DCBAR February 18, 1998

Can a D.C. lawyer send confidential client information by unencrypted email over the Internet without violating the confidentiality rule?

Short answer: The opinion concluded that, in most circumstances, transmitting confidential information by unencrypted email does not by itself violate Rule 1.6, because the rule requires reasonable, not absolute, efforts to protect confidentiality and email is no more exposed than the telephone or fax. The committee added that the sensitivity of the contents or the circumstances of a particular transmission may call for greater security in specific cases.

Apply this to your situation

This page answers the general question as of 1998. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.

Currency note: this opinion is from 1998
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

Opinion 281 (adopted February 18, 1998) considered whether a lawyer who communicates about confidential matters with clients, or with co-counsel jointly representing clients, by unencrypted email over commercial services or the Internet violates Rule 1.6. The committee concluded that the use of unencrypted email is not, by itself, a violation.

The committee noted that a number of early ethics opinions had held that unencrypted electronic transmission violated the confidentiality rule, on the theory that email was too susceptible to interception to use without specific client consent, but that the prevailing later view, which the committee adopted, treats electronic transmission as an acceptable means of conveying client confidences even without specific consent. It identified what it saw as three errors in the pre-1997 opinions. First, every method of communication is subject to some risk of interception (a bugged conference room, a tapped phone line, an intercepted fax), so the question under Rule 1.6 is whether one might reasonably expect the message to remain confidential; the rule requires reasonable, not absolute, security. Second, while a message travels over the Internet it is broken into packets that are difficult to intercept and reassemble, making the risk no greater than the risk that a careless or dishonest phone-company employee could access a telephone call. Third, the Electronic Communications Privacy Act of 1986 (as amended in 1994), 18 U.S.C. Section 2511, makes interception illegal, and 18 U.S.C. Section 2517(4) provides that an intercepted privileged communication does not lose its privileged character, which has supported a reasonable expectation of privacy in electronic messages.

The committee held that the mere use of electronic communication does not violate Rule 1.6 absent special factors, but added an important qualification: the sensitivity of the contents or the circumstances of a particular transmission may dictate higher levels of security in specific instances. Its illustration involved the medium generally, not just email. A lawyer representing an associate in a dispute with the associate's firm could violate Rule 1.6 by faxing confidential information to the firm's mailroom, where others might see it; by the same logic, unencrypted email may be unacceptable in a particular factual context even though it is ordinarily permissible.

Currency note

This opinion was issued in 1998, before the District of Columbia's adoption of the 2007 revisions to the Rules of Professional Conduct. Subsequent rule amendments or later opinions may have changed the analysis. Treat this page as historical context, not current guidance. Verify against current rules before relying on any specific rule, deadline, or requirement mentioned here.

Common questions

Q: Did the opinion require lawyers to encrypt confidential emails?

A: No. The committee concluded that unencrypted email is not, by itself, a violation of Rule 1.6, because the rule requires reasonable rather than absolute efforts to protect confidentiality.

Q: Why did the committee treat email like the telephone and fax?

A: The committee reasoned that every method of communication carries some risk of interception, and that an email broken into packets traveling the Internet is no more exposed than a phone call that a careless or dishonest phone-company employee could access; the legal test is whether one might reasonably expect the message to stay confidential.

Q: Were there situations where the opinion said more security might be required?

A: Yes. The committee concluded that the sensitivity of the contents or the circumstances of a particular transmission may, in specific instances, call for higher security, using the example of confidential information sent to a location where others are likely to see it.

Q: Did the opinion rely on any law outside the ethics rules?

A: Yes. The committee pointed to the Electronic Communications Privacy Act, 18 U.S.C. Section 2511, which makes interception illegal, and Section 2517(4), which preserves the privileged character of an intercepted communication, as support for a reasonable expectation of privacy in email.

Background and rules framework

The opinion interpreted D.C. Rule 1.6 (confidentiality of information), including Rule 1.6(e)'s requirement that lawyers ensure persons working for them use reasonable means to protect client information. It read the rule to require reasonable, not absolute, efforts to maintain confidentiality, and drew on out-of-jurisdiction opinions and the Electronic Communications Privacy Act in reaching its conclusion.

Citations and references

Rules of Professional Conduct:

  • D.C. RPC 1.6 / Model Rule 1.6 (confidentiality of information)

Statutes:

  • 18 U.S.C. Section 2511 (Electronic Communications Privacy Act; interception unlawful)
  • 18 U.S.C. Section 2517(4) (intercepted communication retains privileged character)

Cases:

  • United States v. Keystone Sanitation Co., 903 F. Supp. 803 (M.D. Pa. 1995), reasonable expectation of privacy in electronic messages
  • United States v. Maxwell, 43 Fed. R. Serv. 24 (A.F. Ct. Crim. App. 1995), expectation of privacy in email

Other opinions cited:

  • Vermont Advisory Ethics Op. 97-5; North Dakota Ethics Op. 97-09 (1997); Illinois State Bar Op. 96-10 (1997); Arizona Formal Op. 97-04 (1997); South Carolina Op. 97-08 (1997, overruling Op. 94-27)

See also

Source

Get today's answer for your situation

You just read a 1998 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.