Hiring External ReFa: How Law Firms Regulate Access, Confidentiality, and Handover
External ReFa professionals can provide flexible support to law firms. This checklist shows how to properly manage the engagement, access, confidentiality, and handover.
Check which Jurono starting point fits your firm.
See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.
External legal assistants can effectively relieve a law firm’s workload during peak periods, when covering for staff, or for recurring back-office tasks. The crucial step, however, is not simply billing hours, but establishing a limited, verifiable scope of work: Which tasks are delegated, what client information is required for them, who is authorized to access what, and when does that access end?
A confidentiality clause alone does not resolve these issues. Nor is it sufficient to simply give the external staff member “temporary” access to an existing team login. Law firms need a model for the engagement, professional conduct rules, data protection, employment status, and technical permissions in place before the first actual case begins.
The following practical guide consolidates these decisions into a 6Z model: Objective, Responsibility, Access, Collaboration, Assignment, and Return.
When External Legal Assistants Make Sense—and When They Don’t
External support is particularly well-suited to tasks whose scope and expected outcome can be clearly defined. These may include, for example, document preparation, structured master data entry, filing according to a defined convention, preparation of cost documents, scheduling, or processing standardized responses. However, which activities are permissible and can be meaningfully delegated depends on their actual nature.
It becomes difficult when “support in day-to-day business” effectively means that an external person, without a clear mandate, takes on everything that gets left undone internally. In such cases, there is a lack of priorities, approval thresholds, and clear accountability. The law firm isn’t buying relief; rather, it’s outsourcing its unresolved processes.
The first decision, therefore, is: Is a defined service module being outsourced, or is a vacant internal role to be permanently filled by an external party? In the second case, in addition to professional law and data protection, particular care should be taken to verify whether the actual collaboration still aligns with the requirements of self-employment.
The 6Z Model for Outsourcing
1. Goal: Which bottleneck needs to be eliminated?
“We need help” is not a scope of services. A useful objective describes the initial state and a verifiable outcome:
- New documents are assigned to the correct client within an agreed-upon timeframe.
- Incoming documents are prepared according to a defined naming convention.
- For a defined case group, a completeness check is performed using a professionally approved checklist.
- Backlogs in a limited portfolio are processed by a specified deadline.
The more precise the objective, the easier it is to restrict data access and permissions. Someone tasked with sorting documents for only ten specified clients does not need access to the firm’s entire portfolio.
2. Authority: What Decisions Can Be Made?
The list of tasks should not only enumerate activities but also define decision-making limits. Who answers technical inquiries? Who approves correspondence? May the external legal services provider contact clients directly? Which cases must be immediately escalated to an attorney?
The Legal Services Act defines a legal service as an activity involving specific matters of third parties as soon as it requires a legal review of the individual case. The independent provision of out-of-court legal services is permitted only to the extent that statutory authorization exists. This does not result in a blanket list of prohibited ReFa tasks. However, there is a clear organizational obligation: The law firm must not allow administrative support to slip unnoticed into an independent legal review or consultation.
In practice, a three-step task framework is helpful:
| Step | Example | Rule |
|---|---|---|
| Execution | Transferring data, naming documents, filling out an approved template | according to a documented standard |
| Preparation | Verifying completeness, flagging discrepancies, preparing a draft | no independent professional approval |
| Decide | Assess legal issues, advise the client, approve deadline strategy or content of briefs | by the responsible attorney |
The exact boundary depends on the task and the individual case. In case of uncertainty, the law firm should review the activity in advance in light of professional and legal services regulations.
3. Access: What Information Is Truly Necessary?
Section 43e(1) of the Federal Lawyers’ Act (BRAO) permits a service provider access to confidential information only to the extent necessary for the provision of the service. Paragraph 2 requires careful selection. According to paragraph 3, the contract must be in writing and must, among other things, stipulate the confidentiality obligation, the limitation of access to the necessary information, and the possible involvement of additional persons.
Section 43e(5) of the BRAO is particularly important: If the service directly serves a single client matter, access to third-party confidential information may only be granted with the client’s consent. Whether a specific external ReFa activity falls under this provision cannot be determined based on the professional title alone. The decisive factors are the scope of the engagement and the actual connection to the client’s matter. Law firms should explicitly review this point rather than relying on a general confidentiality clause.
Technically, “necessity” means: individual accounts instead of shared logins, access only to necessary client files or work areas, multi-factor authentication where available, time limits, and traceable logging. Export, deletion, or administrative rights should only be granted if they are part of the assignment.
