Legal Ethics & Technology

ABA Model Rules on Client Data Security

What the ABA says about protecting client data, and what that means for your file sharing practices.

This page is educational, not legal advice. Attorneys should consult their jurisdiction's ethics rules and opinions for specific guidance.

The relevant Model Rules

Several ABA Model Rules and formal opinions bear directly on how lawyers handle client data in electronic communications and file sharing.

Rule 1.1, Competence

Comment [8] to Rule 1.1 was amended in 2012 to make clear that competent representation requires lawyers to "keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology." This isn't aspirational language, it's part of the baseline competence standard.

A lawyer who doesn't understand how their file-sharing tools work, what encryption means, or where client data is stored may be falling short of this obligation without realizing it.

Rule 1.6: Confidentiality of Information

Paragraph (c), added in 2012, requires lawyers to "make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." This applies to electronic communications and file transfers.

Comment [18] elaborates that the "reasonable efforts" standard depends on the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, and the cost and difficulty of implementing those safeguards. The standard is not absolute, but it does require affirmative action.

Rule 5.3, Responsibilities Regarding Nonlawyer Assistance

Lawyers with managerial or supervisory authority must make reasonable efforts to ensure that nonlawyer assistants' conduct is compatible with the lawyer's professional obligations. This extends to vendors and third-party service providers.

If a firm uses a file-sharing service, the supervising lawyer has an obligation to evaluate whether that service's security practices are adequate to protect client information. "We didn't know" is not a defense when the rules require you to find out.

ABA Formal Opinion 477R (May 2017)

This opinion directly addresses a lawyer's obligation to secure electronic communications containing confidential client information. It superseded Formal Opinion 99-413 and concluded that unencrypted email may not always be sufficient, particularly for sensitive communications.

Opinion 477R does not mandate specific technologies. Instead, it establishes a fact-specific analysis: lawyers must consider the sensitivity of the information, the cost and difficulty of additional safeguards, and whether the intended recipients can access encrypted communications. The opinion explicitly states that lawyers may need to use encryption or other security measures when transmitting highly sensitive information.

What "reasonable efforts" actually means

ABA Formal Opinion 477R identifies several factors for determining whether a lawyer's efforts to protect client information are "reasonable" under Rule 1.6(c). This is not a checklist where meeting any single item is sufficient. It's a totality-of-the-circumstances analysis that accounts for the practical realities of each situation.

The opinion explicitly rejects a one-size-fits-all approach. What's reasonable for a routine business contract may be inadequate for a client's medical records or financial disclosures in a contested divorce.

1

Sensitivity of the information

A routine scheduling email and a file containing a client's complete financial disclosures in a divorce proceeding are not the same thing. The more sensitive the information, the more robust the safeguards should be.

2

Likelihood of disclosure if additional safeguards are not employed

Email is routinely intercepted, misdirected, and accessed by unauthorized parties. If the transmission method has known vulnerabilities, that weighs toward additional protection.

3

Cost of additional safeguards

The ABA recognizes that security has costs. But when encrypted file transfer tools cost less than many other routine practice expenses, the cost argument for doing nothing has weakened considerably.

4

Difficulty of implementing additional safeguards

If a security measure is readily available and doesn't require significant technical expertise to deploy, the difficulty argument carries less weight. Tools that require no client-side software installation or account creation reduce this barrier further.

5

Extent to which safeguards adversely affect the lawyer's ability to represent the client

Security shouldn't make it impossible to practice law. But if a tool is as easy to use as attaching a file to an email, it's hard to argue that it adversely affects representation.

Where most firms fall short

Common practices that may not satisfy the "reasonable efforts" standard under current ABA guidance.

Emailing unencrypted sensitive documents

Standard email is transmitted in plaintext across multiple servers. Tax returns, medical records, litigation strategy documents, and financial disclosures sent via unencrypted email are exposed at every hop. Opinion 477R specifically flags this as potentially insufficient for sensitive information.

No data destruction policy

Client documents sitting in shared folders, old email attachments, and cloud storage accounts months or years after a matter closes represent ongoing exposure. Without a systematic approach to data destruction, every closed matter remains a potential liability.

Using consumer tools without security evaluation

Dropbox, Google Drive, and similar consumer tools are designed for convenience, not for the specific security requirements of legal practice. Using them without evaluating their encryption methods, access controls, and data retention policies may fall short of the Rule 5.3 obligation to evaluate vendor security.

No audit trail of document access

If you can't demonstrate who accessed a document, when they accessed it, and from where, you can't demonstrate that you maintained control over client information. An audit trail isn't just good practice, it's how you prove compliance if questioned.

Meeting the standard with technology

How specific technical safeguards map to the factors outlined in Opinion 477R. This is practical guidance, not a legal opinion on compliance.

Encryption at rest and in transit

AES-256-GCM encryption with per-file key isolation means each document has its own encryption key. Even if one key were compromised, other files remain protected. This addresses the "sensitivity of information" factor by applying strong, authenticated encryption to every file regardless of content.

Opinion 477R specifically mentions encryption as one of the safeguards lawyers should consider. Per-file key isolation goes beyond basic encryption by limiting the blast radius of any single compromise.

