by gesetze-im-internet.de on 17 September 2026, quoting the German text with English renderings alongside.
Subsection 1: whose secrets are protected
§ 203(1) StGB punishes „wer unbefugt ein fremdes Geheimnis, namentlich ein zum persönlichen Lebensbereich gehörendes Geheimnis oder ein Betriebs- oder Geschäftsgeheimnis, offenbart, das ihm als“ one of the persons listed there „anvertraut worden oder sonst bekanntgeworden ist“ – anyone who without authority discloses another's secret, in particular one belonging to the personal sphere or a trade or business secret, entrusted to or otherwise made known to them in one of the listed capacities. The list opens with no. 1: „Arzt, Zahnarzt, Tierarzt, Apotheker oder Angehörigen eines anderen Heilberufs, der für die Berufsausübung oder die Führung der Berufsbezeichnung eine staatlich geregelte Ausbildung erfordert“. No. 3 names „Rechtsanwalt, Kammerrechtsbeistand, Patentanwalt, Notar, Verteidiger in einem gesetzlich geordneten Verfahren, Wirtschaftsprüfer, vereidigtem Buchprüfer, Steuerberater, Steuerbevollmächtigten“, no. 7 „Angehörigen eines Unternehmens der privaten Kranken-, Unfall- oder Lebensversicherung oder einer privatärztlichen, steuerberaterlichen oder anwaltlichen Verrechnungsstelle“. Whoever hosts data, maintains systems or provides support for one of these persons comes into contact with their secrets.
Subsection 3: the permission and its limit
§ 203(3) StGB: „Kein Offenbaren im Sinne dieser Vorschrift liegt vor, wenn die in den Absätzen 1 und 2 genannten Personen Geheimnisse den bei ihnen berufsmäßig tätigen Gehilfen oder den bei ihnen zur Vorbereitung auf den Beruf tätigen Personen zugänglich machen. Die in den Absätzen 1 und 2 Genannten dürfen fremde Geheimnisse gegenüber sonstigen Personen offenbaren, die an ihrer beruflichen oder dienstlichen Tätigkeit mitwirken, soweit dies für die Inanspruchnahme der Tätigkeit der sonstigen mitwirkenden Personen erforderlich ist; das Gleiche gilt für sonstige mitwirkende Personen, wenn diese sich weiterer Personen bedienen, die an der beruflichen oder dienstlichen Tätigkeit der in den Absätzen 1 und 2 Genannten mitwirken.“ – there is no disclosure where the professional gives secrets to their own professional assistants or trainees; the professional may disclose secrets to other persons participating in their activity in so far as necessary to use those persons' services; the same applies to participating persons who in turn use further persons.
Sentence 1 concerns the professional's own assistants, such as the medical assistant; giving them access is by definition no disclosure. Sentence 2 concerns the „sonstigen Personen, die an ihrer beruflichen oder dienstlichen Tätigkeit mitwirken“, and that is the category of the external IT provider, the data centre, the software vendor with remote maintenance access. Disclosure to them is permitted, but only „soweit dies für die Inanspruchnahme der Tätigkeit … erforderlich ist“. The limit therefore lies not with the provider as such but with the scope: a maintenance account that exposes the patient database in clear text although maintenance does not require it is not covered by sentence 2. The second half-sentence draws the permission down the chain: the provider too may „weiterer Personen bedienen“ – use further persons – on the same condition.
Subsection 4 sentence 1: the provider as offender
§ 203(4) sentence 1 StGB: „Mit Freiheitsstrafe bis zu einem Jahr oder mit Geldstrafe wird bestraft, wer unbefugt ein fremdes Geheimnis offenbart, das ihm bei der Ausübung oder bei Gelegenheit seiner Tätigkeit als mitwirkende Person oder als bei den in den Absätzen 1 und 2 genannten Personen tätiger Datenschutzbeauftragter bekannt geworden ist.“
This is the provision that hits the software vendor directly. Anyone who as a participating person learns a secret, „bei der Ausübung oder bei Gelegenheit“ – in the course of or on the occasion of – the activity, and discloses it without authority commits the offence without being a physician or lawyer. „Bei Gelegenheit“ also covers what a technician happens to see. Alongside the participating person the provision expressly names the data protection officer working for a professional bound by secrecy; an external data protection officer of a practice thus stands in the same offence as the IT provider.
Subsection 4 sentence 2 nos. 1 and 2: the duty to bind
§ 203(4) sentence 2 StGB: „Ebenso wird bestraft, wer 1. als in den Absätzen 1 und 2 genannte Person nicht dafür Sorge getragen hat, dass eine sonstige mitwirkende Person, die unbefugt ein fremdes, ihr bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit bekannt gewordenes Geheimnis offenbart, zur Geheimhaltung verpflichtet wurde; dies gilt nicht für sonstige mitwirkende Personen, die selbst eine in den Absätzen 1 oder 2 genannte Person sind, 2. als im Absatz 3 genannte mitwirkende Person sich einer weiteren mitwirkenden Person, die unbefugt ein fremdes, ihr bei der Ausübung oder bei Gelegenheit ihrer Tätigkeit bekannt gewordenes Geheimnis offenbart, bedient und nicht dafür Sorge getragen hat, dass diese zur Geheimhaltung verpflichtet wurde; dies gilt nicht für sonstige mitwirkende Personen, die selbst eine in den Absätzen 1 oder 2 genannte Person sind“ – likewise punished is (1) the professional who did not ensure that a participating person who then discloses a secret was bound to secrecy, and (2) the participating person who used a further participating person who then discloses a secret and did not ensure that this person was bound to secrecy; neither applies where the participating person is itself a professional bound by secrecy.
