WSBA 2012

Can a lawyer store confidential client files with a third-party cloud or online storage provider?

Short answer: Yes. A lawyer may use third-party online data storage for confidential client files if the lawyer conducts reasonable due diligence on the provider and continues to monitor its security, to protect confidentiality under RPC 1.6 and client property under RPC 1.15A.

Apply this to your situation

This page answers the general question as of 2012. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.

Currency note: this opinion is from 2012
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

A law firm contracts with a third-party vendor to store client files on a remote server so the lawyer and client can access them over the internet from any location. The committee addressed the ethical duties this arrangement implicates and concluded that a lawyer may use online data storage to hold and back up confidential client information, as long as the lawyer takes reasonable care to keep the information confidential and secure against loss.

The committee grounded the analysis in three rules. RPC 1.6 requires a lawyer to protect client information against all disclosure, and Comment 16 requires the lawyer to act competently to safeguard information against inadvertent or unauthorized disclosure, including by persons under the lawyer's supervision. RPC 1.15A imposes a duty to protect client property, which extends to ensuring stored documents are not lost. RPC 1.1 imposes a duty of competence that, per Comment 6, includes keeping abreast of changes in the law and its practice, which the committee read to include keeping informed about the risks of the technology the lawyer uses.

The committee declined to set fixed security standards, reasoning that the technology changes too rapidly for specific guidance to stay current and that not every lawyer can evaluate a provider's security systems. Instead it held that a lawyer must conduct a due diligence investigation of the provider and cannot rely on a lack of technological sophistication to excuse the failure to do so. It listed possible best practices for a lawyer without advanced technical knowledge, including familiarization with the risks, evaluation of the provider's reputation and history, review of contract terms on confidentiality and data retrieval, notice of unauthorized access, controlled access, and secure backup. The committee emphasized that the duty is not a guarantee that the information is secure from all unauthorized access, but a duty of reasonable care, and that the lawyer must not only perform initial due diligence but also monitor and regularly review the provider's security over time.

In practice

Under the Washington rules as they stood at the time of the opinion, the committee held that cloud storage of confidential client files is permitted if the lawyer exercises reasonable care under RPC 1.6 (confidentiality), RPC 1.15A (client property), and RPC 1.1 (competence). The opinion frames the obligation as one of reasonable care rather than a guarantee of absolute security, and identifies two recurring requirements: an initial due diligence investigation of the provider, and ongoing monitoring and regular review of the provider's security, because a provider's protections can become obsolete over time. The committee listed candidate due diligence steps (evaluating the provider's reputation, reviewing contract terms on confidentiality, data retrieval, and breach notice, and confirming secure access and backup) as practices a lawyer without advanced technical knowledge could use.

Common questions

Q: Can a Washington lawyer store confidential client documents in the cloud?

A: Yes. The committee concluded a lawyer may use third-party online data storage for confidential client information if the lawyer takes reasonable care to keep it confidential and secure against loss, under RPC 1.6 and RPC 1.15A.

Q: Does the lawyer have to investigate the provider first?

A: Yes. The committee held the lawyer must conduct a due diligence investigation of the provider and its services and cannot rely on a lack of technological sophistication to excuse failing to do so.

Q: Is a one-time review enough?

A: No. The committee held the lawyer must not only perform initial due diligence but also monitor and regularly review the provider's security, because a provider's protections can become obsolete or substandard over time.

Q: Does the lawyer guarantee the data cannot be breached?

A: No. The committee said the duty does not rise to a guarantee that the information is secure from all unauthorized access; it is a duty to take reasonable steps to evaluate the risks and meet a reasonable standard of care.

Background and rules framework

The opinion interprets Washington RPC 1.6 (Model Rule 1.6, confidentiality, and Comment 16 on competent safeguarding of information), RPC 1.15A (Model Rule 1.15, safekeeping of client property), and RPC 1.1 (Model Rule 1.1, competence, and Comment 6 on keeping abreast of changes in law and practice). The committee read these together to impose a duty of reasonable care, rather than a fixed technical standard, on a lawyer who entrusts confidential client data to a third-party online storage provider.

Citations and references

Rules of Professional Conduct:

  • Model Rule 1.6 / Washington RPC 1.6 (confidentiality; Comment 16 on safeguarding information)
  • Model Rule 1.15 / Washington RPC 1.15A (safekeeping client property)
  • Model Rule 1.1 / Washington RPC 1.1 (competence; Comment 6 on keeping abreast of practice)

See also

Source

Original opinion text

Reproduced from the official source for research purposes. The linked source is authoritative.

