What are an Arizona lawyer's duties around metadata in electronic documents, and can a lawyer use hidden email-tracking 'web bugs'?
Apply this to your situation
This page answers the general question as of 2022. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.
Plain-English summary
The committee answered three questions about metadata and email-tracking software, approving in part and disapproving in part State Bar of Arizona Opinion 07-03. On the sending side, it agreed that a lawyer who sends an electronic document to a non-privileged person must take reasonable measures to scrub confidential metadata, framing this as part of the ER 1.1 duty of competence (keeping abreast of relevant technology) and the ER 1.6 duty of confidentiality. The committee called this a light burden, since scrubbing tools are built into common programs like Microsoft Word and Adobe Pro. It noted the required degree of scrubbing depends on the circumstances (innocuous creation metadata may need no removal, while substantive edit histories and privileged comments should be removed), and that the duty does not override obligations to provide redlined documents in negotiations or native-format files in discovery.
On the receiving side, the committee disagreed with the part of Opinion 07-03 that flatly barred a receiving lawyer from reviewing any embedded metadata. It rejected the premise that searching for metadata is inherently surreptitious or that metadata is always confidential, adopting the Colorado approach: a receiving lawyer does not act unethically by reviewing metadata readily viewable in the file's native software or operating system, unless the lawyer knows or reasonably should know that the document or the metadata was sent inadvertently. Metadata that appears to be material confidential information, privileged communications, or work product must be assumed inadvertently disclosed, triggering the ER 4.4(b) duty to notify the sender and preserve the status quo. The committee drew a line at "mining": using special software designed to retrieve metadata despite the sending lawyer's reasonable efforts to scrub it violates ER 4.4(a), analogizing it to taking a document from another lawyer's briefcase when their back is turned.
On the third question, the committee concluded that a lawyer may not, without the recipient's prior informed consent, embed hidden email-tracking software (a "web bug," also called a web beacon, pixel tag, or invisible GIF) in emails to clients or other lawyers. Such software secretly reports back when and how an email and its attachments are opened, forwarded, and handled, giving the sender insight into the recipient's work and client communications, and (unlike metadata) there is no reliable way for recipients to detect or block it. The committee held that this is an unwarranted intrusion into the client-lawyer relationship that violates ER 4.4(a) and constitutes conduct involving dishonesty or deceit under ER 8.4(c). It noted the holding does not reach services like Constant Contact or MailChimp that track emails through visibly displayed links the recipient can choose not to click.
In practice
The opinion holds that an Arizona lawyer sending electronic documents to a non-privileged recipient must use available tools to remove confidential metadata, and that a receiving lawyer may look at metadata that is readily visible in the document's native application but must stop and follow the ER 4.4(b) process once it appears the material is confidential, privileged, or inadvertently sent. The opinion treats deliberate "mining" with specialized recovery software, and the use of hidden email web bugs, as prohibited. Because technology and the rules continue to evolve, confirm the current ER 1.6, ER 4.4, and ER 8.4 text and comments before relying on these specifics.
Common questions
Q: Does an Arizona lawyer have to remove metadata before sending a document to the other side?
A: Yes. The opinion concluded that a sending lawyer must take reasonable measures to scrub confidential metadata, treating it as part of the ER 1.1 competence and ER 1.6 confidentiality duties; the required scrubbing depends on how sensitive the metadata is.
Q: Can a lawyer look at metadata in a document received from opposing counsel?
A: Yes, within limits. The opinion concluded a receiving lawyer may review metadata readily viewable in the file's native software, but must follow the ER 4.4(b) inadvertent-disclosure process if the lawyer knows or reasonably should know the metadata is confidential, privileged, or was inadvertently sent.
Q: Is "mining" for metadata allowed?
A: No. The opinion concluded that using software designed to retrieve metadata despite the sender's reasonable efforts to scrub it is "mining" that violates ER 4.4(a).
Q: Can a lawyer put hidden tracking software ("web bugs") in emails to other lawyers?
A: No, not without the recipient's prior informed consent. The opinion concluded that hidden email-tracking web bugs are an unwarranted intrusion into the client-lawyer relationship that violates ER 4.4 and ER 8.4(c).
