UTAHBAR March 9, 2000

Can a lawyer send a client's confidential information by ordinary unencrypted email without violating the duty of confidentiality?

Short answer: Yes. In ordinary circumstances a lawyer may use unencrypted Internet email to transmit confidential client information, because there is a reasonable expectation of privacy in its use; particularly sensitive information or a higher interception risk may call for greater security or following the client's instructions.

Apply this to your situation

This page answers the general question as of 2000. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.

Currency note: this opinion is from 2000
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page as a PDF) is the authoritative source for any reliance.
View original ethics opinion (PDF)

Plain-English summary

Opinion 00-01 addressed a lawyer's duty to protect client confidentiality when using Internet email. The Committee concluded that, in ordinary circumstances, a lawyer may use unencrypted Internet email to transmit confidential client information without violating the Rules. Rule 1.6 imposes a duty to protect confidential information against unauthorized use or disclosure, and opinions addressing electronic communication frame that duty in terms of using a means of communication carrying a reasonable expectation that the information will remain confidential.

The Committee explained that landline telephone, fax, and ordinary mail carry a reasonable expectation of privacy even though interception is possible, and that this level of security (scrambling, encryption, hand-delivery) is not normally required. State bar associations that had considered the issue concluded, with few exceptions, that a reasonable expectation of privacy exists in Internet email. The Committee relied on ABA Formal Opinion 99-413, which concluded that sending confidential client information by unencrypted email does not violate Model Rule 1.6(a) because there is a reasonable expectation of privacy, given the difficulty of intercepting direct email, the huge volume of email traffic, and the fact that interception is a criminal act under the Electronic Communications Privacy Act.

The Committee added qualifications. Where the client information is particularly sensitive, or the lawyer has reason to believe the risk of interception is higher, the lawyer may want to use a means of communication with higher security. The lawyer should abide by any client policy regarding the use of email for confidential information, and a lawyer may wish to advise a client at the time of retention that the lawyer intends to use unencrypted email as one method of communication.

Currency note

This opinion was issued in 2000, before the Utah State Bar's adoption of the 2005 revisions to the Rules of Professional Conduct (the Ethics 2000-based amendments approved by the Utah Supreme Court on September 29, 2005). Subsequent rule amendments or later opinions may have changed the analysis. Treat this page as historical context, not current guidance. Verify against current rules before relying on any specific rule, deadline, or requirement mentioned here.

Common questions

Q: Does a lawyer have to encrypt email to a client?

A: No, not ordinarily. The opinion concluded that in ordinary circumstances a lawyer may use unencrypted Internet email to transmit confidential client information, because there is a reasonable expectation of privacy in its use.

Q: Does the risk that a hacker or ISP could intercept email make its use unethical?

A: No. The opinion stated that the capability of ISP administrators or hackers to intercept email (in violation of federal law) does not render the expectation of privacy unreasonable, any more than the risk of an illegal phone tap removes the reasonable expectation of privacy in a landline call.

Q: When should a lawyer use something more secure than ordinary email?

A: When the matter warrants it. The opinion stated that where the information is particularly sensitive, or the lawyer has reason to believe the interception risk is higher, the lawyer may want a means of communication with higher security and should follow any client policy on the use of email.

Background and rules framework

The opinion interpreted Utah Rule of Professional Conduct 1.6 (confidentiality of information, Model Rule 1.6), which provides that a lawyer shall not reveal information relating to representation of a client except as stated in the rule unless the client consents after consultation. The analysis turned on the "reasonable expectation of privacy" standard the Committee drew from contemporaneous bar opinions and from ABA Formal Opinion 99-413, treating email as functionally comparable to telephone, fax, and mail for confidentiality purposes.

Citations and references

Rules of Professional Conduct:

  • Model Rule 1.6 / Utah Rule 1.6 (confidentiality of information)

Statutes:

  • Electronic Communications Privacy Act, 18 U.S.C. §§ 2510 et seq. (1994)

Other opinions cited:

  • ABA Formal Op. 99-413: unencrypted email does not violate Model Rule 1.6(a)
  • S.C. Bar Op. 97-08; Ill. State Bar Op. 96-10; N.Y. State Bar Op. 709 (1998); Alaska Bar Op. 98-2; D.C. Bar Op. 281 (1998); Ky. Bar Op. E-403 (1998): reasonable expectation of privacy in email

See also

Source

Original opinion text

Reproduced from the official source for research purposes. The two-column PDF has been reassembled into reading order by paragraph; the linked source is authoritative.

