ISBA 2016

Can an Illinois lawyer store client data with a cloud provider, and is due diligence at signup enough?

Short answer: Yes, with reasonable safeguards. The opinion concludes a lawyer may use cloud services if she takes reasonable steps to protect client data, and the duty continues; selecting a reputable provider does not end the obligation to monitor.

Apply this to your situation

This page answers the general question as of 2016. Ezel answers yours: whether it's allowed on your facts, under the current Illinois Rules of Professional Conduct, with citations.

Currency note: this opinion is from 2016
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

A lawyer wants to contract with a third-party provider for cloud-based storage, processing, and transmission of client data in a shared, multi-tenant environment, and plans to conduct due diligence when selecting the provider. The committee is asked whether she may use such a provider and whether due diligence at signup is enough to avoid an ethics violation if a breach later occurs through provider failure or hackers.

The opinion concludes a lawyer may use cloud services, analogizing to ISBA Opinion 10-01 (lawyer may use an outside vendor to monitor a firm's network if reasonable steps protect confidentiality). It frames the issue under three rules: competence (Rule 1.1, whose amended Comment 8, effective January 1, 2016, requires lawyers to keep abreast of the benefits and risks of relevant technology); confidentiality (Rule 1.6, including new Rule 1.6(e)'s requirement of reasonable efforts to prevent inadvertent or unauthorized disclosure, with reasonableness factors in Comment 18); and supervision of nonlawyers (Rule 5.3). Quoting a Nevada opinion, the committee reasons that the risk of a rogue provider employee or hacker is no different in kind from the risk that an employee or burglar reaches paper files; the question is whether the lawyer acted reasonably and competently.

The opinion declines to set specific technical requirements because technology changes quickly, but lists reasonable due-diligence practices: reviewing industry standards; checking the provider's security precautions (firewalls, passwords, encryption), reputation, and breach history; requiring a confidentiality agreement and prompt breach notification; ensuring data is backed up under the lawyer's control; and providing for data retrieval if the agreement ends or the provider fails. On the second question, the opinion concludes the lawyer's obligations do not end at provider selection: Rules 1.6 and 5.3 impose ongoing duties, so the lawyer must conduct periodic reviews and monitor practices as technology evolves.

In practice

Under this opinion, a lawyer may store confidential client information in the cloud if she uses reasonable care to keep it secure, satisfying competence in selecting a provider and assessing risk (Rule 1.1), confidentiality (Rule 1.6), and supervision of the provider (Rule 5.3). The opinion holds that the duty is continuing: choosing a reputable provider does not by itself prevent a violation if a breach later occurs, because the lawyer must conduct periodic reviews and monitor whether the data remains adequately protected as technology changes. The committee deliberately declines to prescribe specific security technologies.

Common questions

Q: Can an Illinois lawyer keep client files in the cloud?

A: Yes. The opinion concludes a lawyer may use cloud-based services provided she takes reasonable steps to protect client confidentiality and secure the data under Rules 1.1, 1.6, and 5.3.

Q: Is doing due diligence when I sign up with the provider enough?

A: No. The opinion holds the obligation does not end at selection; Rules 1.6 and 5.3 require periodic review and ongoing monitoring because protective measures can become obsolete.

Q: What due diligence does the opinion suggest?

A: It lists reviewing industry standards, checking the provider's security, reputation and breach history, requiring a confidentiality and breach-notification agreement, and ensuring backups and data retrieval under the lawyer's control.

Background and rules framework

The opinion interprets Illinois Rule of Professional Conduct 1.1 (competence, including the technology-competence duty in amended Comment 8), Rule 1.6 (confidentiality, including Rule 1.6(e)'s reasonable-efforts requirement and Comment 18), and Rules 5.1 and 5.3 (supervision of lawyers and nonlawyer assistants). These correspond to Model Rules 1.1, 1.6, 5.1, and 5.3.

Citations and references

Rules:

  • Illinois RPC 1.1 and Comment 8 (MR 1.1): competence and technology competence
  • Illinois RPC 1.6, 1.6(e) and Comment 18 (MR 1.6): confidentiality and reasonable safeguards
  • Illinois RPC 5.1, 5.3 (MR 5.1, 5.3): supervision of lawyers and nonlawyers

Other opinions cited:

  • ISBA Opinion 10-01 (2009): outside vendor monitoring a firm's network
  • Nevada Formal Opinion No. 33 (2006); Alabama Op. 2010-2; Iowa Op. 11-01; Tennessee Op. 2015-F-159; Arizona Op. 09-04; Washington State Bar Op. 2215: cloud storage of client data

See also

Source

Get today's answer for your situation

You just read a 2016 opinion on this question. Ezel checks the current Illinois Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.