Can a lawyer store confidential client files electronically on a third party's server, outside the lawyer's exclusive control, without violating confidentiality?
Apply this to your situation
This page answers the general question as of 2006. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.
Plain-English summary
A Nevada attorney asked whether storing electronic client files containing confidential information on a server physically located and maintained by a third party, outside the attorney's direct control, violates the duty of confidentiality. The Committee broadened the question to whether a lawyer violates SCR 156 by storing confidential client information electronically, without client consent, on a device not exclusively in the lawyer's control. It assumed the lawyer's contract required the third party to use all reasonably necessary means to preserve confidentiality and prevent unauthorized access, but that the third party's employees would have access in the course of their work.
The Committee answered that the confidentiality duty is not absolute: the lawyer must act competently and reasonably to safeguard confidential information against inadvertent and unauthorized disclosure, but a lawyer is not strictly liable for every breach. It analogized electronic third-party storage to storing paper files in a third-party warehouse, where the same risk of access by an outside employee exists yet the arrangement is not prohibited. Surveying ABA authority, the opinion relied on ABA Informal Opinion 1127 (central computer storage), ABA Formal Opinion 95-398 (a computer-maintenance company's access, where the duty is not breached so long as the lawyer is reasonable and competent in arranging and managing the outside contractor), and ABA Formal Opinion 99-413 (unencrypted email affords a reasonable expectation of privacy), along with the Ethics 2000 comments [16] and [17] to Model Rule 1.6.
From these, the Committee concluded that traditional confidentiality rules apply to new forms of communication and document storage, and that a lawyer is not responsible for a breach merely by storing information in a way that makes a breach possible, so long as the lawyer (1) exercises reasonable care in selecting a third-party contractor that can be reasonably relied on to keep the information confidential, (2) has a reasonable expectation that the information will be kept confidential, and (3) instructs and requires the contractor to keep the information confidential and inaccessible. A client may consent to any manner of storage, and while the rules prefer that the lawyer obtain informed consent before transmitting confidential information to third parties, they do not prohibit such electronic storage without client consent as long as it complies with the duty to competently and reasonably safeguard confidentiality.
Currency note
This opinion was issued in early 2006, before (and contemporaneously with) the State Bar of Nevada's adoption of the Nevada Rules of Professional Conduct (effective 2006), and interprets former SCR 156 (now NRPC 1.6). It predates the widespread adoption of cloud computing and the ABA's and many states' later, more detailed guidance on cloud storage, encryption, and vendor due diligence. Treat its "reasonable care" framework as the baseline it described at the time and verify current rules and guidance before relying on specifics.
In practice
The opinion holds that, under the rules then in force, a lawyer may use an outside agency to store confidential client information electronically, even without client consent, provided the lawyer reasonably believes confidentiality will be preserved, the provider agrees to maintain it, and the lawyer selects and manages the contractor competently. If the lawyer does not reasonably believe confidentiality will be preserved, or the provider will not agree to keep the information confidential, transmitting the data violates the rule. This duty now sits under NRPC 1.6, and later cloud-specific guidance should be consulted.
Common questions
Q: Does using an outside server or vendor for client files break the duty of confidentiality?
A: Not by itself. The opinion concluded that storing confidential client information with a competent, reliable third party that agrees to keep it confidential does not violate the rule, even if an inadvertent or unauthorized disclosure later occurs.
Q: Is the lawyer strictly liable if the vendor leaks client data?
A: No. The opinion explained the duty is not absolute and the lawyer is not strictly liable; the obligation is to act competently and reasonably to safeguard the information.
Q: Does the lawyer need client consent to store files with a third party?
A: Per the opinion, no, so long as the arrangement complies with the duty to competently and reasonably safeguard confidentiality; the rules prefer informed consent but do not require it for compliant storage.
Q: What should the lawyer do when choosing a storage provider?
A: The opinion lists three things: exercise reasonable care selecting a contractor that can be relied on to keep the information confidential, have a reasonable expectation of confidentiality, and instruct and require the contractor to keep the information confidential and inaccessible.
Background and rules framework
The opinion interprets former SCR 156 (confidentiality; now NRPC 1.6), drawing on the Ethics 2000 comments [16] and [17] to ABA Model Rule 1.6 and on ABA opinions addressing electronic storage and transmission of client information (Informal Op. 1127; Formal Ops. 95-398 and 99-413).
Citations and references
Rules of Professional Conduct:
- Model Rule 1.6 / Nev. SCR 156 (now NRPC 1.6) (confidentiality; comments [16]-[17])
Other opinions cited:
- ABA Formal Op. 95-398 (1995): a maintenance company's access to a lawyer's computer data
- ABA Formal Op. 99-413 (1999): confidentiality and unencrypted email
- ABA Informal Op. 1127 (1970): central computer storage of client information
See also
- ABA Formal Op. 95-398: nonlawyer access to a lawyer's computer database
- CA COPRAC Op. 2023-208: remote practice and protecting client information
Source
- Landing page: https://nvbar.org/for-lawyers/ethics-discipline/ethics-opinions/
- Original PDF: https://nvbar.org/wp-content/uploads/opinion_33.pdf
Get today's answer for your situation
You just read a 2006 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.