Notaries hold the most sensitive data of any profession. Their security is the worst.
Short answer
Notaries hold the most sensitive personal data of any profession outside healthcare: deeds, wills, divorce settlements, beneficiary designations, identity documents, succession files. The average notarial practice runs that data through Office 365 with default settings, a generic VPN, and a backup nobody verified. The gap between the sensitivity of the data they hold and the controls they actually run is the widest in the legal services market today.
What is actually in a notary’s filing system
The contents of a typical notarial archive are remarkable. The full text of every will the practice has drafted, often spanning decades. Every property deed for every transaction the notary has handled. Every divorce settlement, every prenuptial agreement, every adoption file. Identity documents (passports, driver licenses, social security numbers) collected at signing. Bank account information for every wire transfer the practice has executed. The succession files of deceased clients, including beneficiary information and asset inventories.
The same archive holds the most useful identity-theft training set imaginable. The breach of a mid-sized notarial practice produces, in one event, the full identity profile of several thousand individuals: name, date of birth, address history, government ID numbers, signature samples, financial accounts, real estate holdings, family relationships. The aggregate value of that profile, on criminal markets, exceeds the value of most healthcare breaches because the data is already structured and verified.
The typical posture, by the numbers
Surveys of solo and small-firm notaries across France, Belgium, Quebec, and the broader civil-law jurisdictions through 2025 produced a consistent pattern. Roughly seventy percent run client files on Microsoft 365 with default tenant settings, no Conditional Access policies, no Data Loss Prevention rules, no audit logging beyond the defaults. Roughly sixty percent rely on a generic consumer VPN for remote access, when they use one at all. Roughly eighty percent have not tested their backup restoration in the last twelve months. Roughly ninety percent have no documented incident response plan beyond “call the IT person.”
The professional bodies have published guidelines. The guidelines have not been adopted at scale because compliance is voluntary, the audit pressure is light, and the practical IT resources at a solo or two-partner practice are limited. The result is a profession that holds data comparable to a regional bank with the security posture of a small accounting firm.
The four highest-leverage changes
None of these require a security consultant. None require a budget that a solo practice cannot absorb. All four can be done in a focused weekend.
1. Enable Microsoft 365 Conditional Access and MFA enforcement
Microsoft 365 Business Premium includes Conditional Access at no additional cost. The configuration that closes most of the practical attack surface: require multi-factor authentication for all users, block legacy authentication protocols (the IMAP/POP3 channels that bypass MFA in older configurations), require compliant device for access to client data. The configuration takes about an hour and eliminates the credential-stuffing and password-spray attacks that drive most practical breaches.
2. Move client communications off generic email
The largest unforced exposure is client correspondence flowing through ordinary email with no encryption layer. The practical fix is to establish a client portal for document exchange, even a basic one. ProtonMail Business with the secure-link feature, Tresorit for file exchange, or a managed solution like Citrix ShareFile each work. The cost is in the tens of euros per month per user. The framework around third-party storage of credentials is the same one we covered in what law enforcement can actually access from your accounts: data that lives outside your perimeter is exposed by every party that touches it.
3. Test the backup
The backup that has not been restored is not a backup. The single most common failure mode in mid-sized professional services breaches is the discovery, mid-incident, that the backup either does not include the data or cannot be restored within a usable timeframe. The fix is to schedule a quarterly restoration test of a non-trivial subset of files to a separate environment. The test takes a few hours per quarter. It is the difference between a recoverable incident and an unrecoverable one.
4. Document the data inventory
An incident response that does not know what data the practice holds is an incident response that cannot meet GDPR notification deadlines, cannot respond to regulator inquiries, and cannot quantify exposure for the practice’s professional liability carrier. The inventory is a structured list: which categories of data, where they live, who has access, what the retention period is. It is updated quarterly. The same threat-modeling discipline we cover in how to build a threat model in 20 minutes applies, scaled to a professional practice rather than an individual.
The client-facing implication
Most clients have not asked the question. The question is coming. Sophisticated clients (corporate clients, high-net-worth individuals, families involved in cross-border succession) increasingly ask their notary to describe the security posture of the practice before transferring sensitive documents. The answer “we use Office 365” is not the same as the answer “we use Office 365 with Conditional Access, MFA enforcement, audit logging, and quarterly backup verification.” The first answer closes the conversation; the second moves it forward.
The competitive landscape in notarial services is shifting toward firms that can articulate this distinction. Professional bodies will catch up eventually, but in the interim the firms that move first are the ones retaining high-value clients through the transition.
Frequently asked questions
Is my professional liability insurance enough if a breach happens?
Read the policy. Most professional liability policies in civil-law jurisdictions exclude or sub-limit cyber incidents. A separate cyber insurance policy is increasingly standard for practices of any meaningful size. The cyber policy will require, as a condition of coverage, the kinds of controls in the four-point list above. Not having the controls makes coverage harder to obtain and harder to claim.
Do French and Belgian notarial practices have specific obligations under GDPR?
Yes. Notarial practices process sensitive personal data and family-relationship data, both of which trigger heightened GDPR obligations. The CNIL and the Belgian Data Protection Authority have issued guidance specific to notaires. The practical compliance bar is higher than the typical solo practice has implemented. The framework around documenting your data scope is what GDPR requires; the four-point list above is the operational expression of that requirement.
What about the central professional infrastructure (Real, Téléacte, others)?
The professional infrastructure operated by the notarial bodies has its own security posture, generally stronger than what individual practices implement. The exposure is at the practice level: the documents that live on the practice’s local environment before they enter the central infrastructure, and the working drafts and communications that never enter the central system at all. The four-point list addresses the practice-level gap.
If I move to a managed-services provider, am I covered?
Better, not covered. A reputable managed-services provider implements the controls the practice would otherwise need to implement itself. The accountability remains with the practice. The provider’s contractual terms matter (what happens to data on contract termination, who responds to a regulator inquiry, how breach notifications are handled). The principle is the same one we cover in operational identity separation between the notarial study and personal accounts: the data is the practice’s responsibility regardless of which vendor processes it day to day.
There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.
