NYSBA December 8, 2004

Does a lawyer who emails a document containing metadata that reveals client confidences violate the duty of confidentiality?

Short answer: Lawyers must exercise reasonable care when transmitting documents by email to prevent disclosure of confidences and secrets contained in metadata. What reasonable care requires varies with the circumstances, and in some cases (such as a template reused from another client) it calls for removing the metadata.

Apply this to your situation

This page answers the general question as of 2004. Ezel answers yours: whether it's allowed on your facts, under the current New York Rules of Professional Conduct, with citations.

Currency note: this opinion is from 2004
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

DR 4-101(B) bars a lawyer from "knowingly" revealing a client's confidence or secret. The committee was asked whether a lawyer who transmits documents containing metadata reflecting client confidences or secrets violates that rule. The committee explains that word-processing software such as Microsoft Word and WordPerfect creates metadata, hidden data generated while creating and editing documents, which can include prior edits, comments, the names of people who worked on a document, prior versions, and similar information. Not all metadata is a confidence or secret, but it may reveal privileged or embarrassing information. The committee gives a striking example: a prosecutor reusing one cooperating witness's agreement as a template could, through the new document's metadata, expose the original witness's name.

The committee analyzes the duty under DR 4-101. While DR 4-101(B)(1) bars "knowing" disclosure, DR 4-101(D) requires a lawyer to exercise reasonable care to prevent employees, associates, and others whose services the lawyer uses from disclosing confidences or secrets, and EC 4-5 directs care to prevent disclosure. Drawing on N.Y. State 709 (1998), the committee holds that a lawyer using technology must use reasonable care and assess the risks of the transmission method. So when sending a document by email, a lawyer must exercise reasonable care not to inadvertently disclose confidential information. What constitutes reasonable care varies with the subject matter, whether the document was based on a template used for another client, whether there were multiple drafts with comments from multiple sources, whether the client commented, and the identity of the recipients; in some circumstances it may require staying abreast of the technology and the risks, and removing metadata (for example, where the lawyer knows the metadata reflects confidences or is sending to a technologically sophisticated adversary).

The committee also addresses the recipient side: under N.Y. State 749 (2003), a lawyer-recipient may not use technology to mine an opponent's metadata for confidences, which is an impermissible intrusion on the attorney-client relationship; and N.Y. State 700 (1997) treats exploiting an unauthorized disclosure as conduct prejudicial to the administration of justice. It notes that non-lawyer recipients have no comparable Code obligation.

In practice

Under the New York Code as it stood at the time, the opinion holds that emailing a document is like any other communication: the lawyer must use reasonable care under DR 4-101 to avoid inadvertently disclosing confidences and secrets carried in metadata. The committee makes the standard explicitly fact-dependent, listing factors (template reuse, multiple drafters or comments, the recipient's identity and sophistication) that raise the level of care, and notes that in some situations reasonable care calls for removing the metadata before sending. It also confirms the receiving lawyer's separate duty not to exploit metadata in documents an adversary sends.

Common questions

Q: Can a lawyer be responsible for confidential metadata in a document they email?

A: Yes. The committee holds that DR 4-101 requires reasonable care to prevent disclosing client confidences and secrets contained in metadata when transmitting documents by email.

Q: Does the lawyer always have to scrub metadata before sending?

A: Not always. The committee makes the duty one of reasonable care that varies with the circumstances, but notes that in some situations (such as a reused template or a sophisticated adversary recipient) reasonable care may require removing the metadata.

Q: What factors raise the level of care required?

A: The committee lists the document's subject matter, whether it was based on a template used for another client, whether there were multiple drafts and comments, whether the client commented, and the identity of the recipients.

Q: Can the lawyer who receives a document mine its metadata?

A: No. The committee, citing N.Y. State 749, treats using technology to access an opponent's confidences revealed in metadata as an impermissible intrusion on the attorney-client relationship.

Background and rules framework

The opinion applies New York's former Code of Professional Responsibility. DR 4-101(B), (C), and (D) govern the duty of confidentiality, its exceptions, and the duty to exercise reasonable care to prevent disclosure by others (analogous to Model Rules 1.6 and 5.3). DR 1-102(A)(5) bars conduct prejudicial to the administration of justice. The analysis builds on N.Y. State 709 (1998), 749 (2003), and 700 (1997).

Citations and references

Rules of Professional Conduct:

  • MR 1.6 (confidentiality; reasonable efforts to prevent disclosure); NY DR 4-101(B), (C), (D)
  • MR 5.3 (responsibilities regarding nonlawyer assistance); NY DR 4-101(D)

Other opinions cited:

  • N.Y. State 709 (1998): reasonable care in using technology to communicate
  • N.Y. State 749 (2003): a lawyer may not mine an opponent's metadata for confidences
  • N.Y. State 700 (1997): exploiting an unauthorized disclosure is prejudicial to the administration of justice

See also

Source

Get today's answer for your situation

You just read a 2004 opinion on this question. Ezel checks the current New York Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.