WSBA 1998

Can outside IT staff maintain a law office computer network that holds client confidences without client consent?

Short answer: The committee concluded that letting an outside agency's technical personnel access a shared network for maintenance is permissible under RPC 1.6 without client consent, as long as those personnel are instructed and agree that access is for maintenance only and that any confidential information encountered may not be disclosed.

Apply this to your situation

This page answers the general question as of 1998. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.

Currency note: this opinion is from 1998
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

The inquiry concerned the use of outside agents to maintain computer systems. Specifically, a legal services agency shared a computer network with a parent nonprofit, and the nonprofit's technical personnel needed to access the shared portion of the network for maintenance and related purposes. The committee concluded that this access is permissible under RPC 1.6 without the consent of clients, as long as two requisites are met.

First, the nonprofit's employees involved must be instructed and agree that permission is granted for maintenance of the network only and does not extend to review of any confidential material on the system. Second, any acknowledgment the agency has those employees sign must include that instruction, along with an agreement that any confidential information they encounter incidental to their technical work may not be disclosed.

Currency note

This opinion was issued in 1998, before the Washington State Bar Association's adoption of the 2006 revisions to the Rules of Professional Conduct. Subsequent rule amendments or later opinions may have changed the analysis. Treat this page as historical context, not current guidance. Verify against current rules before relying on any specific rule, deadline, or requirement mentioned here. Washington's RPC 1.6 (confidentiality of information) has been amended since 1998, including provisions addressing reasonable efforts to prevent unauthorized disclosure, so verify the current rule text before relying on it.

Common questions

Q: Can outside IT personnel maintain a law office network that holds client confidences without getting client consent?

A: The committee concluded such maintenance access is permissible under RPC 1.6 without client consent, provided two conditions are met.

Q: What conditions did the committee require?

A: The personnel must be instructed and agree that access is for maintenance only and does not extend to reviewing confidential material, and any acknowledgment they sign must include that instruction plus an agreement not to disclose confidential information they encounter.

Q: Did the committee require client consent before outside techs touch the system?

A: No. It concluded the access is permissible under RPC 1.6 without the consent of clients, so long as the two requisites are satisfied.

Background and rules framework

The opinion applied Washington RPC 1.6 (confidentiality of information), corresponding to ABA Model Rule 1.6. The committee made outside technical access permissible without client consent on the condition that the outside personnel are limited to maintenance, are instructed not to review confidential material, and sign an acknowledgment agreeing not to disclose any confidential information encountered.

Citations and references

Rules of Professional Conduct:

  • ABA Model Rule 1.6 (confidentiality of information); Washington RPC 1.6

See also

Source

Original opinion text

Reproduced from the official source for research purposes. The linked source is authoritative.

Advisory Opinion: 1848
Year Issued: 1998
RPC(s): RPC 1.6
Subject: Client confidence or secret; computer system maintained by outside agency

I have been instructed by the Rules of Professional Conduct Committee to respond to your ethics inquiry #1848 concerning the use of outside agents to maintain computer systems.

The Committee has reviewed your inquiry and determined the following: the committee is of the opinion that the stated need for [the parent nonprofit's] technical personnel to access the portion of the computer network that the [legal services agency] shares with [the nonprofit] for maintenance and related purposes is permissible under RPC 1.6 without the consent of clients as long as two requisites are met:

  1. [The nonprofit's] employees involved must be instructed and agree that permission is being granted for maintenance of the network only and does not extend to the review of any confidential material on that system; and 2. any acknowledgment you propose to have [the nonprofit's] employees sign must include the preceding instruction along with an agreement that any confidential information they encounter incidental to their technical work may not be disclosed.

Get today's answer for your situation

You just read a 1998 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.