AI governance · law firm
What legal-AI matter-memory policy should a French law firm use?
Matter memory is not just a chat-retention setting. Before a legal-AI tool keeps facts, extracts or work product from a French matter, the firm should document the purpose, authorised roles, permitted sharing, any restricted-archive stage and the deletion trigger. The GDPR requires purpose-based, limited retention and risk-appropriate safeguards; French professional secrecy also requires lawyers to make people cooperating with them respect confidentiality. This builder produces a policy draft for internal and professional review. It does not configure a product, determine a lawful retention period, or confirm what Julie—or another provider—actually stores.
Verify in your contract or admin console. Persistence, deletion, backups, locations, subprocessors and support access are supplier facts to confirm—not assumptions made here.
Matter-state retention and access matrix
This matrix prepares a documented decision. It is neither a legal schedule nor a product setting.
| State / knowledge | Scope | Recommended access | Decision to record | Evidence / owner |
|---|---|---|---|---|
| Active matter · necessary work | Timeline, instructions and approved research | Matter team named by role | Keep only for purpose; review on change | Owner + review date |
| Active matter · high sensitivity | Sensitive data or privileged strategy | Smallest named role set; prior review | No automatic period; safeguards or no retention | Partner + DPO/security as needed |
| Closed matter · justified archive | Final advice or defined obligation evidence | Archive roles separated from live work | Record rationale, review point and restriction | Archive owner + rationale |
| Closed matter · no continuing need | Redundant prompts and superseded drafts | No operational access before controlled deletion | Delete by process; verify propagation | Deletion owner + evidence |
| Platform evidence | History, DPA, subprocessors and support access | Procurement, privacy and security | Keep for governance, apart from matter substance | Supplier owner + version |
Build a policy outline without setting a retention period
Choose categories only. Enter no client name, matter number, fact or document.
Complete all six categories to display a review outline.
Human validation required
An uncertain answer prevents this outline becoming an operational policy.
Restricted review before retention
Sensitivity or sharing breadth requires human review and supplier evidence.
Archive decision required
A closed matter, dispute or asserted constraint needs a rationale and owner.
Provider evidence gap
Persistence, deletion, access and supplier-chain facts are insufficiently documented.
Active, bounded matter policy
Purpose, roles and trigger are bounded. This is not a configuration or legal approval.
Why is legal-AI matter memory different from session memory?
A matter policy governs a bounded knowledge record, authorised people and the full lifecycle. A session feature describes continuity within a conversation.
What can count as knowledge retained for one legal matter?
List facts, excerpts, uploads or references, notes, outputs, sources and logs separately. They may not share the same purpose, access boundary or lifecycle.
What purpose should a firm record before keeping matter knowledge?
Record the specific legal-work purpose for which the knowledge is needed. Convenience alone does not justify undifferentiated collection or retention.
Who sets a French law firm’s AI retention period?
The accountable organisation documents a purpose-based decision against applicable legal and professional constraints. This page never calculates a universal number.
When should active use, restricted archive and deletion be separated?
Separate stages where a closed matter still has a justified, controlled archive need. Closure is a human review event; archive is not the automatic default.
Who should be able to access AI matter knowledge?
Use named matter roles and a need-to-know boundary, with an accountable review owner. Firm-wide visibility should not be the unexamined default.
Does professional secrecy by itself permit an AI sharing workflow?
No. Secrecy remains a professional duty, while the provider’s factual role, instructions, safeguards and access require a distinct documented review.
What evidence should a provider supply before matter memory is enabled?
Obtain written facts about persistence, deletion propagation, backups, exports, support and admin access, subprocessors, locations and logs.
How should a firm handle closed matters, disputes and legal holds?
Make closure a documented decision point: justified restricted archive, deletion candidate or evidence of another constraint. Never apply one universal timer.
How can the firm evidence access review and revocation?
Maintain a role register, review date, exception reason and accountable reviewer. Auditable evidence is stronger than a generic security promise.
What changes when someone asks for access or erasure, or an incident occurs?
Map the data across the firm and its processors, then use an escalation route that also protects confidential information belonging to other people.
What does this policy builder produce—and what must humans still approve?
It produces a categorical outline and evidence gaps. The firm, matter owner, DPO or security lead and qualified advisers must validate the actual policy.