/Law Firms
// PRIVATE AI FOR LAW FIRMS · DESPACHOS · SPAIN

Your client files
never leave
the firm.

Local AI designed to reduce GDPR, AEPD and professional-secrecy exposure.
Inference, index, embeddings, orchestrator and keys inside your architecture.

> Book a Call
// DESPACHO — Five Capabilities, Day Two

It's DESPACHO — the same engine that's run 81 days in production for gestorías, now doing five things for law firms.

Honest about where this stands: DESPACHO went live 19 August 2026, and this morning the full pipeline ran unattended for the first time. The architecture is the same one that's run unattended for months as GESTOR — but DESPACHO's own operating record is two days, not eighty-three. That's an argument, not evidence yet. Ask us again in a month.

5
Capabilities
3
Official sources
59
Items, today
26
Practice matches
4
Touched a matter
0
Cloud services
Contract Review

Split into clauses, each assessed on its own, with a risk-ordered memo and the clause text beside every finding.

Legal Research

Your own documents — including scanned paper — searched alongside the EU Official Journal, the Court of Justice, and the Catalan gazette, with sources cited.

Client Intake & Conflicts — 24/7

The conflict check runs first — by name, trading alias, and NIF against every existing client and counterparty — then the matter is classified and deadline language is flagged.

Document Drafting

NDAs and engagement letters, drafted from your own templates. Facts are never invented — enforced in code, not just asked for in a prompt.

Compliance Monitoring

DOUE, TJUE, and DOGC, matched against your open matters by name. Spanish case law (CENDOJ) is deliberately excluded — see why below.

Deliberately excludes Spanish case law (CENDOJ/Tribunal Supremo) — the CGPJ licenses reuse of its case-law database, and its reuse regulation expressly defines "reuse" to include indexing and search federation. There's no scale at which building it stays compliant without that licence. A vendor selling sovereignty and compliance to law firms shouldn't ship a product that breaches the CGPJ's own reuse terms.

DESPACHO dashboard — Hoy tab, morning briefing
// The problem
€20M
AEPD maximum fine

GDPR allows fines up to €20 million or 4% of global turnover. Cloud AI use with client data requires legal basis, a processor agreement and demonstrable security. See sources 1 and 5.

Feb 2026
AEPD operational sovereignty doctrine

The AEPD formalised that controllers must retain the ability to define, supervise, audit and cease processing. EU data residency is not enough if the control plane remains outside real operational control. See sources 2 and 3.

~150,000
Abogados colegiados en España

Spain has roughly 150,000 registered lawyers. Most small and mid-sized firms still lack an AI strategy defensible under professional secrecy. The opening belongs to providers who can prove local control of inference, embeddings, index, orchestrator and keys.

! AEPD — Operational Sovereignty Guidance & Agentic AI Guidance (February 2026):
Operational sovereignty is now an Article 32 security criterion. For law firms, it sits on top of Art. 542.3 LOPJ professional secrecy: the architecture must show that a third party does not materially access the firm knowledge base in normal operation.

// The February 2026 Shift

Three guidances. One new legal floor.
Demonstrable sovereignty.

Operational sovereignty

The controller must be able to define, supervise, audit and cease processing. EU data location alone does not settle identity, keys or control-plane control.

Agentic AI

Responsibility for systemic design, supervision, traceability and testing failures remains with the controller, even when a human reviews outputs.

Voice and transcription

Voice, transcription and metadata are personal data; cloud STT tools must be assessed for location, retention, reuse and access.

// Secreto profesional

Why operational sovereignty is now a precondition of the secreto profesional del abogado

The secreto profesional del abogado is not a contractual nicety. It is anchored in Art. 542.3 LOPJ, reinforced by the Estatuto General de la Abogacía Española and the Código Deontológico, and connected to the right of defence under Art. 24 CE.

The operational-sovereignty doctrine does not remove the processor route, but it adds a structural requirement: demonstrable operational control over the means of processing. A cloud architecture with a control plane subject to extraterritorial rules creates exposure that must be documented.

For a law firm the test is clearer: it must be able to honour professional secrecy even where a foreign legal order reaches the AI provider. Local architectures, with inference, embeddings, index, orchestrator and keys in Spain, are designed to reduce that exposure until the duty is enforceable as fact.

The despacho's duty is to the client, not to the cloud provider's lawyers in Washington.
// FAQ

Frequently asked after February 2026

Is an EU region inside a cloud AI provider enough?

No. The February 2026 AEPD doctrine separates data residency from operational sovereignty. The question is not only where the bytes rest, but who can define, supervise, audit, modify or cease the processing. If identity, keys or the control plane depend on an entity subject to extraterritorial rules, the firm has a documented Article 32 risk to assess. See sources 2, 9, 10 and 11.

We have a DPA with the provider. Are we covered?

A valid Article 28 DPA is necessary, but not sufficient. The processor relationship and security of processing are independent duties. A correct contract does not by itself remove operational-sovereignty risk, especially when the law firm knowledge base contains client data, litigation strategy and communications protected by professional secrecy. See sources 1, 2 and 5.

Doesn't the secreto profesional del abogado override the data protection question?