An additional clear restriction applies to beA: A lawyer’s personal access credentials may not be shared. The BRAK refers to a decision by the Federal Court of Justice (BGH) dated June 20, 2023, according to which the transfer of the beA card and PIN to a legal assistant (ReFa) is prohibited. External use does not alter this. Required employee access rights must be organized through the designated, individual authorization channels; the specific configuration must be reviewed separately.
4. Collaboration: Separate Service Agreements, Data Protection, and Employment Status
Three aspects are often conflated in practice:
Under professional law, the focus is on selection, confidentiality, necessary access to confidential information, other persons involved, and, where applicable, the client’s consent pursuant to § 43e BRAO.
Under data protection law, it must be clarified in what capacity the external individual or their company processes personal data. If data processing is carried out on behalf of the controller, the required contract is governed by Art. 28 of the GDPR. Regardless of the question of role, Article 32 requires a level of protection appropriate to the risk. A data processing agreement does not replace the agreements under professional law; conversely, a confidentiality clause does not replace a role assessment under data protection law.
Under social security law, it does not matter whether the contract is titled “freelance work.” Section 7(1) of Book IV of the Social Code (SGB IV) lists being subject to instructions and integration into the work organization as indicators of employment. The German Pension Insurance emphasizes that similar professions can be classified differently depending on how the work is actually performed.
Warning signs that may warrant a more in-depth status assessment include a permanently fixed schedule, extensive individual instructions, full integration as a team member, the absence of independent entrepreneurial risk, or long-term work performed almost exclusively for a law firm. No single characteristic is automatically decisive. The decisive factor is the overall assessment of the specific legal relationship.
In case of doubt, the client and the contractor may apply for a status determination procedure with the German Pension Insurance Clearing House. According to current DRV information, a preliminary decision is also possible under certain conditions even before work begins. This is not a standard requirement for every engagement, but it is a possible avenue for clarification.
5. Classification: How Can External Work Be Verified?
Remote collaboration rarely fails because of video calls. It fails because of assignments that are distributed via chat, email, and verbal instructions. Each task should therefore include at least five pieces of information:
- the relevant case or clearly defined set of documents,
- the expected result,
- the person responsible for the subject matter,
- a deadline or priority,
- the required review and approval step.
This ensures a verifiable handoff. “Please prepare the file,” for example, becomes: “Assign documents from Inbox A to Client B, name them according to Scheme C, mark missing documents from List D; no client communication; complete by Tuesday at 12 p.m.; approval by Person E.”
The handoff must also be structured. A simple “done” does not indicate what was changed, omitted, or escalated. Useful status values include prepared, clarification needed, legal review required, and approved. Ultimate professional responsibility remains with the responsible licensed professional.
The article Client Portal or Email? explains why sensitive collaboration is not just a matter of channel, but also of context. This applies particularly to external legal professionals: documents must not be transmitted securely from a technical standpoint only to then be organizationally assigned to the wrong client matter.
6. Return: Access Must Come to an End
Offboarding comes before onboarding. The contract and the technical implementation should clarify:
- When does access automatically end?
- Who locks accounts and revokes permissions?
- Which local copies, exports, or notes may remain?
- How are work deliverables fully transferred to the law firm?
- How is the return or deletion confirmed?
- What happens to outstanding tasks and follow-up questions?
A common mistake is “temporary” accounts that are still active months later. An end date specified in the engagement letter, a designated person responsible, and a brief final review are more effective than hoping someone will remember to deactivate the account.
The Practical Checklist Before the First Engagement
Before an external legal assistant sees actual client information, the law firm should be able to check off six items:
Scope of Services: Tasks, exclusions, escalation procedures, and approvals are described.
Professional Law: The selection and contract meet the specific requirements of § 43e BRAO; any potential need for consent regarding services directly related to the client matter has been reviewed.
Data Protection: Roles, contractual requirements, data types, storage locations, subcontractors, and security measures are documented. A general tool review is explained in the article GDPR in the Law Firm: Practical Checkpoints for New Tools.
Employment Status: The contract and the planned implementation are consistent; doubts regarding the distinction between self-employment and employment were not merely glossed over with wording.
Access Model: There is a personal account with minimal permissions, a fixed expiration date, and clear logging. Personal beA access credentials are not shared.
Pilot: Collaboration begins with a limited scope and is evaluated after two to four weeks based on inquiries, errors, turnaround time, and rework.
Software Questions That Must Be Answered Before Contracting
Not all law firm software supports external collaboration equally well. Before signing a contract, law firms should verify whether permissions can be limited on a case-by-case basis, whether changes remain traceable, and whether an account can be deactivated without data loss. Equally important are export options, meeting management, multi-factor authentication, and separate roles.
