Can an Illinois lawyer store client data with a cloud provider, and is due diligence at signup enough?
Apply this to your situation
This page answers the general question as of 2016. Ezel answers yours: whether it's allowed on your facts, under the current Illinois Rules of Professional Conduct, with citations.
Plain-English summary
A lawyer wants to contract with a third-party provider for cloud-based storage, processing, and transmission of client data in a shared, multi-tenant environment, and plans to conduct due diligence when selecting the provider. The committee is asked whether she may use such a provider and whether due diligence at signup is enough to avoid an ethics violation if a breach later occurs through provider failure or hackers.
The opinion concludes a lawyer may use cloud services, analogizing to ISBA Opinion 10-01 (lawyer may use an outside vendor to monitor a firm's network if reasonable steps protect confidentiality). It frames the issue under three rules: competence (Rule 1.1, whose amended Comment 8, effective January 1, 2016, requires lawyers to keep abreast of the benefits and risks of relevant technology); confidentiality (Rule 1.6, including new Rule 1.6(e)'s requirement of reasonable efforts to prevent inadvertent or unauthorized disclosure, with reasonableness factors in Comment 18); and supervision of nonlawyers (Rule 5.3). Quoting a Nevada opinion, the committee reasons that the risk of a rogue provider employee or hacker is no different in kind from the risk that an employee or burglar reaches paper files; the question is whether the lawyer acted reasonably and competently.
The opinion declines to set specific technical requirements because technology changes quickly, but lists reasonable due-diligence practices: reviewing industry standards; checking the provider's security precautions (firewalls, passwords, encryption), reputation, and breach history; requiring a confidentiality agreement and prompt breach notification; ensuring data is backed up under the lawyer's control; and providing for data retrieval if the agreement ends or the provider fails. On the second question, the opinion concludes the lawyer's obligations do not end at provider selection: Rules 1.6 and 5.3 impose ongoing duties, so the lawyer must conduct periodic reviews and monitor practices as technology evolves.
In practice
Under this opinion, a lawyer may store confidential client information in the cloud if she uses reasonable care to keep it secure, satisfying competence in selecting a provider and assessing risk (Rule 1.1), confidentiality (Rule 1.6), and supervision of the provider (Rule 5.3). The opinion holds that the duty is continuing: choosing a reputable provider does not by itself prevent a violation if a breach later occurs, because the lawyer must conduct periodic reviews and monitor whether the data remains adequately protected as technology changes. The committee deliberately declines to prescribe specific security technologies.
Common questions
Q: Can an Illinois lawyer keep client files in the cloud?
A: Yes. The opinion concludes a lawyer may use cloud-based services provided she takes reasonable steps to protect client confidentiality and secure the data under Rules 1.1, 1.6, and 5.3.
Q: Is doing due diligence when I sign up with the provider enough?
A: No. The opinion holds the obligation does not end at selection; Rules 1.6 and 5.3 require periodic review and ongoing monitoring because protective measures can become obsolete.
Q: What due diligence does the opinion suggest?
A: It lists reviewing industry standards, checking the provider's security, reputation and breach history, requiring a confidentiality and breach-notification agreement, and ensuring backups and data retrieval under the lawyer's control.
Background and rules framework
The opinion interprets Illinois Rule of Professional Conduct 1.1 (competence, including the technology-competence duty in amended Comment 8), Rule 1.6 (confidentiality, including Rule 1.6(e)'s reasonable-efforts requirement and Comment 18), and Rules 5.1 and 5.3 (supervision of lawyers and nonlawyer assistants). These correspond to Model Rules 1.1, 1.6, 5.1, and 5.3.
Citations and references
Rules:
- Illinois RPC 1.1 and Comment 8 (MR 1.1): competence and technology competence
- Illinois RPC 1.6, 1.6(e) and Comment 18 (MR 1.6): confidentiality and reasonable safeguards
- Illinois RPC 5.1, 5.3 (MR 5.1, 5.3): supervision of lawyers and nonlawyers
Other opinions cited:
- ISBA Opinion 10-01 (2009): outside vendor monitoring a firm's network
- Nevada Formal Opinion No. 33 (2006); Alabama Op. 2010-2; Iowa Op. 11-01; Tennessee Op. 2015-F-159; Arizona Op. 09-04; Washington State Bar Op. 2215: cloud storage of client data
See also
- NY State Bar Op. 842: Using an Outside Online Storage Provider for Client Data
- NY State Bar Op. 1020: Cloud Storage for Sharing Transaction Documents
- ABA Formal Op. 498: Virtual Practice
Source
- Landing page: https://www.isba.org/ethics/opinions/1606
Get today's answer for your situation
You just read a 2016 opinion on this question. Ezel checks the current Illinois Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.