The two obligations are independent and both apply. Art. 542.3 LOPJ binds the lawyer to professional secrecy over facts and documents learned in the exercise of the defence, with constitutional connection to Art. 24 CE. A cloud provider whose control plane is reachable under US extraterritorial law creates exposure that must be documented. AIibiza includes a reinforced secrecy clause of indefinite duration and a local architecture designed to eliminate material supplier access in normal operation. See sources 13, 14 and 15.

What if we only use AI for drafts or emails?

The moment a name, DNI, contract, litigation strategy, client email or evidentiary document enters the prompt, you are processing personal data and may be processing material protected by professional secrecy. The AEPD has explicitly warned workers about what they entrust to AI tools. See source 4.

What about Aranzadi / Lefebvre / vLex AI features? They're legal-market tools, aren't they?

Spanish or European branding does not settle the sovereignty question by itself. Where a legal-AI product depends on infrastructure, identity, keys or a control plane under a non-EEA or US-regulated entity, it creates a class of risk the firm must document. For despachos specifically, the argument carries additional weight under Art. 542.3 LOPJ: the duty sits with the abogado and cannot be outsourced simply by signing a vendor DPA. AIibiza is designed so inference, embeddings, index, orchestrator and keys can sit on hardware the client can physically point to. See sources 2, 9, 10, 11 and 13.

What does AIibiza add beyond an internal AI policy?

An internal policy without verifiable architecture does not prove operational sovereignty. AIibiza delivers local hardware, audit logs, key control, local RAG, regression testing and AEPD documentation so the firm can show how processing happens, who accessed it, what is retained and how the system can be stopped. See sources 2 and 3.

Does agentic AI change the law firm’s responsibility?

Yes. The AEPD agentic AI guidance requires analysis of systemic design failures: supervision, testing, traceability and circuit breakers. A lawyer reviewing an output does not automatically shift responsibility if the system was designed badly. See source 3.

// Benchmark

AIibiza vs legal SaaS after the February 2026 doctrine

DimensionAranzadi / Lefebvre / vLexAIibiza
HostingSaaS architecture: verify region, processor chain, IAM, keys and control planeLocal appliance inside the firm or Spanish-sovereign data centre
GDPR Art. 28Standard DPA and subprocessor chain to reviewClient data designed to be processed locally; AIibiza access governed by a DPA (drafted, in legal review), just-in-time authorization and audit logs
GDPR Art. 32Non-EEA or US-controlled dependencies create sovereignty risk to assessDesigned to keep inference, index, orchestrator and keys under local control
Agentic AIVerify transparency, action logs and testing evidencePer-action log, versioned prompts, regression tests and declarative circuit breakers
Secreto profesional (Art. 542.3 LOPJ)Cloud architecture may create documented exposure to foreign legal ordersOn-premise architecture designed to eliminate material supplier access in normal operation
BOE / BOIB / jurisprudenciaCoverage depends on product and licenceLocal ingestion adapted to the firm and its practice
Data exitReview vendor ecosystem export termsMarkdown/Obsidian/QMD on your own filesystem
// Sources

Regulatory and technical sources

  1. 1.AEPD — AI and Data Protection Guide — 2024 guidance on AI processing, legal basis, Article 28 processors and Article 32 security.
  2. 2.AEPD — Soberanía operativa en el tratamiento de datos personales — February 2026 operational-sovereignty doctrine for personal-data processing.
  3. 3.AEPD — Orientaciones sobre IA agéntica — February 2026 AEPD guidance on agentic AI and controller responsibility.
  4. 4.AEPD — Cuidado con lo que le confías a la inteligencia artificial — AEPD January 2026 decalogue on personal data in AI tools.
  5. 5.GDPR — Regulation (EU) 2016/679 — Article 28 processor duties, Article 32 security, and maximum administrative fines.
  6. 6.Ley 10/2010 PBC/FT — Anti-money-laundering obligations for sujetos obligados.
  7. 7.Ley General Tributaria, Art. 95 — Tax secrecy.
  8. 8.EU AI Act — Regulation (EU) 2024/1689 — Article 50 transparency duties in force from August 2026; high-risk system obligations deferred to December 2027 / August 2028 by the Digital Omnibus.
  9. 9.US CLOUD Act (18 U.S.C. § 2713) — Extraterritorial reach of US data requests over US-headquartered cloud providers.
  10. 10.US FISA Section 702 — Surveillance exposure for non-US persons processed on US infrastructure.
  11. 11.Executive Order 14117 — US bulk-data and government-related data access framework.
  12. 12.AEPD — Transcripción de voz con IA — AEPD blog guidance on voice data, transcription, responsibility, rights and transparency.
  13. 13.Ley Orgánica 6/1985, del Poder Judicial — Art. 542 — Professional secrecy of lawyers.
  14. 14.Estatuto General de la Abogacía Española — Real Decreto 135/2021 — Professional framework for Spanish lawyers.
  15. 15.Código Deontológico de la Abogacía Española — Spanish lawyers' code of professional conduct.
// Start the conversation

Ready to stop watching
AI happen and start
running it?

We take a small number of new clients per quarter. If you are considering working with AI Ibiza, the conversation starts here.

base: Ibiza, Spain — clients: worldwide
response_time: within 24 hours
new_clients: limited / per quarter

Or reach Gee directly on WhatsApp

+66 80 223 7720