Background and rules framework
The opinion interprets Arizona ER 4.4 (respect for the rights of others, including the ER 4.4(a) bar on improper methods of obtaining evidence and the ER 4.4(b) inadvertent-disclosure procedure; Model Rule 4.4), ER 1.6 (confidentiality, including the duty to act competently to safeguard client information; Model Rule 1.6), ER 1.1 (competence, including comment 6 on keeping abreast of relevant technology; Model Rule 1.1), and ER 8.4(c) (misconduct involving dishonesty or deceit; Model Rule 8.4), with the ER 1.0 definitions of "knows" and "reasonably should know."
Citations and references
Rules of Professional Conduct:
- MR 4.4 / Arizona ER 4.4(a)-(b) (respect for rights of others; inadvertent disclosure)
- MR 1.6 / Arizona ER 1.6 (confidentiality; competent safeguarding)
- MR 1.1 / Arizona ER 1.1 (competence; technology comment 6)
- MR 8.4 / Arizona ER 8.4(c) (dishonesty, fraud, deceit, misrepresentation)
- MR 1.0 / Arizona ER 1.0(f), (i) (definitions of "knows," "reasonably should know")
Other opinions cited:
- State Bar of Arizona Op. 07-03 (approved in part, disapproved in part): metadata duties
- ABA Formal Op. 06-442: review and use of metadata
- Colorado Formal Op. 119; D.C. Op. 341; Maryland Op. 2007-09; Pennsylvania Op. 2009-100; Texas Op. 665; Wisconsin EF-12-01: metadata review and inadvertence
- Mississippi Op. 259; Oregon Op. 2011-187; Washington Op. 2216: "mining" metadata
- Illinois Op. 18-01; Pennsylvania Op. 2017-300; Alaska Op. 2016-1; New York Op. 749: email web bugs
See also
- ABA Formal Op. 06-442: Review and Use of Metadata
- CBA Formal Op. 119: Metadata Duties
- DC Ethics Op. 341: Reviewing Document Metadata
- AK Bar Ethics Op. 2016-1: Email Web Bugs / Tracking
- AL Ethics Op. 2007-02: Mining and Metadata
Source
- Landing page: https://www.azcourts.gov/cld/Attorney-Ethics-Advisory-Committee/Opinions-Issued-by-the-Committee
- Original PDF: https://www.azcourts.gov/Portals/0/26/EO-20-0008%20%20Opinion_1.pdf
Original opinion text
Reproduced from the official source for research purposes. The linked source is authoritative.
SUPREME COURT OF ARIZONA
ATTORNEY ETHICS ADVISORY COMMITTEE
Ethics Opinion File No. EO-20-0008
The Attorney Ethics Advisory Committee was created in accordance with Rule 42.1.
A lawyer who authors and sends an electronic document to someone other than the client on whose
behalf the document was drafted, or other privileged persons, is responsible, under ER 1.6, for first
scrubbing the document of confidential metadata that may be contained within the electronic file
using standard software applications for doing so.
A lawyer who receives an electronic document or other type of electronic file from another lawyer
may ethically use the software applications within which the file was created and saved to retrieve
and review embedded metadata unless the lawyer knows or reasonably should know that the
metadata was included inadvertently—in which case the receiving lawyer should follow the
process in ER 4.4(b). Metadata that contains material information that the lawyer knows or
reasonably should know is confidential or privileged should be assumed to be inadvertently
disclosed. “Mining” for metadata, meaning searching for metadata using software applications that
are designed to retrieve metadata despite a sending lawyer’s reasonable efforts to scrub it, violates
ER 4.4(a). This opinion approves in part and disapproves in part State Bar of Arizona Opinion 07-
03.
A lawyer may not, without the prior informed consent of the recipient, ethically embed in an email
to potential, current, or future clients, or other lawyers, hidden email-tracking software, also known
as a web beacon, pixel tag, clear GIF or invisible GIF. Use of such a device violates ER 4.4.
ISSUES PRESENTED
1. If a lawyer sends an electronic communication, what ethical duty does the lawyer have to prevent
the disclosure, through metadata embedded therein, of confidential or privileged information?
2. May a lawyer who receives an electronic communication examine it for the purpose of
discovering the contents of the metadata that may be embedded within it?
