When your client's GDPR export becomes a weapon
Defense in depth for processing adversarial PDFs and XLSX files
Enno Richter
Published on
An uncomfortable truth from our day-to-day work with online gambling operators: the PDF and XLSX files your clients receive as GDPR data exports are not harmless. They come from adversaries in an active legal dispute – operators with a strong interest in not having that data analysed cleanly.
In our threat modelling we therefore assume, by default:
Every incoming file may be weaponised – up to and including zero-day exploits in PDF or Office parsers.
This is not a theoretical concern. PDF and Excel components have been among the most heavily attacked software components for years. Crafted documents are a standard initial-access vector for targeted attacks – particularly in legal disputes involving high amounts in controversy.
What this means for your firm
If you open these files locally on firm devices, forward them by email, or run them through a generic tool, the following assets are immediately at risk:
- Client files and attorney-client privilege (§ 43a BRAO under German law, equivalent professional secrecy duties elsewhere)
- Evidence in ongoing matters
- beA accounts, DATEV integrations, claims-management systems
- Cloud storage and collaboration platforms
- Bank credentials of the firm and its clients
A single successful attack can result in full compromise – and triggers the 72-hour breach notification obligation under GDPR as well as professional duties under § 43e BRAO.
What Convexio is built for
Convexio is built ground-up on the principle of defense in depth. We assume that any individual control layer can fail, and that no single measure is sufficient on its own.
In practice that means:
- High-risk processing happens where it is safe – in tightly isolated, purpose-hardened environments, separated from any client-side system.
- Compromised files cannot “phone home” – the processing environment has no unrestricted internet access. Data exfiltration and second-stage payloads are blocked at the network layer.
- Strict tenant separation – data from different firms and matters is isolated at the database and storage layers. Cross-tenant access is structurally impossible, not merely “usually prevented”.
- Encryption at rest and in transit – end-to-end, including internal communication.
- Processing on German soil only – all servers in Germany, data processing agreement under Art. 28 GDPR, documented 72-hour breach notification process.
- Full audit trail – every data access and every change is logged in a way that holds up in court.
Concretely: even if an incoming file contains a zero-day exploit, the blast radius is limited to a short-lived, isolated processing environment – no access to client data, no persistence, no path to the open internet.
Auditable, not just claimed
Security that nobody can audit is marketing. Our posture is reviewable:
- Full information security management system per ISO/IEC 27001:2022 – Statement of Applicability, risk register, treatment plan, and audit programme all documented.
- Built and operated by an ISO 27001 Senior Lead Implementer with over 20 years of IT security experience.
- Regular penetration tests by certified pentesters (OSCP, OSEP, and others).
- Internal audit Q2 2026; external certification audit in preparation.
Three questions every firm should ask itself
- Where are adversary documents being opened? Ideally not on the same device that holds your client files.
- What happens when a file turns out to be malicious? Is the damage contained to a clearly bounded area – or does it reach your entire IT estate?
- Could you demonstrate, in an incident, that you acted according to the state of the art? Art. 32 GDPR and § 43e BRAO require exactly that.
We help firms answer all three with “yes”.
If you’d like to see how Convexio fits into your matter workflow, book a demo or write to us at info@convexio.de.