NYSBA April 11, 2022

Can a lawyer let a smartphone app access the contacts list when it contains clients whose identity is confidential?

Short answer: Only with due diligence. The opinion concludes a lawyer may not grant an app access to contacts containing confidential client information unless, after reviewing the app's policies, the lawyer concludes no human will view it and it will not be sold or transferred to third parties without client consent.

Apply this to your situation

This page answers the general question as of 2022. Ezel answers yours: whether it's allowed on your facts, under the current New York Rules of Professional Conduct, with citations.

Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

The inquirer's smartphone, when downloading or opening apps, is sometimes asked to let the app access the phone's "contacts," which include clients from criminal representations. The question is whether the lawyer may consent.

The opinion grounds the analysis in Rule 1.6(c), which requires reasonable efforts to prevent unauthorized access to confidential information, and Rule 1.6(a)'s definition of confidential information (privileged, embarrassing or detrimental, or information the client asked be kept confidential). It draws the governing standard from N.Y. State 820 (2008), which permitted use of an email service that computer-scans messages for ads only if no human reads the messages and the provider does not reserve the right to disclose content to third parties without permission. The opinion also relies on N.Y. State 1088 (2016) for when a client's name is itself confidential, noting clients are more likely to find disclosure of the representation embarrassing or detrimental in criminal, bankruptcy, debt collection, or family law matters.

Applying these, the opinion says a lawyer must first determine whether even one contact is confidential, considering factors such as whether the contact data identifies the owner as a lawyer or names a practice area, whether people are labeled as clients, and whether the entry includes addresses, phone numbers, or other non-public information. If any contact is confidential, the lawyer must not grant the app access unless reasonable due diligence into the app's stated policies shows the information will be handled so that it is not disclosed to additional third parties without the client's consent.

In practice

Under this opinion, a New York lawyer should audit the smartphone contacts list before granting an app access, treating a contact as confidential where it would reveal a client relationship the client wants private or that could embarrass the client. Per the opinion, if any contact is confidential, the lawyer may consent only after reviewing the app's policies and concluding that no human will view the data and it will not be sold or transferred to other third parties without client consent.

Common questions

Q: Can a lawyer let apps access the phone's contacts at all?

A: Per the opinion, yes, if no contact is confidential; if any is, only after diligence shows the app will not expose it to humans or third parties without client consent.

Q: When is a client's name in the contacts confidential?

A: Per the opinion, when the client asked that it be kept confidential, or when, under N.Y. State 1088, disclosure of the representation would likely be embarrassing or detrimental, as is more likely in criminal, bankruptcy, debt collection, or family law matters.

Q: What standard governs sharing data with a technology provider?

A: Per the opinion, the N.Y. State 820 standard: permissible only if no human reads the information and the provider does not reserve the right to disclose it to third parties without permission.

Background and rules framework

The opinion interprets New York Rule 1.6, in particular the duty under Rule 1.6(c) to make reasonable efforts to prevent unauthorized access to confidential information and the Rule 1.6(a) definition of confidential information. Rule 1.6 corresponds to ABA Model Rule 1.6.

Citations and references

Rules of Professional Conduct:

  • New York Rules of Professional Conduct 1.6(a), 1.6(c)
  • ABA Model Rule 1.6 (analogue)

Other opinions cited:

  • N.Y. State 820 (2008): standard for using a provider that scans communications
  • N.Y. State 1088 (2016): when a client's name is confidential; N.Y. State 842 (2010), 709 (1998); N.Y. City 2017-5

See also

Source

Get today's answer for your situation

You just read a 2022 opinion on this question. Ezel checks the current New York Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.