3. May a lawyer embed hidden software in an email to another lawyer that tracks information about
the handling and viewing of the email?
RELEVANT ETHICS OPINIONS
State Bar of Arizona, Rules of Professional Conduct committee, Opinion No. 07-03
ABA Formal Op. 06-442
1
Page 2
APPLICABLE ARIZONA RULES OF PROFESSIONAL CONDUCT
ER 1.0 Terminology
(f) “Knowingly,” “known,” or “knows” denotes actual knowledge of the fact in question. A
person's knowledge may be inferred from circumstances.
(i) “Reasonably should know” when used in reference to a lawyer denotes that a lawyer of
reasonable prudence and competence would ascertain the matter in question.
ER 1.1. Competence
A lawyer shall provide competent representation to a client. Competent representation requires
the legal knowledge, skill, thoroughness and preparation reasonably necessary for the
representation.
Comment
Maintaining Competence
[6] To maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the
law and its practice, including the benefits and risks associated with relevant technology, engage
in continuing study and education and comply with all continuing legal education requirements to
which the lawyer is subject.
ER 1.6. Confidentiality of Information
(a) A lawyer shall not reveal information relating to the representation of a client unless the
client gives informed consent, the disclosure is impliedly authorized in order to carry out
the representation or the disclosure is permitted or required by paragraphs (b), (c) or (d),
or ER 3.3(a)(3).
Comment
Acting Competently to Preserve Confidentiality
[22] Paragraph (e) requires a lawyer to act competently to safeguard information relating to the
representation of a client against unauthorized access by third parties and against inadvertent or
unauthorized disclosure by the lawyer or other persons who are participating in the representation
of the client or who are subject to the lawyer's supervision. See ERs 1.1, 5.1 and 5.3. The
unauthorized access to, or the inadvertent or unauthorized disclosure of, information relating to
2
Page 3
the representation of a client does not constitute a violation of paragraph (e) if the lawyer has made
reasonable efforts to prevent the access or disclosure. …
ER 4.4. Respect for Rights of Others
(a) In representing a client, a lawyer shall not use means that have no substantial purpose other
than to embarrass, delay, or burden any other person, or use methods of obtaining evidence
that violate the legal rights of such a person.
(b) A lawyer who receives a document or electronically stored information and knows or
reasonably should know that the document or electronically stored information was
inadvertently sent shall promptly notify the sender and preserve the status quo for a
reasonable period of time in order to permit the sender to take protective measures.
Comment
[1] Responsibility to a client requires a lawyer to subordinate the interests of others to those of
the client, but that responsibility does not imply that a lawyer may disregard the rights of
others. It is impracticable to catalogue all such rights, but they include legal restrictions on
methods of obtaining evidence from others and unwarranted intrusions into privileged
relationships, such as the client-lawyer relationship.
[3] … A receiving lawyer who discovers metadata embedded within a document or
electronically stored communication and who knows or reasonably should know that the
metadata reveals confidential or privileged information has a duty to comply with the
procedures set forth in ER 4.4(b).
ER 8.4. Misconduct
It is professional misconduct for a lawyer to:
(c) engage in conduct involving dishonesty, fraud, deceit or misrepresentation;
OPINION
Metadata
Electronic documents and other electronic files contain “metadata” – information about the file,
such as when and by whom it was created, when and how and by whom it was subsequently edited
and modified, and even embedded “comments.” SBA Opinion 07-03 concludes that a lawyer
sending an electronic document to anyone—other than the client, other lawyers and staff within
the lawyer’s firm, or other privileged persons—must take reasonable measures to “scrub” the
document of such confidential information, except to the extent prohibited by a rule, order, or
procedure of a court or other applicable provision of law.
This is consistent with the ethics opinions of all other jurisdictions that have addressed the issue
and the Committee agrees with this conclusion. The burden to ensure that confidential information
3
Page 4
is protected rests in the first instance on the shoulders of the sending lawyer, and it is by no means
a heavy burden. “Scrubbing” software is commonly available. It is even included within the
programs—Microsoft Word and Adobe Pro, for example—that lawyers most often use to create
most of the electronic files they create and share. Understanding how to run these simple
processes—or relying on staff that are proficient at running them—is part of a lawyer’s duty of
competence under ER 1.1. Ariz. R. Sup. Ct., Rule 42, ER 1.1, cmt. ¶ 6 (duty to “keep abreast of
changes in the law and its practice, including the benefits and risks associated with relevant
technology”).
