Jurono Magazine

Check Opponents First, Then Open the File: Conflict Checks in Digital Client Intake

Practical guide for a two-step digital intake: Law firms initially record only parties relevant to potential conflicts of interest and do not access the case details or enable document uploads until a lawyer has given approval.

August 04, 202611 min readJurono Editorial TeamCheck the law firm for conflicts of interest
JEJurono Editorial TeamJurono Magazine
Next step

Check which Jurono starting point fits your firm.

See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.

A prospective client opens the law firm’s contact form, pastes a novella-length message into the free-text field, and uploads an employment contract, a warning letter, medical records, and all previous correspondence. Only then does the team realize: The opposing party is already being represented by the firm. What appears to be a convenient digital initial contact has thus created several problems at once. The inquiry must be reviewed for compliance with professional ethics, treated confidentially, technically isolated, and properly closed in accordance with data protection laws—even though it is not yet certain whether a retainer agreement will be established.

The solution is not to revert digital client inquiries back to phone calls and paper. It lies in changing the order: first conflict details, then the facts of the case and documents. This practical guide shows how law firms can integrate a digital conflict check into their client intake process, both organizationally and technically. It does not replace an examination of the specific individual case, but it does provide a solid foundation for your firm’s own intake process.

Why the Conflict Check Belongs at the Beginning

Checking for conflicting interests is not an administrative oversight that can be corrected after the file has been created. Section 43a(4) of the Federal Lawyers’ Act (BRAO) prohibits the practice of law if another client has already been advised or represented in the same legal matter with conflicting interests. The prohibition on practice may extend to other attorneys within the same law firm.

If a violation is only discovered during the course of the case, § 3(2) BORA requires a clear response: The client must be informed immediately, and all mandates in the same legal matter must be terminated. A conflict identified too late can thus quickly turn into a problem involving liability, compensation, and trust.

This is precisely why the conflict check is not a task that should begin only after the initial consultation or after the complete documents have been uploaded. It is the first professional step in accepting a client. The software can identify matches and highlight risks. However, the legal assessment of whether the same legal matter and conflicting interests actually exist remains a decision for the attorney.

What Professional Law Actually Prohibits

For a robust process, three questions must be addressed separately:

Is this the same legal matter? Similar areas of law or comparable cases are not automatically sufficient. The specific facts of the case are decisive. Identical names may trigger a match, but do not necessarily constitute a prohibition on representation.

Are the interests actually in conflict? Even multiple parties on the same side may later develop different objectives. Particularly in cases involving multiple clients, corporate law disputes, inheritance matters, or family law situations, the assessment must therefore not stop at the obvious opposing party.

Who within the law firm is affected? The extension to the firm may result in not only the person previously involved but also other practicing attorneys being prohibited from taking action. The client’s consent is not a universal fix in this context. Under the strict conditions of § 43a(4) BRAO, it may extend to other members of the legal profession. Section 3(4) of the BORA then requires, among other things, separate handling of cases, the exclusion of mutual access to paper files and electronic data—including beA—and a ban on communication between the teams. These precautions must be documented.

This is particularly relevant in practice for small law firms: Those who cannot technically establish a reliable separation should not pretend that the conflict can be resolved with an additional folder or an informal agreement.

Why “Tell us everything” Is the Wrong First Step

Many online forms begin with a large free-text field: “Please describe your case in detail.” From a user-friendliness perspective, this seems generous. From the perspective of a controlled intake process, it is risky.

Even the very first inquiry may contain highly sensitive information: health data, union membership, details regarding sexual orientation, criminal allegations, data pertaining to children, or information about uninvolved third parties. Article 5 of the GDPR requires purpose limitation and data minimization. Article 9 provides enhanced protection for special categories of personal data. Depending on the circumstances, the legal basis may stem from pre-contractual measures, the assertion or defense of legal claims, or other grounds for authorization. However, this does not alter the fundamental principle: No more data should be collected than is necessary for the respective step in the process.

For the initial conflict check, the law firm generally does not yet need a complete medical history, a full chat log, or an 80-page contract file. It first needs identifying information about the parties involved and a brief overview of the facts. Separating these steps not only reduces data protection risks. The team can also review the information more quickly because the relevant core details do not get lost among attachments and emotionally resonant details that are unnecessary for the conflict check.

The Better Process: A Two-Step Digital Client Onboarding

Step 1: Collect Conflict Data

The first form should be as short as possible and as precise as necessary. Typical fields include:

  • Name and contact information of the person or organization making the inquiry
  • Names of the opposing party and other key parties involved
  • Affiliated companies, former names, or alternative spellings, if known
  • Roles of the parties involved, such as employer, spouse, co-heir, or contractual partner
  • General classification of the matter and the area of law
  • Note regarding imminent deadlines
  • Very brief description of the facts, with an explicit note not to submit any confidential details or documents yet

The information required depends on the area of law. An employment law firm will list different parties to a conflict than a corporate law boutique. It is crucial that the form does not automatically prioritize the complete client questionnaire.

After submission, the request is assigned a status such as “Conflict Check Pending.” Document uploads and detailed fact fields remain locked until approval. The system searches for potential matches in client files, previous inquiries, lists of parties involved, and, where applicable, archived records. A match does not automatically result in rejection but triggers a documented human review.

Stage 2: Substantive Intake After Approval

Only once the conflict check is complete is the detailed intake form opened. Now, deadlines, objectives, facts of the case, documents, special data categories, cost issues, and communication preferences can be queried in a structured manner.

