Few firms still keep every document on a server in the back room. Email, documents, billing, and client portals commonly live in cloud services. That raises a question managing partners often ask: what does the ethics rule on confidentiality expect of us when client information sits in someone else's data center?
ABA Model Rule 1.6(c) says a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. The comments list factors for judging reasonableness, including the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost of safeguards, and the difficulty of implementing them. ABA Formal Opinion 477R discusses these factors in the context of electronic communications.
This post is general information, not legal advice. State rules and ethics opinions on cloud computing vary, so check your state bar's guidance.
What "reasonable" tends to mean
The rule does not demand perfection or a particular product. It asks for a thoughtful, proportionate set of precautions. Many state ethics opinions on cloud storage, in general terms, have said that lawyers may use cloud services if they take reasonable care in selecting and using the provider. That generally involves understanding the vendor's security, confidentiality terms, and your ability to retrieve data.
A practical due diligence list
Before choosing a cloud service
- Security controls. Does it offer encryption in transit and at rest, MFA, role-based access, and audit logs?
- Independent assurance. Can the vendor provide recent audit reports, such as SOC 2, and will your technical advisor review them?
- Confidentiality terms. Does the agreement prohibit the vendor from using your data for its own purposes or disclosing it except as required?
- Data location and subprocessors. Where is data stored, and who else touches it?
- Breach notification. Does the vendor commit to notify you promptly, and within what time?
- Data return. Can you retrieve all your data in a usable form, and what happens when you leave?
- Resilience. What are the vendor's availability and backup commitments?
When you configure it
The most secure platform can be set up badly. Reasonable efforts include how you use the service.
- Enforce MFA for every user
- Restrict sharing to named people and set links to expire
- Limit external sharing by default, with exceptions approved
- Use groups and matter-level permissions rather than blanket access
- Turn on logging and alerts
- Keep devices encrypted and managed
When people use it
- Train staff on safe sharing practices
- Discourage personal consumer storage for client files
- Set rules for sending sensitive documents, such as secure portals instead of unencrypted attachments
- Define how to handle lost or stolen devices
Consumer versus business tools
A free consumer file-sharing account may have different data handling, retention, and administrative controls than a business plan. The terms of service matter. A firm that allows personal accounts for client work gives up visibility and control. Where convenience pushes people toward personal tools, offer a sanctioned alternative.
Communicating with clients
Some clients specify in outside-counsel guidelines which tools or locations are acceptable, and some prohibit certain cloud services. Check engagement terms. Opinion 477R notes that heightened security measures or client consent may be appropriate in some circumstances, such as particularly sensitive information or client instructions.
Keep records
Document your reasoning. A short memo on why you chose a platform, which settings you enabled, and what you reviewed shows thoughtfulness. Revisit it annually or when something changes, such as a vendor breach, an acquisition, or a new feature that alters data handling.
If the vendor has an incident
Have a plan:
- Confirm what the vendor says was affected.
- Assess whether client information was involved.
- Consult counsel about notification duties. ABA Formal Opinion 483 discusses lawyers' obligations after a data breach.
- Document your response.
- Reassess the relationship.
Common pitfalls
- Assuming a well-known brand removes the need for review
- Leaving default sharing settings in place
- Forgetting about old services nobody uses but still hold files
- Allowing departing staff to retain access
- Skipping backups on the assumption that the vendor handles everything
Where we fit
Counsel Cyber helps firms review cloud vendors, harden configurations, and document their reasoning. If you want a practical review of how client data is stored and shared across your firm, we are glad to help.