The degree of electronic scrubbing that is required will depend on the circumstances. Some
information may be so innocuous that a lawyer is, under the circumstances, justified in concluding
that its disclosure is impliedly authorized by the client – for example, information about when and
by whom the document was created and modified when this is already generally known to the
receiving party or is simply immaterial. More sensitive metadata, which will typically include
things like the history of substantive edits and embedded comments made or inserted by the lawyer
or the client—particularly any privileged communications between the lawyer and client—should
be removed before the lawyer shares the file with a non-privileged person.
This of course does not in any way limit the professional obligation of the lawyer to provide a
“redlined” document to the lawyers for other parties that show changes made to a draft joint
document under negotiation (whether a motion, stipulation, contract, etc.) (see Ariz. R. Sup. Ct.,
Rule 41, Creed of Professionalism § B(12)), nor does it limit the obligation to provide files in their
native format, with intact metadata, when required by discovery and disclosure rules or other
applicable law.
The SBA Opinion, however, goes on to conclude that a lawyer who receives an electronic
document or other file may not deliberately access and review any metadata embedded in it, but
rather must treat the metadata as “inadvertently sent” within the meaning of ER 4.4(b)—even when
the electronic document itself was not inadvertently sent—unless review is otherwise allowed by
a rule, order, or procedure of a court or other applicable provision of law. There are a few opinions
from other jurisdictions that take this same general approach. See North Carolina Bar 2009 Formal
Ethics Opinion 1 (January 15, 2010); Maine board of Overseers of the Bar Professional Ethics
Commission Opinion #196, Transmission, Retrieval and Use of Metadata Embedded in
Documents (October 21, 2008); New Hampshire Bar Association Ethics Committee Advisory
Opinion #2008-09/04, Disclosure, Review, and Use of Metadata in Electronic Materials (May 15,
2009); Professional Ethics of the Florida Bar Opinion 06-2 (September 15, 2006); New York State
Bar Association Committee on Professional Ethics Opinion Number 749 (December 14, 2001).
But, as noted by a Colorado ethics opinion, these opinions “appear to be based on an implied
premise that searching for metadata is surreptitious or otherwise involves procedures that are
difficult or complicated. They also seem to assume that metadata generally contain Confidential
Information and that any metadata transmitted to a third party must, therefore, have been
transmitted inadvertently.” Colorado Formal Opinion 119, Disclosure, Review, and Use of
Metadata (May 17, 2008). The Committee agrees that these assumptions are generally
unwarranted and therefore rejects the blanket prohibition in the SBA Opinion and instead
4
Page 5
concludes that the receiving lawyer does not act unethically by reviewing metadata that is readily
viewable within the file’s native software application or normal operating systems unless the
lawyer knows or reasonably should know that the document itself was inadvertently sent or was
sent with the metadata inadvertently included.
Though “mere uncertainty” does not rise to the level of actual or constructive knowledge (The
District of Columbia Bar Association Ethics Opinion 341 (September 2007)), inadvertence may
be inferred from the nature of the metadata. Specifically, metadata that appears to be material
confidential information or that reveals privileged communications or work product should be
assumed by the receiving lawyer to have been inadvertently provided by the sending lawyer, and
the receiving lawyer should follow the ER 4.4(b) process. This is consistent with the comment to
Arizona’s version of ER 4.4 (see cmt. ¶ 3), and with the approach of most other jurisdictions that
have addressed the issue. In addition to the Colorado and D.C. opinions, see Wisconsin Formal
Ethics Opinion EF-12-01, The Transmission and Receipt of Electronic Documents Containing
Metadata (Rev. April 27, 2018); Texas State Bar Association Professional Ethics Committee
Opinion 665 (December 2016); Pennsylvania Bar Association Committee On Legal Ethics and
Professional Responsibility, Formal Opinion 2009 – 100, Ethical Obligations on the Transmission
and Receipt of Metadata (2009); Maryland State Bar Association Committee on Ethics Opinion
2007-09, Ethics of Viewing and/or Using Metadata (January 1, 2007).