Those who are already comparing systems for this purpose will find a more comprehensive decision matrix in the Law Firm Software Comparison for Everyday Use. What matters is not the number of roles listed in the marketing text, but whether the specific external workflow can be mapped out and tested.
The Jurono Perspective: Structure Over Additional Staff
Jurono views structured client onboarding and subsequent case management as a cohesive workflow. The same principle is central to external collaboration: An additional person can only effectively lighten the workload if information, tasks, and responsibilities are not scattered across email inboxes and individual agreements.
The access and collaboration options available and suitable for a specific Jurono implementation should be evaluated based on the current scope of features. Jurono does not replace contract drafting or case-by-case reviews under professional, data protection, or social security law. However, a demo can help compare the planned workflow—from intake to controlled task handoff—with your firm’s current processes.
Conclusion: Outsourcing Starts with Limited Access
A free ReFa account is not simply an additional mailbox with an hourly quota. Collaboration becomes sustainable when objectives, responsibilities, access, cooperation, assignment, and handover are clarified before the first actual task is undertaken.
The best way to start is not with full access, but with a pilot: a defined task module, a few designated cases, role-based permissions, fixed approvals, and a documented offboarding process. This allows you to verify whether the workload is actually reduced—without relinquishing control, client confidentiality, or responsibilities.
This article is intended to provide general organizational and legal guidance and does not constitute individual legal advice. The specific terms of engagement and technical implementation must be reviewed on a case-by-case basis.
Sources
- Federal Ministry of Justice / Federal Office of Justice – “§ 43e BRAO – Use of Services,” current version of the law, https://www.gesetze-im-internet.de/brao/__43e.html,, accessed: August 11, 2026. Supporting information: Requirements for selection, contract, necessary access to confidential information, other persons, foreign countries, and services directly related to the mandate.
- Federal Ministry of Justice / Federal Office of Justice – “§ 203 StGB – Breach of Private Confidentiality,” current version of the law, https://www.gesetze-im-internet.de/stgb/__203.html,, accessed August 11, 2026. Supporting statement: Involvement of other participating individuals and criminal consequences of unauthorized disclosure or failure to comply with obligations.
- Federal Ministry of Justice / Federal Office of Justice – “Sections 2 and 3 of the Legal Services Act (RDG),” current version of the law, https://www.gesetze-im-internet.de/rdg/__2.html and https://www.gesetze-im-internet.de/rdg/__3.html,, accessed August 11, 2026. Supporting statement: Definition and general requirement for authorization of independent out-of-court legal services.
- Federal Ministry of Justice / Federal Office of Justice – “Section 7 SGB IV – Employment,” current version of the law, https://www.gesetze-im-internet.de/sgb_4/__7.html,, accessed August 11, 2026. Supporting statement: Subordination to instructions and integration as legal criteria for employment.
- German Federal Pension Insurance – “Frequently Asked Questions About the Status Determination Procedure,” no publication date specified, https://www.deutsche-rentenversicherung.de/DRV/DE/Rente/Arbeitnehmer-und-Selbststaendige/03_Selbststaendige/beliebte-fragen-statusfestellungsverfahren.html,, accessed August 11, 2026. Supporting statement: Case-by-case review, eligibility to apply, and possible preliminary decision prior to the start of employment.
- European Union, EUR-Lex – “Regulation (EU) 2016/679,” April 27, 2016, in particular Articles 28 and 32, https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:02016R0679-20160504,, accessed August 11, 2026. Supporting statement: Requirements for data processing on behalf of a controller and security measures appropriate to the risk.
- German Federal Bar Association – “Attorneys May Not Disclose Their beA Access Credentials to Legal Assistants,” October 2, 2023, https://www.brak.de/newsroom/news/anwaelte-duerfen-ihre-bea-zugangsdaten-nicht-an-refa-weitergeben/,, accessed August 11, 2026. Supporting statement: Analysis of the Federal Court of Justice (BGH) decision of June 20, 2023, Case No. 2 StR 39/23, regarding the impermissible disclosure of personal beA access credentials.
Jurono Editorial Team
August 11, 2026
Keep reading
Digitalise your firm?
See how Jurono structures your client intake.
Declining Client Inquiries: Five Workflow Mistakes Law Firms Should Avoid
Rejected Client Inquiry: What Law Firms Delete—and What They Are Allowed to Keep for Conflict Checks
Client Portal or Email? Which Channel Is Best for Which Type of Law Firm Communication?
Turn magazine insight into a concrete starting point
Evaluate Jurono the privacy-compliant way
See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.