In brief: The National Bar Council (CNB) updated its recommendation on the digitization of client files in 2026. Article 66-5 of the 1971 law remains the foundation, but seven practical obligations have been added — and several are checked during the Bar audit. Here is what they are, and how a vault installed on your own premises meets them without locking your firm into a foreign vendor.
You are expecting your Bar audit in six months. You know you will have to explain how you protect professional privilege on the documents your clients send you — via email, WhatsApp, or the shared Drive you finally opened last year. The idea makes you uncomfortable. You are right: the auditor’s assessment grid is not the same as it was in 2019.
Since the last update of the CNB recommendation on digitization, auditors have a clear list of points to verify. Most stem directly from Article 66-5 of the law of December 31, 1971, which defines professional privilege as absolute, general, and unlimited in time. The rest comes from the GDPR, the RIN (Internal Regulations), and the case law accumulated on data leaks since 2020. An overview.

What Article 66-5 says exactly
Article 66-5 protects “all correspondence exchanged between the client and their lawyer, between the lawyer and their peers,” with the exception of those marked “official.” The text extends this protection “to meeting notes and, more generally, to all documents in the file.” The word “document” is intentionally broad: it covers the PDF your client sent you, the scan you made at the office, the note you took after the meeting, and the Excel timeline you built to prepare your submissions.
The consequence is clear: as soon as one of these items leaves your controlled perimeter — your Gmail inbox, a Drive shared with your intern, a WeTransfer transfer — the secret is no longer formally protected. The Court of Cassation has reiterated this several times: digital materialization does not erase the obligation, it shifts it to the person choosing the tool.
The 7 practical obligations the auditor looks for
1. Access traceability
The auditor wants to be able to reconstruct who, within the firm, accessed a given file, on what date, and from which workstation. A shared Drive that only logs when a file is opened is not enough. You need an audit log for which you can prove integrity — meaning no one can modify it after the fact, not even you.
2. Separation by folder
Compartmentalization is explicitly required. Documents in a file must not be accessible to a staff member not working on that file. On a Drive structured by folder, everyone sees everything by default. In a vault that applies the principle of least privilege, access is explicit, folder by folder.
3. Enforceable timestamping of receipt
When a client uploads a document, you must be able to prove on what date it was received — not sent. The timestamp of an email in Gmail can be contested; it depends on the mail server. A document uploaded to a vault that you own and that records the date of receipt in its immutable log has much higher evidentiary value.
4. Encrypted storage at rest
It is not just about encryption in transit (TLS) — it is about encryption while the file sits on the disk. Most consumer-grade Drives do not provide client-side encryption. A professional vault must encrypt at least at the folder level, ideally using a key that remains under your control.
5. Proof of purging at the end of the file
The GDPR mandates a limited retention period. Upon closing a file, you must be able to prove that the documents have been purged — or archived in a form that respects the original purpose. A Drive that stores everything indefinitely is not compliant.
6. Resistance to foreign data requests
If your documents reside with an American provider — TaxDome, HoneyBook, SuiteDash, Notion — they are accessible via requests under the CLOUD Act, without you being informed. French professional secrecy does not prevent an American requisition. For law firms or cases involving sensitive matters, this is unacceptable.
7. True data portability
The GDPR grants the client a right to portability. Upon request, a lawyer must be able to return a client’s file documents in a readable format. Many SaaS platforms make this process so slow or degraded that it is discouraged. A vault installed on your own server can export a ZIP file in seconds.

Why a self-hosted vault ticks all seven boxes at once
The logic is simple. When the vault runs on your WordPress, hosted with OVH, Scaleway, or Infomaniak, you have control over the code, the server, and the jurisdiction. Traceability, separation, timestamping, and encryption become parameters you control. Resistance to foreign requisition is mechanical: no third-party provider has access.
This is exactly the promise of Client Vault Pro: a WordPress plugin that you install, that you remain the owner of, which covers the seven audit requirements without you having to deal with a foreign SaaS provider. You remain in control, and your clients stay protected.
What you can do starting this month
You do not need to wait for the audit to move forward. Three actions, in this order. One: perform an honest inventory. List where the documents from your last ten cases currently live. You will likely be surprised. Two: identify your most exposed pain point — it is usually the document received via WhatsApp or unencrypted email. Three: choose a sovereign channel for the next case you open. Not all of them, just the next one. You will see the difference in traceability from the very first week.
On the day of the audit, you want to be able to answer the seven questions without hesitation. The best way to prepare for it is not to wait until the day before.