No. 1 reaches the practice, the law firm, the hospital: liable is anyone who „nicht dafür Sorge getragen hat“ that the provider „zur Geheimhaltung verpflichtet wurde“, if the provider later discloses a secret. Liability hangs on two conditions, the omitted binding and the later disclosure by the provider; the binding is the only one the professional controls. No. 2 extends the same duty to the provider vis-à-vis its subcontractors: whoever „einer weiteren mitwirkenden Person bedient“ – uses a further participating person – must bind that person. For a software vendor that outsources hosting or support to third parties this means it becomes an addressee of the duty to bind in its own right. The exception at the end of both numbers applies only where the participating person is itself a professional bound by secrecy, such as a physician acting for another physician.
Subsection 6: the increased range
§ 203(6) StGB: „Handelt der Täter gegen Entgelt oder in der Absicht, sich oder einen anderen zu bereichern oder einen anderen zu schädigen, so ist die Strafe Freiheitsstrafe bis zu zwei Jahren oder Geldstrafe.“ – where the offender acts for payment or with intent to enrich themselves or another or to harm another, the penalty is imprisonment of up to two years or a fine. Selling patient data falls under it; the range applies to all offenders under subsections 1 to 4.
What this means alongside the GDPR
§ 203 StGB and the processing contract under Article 28 of Regulation (EU) 2016/679 are often dealt with in one document in practice, but they are two different obligations. The Article 28 GDPR contract governs the processing of personal data on behalf of a controller; the binding under § 203(4) sentence 2 StGB concerns the secrecy of another's secrets, which include trade and business secrets with no personal reference. An Article 28 contract without an express secrecy obligation under § 203 StGB does not evidence the binding; a § 203 binding without an Article 28 contract does not satisfy the GDPR. This article names no GDPR fines; it deals with the criminal provision.
What a provider and what its customer have to hold
The wording produces two items for each side. The professional bound by secrecy needs, first, evidence that every participating provider „zur Geheimhaltung verpflichtet wurde“, dated and before first access, and second, a limitation of access to what is „für die Inanspruchnahme der Tätigkeit … erforderlich“. The provider needs, first, the same evidence towards each of its own subcontractors under no. 2, and second, an internal rule that makes the offence of subsection 4 sentence 1 known to its employees, because they can be offenders themselves.
In CIVAC the secrecy declarations per provider and per subcontractor can be filed as dated documents, the review of access scope run as a recurring task of the data protection officer, and the instruction of the company's own staff on § 203(4) StGB recorded as training evidence. It changes nothing about the duty itself. Whether an access was necessary and whether a disclosure was unauthorised is decided, if it comes to that, by the criminal court; the platform records that binding, limiting and instruction took place.
Where this article ends
CIVAC is not a law firm and does not provide legal services within the meaning of the German Legal Services Act (Rechtsdienstleistungsgesetz). This article reproduces § 203(1), (3), (4) and (6) StGB verbatim. Whether a particular provider is a participating person, which access is necessary in a given case, what form a secrecy obligation must take and whether a particular disclosure was unauthorised is not decided by this text but, in dispute, by the competent court.
Frequently asked questions
May a medical practice host its patient data with an external provider at all?
§ 203(3) sentence 2 StGB permits disclosure to „sonstigen Personen, die an ihrer beruflichen oder dienstlichen Tätigkeit mitwirken, soweit dies für die Inanspruchnahme der Tätigkeit der sonstigen mitwirkenden Personen erforderlich ist“. The permission exists but is limited to what is necessary and presupposes under subsection 4 sentence 2 no. 1 that the provider is bound to secrecy.
Is the software vendor itself criminally liable?
Yes, under § 203(4) sentence 1 StGB, if it „unbefugt ein fremdes Geheimnis offenbart, das ihm bei der Ausübung oder bei Gelegenheit seiner Tätigkeit als mitwirkende Person … bekannt geworden ist“. The range is imprisonment of up to one year or a fine, under subsection 6 up to two years for acting for payment or with intent to enrich or harm.
What happens if the practice never bound the provider?
If the provider later discloses a secret without authority, under § 203(4) sentence 2 no. 1 StGB the professional who „nicht dafür Sorge getragen hat, dass eine sonstige mitwirkende Person … zur Geheimhaltung verpflichtet wurde“ is also liable. The omitted binding thus becomes the professional's own criminal liability in the event of disclosure.
Does this also apply to the provider's subcontractor?
Yes. § 203(3) sentence 2 second half StGB extends the permission to „weitere Personen“ whom the participating person uses, and § 203(4) sentence 2 no. 2 StGB punishes the participating person who „nicht dafür Sorge getragen hat, dass diese zur Geheimhaltung verpflichtet wurde“.
Is the Article 28 GDPR processing contract enough?
§ 203(4) sentence 2 no. 1 StGB requires that the participating person „zur Geheimhaltung verpflichtet wurde“. Whether a particular contract text contains that binding is a question of its content; a contract that governs only the processing of personal data without addressing secrecy under § 203 StGB does not evidence it.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

§ 83 MPDG: whoever informs professional circles about medical devices is a medical device adviser – with proven expertise, regular training paid for by the principal and a recording duty that reaches the PRRC
