Direct answer
I would pause the specific part of the architecture that creates the violation, get an actual legal read rather than my own guess at the law, and keep the client relationship going by treating this as solving their compliance problem for them, since the exposure is their liability too.
Steps to resolve the legal and ethical risk
- Confirm the issue is real with your own legal or privacy counsel, since architects are usually right about the shape of a risk but not always the precise legal threshold.
- Isolate the exact component causing the exposure, for example a cross-border data transfer or a missing consent mechanism, rather than treating the whole proposal as tainted.
- Propose the compliant alternative alongside the disclosure, so the conversation is solution-first, and put the cheaper option first. There are usually two routes and they differ by an order of magnitude in cost: add the safeguard the law actually asks for and keep the architecture, for example standard contractual clauses plus a transfer risk assessment, or a consent mechanism where consent is what is missing; or remove the trigger entirely by keeping the processing inside the client's own region. Re-architecting is the fallback, not the opener, because a client hears "your design is illegal and also needs rebuilding" very differently from "your design needs one document and one control you do not have yet." Which route is available is a legal question, not an architecture preference, so ask counsel which one the specific regulation accepts here before you take either to the client.
- Document the identified risk and its resolution internally regardless of what the client decides, so you are not the only one who knew and said nothing if they choose to proceed anyway.
Handling the client relationship while doing it
Bring the client into the conversation early, framed as partnership: "we caught something in the design that could expose you to this specific regulation, here is the fix," rather than "you asked for something illegal." Most clients treat a caught compliance gap as good news, not friction, when it is framed this way.
Worked example
A proposed architecture for an EU-based client would replicate user analytics data to a US region for processing, without the transfer safeguard their jurisdiction's privacy law requires for data leaving the EU. Flag it the moment it is caught in design review, and verify with your privacy or legal function both that a safeguard is genuinely required here and which safeguards would satisfy it. If counsel says the transfer can be made lawful with the standard contractual terms and a documented transfer assessment, that is the first option you bring, because it keeps the design and the timeline intact. If counsel says the safeguard route does not hold for this data or this recipient, then you bring the revised architecture that processes analytics within-region, adding a bounded amount of infrastructure cost, instead of the original design. Either way you present one recommended route and one alternative, not just the expensive one.
Trade-offs and pitfalls
Self-diagnosing the legal violation without an actual privacy or legal read risks either overreacting to something permissible or underreacting to something genuinely serious. Letting relationship management soften a real violation into a nice-to-have fix in the proposal, rather than a required one, is the other pitfall.