Utah Ethics Opinions 2000. 00-01. USB EAOC Opinion No. 00-01

Utah State Bar Ethics Advisory Opinion Committee

Opinion No. 00-01 Approved March 9, 2000

Issue: What are the ethical obligations of a lawyer to protect client confidentiality in the use of Internet e-mail communications?

Opinion: A lawyer may, in ordinary circumstances, use unencrypted Internet e-mail to transmit client confidential information without violating the Utah Rules of Professional Conduct.

Analysis: Utah Rules of Professional Conduct 1.6 imposes a duty on the lawyer to protect confidential information against unauthorized use or disclosure. (fn1) Opinions that have addressed this issue in the area of electronic communication have characterized the obligation of the lawyer to use a means of communication that has a "reasonable expectation" that the information will remain confidential. (fn2)

With respect to land-line telephone, fax machine and ordinary mail, a reasonable expectation of privacy has been deemed to exist, and a lawyer can use these means of communication to transmit confidential client information. It is recognized that a reasonable expectation of privacy does not mean certainty of privacy. Land-line telephone conversations can be intercepted, and the means to prevent interception are available through scrambling technology. Faxes can also be encrypted, and mail can be hand-delivered. This level of security, however, is not normally required, although circumstances can arise that require increased security in client communications by a lawyer.

State bar associations that have considered this issue have concluded, with few exceptions, that a reasonable expectation of privacy exists in the use of Internet e-mail and a lawyer may use this form of communication to transmit confidential client information. (fn3)

The American Bar Association has also concluded in a recent formal opinion that the use of Internet e-mail does not violate any Rule of Professional Conduct. In Formal Opinion No. 99-413, the ABA concluded that: "A lawyer sending confidential client information by unencrypted e-mail does not violate Model Rule 1.6(a) in choosing that mode to communicate. This is principally because there is a reasonable expectation of privacy in its use."

Analyzing the characteristics of e-mail, ABA Opinion 99-413 concludes that e-mail is virtually indistinguishable from the process of sending a fax. The opinion states that there is a reasonable expectation of privacy, in part, because of the difficulty of intercepting direct e-mail, the current huge volume of e-mail traffic, and the fact that interception of e-mail is a criminal act. (fn4)

There is little evidence that unencrypted e-mails pose any greater risk of unauthorized disclosure than other forms of communication commonly used, such as telephone and facsimile. (fn5) The fact that Internet service provider (ISP) administrators or hackers are capable of intercepting e-mail (in violation of federal law) does not render the expectation of privacy unreasonable, any more than the risk of an illegal telephone tap removes the reasonable expectation of privacy in a land-line telephone call. (fn6)

Where the client information is particularly sensitive or the lawyer has reason to believe that the risk of interception of the communication is higher, he may want to use a means of communication with higher security. The lawyer should abide by any policy of the client regarding the use of e-mail (or any other means of communication) for its confidential information. A lawyer may wish to advise a client at the time he is retained that the lawyer intends to use unencrypted e-mail as one of the methods of communication with the client.

Footnotes

  1. Rule 1.6(a) provides: "A lawyer shall not reveal information relating to representation of a client except as stated in paragraph (b), unless the client consents after consultation."

  2. ABA Comm. on Ethics and Professional Responsibility, Formal Op. 99-413; S.C. Bar Ethics Advisory Comm. Op. 97-08, www.scbar.org; Ill. State Bar Ass'n Op. 96-10, www.illinoisbar.org; N.Y. State Bar Ass'n Comm. on Prof. Ethics Op. 709 (1998) www.nysba.org/opinions.

  3. See cases at n.2, supra. Contra, Penn. Bar Ass'n Comm. on Legal Ethics Op. 97-130 (absent the client's consent after consultation, lawyer should not use unencrypted e-mail to communicate information concerning the representation where interception would be damaging to the client); Iowa Bar Ass'n Op. 1997-1; State Bar of Ariz. Advisory Op. 97-04, www.azbar.org.

  4. Electronics Communications Privacy Act, 18 U.S.C. §§ 2510 et seq. (1994).

  5. N.Y. State Bar Ass'n Op. 709; Ill. State Bar Ass'n Op. 96-10.

  6. ABA Op. 99-413; Alaska Bar Ass'n Op. 98-2; D.C. Bar Op. 281 (1998), www.dcbar.org; Ky. Bar Ass'n Ethics Comm. Advisory Op. E-403 (1998), www.uky.edu; N.Y. State Bar Ass'n Op. 709 (1998).

Rule Cited: 1.6

Get today's answer for your situation

You just read a 2000 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.