Automatic data destruction

Cryptographic erasure, destroying encryption keys so that the underlying data becomes mathematically unrecoverable, addresses the data retention problem directly. Documents don't linger in forgotten folders or old email threads. When the deadline passes, access ends permanently.

This maps to the "likelihood of disclosure" factor: data that no longer exists can't be disclosed. Firms that retain client documents indefinitely carry indefinite exposure.

Immutable audit trail

Every access event logged with timestamps, IP addresses, and user agents. This is how you demonstrate that you maintained control over client information and can account for every interaction with a document.

If a state bar or client questions your data handling practices, an audit trail is the difference between "we believe it was secure" and "here's the record."

No client account required

Opinion 477R's factors include whether recipients can access encrypted communications. Tools that require clients to create accounts, install software, or manage encryption keys themselves create barriers that may cause clients to revert to less secure methods. A secure link with optional PIN protection provides strong security without shifting technical burden to the client.

State-specific requirements

The ABA Model Rules are a starting point. Most states have adopted them with variations, and many state bars have issued their own ethics opinions addressing technology, cloud computing, and electronic communications. Your obligations are defined by your state's rules, not the ABA Model Rules directly.

The following is a non-exhaustive overview. Attorneys should consult their state bar's ethics resources for current, jurisdiction-specific guidance.

California

California Formal Opinion 2010-179 addressed confidentiality obligations in the context of technology use, concluding that lawyers must assess the level of security of their technology before using it to transmit confidential information.

New York

NYSBA Ethics Opinion 842 (2010) and subsequent opinions address cloud computing and electronic storage, requiring lawyers to take reasonable care to ensure that confidentiality is maintained when using online data storage.

Illinois

Illinois ARDC has adopted a version of Model Rule 1.1 including the technology competence language. Illinois Opinion 16-06 specifically addresses cloud computing and lawyers' obligations to protect client data.

Texas

Texas Ethics Opinion 680 (2018) addresses cloud storage and permits lawyers to use cloud-based services for storing client files if the lawyer takes reasonable precautions to safeguard confidential information.

Florida

Florida Bar Opinion 12-3 addresses cloud computing and requires lawyers to exercise reasonable care in selecting and using cloud service providers, including understanding how data is stored and who can access it.

This list is not comprehensive. Over 35 states have adopted some form of the technology competence amendment to Rule 1.1. Check your jurisdiction for the most current guidance.

Frequently asked questions

Common questions about ABA data security obligations and electronic file sharing.

Not in those exact words. The Model Rules do not mention "encryption" specifically. However, ABA Formal Opinion 477R (2017) concludes that the duty of confidentiality under Rule 1.6 may require encryption or other security measures when transmitting highly sensitive information. The opinion establishes a context-dependent analysis: the more sensitive the information, the stronger the case for encryption. For routine communications, unencrypted email may still be acceptable. For sensitive client documents, financial records, medical information, litigation strategy, the analysis shifts significantly toward requiring additional safeguards.
Most states have adopted some version of the Model Rules, but many have issued their own ethics opinions that may be more specific. Some states have explicitly addressed encryption, cloud computing, or electronic file sharing. Check your state bar's ethics opinions and advisory resources. If your state hasn't issued specific technology guidance, the ABA Model Rules and opinions serve as persuasive authority. Your state bar's ethics hotline can often provide informal guidance on specific technology questions.
Opinion 477R does not categorically prohibit unencrypted email. It does require a case-by-case analysis. For a scheduling confirmation or general case update, standard email is likely fine. For a file containing a client's complete tax returns, business valuations, or medical records, the analysis under the factors outlined in Opinion 477R, particularly sensitivity of information and likelihood of disclosure, weighs heavily toward additional safeguards. The practical question isn't whether email works, but whether you could defend your choice to use it for that particular transmission.
There is no single minimum standard defined in the Model Rules. "Reasonable efforts" is intentionally flexible. However, the factors from Opinion 477R provide a framework: encryption in transit and at rest, access controls, audit logging, and a data destruction policy collectively address the major areas of concern. A tool that provides end-to-end encryption, requires no client account creation, logs all access events, and automatically destroys data after a defined period addresses the primary factors the ABA has identified. Whether that's sufficient depends on the specific circumstances of each matter.
Client consent is one factor, but it doesn't eliminate the lawyer's independent obligation under Rule 1.6(c). Comment [18] notes that a client may give informed consent to a particular mode of communication, but the lawyer still must make reasonable efforts appropriate to the circumstances. If the information is highly sensitive and a more secure option is readily available at minimal cost, relying solely on consent may not satisfy the "reasonable efforts" standard.
Yes. Rule 1.6 applies to all information relating to the representation, regardless of the recipient. Sending sensitive client documents to opposing counsel via unencrypted email creates the same exposure risk. Many firms are beginning to use secure file transfer for inter-firm document exchange in addition to client-facing communications.

Put reasonable efforts into practice

Encrypted file transfer with audit trails and automatic destruction. Set up your first secure drop in under 2 minutes.