Compliance and confidentiality
starts on your device.
CamoText masks content on your own machine, before anything reaches an external service. This page maps some specific obligations, by regulation and profession, to how our architecture mitigates them.
01.There Is No Second Party
Nearly every privacy obligation on this page is triggered by a disclosure of data moving from you to someone else. Cloud redaction tools, AI platforms, and transcription services all trigger it, then spend their own compliance pages explaining how they mitigate it: contractual terms, encryption in transit, retention windows, sub-processor lists which may periodically change.
CamoText never receives your data. Not encrypted, not transiently, not in logs. The masking happens inside a single local process, in memory, on hardware you already control. For the masked content, the obligations below aren't just mitigated; many are never engaged at all.
We don't process personal data on your behalf. No data processing agreement to negotiate, no sub-processor register to monitor, no vendor to add to your Article 30 record for this product.
Nothing crosses a border, because nothing leaves the device. International transfer rules aren't engaged by CamoText itself.
We hold no copy of your documents. A compromise of our systems cannot expose your client data, because your client data was never there.
02.GDPR: Pseudonymisation as a Named Article 32 Measure
The GDPR requires a lawful basis, a security posture proportionate to the risk, and control over onward disclosure for the use of AI on personal data.
Masking before the prompt helps address all three, and is the one measure the Regulation names in the text of the security article itself.
| Obligation | What It Requires | How CamoText Discharges It |
|---|---|---|
| Security of processingArt. 32(1)(a) | Measures appropriate to the risk, expressly including pseudonymisation and encryption. | Pseudonymisation is the product. Consistent tokens replace direct and indirect identifiers before any external system is involved. |
| Pseudonymisation, properly doneArt. 4(5) | The "additional information" that would allow re-identification must be kept separately and protected. | The mapping key is written only to a local path you choose, or discarded entirely. It's not bundled with the output and not transmitted (separation contemplated by Art. 4(5)). |
| Data minimisationArt. 5(1)(c) | Only data adequate and limited to what's necessary for the purpose. | Analytical purposes rarely require identity. The human-in-the-loop review process ensures identifiers avoid exposure to the AI service. |
| Processor obligationsArt. 28(3) | A written contract with anyone processing personal data on your behalf. | Not engaged. CamoText LLC is not a processor of your data: we have no access to it at any point. No DPA is required, and none is offered, because there's nothing to govern. |
| International transfersCh. V, Art. 44–49 | A valid transfer mechanism before personal data leaves the EEA. | Not engaged by CamoText. Where you subsequently use a US-hosted AI service, the material you transfer contains pseudonyms rather than identifiers, materially changing the transfer risk assessment. |
| DPIAArt. 35 | An assessment where processing is likely to result in high risk. | Masking is a mitigating measure to record under Art. 35(7)(d). Because the tool performs no transmission and retains nothing, its own risk profile is short to document. |
| Record of processingArt. 30 | Categories of recipients, transfers, and safeguards. | CamoText adds no recipient and no transfer to your register. |
| Breach notificationArts. 33–34 | Notification of breaches affecting personal data, with severity assessed by reference to the data exposed. | Where exposed material was masked and the key held separately, the severity assessment changes accordingly. We never receive your data. |
Pseudonymised, not anonymous. We describe CamoText's output as pseudonymised in GDPR context. Pseudonymised data remains personal data under Recital 26. Whether a given output is genuinely anonymous depends on the residual re-identification risk in that specific document; free text can identify a person without naming them. That judgment is yours, which is why every output is presented for human review before it goes anywhere. Anyone selling "GDPR-compliant anonymisation" as a guaranteed output state is overstating what any software can determine.
AI Act
Regulation (EU) 2024/1689 imposes obligations on deployers as well as providers, phasing in through 2027. Masking inputs doesn't itself satisfy any AI Act obligation, but it reduces the personal-data footprint of deployment and supports the AI-literacy and governance measures firms are being asked to evidence via a demonstrable, defensible process. The EDPB's Opinion 28/2024 on personal data in AI models is the useful companion reading for how supervisory authorities are framing model inputs.
03.UK GDPR, the ICO, and SRA Confidentiality
The UK GDPR and Data Protection Act 2018 track the EU analysis above. Two additions matter for UK firms.
| Obligation | What It Requires | How CamoText Discharges It |
|---|---|---|
| ConfidentialitySRA Code of Conduct, para. 6.3 | Client information kept confidential unless disclosure is required or permitted by law, or the client consents. | Uploading an unredacted matter file to a third-party AI service is a disclosure. Properly masking first can mean no identifiable information is disclosed, so material-specific consents may not be required. |
| Competence and supervisionSRA Principles; Code paras. 3.2–3.5 | Services delivered competently, with effective supervision of the work. | Human-in-the-loop review is mandatory in the workflow, as CamoText cannot automatically communicate output to an external service. Every detection is presented for confirmation, reversal, or extension before output. |
| ICO anonymisation guidance | A risk-based, documented assessment of re-identification, including the "motivated intruder" test. | CamoText produces the pseudonymised output and a reviewable record of what was replaced. The re-identification assessment remains a human judgment, supported by a visible list of every substitution made. |
| Legal professional privilege | Preservation of privilege, which can be compromised by disclosure to third parties. | No third party receives the material until the output is reviewed and confirmed as not containing identifiable privileged information. |
Buying from the UK? CamoText Pro is the right product for English-language practice. International adds recognition models for Spanish, French, German, and Italian document content: choose it only if your matters involve those languages, not because you're outside the US.
