Rejected Client Inquiry: What Law Firms Delete—and What They Are Allowed to Keep for Conflict Checks
Rejected Client Inquiry: Learn what data law firms delete, when § 50 BRAO applies, and how a streamlined retention policy enables conflict checks.
Check which Jurono starting point fits your firm.
See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.
A rejected client inquiry does not automatically belong in the client file for six years, nor should it be immediately and completely discarded. The decisive factors are what purpose still exists after the rejection, what data is necessary for that purpose, and whether a legal engagement was ever established in the first place.
For law firms, this means: The complete inquiry, a small conflict-check data set, and technical logs must not be treated as a single data block. A robust process separates these levels, documents the respective legal basis, and sets a verifiable deletion date.
This article debunks five common myths and translates them into a practical three-level model for intake, rejection, and deletion.
Myth 1: Every client inquiry becomes a six-year case file
Section 50 of the Federal Lawyers’ Act (BRAO) requires attorneys to maintain case files regarding the handling of their engagements and, as a general rule, to retain them for six years. The retention period begins at the end of the calendar year in which the engagement was concluded. This rule also applies to electronically maintained case files.
In the case of a mere inquiry, it must therefore first be clarified whether a retainer has been established. A clear rejection following a review of jurisdiction or conflicts of interest is not the same as a retainer for legal advice that has already been accepted. Conversely, a case does not become a non-binding inquiry simply because the law firm labels it as such in the system: If legal issues have already been reviewed, recommendations for action have been provided, or an initial consultation subject to a fee has been conducted, the legal classification may differ.
The practical implication is not “delete after six years or immediately,” but rather: First, determine the type of case.
- Initial contact without a retainer
- Preliminary review with open retainer status
- Rejected retainer after limited review
- Mandate accepted and later terminated
Only if these statuses can be clearly distinguished can § 50 BRAO be applied appropriately. In case of doubt, the law firm should legally review the timing and scope of accepting a mandate and communicate this clearly.
Myth 2: After a rejection, the entire inquiry must be deleted immediately
The GDPR requires storage limitations: Personal data may only be stored in an identifiable form for as long as necessary for the respective purposes. Article 17 of the GDPR provides for erasure, among other things, when data is no longer necessary for the original purpose. At the same time, the provision includes exceptions, such as for legal obligations or where data is necessary for the establishment, exercise, or defense of legal claims.
A rejection often brings an end to the purpose of “reviewing and initiating a retainer agreement.” However, this does not necessarily mean that every piece of information must be deleted from every system at that very moment. There may still be limited purposes: sending and providing proof of the rejection, returning submitted originals, handling a follow-up inquiry, defending against specific foreseeable claims, or conducting a later conflict check.
These purposes do not constitute a free pass for data retention. For each purpose, the law firm must answer:
- What specific information is still needed?
- What is the legal basis for further processing?
- Who is authorized to access it?
- What event triggers review, restriction, or deletion?
A blanket justification such as “might be useful later” does not satisfy this model. Equally problematic is a CRM status of “rejected” if the message, attachments, and health data remain fully searchable indefinitely.
Myth 3: The law firm needs the entire file for future conflict checks
Section 43a(4) of the German Federal Lawyers’ Act (BRAO) prohibits representation in the same legal matter where there is a conflict of interest. The Munich Bar Association points out that the required conflict-of-interest review may justify continued storage. However, this does not imply a blanket retention period nor the necessity to permanently retain every document sent.
For a later conflict check, a core record is generally more helpful than a complete case file. Depending on the law firm’s structure and area of law, it may include:
- Names or unique identifiers of the parties involved,
- Roles in the reviewed case,
- A concise description of the legal matter that is not unnecessarily detailed,
- Date and result of the conflict-of-interest review,
- The person responsible for conducting the review.
The law firm must justify whether and for how long such a data record is required. Particularly sensitive information under Article 9 of the GDPR, detailed case facts, copies of identification documents, or complete attachments do not belong in the core record simply because they were once received.
This ties in with the article Check Opponents First, Then Open the File: A good conflict check begins with the necessary information on the parties involved, not with a digital file that is as complete as possible.
