ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Rule 1.6(c) and Reasonable Efforts to Protect Client Data

What ABA Model Rule 1.6(c) means by reasonable efforts, which factors the comments list, and how law firms can document practical safeguards.

3 min readBy Counsel Cyber Team

Model Rule 1.6 is best known for confidentiality: a lawyer generally may not reveal information relating to the representation of a client unless the client consents or an exception applies. Paragraph (c), added in 2012, addresses something different. It says a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.

That sentence is the ethical foundation for much of what law firms do in cybersecurity. This post looks at what "reasonable efforts" has been understood to mean and how a firm can show that it meets the standard. As always, this is general information. Your state's version of the rule and its ethics opinions control, so confirm with your state bar.

What the comments say about reasonableness

The comments to Rule 1.6 describe factors for determining whether efforts are reasonable. They include:

  • The sensitivity of the information
  • The likelihood of disclosure if additional safeguards are not employed
  • The cost of employing additional safeguards
  • The difficulty of implementing the safeguards
  • The extent to which the safeguards adversely affect the lawyer's ability to represent clients

The comments also note that a client may require special security measures not required by the rule, or may give informed consent to the use of methods that would otherwise be prohibited.

The key point is that this is a balancing test, not a checklist. A firm handling sensitive trade secrets or health records faces a different risk than a firm handling routine uncontested matters, so safeguards can reasonably differ.

What ABA Opinion 477R adds

ABA Formal Opinion 477R, on securing communication of protected client information, builds on this framework. It describes a fact-based, risk-based approach and identifies steps lawyers may consider: understanding the nature of the threat, understanding how client confidential information is transmitted and where it is stored, understanding and using reasonable electronic security measures, determining how electronic communications about client matters should be protected, labeling client information as confidential, training lawyers and nonlawyers in technology and information security, and conducting due diligence on vendors.

You can read those as a roadmap for a firm's security program.

Translating it into practice

Consider each item as an operational question.

Know where client data lives

Maintain an inventory of systems: email, document management, practice-management software, file shares, laptops, phones, backups and any personal or shadow tools. You cannot protect what you have not listed.

Use baseline technical controls

Reasonable today commonly includes multi-factor authentication, encryption of laptops and mobile devices, up-to-date patching, endpoint protection, email filtering and tested backups. These are widely available and affordable relative to the risk, which matters under the cost factor.

Handle unusually sensitive matters differently

If a client or matter warrants it, use additional protections such as restricted matter permissions, encrypted file transfer or limits on devices used. Agree on this with the client where possible and record it.

Train people

Staff are the most frequent entry point for attackers. Regular training on phishing, payment verification and safe handling of files supports the supervision duties in Rules 5.1 and 5.3.

Vet vendors

Cloud providers, outsourced IT, e-discovery vendors and shredding services all handle client information. Collect security documentation, review contract terms about confidentiality and breach notification, and revisit them periodically.

Documenting reasonableness

If something goes wrong, the question will be whether the firm acted reasonably beforehand. Documentation helps. Keep:

  1. A written information security policy appropriate to your size
  2. An inventory of systems and vendors
  3. Records of training, including dates and attendance
  4. Results of backup restore tests and phishing simulations
  5. Notes of decisions about safeguards and why they were chosen
  6. An incident response plan with contacts

You do not need perfect documents. You need evidence that the firm thought about the risks and acted in proportion.

What reasonable efforts does not mean

It does not guarantee that nothing will ever happen. The comments indicate that a disclosure does not by itself violate the rule if the lawyer made reasonable efforts. Equally, doing nothing is hard to defend. After an incident, Rule 1.4 on client communication and ABA Formal Opinion 483 on lawyers' obligations after a data breach come into play.

A simple annual routine

  • Review the system inventory and vendor list each year.
  • Reassess which safeguards are standard in the industry and whether you have them.
  • Update policies and retrain staff.
  • Run a restore test and a tabletop exercise.

Counsel Cyber helps firms apply this framework in practical terms, including policy templates, vendor review checklists and a documented security baseline. If you want help showing that your safeguards are reasonable and current, we can start with a short review.