In short: clients are increasingly asking questions about the security of their data. Five questions come up for every sensitive case. Here are the reasoned responses, the legal references to cite, and a ready-to-send email template to turn these inquiries into proof of professionalism.
Before 2020, a client asking you “where is my data?” was an exception. Today, it is almost the norm in high-stakes cases—divorce with assets, M&A due diligence, criminal complaints, extensive medical records, international taxation. The question is no longer a sign of mistrust. It is a sign of client maturity. Answering well is becoming a competitive advantage.
I have listed the five questions that my Client Vault users receive most often. For each, you will find a reasoned response, the specific legal reference to mention, and a practical box. At the end, there is an email template you can reuse as is.

Question 1: “Where is my data stored?”
The honest answer consists of three elements. First, the physical location of the server—which host, in which country. Second, the jurisdiction of the software publisher—this determines exposure to the Cloud Act. Third, the duration and mechanism of data retention.
A sovereign firm can respond: “Your documents are stored on our infrastructure, hosted by [OVH/Scaleway/Infomaniak], in France. No third-party publisher has access to them. Retention is limited to the duration of the case plus the legal limitation period, after which the data is purged.” It is concise, precise, and defensible. Reference: GDPR Article 5.1.b (purpose limitation) and 5.1.e (storage limitation).
Question 2: “Who can read my documents?”
The client wants to know specifically who in your firm has access to their files. The answer must state the principle — access is limited to the staff assigned to the case — and specify the mechanism — every opening is tracked in an audit log that the client may request an excerpt from.
On a standard shared Drive, this response is difficult to uphold. In a professional vault configured per file, it becomes automatic. Reference: GDPR Article 32 (security of processing) and Article 5.1.f (integrity and confidentiality).
Question 3: “What if you get hacked?”
The client is not asking for a zero-intrusion guarantee — they know that does not exist. They want to know three things: How long it takes you to detect an intrusion. How you will notify them. How much data would be exposed if it were to happen.
The answer is threefold. One: your installation is monitored — either by your WordPress provider or via a monitoring service that you specify. Two: in the event of a breach likely to create a risk for the client, you will notify the CNIL within 72 hours and the affected client without delay. Three: encryption at rest limits the exposure of an intrusion to a subset of the file — not the entirety. Reference: GDPR Article 33 (CNIL notification) and Article 34 (notification to the data subject).
Question 4: “Can I retrieve all my data when the case is closed?”
This is the right to portability. The client can request it at any time, not just upon account closure. Your obligation: return the documents they provided in a structured, commonly used, and machine-readable format. Practically speaking: a ZIP file containing the original files and an index.
Many SaaS providers make this process so slow or degraded—using proprietary formats, screenshots, or losing metadata—that they are effectively in breach of regulations. A vault installed on your own infrastructure exports a clean ZIP file in seconds. Reference: GDPR Article 20 (right to portability).
Question 5: “Can my data be transferred abroad?”
This is the most sensitive question because it depends less on your intent and more on the architecture of your tools. If you use TaxDome, Notion, HoneyBook, Dropbox, or any other American SaaS, the honest answer is “yes, at any time, due to CLOUD Act requisitions, and without any way for me to prevent it.” If you use a sovereign installation hosted in France, the honest answer is “no, by design.”
This difference is not marketing; it is a verifiable legal fact. For a client facing strategic or criminal legal stakes, this is often the deciding factor in choosing you over a competitor who lacks that control. Reference: Schrems II ruling (July 16, 2020) and the US CLOUD Act (March 2018).
Email template to send to a client asking these questions
« Hello [Prénom],
You asked me about the security of your data. I thank you for this question — it is exactly the type of vigilance that I recommend to all my clients. Here are the factual elements upon which you can rely. Your documents are stored on my Client Vault installation, hosted at [OVH], in France. No third-party publisher has access to them. Internal consultation is limited to [Maître X] and myself, and every access is logged. In the event of an incident, you would be notified without delay and the CNIL within 72 hours. Upon closing the file, I will provide you with all documents in a usable ZIP file upon request. No foreign requisition can, by design, reach your data. If you wish for additional technical details, my door is open. Best regards, [Signature] »
This email takes two minutes to personalize. It transforms a potentially awkward question into a demonstration of your professionalism. And it reassures exactly the clients who pay you the most.



