What must a Colorado lawyer do after a data breach exposes client information?
Apply this to your situation
This page answers the general question as of 2020. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.
Plain-English summary
Opinion 141 addresses what ethical obligations arise from a breach of a lawyer's data systems. The Committee builds on its revised Formal Opinion 90 (preservation of client confidences in modern communications) and expressly concurs with and adopts the guidance of ABA Formal Op. 483, "Lawyers' Obligations After an Electronic Data Breach or Cyberattack" (2018). The opinion's syllabus states the core duty: a lawyer must make reasonable efforts to prevent, monitor for, halt, and investigate any security breach of data the lawyer controls, and in the event of a breach must timely notify current clients and affected third persons. The opinion expressly does not address separate statutory notification obligations or duties owed to third parties outside the ethics rules.
The duty is grounded in several Rules. Rule 1.6(c) requires reasonable efforts to prevent inadvertent or unauthorized disclosure of, or access to, information relating to a representation, and Comment [18] lists factors (sensitivity of the information, likelihood of disclosure, cost and difficulty of safeguards, and effect on the lawyer's ability to represent clients) for judging reasonableness. Rules 1.1 (competence, including keeping abreast of relevant technology), 5.1, and 5.3 require the lawyer to oversee staff and outside vendors. The opinion stresses that this is not a strict-liability standard: an ethical violation does not necessarily occur simply because an intrusion was not immediately detected, and the obligation is one of reasonable efforts, not invulnerability. It identifies three forms a breach can take, misappropriation of electronically stored information, destruction or alteration of it, or loss of access (such as a crypto-locking attack), and says a lawyer should develop an incident-response plan and a data-backup plan in advance, bearing any restoration losses as an overhead expense.
On notice, the opinion follows ABA Formal Op. 483: when a breach involves, or has a substantial likelihood of involving, material client confidential information, the lawyer has a duty under Rule 1.4(a)(3) and (b) to notify the client and explain the intrusion enough for the client to make informed decisions. Where information is merely rendered inaccessible, notice is required if the lawyer's provision of the services for which she was hired is significantly impaired. As to former clients, the Committee, like the ABA Standing Committee, is "unwilling to require notice to a former client as a matter of legal ethics" absent a black-letter rule, while encouraging lawyers to reach agreement with clients before or at termination about how their electronic information will be handled (Rules 1.16(d), 1.16A, 1.9(c)).
In practice
The opinion holds that, under the Colorado rules as they stood at the time of the opinion, a lawyer's obligations after a data breach are framed by reasonableness rather than a guarantee of security. Per the opinion, the lawyer must make reasonable efforts to prevent, monitor for, stop, and investigate a breach of data the lawyer controls (Rules 1.6(c), 1.1, 5.1, 5.3), and must timely notify a current client when a breach involves, or is substantially likely to involve, material confidential information, or when loss of access significantly impairs the services for which the lawyer was hired (Rule 1.4). The Committee declines to require notice to former clients as a matter of ethics, and it does not address separate statutory breach-notification duties, which it flags exist under Colorado law (C.R.S. sections 6-1-713.5 through 6-1-716). Because this opinion predates the most recent five years, verify the current Rules and any statutory notification requirements before relying on the specific obligations it describes.
Common questions
Q: Do I violate the ethics rules just because my firm got hacked?
A: Not automatically. The opinion adopts ABA Formal Op. 483's view that the duty is one of reasonable efforts, not strict liability, and that "an ethical violation does not necessarily occur if a cyber-intrusion or loss of electronic information is not immediately detected."
Q: When do I have to tell a client about a breach?
A: When the breach involves, or has a substantial likelihood of involving, material client confidential information, the opinion concludes the lawyer must notify the client under Rule 1.4 and explain the intrusion enough for the client to make informed decisions; loss-of-access events require notice if they significantly impair the services the lawyer was hired to perform.
Q: Do I have to notify former clients?
A: Not as a matter of ethics, under this opinion. The Committee, following the ABA, is "unwilling to require notice to a former client as a matter of legal ethics" in the absence of a black-letter rule, though it encourages agreeing with clients in advance about handling their electronic information.
Q: What am I expected to do before a breach happens?
A: The opinion says a lawyer should make reasonable efforts to prevent and monitor for breaches, and should develop an incident-response plan and a data-backup plan in advance, with restoration costs treated as the lawyer's overhead.
Background and rules framework
The opinion interprets Colo. RPC 1.6(c) (reasonable efforts to safeguard information relating to a representation) and its Comment [18] factors, together with Rule 1.1 (competence, including technological competence under Comment [8]), Rules 5.1 and 5.3 (supervision of lawyers, staff, and outside vendors), Rule 1.4(a) and (b) (communication), and Rules 1.9(c), 1.16(d), and 1.16A (former-client confidentiality and file duties). It adopts the framework of ABA Formal Op. 483 and builds on revised CBA Formal Op. 90 and ABA Formal Op. 477R. The opinion notes, without analyzing, that Colorado statutory breach-notification duties (C.R.S. 6-1-713.5 to 6-1-716) exist separately from the ethics rules.
Citations and references
Rules of Professional Conduct:
- Colo. RPC 1.6(c) / Model Rule 1.6(c) (reasonable efforts to prevent unauthorized disclosure or access)
- Colo. RPC 1.1 / Model Rule 1.1 (competence, including technology; Comment [8])
- Colo. RPC 5.1 and 5.3 / Model Rules 5.1, 5.3 (supervision of lawyers, staff, and nonlawyer assistants/vendors)
- Colo. RPC 1.4(a)(3) and (b) / Model Rule 1.4 (keeping the client informed)
- Colo. RPC 1.9(c), 1.16(d), 1.16A (former-client confidentiality; surrender and retention of files)
Statutes:
- C.R.S. sections 6-1-713.5 through 6-1-716 (Colorado statutory data-breach notification; noted as separate from ethics duties)
Other opinions cited:
- ABA Formal Op. 483 (2018): lawyers' obligations after an electronic data breach or cyberattack (adopted by the Committee)
- ABA Formal Op. 477R (2017): securing communication of protected client information
- CBA Formal Op. 90 (rev. 2018): preservation of client confidences in view of modern communications technology
See also
- ABA Formal Op. 483: Lawyers' Obligations After a Data Breach
- ABA Formal Op. 477R: Securing Communication of Client Information
- CA COPRAC Op. 2020-203: Data Breach
Source
- Landing page: https://www.cobar.org/ethicsopinions
- Original PDF: https://www.cobar.org/Portals/COBAR/Repository/ethicsOpinions/72020/Opinion%20141Final7-2020.pdf
Get today's answer for your situation
You just read a 2020 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.