This separation has another advantage: The status “conflict-free” does not yet mean “case accepted.” In between, there may be steps such as assessing professional suitability, capacity, compensation, legal aid or pro bono assistance, identity verification, and the formal confirmation of the retainer. A good system maps these stages separately, rather than treating every inquiry immediately as a retainer or case file.

What the Software Must Be Capable of for a Useful Conflict Check

A simple full-text search for exactly entered names is not sufficient. In practice, search results can be compromised by double-barreled names, typos, former company names, corporate structures, various roles, and individuals acting on behalf of multiple companies simultaneously.

A robust digital process should therefore support at least the following:

Structured party roles. Names must not simply be stored as free text in a note. The system must be able to distinguish between clients, opposing parties, corporate bodies, witnesses, affiliated companies, and other involved parties.

Similarity and variant alerts. Alternative spellings, former names, and known corporate relationships should appear as possible matches. The software may assist in this process but must not pretend that an algorithm can determine the legal identity of the case.

Firm-wide review. The review must cover the relevant data from the entire scope of professional practice, not just the personal calendar or email inbox of the attorney in charge.

Access permissions and restrictions. While a request is being reviewed, only the individuals necessary for that task should have access. In the case of separate teams, access restrictions must be technically enforceable and documentable.

Traceable Decisions. Who searched, when, which results were reviewed, and why was a request approved or rejected? Brief, factual documentation provides better protection than a green checkmark without context.

Defined Rejection and Deletion Process. Rejected requests must not remain in the general inbox indefinitely. There must be clear responsibilities, deadlines, and rules for deletion or restricted retention.

Five Common Mistakes in Everyday Law Firm Operations

1. The document upload is immediately accessible

This causes the law firm to collect sensitive content before it even knows whether it is permitted to look into the matter at all. It is better to have a technically restricted upload until after the conflict check has been completed.

2. Only the obvious opposing party is identified

In the case of corporations, families, communities of heirs, or multiple opposing parties, the conflict may involve a person who does not even appear in the first sentence of the inquiry. The form must specifically ask for the parties involved and their roles.

3. Previous inquiries are ignored

Even rejected or abandoned contacts may be relevant for review and confidentiality purposes. This does not mean that every inquiry can be stored indefinitely. It means that deletion and conflict-checking strategies must be considered together.

4. A match is automatically treated as a conflict

This results in unnecessary rejections. The same name does not automatically mean the same person, and the same person does not automatically mean the same legal matter. Automation should presort, not make decisions.

5. “Chinese Walls” exist only on paper

Section 3(4) of the BORA requires genuine organizational and technical separation. If Team A still sees Team B’s file in a global search, that is not an access restriction—it is merely a charade involving user roles.

What Should Happen to Rejected Inquiries

The GDPR does not specify a blanket retention period for every rejected client inquiry. The law firm must determine its specific purpose and assess how long the data remains necessary for that purpose. Possible purposes include, for example, documenting a conflict-of-interest decision, defending against future claims, or complying with legal obligations. As soon as the purpose no longer applies, retention limits and deletion obligations take effect.

In practice, this requires a written deletion policy with different categories: a simple contact request without specific details, a rejected request following a conflict-of-interest review, a detailed initial consultation, and a retained client. Retaining complete sets of documents for years as a precaution because they “might be useful again” is not a valid purpose.

Data subjects must also be transparently informed, in accordance with Article 13 of the GDPR, about who processes their data, for what purposes and on what legal grounds, how long it will be stored, and what rights they have. This information should be clearly visible at the beginning of the digital intake process, not hidden in a hard-to-find link in the footer.

A Concise Checklist for Your Law Firm

  1. Is the conflict check represented as a separate status prior to the substantive review of the case?
  2. Is only the data necessary for the conflict check collected initially?
  3. Are document uploads and detailed free-text fields locked until approval is granted?
  4. Does the system capture all relevant parties, roles, name variations, and affiliated organizations?
  5. Is the review conducted firm-wide rather than only within an individual’s caseload?
  6. Are matches evaluated by a qualified person and documented in a traceable manner?
  7. Can access restrictions actually be enforced technically?
  8. Is there a tiered process for rejection, retention, and deletion?

If you answer “no” to several of these questions, you don’t necessarily need new law firm software right away. The first step is to define a clear target process. Only then can you assess whether the existing systems reliably support it or are merely held together with manual workarounds.

Conclusion: The Intake Doesn’t Start with the File

Digital client intake is effective when it not only provides the law firm with more data but also enables better decisions. The conflict check should therefore take place before the detailed description of the facts, before document uploads, and certainly before the file is created.

Digital law firm platforms such as Jurono can help guide inquiries through separate process stages, record parties in a structured manner, and document decisions in a traceable way. However, they do not replace a lawyer’s assessment of a conflict of interest or a law firm-specific authorization and deletion policy.

The most useful test is surprisingly simple: Open your own contact form today and pretend you’re already representing the opposing party. Can the prospective client still immediately upload all confidential information and documents? If so, your intake process is convenient but not yet controlled.

The conflict check is part of the larger intake workflow. The owner page digital client intake therefore explicitly separates structured preparation from law firm decisions.

JE

Jurono Editorial Team

August 04, 2026

Turn magazine insight into a concrete starting point

Evaluate Jurono the privacy-compliant way

See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.