Myth 4: Deletion Means Clicking “Rejected” in the Intake System
A status change is, at first, merely a technical decision. Technically, the same data may still reside in the intake system, in email inboxes, in downloads, in team chats, in law firm software, in local work folders, in backups, and in logs.
Therefore, the deletion process should reflect the data flow. The article Contact Form or Digital Intake? explains why an inquiry doesn’t end with the form. The same applies to deletion: it must be planned along the entire data transfer path.
A system map with five questions is useful:
| Stage | Check Question |
|---|---|
| Intake | Are free-text entries and uploads removed after rejection, or are they merely hidden? |
| Are additional copies created through notifications or forwards? | |
| Law Firm Software | Is every inquiry automatically converted into a file or a contact? |
| Exports | Where are downloaded documents and spreadsheets stored? |
| Backups/Logs | When are data excluded from backups, and how are they protected from regular use until then? |
Backups do not need to be individually searchable or overwritten immediately, unlike production data. However, the backup strategy should address restoration, access protection, and regular overwriting in such a way that deleted requests do not re-enter daily operations unchecked. The specific technical implementation depends on the system and should be addressed during tool testing.
Myth 5: A single retention period is sufficient for all rejected requests
The GDPR does not specify a universal number of months or years for rejected client requests. Rather, Article 13 requires transparent information about the retention period or, if this cannot be specified, about the criteria used to determine it. The retention limit under Article 5 requires an assessment based on the purpose of the processing.
A law firm should therefore not simply adopt a standard figure without reviewing its own processes. A case involving a simple request for a callback, an inquiry rejected due to a conflict of interest, an urgent matter whose content has already been reviewed, and an initial consultation that has been billed all have different timelines, risks, and legal bases.
Event-based deletion rules are preferable:
- Once the rejection has been sent and there are no further pending organizational actions, the operational intake purpose ends.
- Once documents have been returned or follow-up inquiries have been resolved, the entire case file may be ready for deletion.
- If a justified retention core remains for conflict reviews, it is managed separately and regularly reviewed for necessity.
- If a specific legal dispute or claim is foreseeable, the documentation required for it is assessed separately, access is restricted, and it is not routinely reused.
- If a retainer agreement was in place, the relevant professional and other retention obligations apply.
The Munich Bar Association recommends technical precautions, a deletion policy, and a retention schedule. It is important to follow up on these matters: An entry without a review date is often nothing more than indefinite storage with a more pleasant-sounding name.
The Three-Level Model for Rejected Inquiries
For small and medium-sized law firms, the decision can be broken down into three separate data levels.
Level 1: The Case File
It contains the original message, questionnaire responses, attachments, internal notes, and the rejection notice. Once the initial client engagement process is complete, a review is conducted to determine whether and to what extent there is still a purpose for retaining the information. Content that is no longer required is deleted; content to be retained is documented with the legal basis, access permissions, and review date.
Level 2: The Restricted Core
It contains only the information necessary for a justified subsequent conflict review. The retention core must not become a shadow archive of fully rejected mandates. Access, search logic, and review frequency should be more strictly defined than for normal contact data.
Level 3: System Traces
These include delivery receipts, audit logs, security logs, and backup states. They serve their own technical or security-related purposes. The law firm documents what content is actually included, who has access, how long the trace is needed, and what happens in the event of a restore.
This separation prevents two common mistakes: the premature destruction of required evidence and the indefinite storage of a complete request solely for the sake of a potential future conflict check.
A Practical Seven-Step Workflow
1. Limit Incoming Data. Before conducting a conflict check, collect only the client information necessary for that purpose. Request detailed case details and uploads at a later stage. The article Digital Client Onboarding: Fewer Follow-Up Inquiries explains this in more detail.
2. Set a clear status. “New,” “Under Review,” “Case Accepted,” “Rejected,” and “Pending Clarification” must trigger different actions in the system.
3. Document rejections. Record when and how the rejection was sent. The documentation should remain concise and contain no unnecessary professional assessment.
4. Classify data. Evaluate the complete case file, any restricted data, and system logs separately.
5. Define the legal basis and trigger. For each remaining category, document the purpose, legal basis, access, retention period, and deletion event.