The Committee also, however, agrees with the three jurisdictions that have distinguished between
permissible viewing of readily discernable metadata and truly “mining” for metadata, and have
found the latter to be ethically problematic.
While there is no universally-accepted definition of "mining metadata", the term is
defined herein as the act of intentionally seeking out and viewing metadata
embedded in a document through the use of software other than the native software
application with which the document was created or a native operating system for
the purpose of seeking discovery of information that is confidential, legally
privileged, or otherwise not intended to be disclosed on the face of the document.
Mississippi Bar Ethics Opinion No. 259 (November 29, 2012). See also Oregon Formal Opinion
No. 2011-187 (revised 2015); and Washington State Bar Association Advisory Opinion 2216
(2012). Using special software to discover metadata despite the sending lawyer’s reasonable
efforts to scrub it is analogous to taking a document out of another lawyer’s briefcase when their
back is turned. The briefcase owner may have a duty to ensure that the briefcase isn’t standing
open on opposing counsel’s conference table with sensitive material at the top of its contents, but
they shouldn’t have to lock it.
Web Bugs
The Committee received an inquiry regarding whether it is ethical for a lawyer to embed a “web
bug” in emails to other lawyers. As described in an opinion issued by the Illinois State Bar
Association Professional Conduct Advisory Committee, a “web bug”—also called a web beacon,
5
Page 6
pixel tag, clear GIF or invisible GIF 1—is a piece of software, hidden with an email message, that
“permit[s] the sender of an email message to secretly monitor the receipt and subsequent handling
of the message, including any attachments”:
The specific technology, operation, and other features of such software appear to
vary among vendors. Typically, however, tracking software inserts an invisible
image or code into an email message that is automatically activated when the email
is opened. Once activated, the software reports to the sender, without the knowledge
of the recipient, detailed information regarding the recipient’s use of the message.
Depending on the vendor, the information reported back to the sender may include:
when the email was opened; who opened the email; the type of device used to open
the email; how long the email was open; whether and how long any attachments,
or individual pages of an attachment, were opened; when and how often the email
or any attachments, or individual pages of an attachment, were reopened; whether
and what attachments were downloaded; whether and when the email or any
attachments were forwarded; the email address of any subsequent recipient; and the
general geographic location of the device that received the forwarded message or
attachment. At the sender’s option, tracking software can be used with or without
notice to the recipient.
ISBA Professional Conduct Advisory Opinion No. 18-01 (January 2018). It is easy to imagine the
various ways in which such information might provide the sending lawyer with significant insights
into the receiving lawyer’s work project, the lawyer’s communications to and from their client,
and how the lawyer and client evaluate the information in the email (and any documents attached)
and hence the matter within which the email has been generated. Importantly, unlike with
metadata-scrubbing software, there does not appear to be any readily available and consistently
reliable devices or programs capable of detecting or blocking web bugs before they have
transmitted data about the email recipient. Therefore, if a lawyer chooses to use a web bug,
there is no realistic way for the receiving lawyers to protect themselves.
The Illinois ethics opinion, as well opinions issued in Pennsylvania, Alaska, and New York,
conclude that the use of such software is ethically prohibited. See Pennsylvania Bar Association
Legal Ethics and Professional Responsibility Committee Formal Opinion No. 2017-300 (2017);
Alaska Bar Association Ethics Opinion No. 2016-1 (October 2016); New York State Bar
Association Opinion 749 (December 2001). The Committee agrees with the reasoning and
conclusions of these opinions. The use of such software constitutes an “unwarranted intrusion[]
into … the client-lawyer relationship,” which violates ER 4.4’s prohibition on a lawyer’s
employment of “methods of obtaining evidence that violate the legal rights of such a person.” Ariz.
R. Sup. Ct., Rule 42, ER 4.4(a) and Comment ¶ 1. It also falls within ER 8.4’s prohibition of
1
This opinion does not encompass services such as Constant Contact or MailChimp that track
emails but do so prominently displayed links and images that the email recipient can choose not
to click.
6
Page 7
“conduct involving dishonesty, fraud, deceit or misrepresentation. Ariz. R. Sup. Ct., Rule 42, ER
8.4(c).
7
Get today's answer for your situation
You just read a 2022 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.