04.Model Rules 1.6 and 5.3, and Formal Opinion 512
ABA Formal Opinion 512 (July 2024) addressed generative AI directly: entering client information into a self-learning or third-party-hosted tool can constitute a disclosure requiring informed client consent, and lawyers must understand a tool's data-handling before use.
| Obligation | What It Requires | How CamoText Discharges It |
|---|---|---|
| Confidentiality of informationModel Rule 1.6(a), (c) | No revelation of information relating to the representation; reasonable efforts to prevent unauthorised access. | Identifiers are removed before the tool that would receive them is ever opened. The reasonable-efforts standard is met with a technical control rather than a vendor promise. |
| Technological competenceRule 1.1, cmt. 8 | Keeping abreast of the benefits and risks of relevant technology. | Every security claim we make is built to be easily verified: disable the network adapter and confirm the product still works. |
| Nonlawyer assistanceRule 5.3 | Reasonable assurance that outside vendors' conduct is compatible with your obligations. | There's no outside vendor handling the data during CamoText use; we have no access (even at installation and license imprint), so there is no relevant vendor conduct. |
| Informed consentFormal Op. 512; Rule 1.6(a) | Client consent where AI use involves disclosure of their information. | Where the material reaching the model is properly masked, the scope of what you must disclose and obtain consent for narrows substantially. |
State bar associations (including California, New York, Florida, Texas, and DC) have issued their own AI guidance, generally consistent with Op. 512. Check your own jurisdiction's most recent opinion.
05.HIPAA: Safe Harbor Identifiers, and Why We're Not a Business Associate
The de-identification standard at 45 CFR § 164.514(b)(2) lists eighteen identifier categories. Adequately mask and remove all eighteen, with no actual knowledge that the remainder could identify the individual, and the information is no longer protected health information.
| Obligation | What It Requires | How CamoText Discharges It |
|---|---|---|
| Safe Harbor de-identification45 CFR § 164.514(b)(2) | Removal of eighteen enumerated identifier categories. | CamoText detects pertinent data across the categories, including names, geographic subdivisions, contact details, account and record numbers, device identifiers, URLs, IP addresses, and biometric-adjacent references, and has an intuitive highlight-to-anonymize user feature for the subjective category details. |
| Re-identification key§ 164.514(c) | Any code permitting re-identification must not be derived from or related to the individual, and must not be disclosed. | Tokens are randomly generated. The key is stored locally at your election, or discarded. |
| Business associate§ 164.502(e); § 164.308(b) | A BAA with anyone creating, receiving, maintaining, or transmitting PHI on your behalf. | Not engaged. We don't create, receive, maintain, or transmit PHI. Licensed desktop software that never contacts the vendor doesn't make the vendor a business associate. No BAA is required from us. |
| Minimum necessary§ 164.502(b) | Limiting use and disclosure to the minimum necessary. | Masking is the operational form of this rule when the recipient is an analytical tool that has no need to know identity. |
| Psychotherapy notes§ 164.508(a)(2) | Authorisation for most uses and disclosures, with narrow exceptions. | Process notes can be worked with locally, and if AI assistance is used, only de-identified narrative leaves the machine. Try CamoVoice for a HIPAA-compliant transcription service. |
Read this before relying on Safe Harbor. Automated detection does not equal certified de-identification. Free-text clinical narrative can identify a patient without containing a single listed identifier, such as a rare diagnosis, a described incident, or an employer. Safe Harbor also requires the absence of actual knowledge of residual identifiability, a human determination no software can make for you. CamoText is built to make that review fast and complete, not to remove it. If you need a formal § 164.514(b)(1) expert determination, engage a qualified statistician.
06.§ 203 StGB, BRAO, and the DSK Position on AI
Germany is the jurisdiction where the case for local masking is strongest, because breach of professional secrecy can be a criminal offence.
