Operational sovereignty
The controller must be able to define, supervise, audit and cease processing. EU data location alone does not settle identity, keys or control-plane control.
Local AI designed to reduce GDPR, AEPD and professional-secrecy exposure.
Inference, index, embeddings, orchestrator and keys inside your architecture.
Honest about where this stands: DESPACHO went live 19 August 2026, and this morning the full pipeline ran unattended for the first time. The architecture is the same one that's run unattended for months as GESTOR — but DESPACHO's own operating record is two days, not eighty-three. That's an argument, not evidence yet. Ask us again in a month.
Split into clauses, each assessed on its own, with a risk-ordered memo and the clause text beside every finding.
Your own documents — including scanned paper — searched alongside the EU Official Journal, the Court of Justice, and the Catalan gazette, with sources cited.
The conflict check runs first — by name, trading alias, and NIF against every existing client and counterparty — then the matter is classified and deadline language is flagged.
NDAs and engagement letters, drafted from your own templates. Facts are never invented — enforced in code, not just asked for in a prompt.
DOUE, TJUE, and DOGC, matched against your open matters by name. Spanish case law (CENDOJ) is deliberately excluded — see why below.
Deliberately excludes Spanish case law (CENDOJ/Tribunal Supremo) — the CGPJ licenses reuse of its case-law database, and its reuse regulation expressly defines "reuse" to include indexing and search federation. There's no scale at which building it stays compliant without that licence. A vendor selling sovereignty and compliance to law firms shouldn't ship a product that breaches the CGPJ's own reuse terms.
GDPR allows fines up to €20 million or 4% of global turnover. Cloud AI use with client data requires legal basis, a processor agreement and demonstrable security. See sources 1 and 5.
The AEPD formalised that controllers must retain the ability to define, supervise, audit and cease processing. EU data residency is not enough if the control plane remains outside real operational control. See sources 2 and 3.
Spain has roughly 150,000 registered lawyers. Most small and mid-sized firms still lack an AI strategy defensible under professional secrecy. The opening belongs to providers who can prove local control of inference, embeddings, index, orchestrator and keys.
! AEPD — Operational Sovereignty Guidance & Agentic AI Guidance (February 2026):
Operational sovereignty is now an Article 32 security criterion. For law firms, it sits on top of Art. 542.3 LOPJ professional secrecy: the architecture must show that a third party does not materially access the firm knowledge base in normal operation.
The controller must be able to define, supervise, audit and cease processing. EU data location alone does not settle identity, keys or control-plane control.
Responsibility for systemic design, supervision, traceability and testing failures remains with the controller, even when a human reviews outputs.
Voice, transcription and metadata are personal data; cloud STT tools must be assessed for location, retention, reuse and access.
The secreto profesional del abogado is not a contractual nicety. It is anchored in Art. 542.3 LOPJ, reinforced by the Estatuto General de la Abogacía Española and the Código Deontológico, and connected to the right of defence under Art. 24 CE.
The operational-sovereignty doctrine does not remove the processor route, but it adds a structural requirement: demonstrable operational control over the means of processing. A cloud architecture with a control plane subject to extraterritorial rules creates exposure that must be documented.
For a law firm the test is clearer: it must be able to honour professional secrecy even where a foreign legal order reaches the AI provider. Local architectures, with inference, embeddings, index, orchestrator and keys in Spain, are designed to reduce that exposure until the duty is enforceable as fact.
The despacho's duty is to the client, not to the cloud provider's lawyers in Washington.
No. The February 2026 AEPD doctrine separates data residency from operational sovereignty. The question is not only where the bytes rest, but who can define, supervise, audit, modify or cease the processing. If identity, keys or the control plane depend on an entity subject to extraterritorial rules, the firm has a documented Article 32 risk to assess. See sources 2, 9, 10 and 11.
A valid Article 28 DPA is necessary, but not sufficient. The processor relationship and security of processing are independent duties. A correct contract does not by itself remove operational-sovereignty risk, especially when the law firm knowledge base contains client data, litigation strategy and communications protected by professional secrecy. See sources 1, 2 and 5.
The two obligations are independent and both apply. Art. 542.3 LOPJ binds the lawyer to professional secrecy over facts and documents learned in the exercise of the defence, with constitutional connection to Art. 24 CE. A cloud provider whose control plane is reachable under US extraterritorial law creates exposure that must be documented. AIibiza includes a reinforced secrecy clause of indefinite duration and a local architecture designed to eliminate material supplier access in normal operation. See sources 13, 14 and 15.
The moment a name, DNI, contract, litigation strategy, client email or evidentiary document enters the prompt, you are processing personal data and may be processing material protected by professional secrecy. The AEPD has explicitly warned workers about what they entrust to AI tools. See source 4.
Spanish or European branding does not settle the sovereignty question by itself. Where a legal-AI product depends on infrastructure, identity, keys or a control plane under a non-EEA or US-regulated entity, it creates a class of risk the firm must document. For despachos specifically, the argument carries additional weight under Art. 542.3 LOPJ: the duty sits with the abogado and cannot be outsourced simply by signing a vendor DPA. AIibiza is designed so inference, embeddings, index, orchestrator and keys can sit on hardware the client can physically point to. See sources 2, 9, 10, 11 and 13.
An internal policy without verifiable architecture does not prove operational sovereignty. AIibiza delivers local hardware, audit logs, key control, local RAG, regression testing and AEPD documentation so the firm can show how processing happens, who accessed it, what is retained and how the system can be stopped. See sources 2 and 3.
Yes. The AEPD agentic AI guidance requires analysis of systemic design failures: supervision, testing, traceability and circuit breakers. A lawyer reviewing an output does not automatically shift responsibility if the system was designed badly. See source 3.
| Dimension | Aranzadi / Lefebvre / vLex | AIibiza |
|---|---|---|
| Hosting | SaaS architecture: verify region, processor chain, IAM, keys and control plane | Local appliance inside the firm or Spanish-sovereign data centre |
| GDPR Art. 28 | Standard DPA and subprocessor chain to review | Client data designed to be processed locally; AIibiza access governed by a DPA (drafted, in legal review), just-in-time authorization and audit logs |
| GDPR Art. 32 | Non-EEA or US-controlled dependencies create sovereignty risk to assess | Designed to keep inference, index, orchestrator and keys under local control |
| Agentic AI | Verify transparency, action logs and testing evidence | Per-action log, versioned prompts, regression tests and declarative circuit breakers |
| Secreto profesional (Art. 542.3 LOPJ) | Cloud architecture may create documented exposure to foreign legal orders | On-premise architecture designed to eliminate material supplier access in normal operation |
| BOE / BOIB / jurisprudencia | Coverage depends on product and licence | Local ingestion adapted to the firm and its practice |
| Data exit | Review vendor ecosystem export terms | Markdown/Obsidian/QMD on your own filesystem |
We take a small number of new clients per quarter. If you are considering working with AI Ibiza, the conversation starts here.