6. Perform system-wide deletion. Include intake, email, files, exports, and connected services. A general verification logic is provided in GDPR in the Law Firm: Practical Checkpoints for New Tools.
7. Perform a spot check. Regularly trace a few rejected cases from intake through the backup process. This reveals whether the documented process actually works.
Jurono Context: The Lifecycle Begins Before the File Is Created
Jurono considers the structured client onboarding process to be part of the subsequent workflow. This continuity is relevant for deletion rules: Even at the data collection stage, it should be clear which data is required prior to a conflict check, which status triggers further processing, and how rejected requests are handled.
Which deletion, authorization, and logging functions are available in a specific Jurono implementation and suitable for your own purposes should be assessed based on the current scope of functionality. Jurono does not replace the legal definition of retention periods or the review of individual cases. However, a demo can be used to simulate the planned request lifecycle—from receipt to rejection—based on real-world law firm scenarios.
Conclusion: Terminate the Purpose, Not the Request
After a client has been turned down, neither blanket retention nor blanket immediate deletion is a convincing approach. The law firm must clarify whether a retainer existed and which limited purposes continue to apply after the rejection.
The three-tier model provides a practical framework for this: complete case data, a minimal retention core, and technical system logs are evaluated separately. Assigning a purpose, a legal basis, access rights, and a deletion event to each data record simultaneously reduces data protection risks, shadow archives, and uncertainty during the next compliance review.
This article is intended to provide general organizational and legal guidance and does not constitute individual legal advice. Whether a contract was concluded and what retention is permissible or required in each individual case must be examined on a case-by-case basis.
Sources
- European Union, EUR-Lex – “Regulation (EU) 2016/679 (General Data Protection Regulation)”, April 27, 2016, in particular Articles 5, 6, 9, 13, 17, 18, and 25, https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:02016R0679-20160504, Accessed: August 12, 2026. Key provisions: Purpose limitation, data minimization, storage limitation, legal bases, special categories of data, transparency, erasure, restriction, and data protection through design.
- Federal Ministry of Justice / Federal Office of Justice – “§ 43a BRAO – Fundamental Obligations,” current version of the law, https://www.gesetze-im-internet.de/brao/__43a.html,, accessed August 12, 2026. Supporting statement: Confidentiality and prohibition on activities in cases of conflicting interests.
- Federal Ministry of Justice / Federal Office of Justice – “§ 50 BRAO – Case Files,” current version of the law, https://www.gesetze-im-internet.de/brao/__50.html,, accessed: August 12, 2026. Supporting statement: Maintenance and six-year retention of case files regarding the handling of cases; corresponding application to electronic file management.
- Munich Bar Association – “Data Protection in Law Firms,” no publication date indicated, https://www.rak-muenchen.de/rechtsanwaelte/mitgliederservice/datenschutz-in-anwaltskanzleien/,, accessed August 12, 2026. Supported statement: Storage limits, possible retention purpose for conflict-of-interest reviews, and recommendations for technical deletion measures, a deletion policy, and a retention schedule.
- Hessian Commissioner for Data Protection and Freedom of Information – “Rights of Data Subjects vis-à-vis Attorneys,” as of March 31, 2023, https://datenschutz.hessen.de/datenschutz/polizei-und-justiz/rechte-betroffener-personen-gegenueber-rechtsanwaeltinnen-und-anwaelten, Retrieved: August 12, 2026. Supporting statement: Relationship between Art. 17 of the GDPR and § 50 of the BRAO in existing client-attorney relationships, as well as special considerations for individuals without such a relationship.
Jurono Editorial Team
August 12, 2026
Keep reading
Digitalise your firm?
See how Jurono structures your client intake.
Declining Client Inquiries: Five Workflow Mistakes Law Firms Should Avoid
Hiring External ReFa: How Law Firms Regulate Access, Confidentiality, and Handover
Client Portal or Email? Which Channel Is Best for Which Type of Law Firm Communication?
Turn magazine insight into a concrete starting point
Evaluate Jurono the privacy-compliant way
See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.