Can a law firm store client files with a third-party online vendor, such as in the cloud, and access them remotely?
Apply this to your situation
This page answers the general question as of 2026. Ezel answers yours: whether it's allowed on your facts, under the current Oregon Rules of Professional Conduct, with citations.
Plain-English summary
A law firm contracts with a third-party vendor to store client files and documents online on a remote server, so the lawyer and client can access them over the internet from any location. The opinion asks whether the lawyer may do so, and answers yes, qualified.
The opinion applies Oregon RPC 1.6, which requires keeping client information confidential and, in subsection (c), requires reasonable efforts to prevent inadvertent or unauthorized disclosure of or access to that information, together with Oregon RPC 5.3, which governs a lawyer's responsibility for nonlawyer service providers. It concludes a lawyer may store client materials on a third-party server as long as the lawyer satisfies the duties of competence and confidentiality by reasonably keeping the information secure. That requires taking reasonable steps to ensure the storage company will reliably secure the data and keep it confidential, which may be satisfied by a vendor's compliance with industry standards if those standards meet the minimum requirements the rules impose on the lawyer.
The opinion identifies concrete reasonable steps: ensuring the service agreement requires the vendor to preserve the confidentiality and security of the materials, requiring the vendor to notify the lawyer of any unauthorized third-party access, and investigating how the vendor backs up and stores its data and metadata. The opinion notes that the reasonableness of the steps is measured against the technology available at the time to secure data against unintentional disclosure, that Oregon RPC 1.6(c) does not require protecting against advanced state-level interception beyond the public's reach, and that because a vendor's protections may become obsolete, the lawyer may need to reevaluate them over time. A lawyer handling national-security matters may want additional precautions, and the lawyer's obligations after a security breach are outside the opinion's scope.
In practice
This opinion was revised in 2026 and interprets the current Oregon Rules of Professional Conduct. The opinion holds that third-party or cloud storage of client files is permissible when the lawyer takes reasonable steps to secure the data and keep it confidential. Per the opinion, the analysis turns on reasonableness under Oregon RPC 1.6(c): a written vendor agreement requiring confidentiality, security, and breach notice; investigation of the vendor's backup and storage practices; and reliance on industry standards only where they meet the rules' minimums. The opinion holds that reasonableness is judged against current technology and that the lawyer may need to reassess a vendor's safeguards as technology advances.
Common questions
Q: Can an Oregon lawyer keep client files with a cloud or third-party storage vendor?
A: Yes, qualified. The opinion concludes a lawyer may store client materials on a third-party server if the lawyer meets the competence and confidentiality duties by reasonably securing the data.
Q: What steps does the lawyer have to take with the vendor?
A: The opinion concludes reasonable steps may include a service agreement requiring the vendor to preserve confidentiality and security, requiring notice of unauthorized access, and investigating how the vendor backs up and stores data and metadata.
Q: Does relying on the vendor's industry-standard security satisfy the rules?
A: It can. The opinion concludes a vendor's compliance with industry standards may satisfy the lawyer's duty, but only if those standards meet the minimum requirements the rules impose on the lawyer.
Q: Is the lawyer's duty a one-time check?
A: No. The opinion concludes reasonableness is measured against current technology, and because a vendor's protections may become obsolete, the lawyer may be required to reevaluate them over time.
Background and rules framework
The opinion interprets Oregon RPC 1.6 (confidentiality), including the reasonable-care duty in 1.6(c), and Oregon RPC 5.3 (responsibilities regarding nonlawyer assistance), corresponding to Model Rules 1.6 and 5.3. It treats third-party online storage, sometimes called cloud computing, as permissible subject to reasonable safeguards.
Citations and references
Rules of Professional Conduct:
- Oregon RPC 1.6 / Model Rule 1.6 (confidentiality; reasonable care against unauthorized access)
- Oregon RPC 5.3 / Model Rule 5.3 (responsibilities regarding nonlawyer assistance)
Other opinions cited:
- OSB Formal Ethics Op. No. 2005-141 (rev 2026) (third-party handling of client materials); OSB Formal Ethics Op. No. 2005-129 (rev 2026)
- New Jersey Ethics Op. No. 701; Arizona Ethics Op. No. 09-04 (electronic storage of client files)
See also
- ABA Formal Op. 477R: Securing Communication of Protected Client Information
- ABA Formal Op. 483: Lawyers' Obligations After an Electronic Data Breach
- OSB Ethics Op. 2005-141: Recycling Client Documents
Source
- Landing page: https://www.osbar.org/ethics/toc.html
- Original PDF: https://www.osbar.org/_docs/ethics/2011-188.pdf
Get today's answer for your situation
You just read a 2026 opinion on this question. Ezel checks the current Oregon Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.