Advisory Opinion: 2215
Year Issued: 2012
RPC(s): RPC 1.1, 1.6, 1.15A
Subject: Cloud Computing

This opinion addresses certain ethical obligations related to the use of online data storage managed by third party vendors to store confidential client documents.

Illustrative Facts:

Law Firm contracts with third-party vendor to store client files and documents online on remote server so that Lawyer and Client could access the documents over the Internet from any remote location.

Rules of Professional Conduct Implicated:

RPC 1.1, 1.6, 1.15A

Analysis:

Various service providers are offering data storage systems on remote servers that can be accessed by subscribers from any location over the Internet. This is one aspect of so-called “cloud computing,” and lawyers may be interested in using these services to store confidential client documents and other data. Use of these third party storage systems, however, means that confidential client information is outside of the direct control of the lawyer and raises particular ethical questions.

Under RPC 1.6, a lawyer owes a client the duty to keep all client information confidential, unless the information falls within a specified exception. The duty of confidentiality extends beyond deliberate revelations of client information and requires a lawyer to protect client information against all disclosure. Comment 16 to RPC 1.6 states: “A lawyer must act competently to safeguard information relating to the representation of a client against inadvertent or unauthorized disclosure by the lawyer or other persons who are participating in the representation of the client or who are subject to the lawyer’s supervision. See Rules 1.1, 5.1 and 5.3.” In order to use online data storage, a lawyer is under a duty to ensure that the confidentiality of all client data will be maintained.

In addition to client confidentiality, the lawyer is also under a duty to protect client property, under RPC 1.15A. A lawyer using online data storage of client documents is therefore under a duty to ensure that the documents will not be lost.

It is impossible to give specific guidelines as to what security measures should be in place with a third party service provider of online data storage in order to provide adequate protection of client material, because the technology is changing too rapidly and any such advice would be quickly out of date. It is also impractical to expect every lawyer who uses such services to be able to understand the technology sufficiently in order to evaluate a particular service provider’s security systems. A lawyer using such a service must, however, conduct a due diligence investigation of the provider and its services and cannot rely on lack of technological sophistication to excuse the failure to do so. While some lawyers may be able to do more thorough evaluations of the services available, best practices for a lawyer without advanced technological knowledge could include:

  1. Familiarization with the potential risks of online data storage and review of available general audience literature and literature directed at the legal profession, on cloud computing industry standards and desirable features.

  2. Evaluation of the provider’s practices, reputation and history.

  3. Comparison of provisions in service provider agreements to the extent that the service provider recognizes the lawyer’s duty of confidentiality and agrees to handle the information accordingly.

  4. Comparison of provisions in service provider agreements to the extent that the agreement gives the lawyer methods for retrieving the data if the agreement is terminated or the service provider goes out of business.

  5. Confirming provisions in the agreement that will give the lawyer prompt notice of any nonauthorized access to the lawyer’s stored data.

  6. Ensure secure and tightly controlled access to the storage system maintained by the service provider.

  7. Ensure reasonable measures for secure backup of the data that is maintained by the service provider.

A lawyer has a general duty of competence under RPC 1.1, which includes the duty “to keep abreast of changes in the law and its practice.” RPC 1.1 Comment 6. To the extent that a lawyer uses technology in his or her practice, the lawyer has a duty to keep informed about the risks associated with that technology and to take reasonable precautions. The lawyer’s duties discussed in this opinion do not rise to the level of a guarantee by the lawyer that the information is secure from all unauthorized access. Security breaches are possible even in the physical world, and a lawyer has always been under a duty to make reasonable judgments when protecting client property and information. Specific practices regarding protection of client property and information have always been left up to individual lawyers’ judgment, and that same approach applies to the use of online data storage. The lawyer must take reasonable steps, however, to evaluate the risks involved with that practice and to ensure that steps taken to protect the information are up to a reasonable standard of care.

Because the technology changes rapidly, and the security threats evolve equally rapidly, a lawyer using online data storage must not only perform initial due diligence when selecting a provider and entering into an agreement, but must also monitor and regularly review the security measures of the provider. Over time, a particular provider’s security may become obsolete or become substandard to systems developed by other providers.

Conclusion

A lawyer may use online data storage systems to store and back up client confidential information as long as the lawyer takes reasonable care to ensure that the information will remain confidential and that the information is secure against risk of loss.

Get today's answer for your situation

You just read a 2012 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.