| Obligation | What It Requires | How CamoText Discharges It |
|---|---|---|
| Criminal secrecy§ 203 StGB | Unauthorised disclosure of a secret entrusted to a lawyer, doctor, or psychotherapist is a criminal offence. § 203(3) permits involvement of assisting persons, subject to obligations and care in selection. | The cleanest position is not to rely on the assisting-person route at all. A vendor who never receives the secret is not an assisting person, and no disclosure occurs. |
| Professional duty§ 43a(2) BRAO | Verschwiegenheitspflicht extending to everything learned in the course of the mandate. | Removing identifying content before any external service is used; the mandate details stay on the Kanzlei's own hardware. |
| Supervisory guidanceDSK orientation on AI; BDSG | German authorities have emphasised input minimisation and caution about entering personal data into AI systems. | Input minimisation is precisely the function performed, with a bundled model trained on German-language names and organisations in CamoText International. |
| Works council§ 87(1) Nr. 6 BetrVG | Co-determination for technical systems suited to monitoring employee conduct or performance. | CamoText produces no telemetry, no usage logs, no central console, and no administrator visibility into employee activity. There's nothing for the system to monitor with, which materially shortens the Betriebsrat conversation. |
07.Secret Professionnel and CNIL Expectations
| Obligation | What It Requires | How CamoText Discharges It |
|---|---|---|
| Secret professionnelArt. 226-13 Code pénal; RIN Art. 2 | Absolute and unlimited professional secrecy for avocats, breach of which is criminally sanctioned. | Masking before transmission means no covered information is revealed to a third party. The obligation being général, absolu et illimité, removing the disclosure entirely is the only fully reliable posture. |
| CNIL AI guidanceLoi Informatique et Libertés; CNIL recommendations | Minimisation of personal data in AI development and use; documented security measures. | Local pseudonymisation is a documented, demonstrable measure that produces a reviewable substitution record. |
| Souveraineté des données | Practical concern about client data reaching non-EU providers. | Data never reaches us. There's no hosting location to assess because there's no hosting outside of your own hardware. |
08.Garante Enforcement and the Codice Deontologico
The Garante has been an active EU authority on generative AI specifically, including its 2023 temporary limitation on ChatGPT and subsequent enforcement action. Italian professionals are correspondingly cautious about what enters a prompt.
| Obligation | What It Requires | How CamoText Discharges It |
|---|---|---|
| Segreto professionaleArt. 13, Codice deontologico forense; Art. 622 c.p. | Strict duty of confidentiality and secrecy over client affairs. | Identifying content never leaves the studio's hardware. |
| Codice PrivacyD.Lgs. 196/2003, as amended; GDPR | Security measures appropriate to risk; pseudonymisation expressly contemplated. | See the GDPR mapping above; the Italian-language model in CamoText International recognises Italian names, organisations, and codice fiscale patterns. |
09.LOPDGDD, AEPD Anonymisation Guidance, and the Estatuto
| Obligation | What It Requires | How CamoText Discharges It |
|---|---|---|
| Secreto profesionalEstatuto General de la Abogacía Española; Art. 199 CP | Duty of secrecy over facts learned through the professional relationship. | No third party receives identifiable client information. |
| AEPD anonymisation guidanceLOPDGDD 3/2018 | The AEPD has published detailed guidance distinguishing anonymisation from pseudonymisation and stressing residual risk assessment. | We describe the output as pseudonymised and surface every substitution for review, rather than asserting anonymity the software cannot guarantee. Spanish DNI, NIE, and NIF patterns are recognised. |
10.FISMA, NIST, and Procurement Review
For US federal and state agencies, the relevant question in an ATO or security review is usually the system boundary. CamoText's boundary is a single user-space process on an endpoint you already accredit.
| Reference | Relevance | Position |
|---|---|---|
| NIST SP 800-53 Rev. 5 | Control baseline for federal systems. | SC-7, SI-7, SA-8(33), SA-8(6), AU-2, and SC-28 are mapped in the Security & Privacy section of the product page. |
| NIST SP 800-188 | De-identifying government datasets. | The design follows its emphasis on documented, reviewable transformation and retained governance over re-identification keys. |
| FedRAMP | Cloud service authorisation. | Not applicable. FedRAMP governs cloud services; CamoText isn't one. There's no service to authorise. |
| SOC 2 / ISO 27001 | Third-party attestation of vendor controls. | Not held. Those attestations assure you about a vendor's handling of your data. We handle none, and offer direct verification instead. |
Disable every network interface, run CamoText, and confirm full functionality. Run a packet capture and confirm zero connections. Inspect the filesystem for artefacts outside your chosen output path. Inspect the process tree for children. Four tests, one afternoon, no reliance on anything we've told you.
Including at install. Start the capture before installation, not after. Licence activation is validated entirely on the machine — there's no first-launch check-in and no periodic re-validation, so the product installs and activates on hardware that has never touched a network. Most software marketed as offline can't pass this test; it's the one worth running first.
11.What This Page Does Not Say
Compliance is a property of your practice, not of a binary. Four things we will not claim:
| We do not claim | Because |
|---|---|
| That CamoText makes you compliant | It's one technical measure. Lawful basis, retention, subject rights, training, and supervision remain yours. |
| That output is anonymous data | Pseudonymised data is still personal data. Residual identifiability in free text is a human judgment. |
| That detection is complete | Models running on laptop hardware can miss terms and flag false positives. Review is mandatory, and the interface is built around that fact. |
| That we have audited certifications | We don't hold SOC 2 or ISO 27001. We think observable behaviour is better evidence for this architecture, and we'd rather say so plainly than imply otherwise. |
CamoText was built by the founding attorney of Varia Law. This page maps published obligations to product behaviour, not advice on your circumstances.
Send this to whoever has to approve it.
Every claim on this page is testable in an afternoon: disable the network, run CamoText, and watch nothing happen on the wire. The full control mapping, data-flow diagram, and verification steps live in the Security & Privacy section of the product page, or email us and we'll walk your security or compliance team through it directly.