WISBAR 2015

Can a Wisconsin lawyer store and transmit client information using cloud computing services?

Short answer: Yes. The opinion concludes that a lawyer may use cloud computing as long as the lawyer makes reasonable efforts, commensurate with the risks, to protect the confidentiality of client information and to preserve reliable access to it. The opinion rejects any strict-liability or guarantee standard and lists the factors a lawyer weighs in deciding what efforts are reasonable, including the information's sensitivity, the provider's reputation and terms of service, and the difficulty and cost of additional safeguards.

Apply this to your situation

This page answers the general question as of 2015. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.

Currency note: this opinion is from 2015
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page as a PDF) is the authoritative source for any reliance.
View original ethics opinion (PDF)

Plain-English summary

Opinion EF-15-01 (originally issued 2015; amended September 8, 2017 to reflect changes in Wisconsin's Rules of Professional Conduct) addresses whether and how a lawyer may use cloud computing, which the committee describes, quoting the Pennsylvania bar, as "merely 'a fancy way of saying stuff's not on your computer.'" The committee frames the question as no longer whether to use cloud computing but how to use it safely and ethically, because the provider adds a layer of risk between the lawyer and client information even though the ultimate responsibility for confidentiality and security stays with the lawyer.

The committee identifies four implicated rules and analyzes each. Under SCR 20:1.1 (competence), a lawyer who uses cloud computing has a duty to understand the technology and its impact on professional obligations, and to keep abreast as technology and privacy laws change; the committee relies on ABA Comment [8] that competence includes keeping up with the benefits and risks of relevant technology. Under SCR 20:1.4 (communication), the committee concludes a lawyer is not required in every representation to tell the client that the lawyer uses the cloud, but must give the client enough information to participate meaningfully, and where a provider's security breach affects the client's information, SCR 20:1.4(a)(3) and (b) require the lawyer to inform the client of the breach.

Under SCR 20:1.6 (confidentiality), the committee treats processing, transmission, and storage in the cloud as an impliedly authorized disclosure to the provider, so long as the lawyer takes reasonable steps to ensure adequate safeguards. It anchors the standard in SCR 20:1.6(d), effective January 1, 2017, which requires "reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to," client information, and in ABA Comment [18], under which unauthorized access or disclosure is not a violation "if the lawyer has made reasonable efforts to prevent the access or disclosure." Under SCR 20:5.3 (nonlawyer assistants), the committee treats a cloud provider as a nonlawyer service provider outside the firm, requiring reasonable efforts to ensure the provider's services are compatible with the lawyer's obligations.

Part II concludes that the rules impose no strict-liability standard and require no guarantee against disclosure or loss; instead the lawyer must make reasonable efforts commensurate with the risk, which vary with the technology, the type of practice, and the individual client. The committee lists eleven non-exclusive risk factors (including the information's sensitivity, the client's instructions, the attorney's ability to assess the technology's security, the likelihood of disclosure, the cost and difficulty of additional safeguards, the provider's experience and reputation, the terms of the service agreement, and the legal and ethical environments of the jurisdictions where the services are performed) and gives general guidance, such as understanding basic computer security (firewalls, updates, strong passwords, multifactor authentication, and encryption), the dangers of public Wi-Fi and file-sharing sites, the importance of backups in more than one place, reading the provider's terms of service, consulting someone with the necessary expertise when the lawyer lacks it, and considering an engagement-letter provision explaining the use of cloud services.

In practice

Under this opinion, and under the Wisconsin rules as amended through the 2017 version it analyzes, conduct matching its fact pattern is treated as follows. The committee concludes that a Wisconsin lawyer may store, transmit, and access client information using cloud computing without per-representation client consent, provided the lawyer makes reasonable efforts commensurate with the risks to protect confidentiality and preserve access. The opinion makes the analysis fact-specific: what is reasonable for one practice or client may not be for another, and the lawyer weighs the listed factors rather than meeting fixed technical requirements. The committee also concludes that a lawyer must inform the client of a provider breach that affects the client's information, and that client consent may be necessary when information is highly sensitive.

Common questions

Q: May a Wisconsin lawyer use cloud computing to store client files?

A: Yes. The committee concludes a lawyer may use cloud computing as long as the lawyer makes reasonable efforts, commensurate with the risks, to protect the confidentiality of client information and to keep it reliably accessible.

Q: Does the lawyer have to get client consent before using the cloud?

A: Not in every representation. The committee concludes a lawyer need not inform the client in all cases, but must provide enough information for the client to participate meaningfully, and notes that consent may be necessary where the information is highly sensitive.

Q: What standard applies if client data is breached despite the lawyer's precautions?

A: A reasonable-efforts standard, not strict liability. The committee, relying on ABA Comment [18], concludes that unauthorized access or disclosure is not a rule violation if the lawyer made reasonable efforts to prevent it; SCR 20:1.4 separately requires the lawyer to inform the client of a breach affecting the client's information.

Q: What factors decide whether the lawyer's efforts were reasonable?

A: The committee lists eleven non-exclusive factors, including the information's sensitivity, the client's instructions, the attorney's ability to assess the technology's security, the likelihood of disclosure, the cost and difficulty of additional safeguards, the provider's experience and reputation, the terms of the service agreement, and the legal and ethical environments of the jurisdictions where the services are performed.

Q: What if the lawyer does not understand the technology?

A: The committee concludes that competence requires at least a cursory understanding of the technology used, and that a lawyer who lacks the necessary knowledge should consult someone who has it, such as a technology consultant.

Background and rules framework

The opinion interprets four Wisconsin rules and their Model Rule analogues: SCR 20:1.1 / Model Rule 1.1 (competence, including ABA Comment [8] on keeping abreast of relevant technology), SCR 20:1.4 / Model Rule 1.4 (communication, including notice of a breach), SCR 20:1.6 / Model Rule 1.6 (confidentiality, anchored in SCR 20:1.6(d), effective January 1, 2017, and ABA Comments [18] and [19]), and SCR 20:5.3 / Model Rule 5.3 (responsibilities regarding nonlawyer assistants, treating a cloud provider as a nonlawyer service provider outside the firm). The committee surveys cloud-computing opinions from many other jurisdictions in an appendix and adopts the consensus reasonable-efforts standard rather than a list of mandatory technical measures.

Citations and references

Rules of Professional Conduct:

  • Wis. SCR 20:1.1 / Model Rule 1.1 (competence)
  • Wis. SCR 20:1.4 / Model Rule 1.4 (communication)
  • Wis. SCR 20:1.6, 20:1.6(d) / Model Rule 1.6 (confidentiality)
  • Wis. SCR 20:5.3 / Model Rule 5.3 (responsibilities regarding nonlawyer assistants)

Statutes:

  • Wis. Stat. § 134.98 (data-breach notification; noted as beyond the opinion's scope)

Other opinions cited:

  • ABA Formal Op. 477 (May 2017): it is not always reasonable to rely on unencrypted email
  • Calif. Formal Ethics Op. 2010-179: confidentiality and competence using technology
  • Pa. Ethics Op. 2011-200; N.H. Ethics Op. 2012-13/4; Fla. Ethics Op. 12-3; N.Y. State Bar Op. 842; and other state cloud-computing opinions surveyed in Appendix A

See also

Source

Get today's answer for your situation

You just read a 2015 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.