Can a lawyer store client confidential information with an outside online 'cloud' storage provider, and what precautions are required?
Apply this to your situation
This page answers the general question as of 2010. Ezel answers yours: whether it's allowed on your facts, under the current New York Rules of Professional Conduct, with citations.
Plain-English summary
A solo practitioner wants to back up client files to an online "cloud" data-storage system (servers maintained by an outside provider) so the files survive if the lawyer's own computers fail; the system is password-protected and the data is encrypted. The opinion asks whether storing confidential information this way is consistent with the duty of confidentiality, and what steps are required.
The opinion grounds the analysis in Rule 1.6. Rule 1.6(a) bars knowingly revealing confidential information without an exception, but the opinion stresses that the duty goes further: a lawyer must take reasonable care to affirmatively protect the information, citing N.Y. County 733 (2004). Rule 1.6(c) requires a lawyer to exercise reasonable care to prevent others whose services the lawyer uses from disclosing client information. The opinion is careful to note that "reasonable care" does not mean the lawyer guarantees the information is secure against any unauthorized access. It draws an analogy to N.Y. State 709 (1998) (transmitting confidential information by email is permitted with reasonable care, but extraordinarily sensitive information may require a more secure means under the lawyer's control), and to opinions from New Jersey and Arizona approving electronic storage of client files with sufficient precautions.
The opinion concludes that a lawyer may use a cloud backup system to store client files provided the lawyer takes reasonable care that the system is secure and confidentiality is maintained. It lists steps that may be part of reasonable care: (1) ensuring the provider has an enforceable confidentiality and security obligation and will notify the lawyer if served with process for client information; (2) investigating the provider's security measures, policies, and recovery methods; (3) using available technology to guard against reasonably foreseeable attempts to infiltrate the data; and (4) investigating the provider's ability to purge and wipe copies and migrate the data if the lawyer changes providers.
Finally, the opinion emphasizes that the duty is ongoing. Because technology and the security of stored data change rapidly, the lawyer should periodically reconfirm that the provider's measures remain effective; if the lawyer learns the measures are inadequate or learns of a breach, the lawyer must investigate, notify any affected clients (Rule 1.4), and discontinue the service absent adequate remediation. The opinion also directs lawyers to monitor developments in the law of privilege, citing City of Ontario v. Quon and Stengart v. Loving Care Agency.
In practice
Under this opinion, a New York lawyer may store and back up client confidential information with an outside cloud provider, but the permission is conditioned on the lawyer exercising reasonable care under Rule 1.6: vetting the provider's confidentiality obligations and security, using available protective technology, and retaining the ability to move or purge the data. The opinion holds that the obligation continues after setup; the lawyer should periodically reconfirm the provider's security and, on learning of inadequacy or a breach, must investigate, notify affected clients under Rule 1.4, and stop using the service unless the issue is remediated.
Common questions
Q: Can a New York lawyer store client files in the cloud?
A: Yes. The opinion concludes a lawyer may use an online cloud data-backup system to store client files, provided the lawyer takes reasonable care under Rule 1.6 to ensure the system is secure and confidentiality is maintained.
Q: Does the lawyer have to guarantee the data can never be accessed by anyone?
A: No. The opinion states that exercising "reasonable care" under Rule 1.6 does not mean the lawyer guarantees the information is secure from any unauthorized access.
Q: What steps count as reasonable care with a cloud provider?
A: The opinion lists ensuring an enforceable confidentiality and security obligation (and notice if the provider is served with process), investigating the provider's security and recovery methods, using available technology against infiltration, and confirming the provider can purge data and allow migration.
Q: Is the lawyer's duty over once the provider is selected?
A: No. The opinion says the lawyer should periodically reconfirm the provider's security as technology changes, and on learning of inadequate security or a breach must investigate, notify affected clients under Rule 1.4, and discontinue the service absent adequate remediation.
Background and rules framework
The opinion interprets New York Rule 1.6, which corresponds to Model Rule 1.6 (confidentiality of information). Rule 1.6(a) prohibits knowingly revealing confidential information, and Rule 1.6(c) requires reasonable care to prevent others whose services the lawyer uses from disclosing it. Rule 1.4 (Model Rule 1.4, communication) supports the duty to notify clients of a breach. The opinion applies the confidentiality framework to outsourced electronic storage, building on N.Y. State 709 (1998) on electronic transmission and on out-of-state opinions approving electronic file storage with safeguards.
Citations and references
Rules of Professional Conduct:
- MR 1.6 (confidentiality of information)
- MR 1.4 (communication)
- NY Rule 1.6(a), (c); NY Rule 1.4
Cases:
- City of Ontario, Calif. v. Quon, 130 S. Ct. 2619 (2010), on review of messages on government pagers
- Scott v. Beth Israel Medical Center, 17 Misc. 3d 934 (N.Y. Sup. 2007), on email privilege under an employer monitoring policy
- Stengart v. Loving Care Agency, Inc., 201 N.J. 300 (2010), on privilege in personal email accessed on an employer device
Other opinions cited:
- N.Y. State 709 (1998): reasonable care in transmitting confidential information by email
- N.Y. County 733 (2004): duty to preserve client confidences in digital or paper form
- New Jersey Opinion 701 (2006); Arizona Opinions 05-04 and 09-04: electronic storage of client files with precautions
See also
- NY State Bar Op. 1020: Cloud storage for sharing transaction documents
- NY State Bar Op. 1019: Remote access to firm files from home
- TX Ethics Op. 705: Generative AI in the practice of law
Source
- Landing page: https://nysba.org/ethics-opinion-842/
Get today's answer for your situation
You just read a 2010 opinion on this question. Ezel checks the current New York Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.