Privacy

Client Confidentiality for Translators: Why Trust Is the Human Edge Against AI

As machine translation absorbs routine work, the human, certified end of the market competes on trust, and confidentiality is a large part of it. Here's what confidential document handling means in practice: NDAs, end-to-end encryption, GDPR, and clear deletion.

As machine translation absorbs routine work, the human, certified end of the market competes on trust, and confidentiality is a large part of it. Handling a client's documents privately, with end-to-end encryption and a clear deletion policy, is part of what a person offers that an automated pipeline does not. This is what confidential handling means in practice.

Why confidentiality became a competitive edge

Machine translation is good enough for a lot of everyday text, and it has pushed rates down at the generalist end of the market. What holds its value is work where an error or a leak is expensive: legal filings, medical records, patents, and the certified translation of personal documents for immigration and official use. Clients pay a human for judgment and for accountability. Part of that accountability is how their documents are handled, because these are often the most sensitive papers a person owns.

What clients of certified and legal translation worry about

A client sending a birth certificate, a court judgment, or a bank statement is trusting a stranger with their identity and their private affairs. Their concerns are practical:

  • Where does the file go, and who can read it along the way?
  • Does it sit in an inbox or a cloud folder after the job is done?
  • Could it be forwarded, leaked, or caught up in someone else's data breach?
  • If they ask, can you tell them what you hold and delete it?

Meeting those concerns is not just good ethics. It is the reason a nervous first-time client chooses a professional over the cheapest option.

The building blocks of confidential handling

NDAs. Most agencies sign a non-disclosure agreement before a translator reads a sensitive document. The NDA sets the expectation. The workflow has to live up to it.

Data minimisation. Ask for the document you need to translate, and no more. The less you hold, the less there is to protect.

End-to-end encryption. The document should be encrypted so that only you, the translator, can read it, not the tool or platform in the middle. This is the difference between "encrypted in transit" (a baseline that every service should meet) and "only the recipient can read it."

Deletion and retention. Keep the source file only as long as the job needs, then delete it. A clear retention policy, and a habit of actually deleting, is part of the promise.

GDPR, where it applies. If you handle the personal data of people in the EU or UK, you're generally expected to collect only what you need, keep it secure, delete it when done, and be able to show how it was handled if a client asks.

Zero-knowledge: what "we can't read it" means

A zero-knowledge, or end-to-end encrypted, intake encrypts the document on the client's device before it's sent. The only person who can decrypt it is the intended recipient, the translator. The tool passing the file along never holds a readable copy, so a breach of that tool's servers doesn't expose the client's document. For a translator selling trust, being able to say "not even the tool we use can read your file" is a stronger promise than "we store it securely."

A short checklist for confidential handling

  • Sign the NDA, and use an intake channel that matches it.
  • Collect the source document through an end-to-end encrypted link, not email.
  • Don't make the client create an account to send one file.
  • Keep each client's document isolated from every other job.
  • Delete the source after delivery, or use a request that expires.

Where doconvoy fits

doconvoy is a way to run that intake. The client opens a link in your name and uploads the document without an account, it's encrypted in their browser so doconvoy never holds a readable copy, and the request expires on a schedule you set. It turns the confidentiality you promise into something the client can see happening. For the practical setup, see how to receive documents for translation securely and the secure document collection workflow for certified translators.

Collect the documents you translate through an encrypted, no-account link that expires after the job.

Make confidentiality something clients can see

Related: How to receive documents for translation securely · Is it safe to send documents for translation by email? · Secure document collection for certified translators · Access Controls

Common questions

Why does confidentiality matter more for translators now?

Machine translation has taken much of the routine, low-stakes work, while specialist and certified work, where a mistake or a leak is costly, is holding its value. Confidential handling of a client's documents is part of what a human translator offers that a cheap AI pipeline does not.

What does zero-knowledge or end-to-end encryption mean for a translation workflow?

It means the document is encrypted on the client's device and can only be read by the translator, not by the tool or platform passing it along. The intake provider never holds a readable copy, so a breach of their servers doesn't expose your client's file.

Do translators have to follow GDPR?

If you handle the personal data of people in the EU or UK, generally yes. That includes collecting only what you need, keeping it secure, deleting it when the job is done, and being able to show how it was handled if asked.