ABA Model Rule 1.6 and Cloud Storage: What Lawyers Need to Know
A plain-language guide to reasonable safeguards, vendor review, encryption, access, breach response, exports, and local-first alternatives.
Email, file storage, practice management, backups, and electronic signatures can all place client information in a provider’s systems. That does not make cloud services unethical. It does mean the lawyer should understand the arrangement well enough to make reasonable decisions about it.
What the model rule says
ABA Model Rule 1.6(c) states:
A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
The duty concerns reasonable effort, not a guarantee that no incident can ever happen. Comment 18 points to factors including the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost and difficulty of safeguards, and whether they would interfere with the representation.
The analysis should therefore match the matter. A protective order, trade secret, criminal-defense file, health record, or threatened person may call for safeguards beyond the firm’s ordinary baseline.
Jurisdictions adopt and interpret professional rules differently. Check the current rules and ethics opinions where the lawyer practices rather than treating the ABA model text as the final local answer.
Competence includes the tools used in practice
Comment 8 to Model Rule 1.1 includes the benefits and risks of relevant technology among the changes lawyers should keep abreast of.
That does not require a lawyer to inspect source code or manage a data center. It does require enough understanding to recognize a material risk, ask the provider or a qualified adviser, and act on the answer.
Questions to answer before client data is uploaded
Who can access it?
Identify the provider personnel, contractors, and subprocessors that can reach customer content. Ask how access is approved, logged, and reviewed. If information is processed in other countries, consider whether client instructions, protective orders, or regulatory duties make location relevant.
What does encryption protect?
Encryption in transit protects data moving between systems. Encryption at rest protects stored media and copies. Both are important.
They do not necessarily prevent the provider from reading the content. If the service needs to index, search, preview, or process files, it may hold or control keys that make access possible. Ask directly who controls the keys and under what circumstances the provider can decrypt customer data.
End-to-end or client-held-key designs can reduce provider access, but the details matter. Recovery keys, file names, metadata, previews, logs, and integrations may be handled differently from document contents.
What does the contract promise?
Review confidentiality, security, retention, subprocessors, breach notice, legal demands, data use, AI training, termination, and deletion. Product pages are not a substitute for the agreement governing the account.
Save the version reviewed. Assign someone to revisit it when the provider announces material changes.
Can the firm leave?
Test what an export contains. A readable contact list is not enough if matter links, documents, custom fields, communications, financial records, or dates disappear.
Find out whether export is self-service, whether it requires separate downloads, how long the account remains available after cancellation, and when the provider deletes remaining copies.
What happens after an incident?
Ask how quickly the provider will notify the firm, what information it will supply, and how the firm can preserve logs or evidence. ABA Formal Opinion 483 discusses lawyers’ obligations after a data breach, including efforts to stop the breach, restore operations, and evaluate client notice.
The firm’s own response plan should include contacts for the provider, insurer, bank, technical support, counsel, and affected clients. The middle of an incident is a poor time to search for an account number.
Cloud and local systems have different failure paths
A well-run cloud service may offer strong physical security, redundancy, monitoring, and recovery that a small office could not reproduce. It also introduces provider access, contractual dependence, internet dependence, and a larger shared target.
A local-first system can keep routine matter content on hardware the firm controls and reduce disclosure to a software provider. It shifts more responsibility to device security, access management, backup, and recovery. Optional synchronization can reintroduce remote infrastructure, even when content is encrypted before upload.
Neither label settles the ethics analysis. Map the actual data path: what leaves the device, what stays readable, who holds keys, which other services receive copies, and how the firm recovers from loss.
A short annual review
For every service that handles client information, keep a record of:
- the purpose and data involved;
- current access and encryption design;
- contract and subprocessor review;
- MFA and administrator settings;
- backup and restoration test;
- export test;
- incident contact; and
- any matter that needs stronger treatment.
Cloud storage is not a one-time ethical verdict. It is a supervised relationship. The lawyer’s task is to choose deliberately, check the important promises, and revisit the decision as the technology, provider, and practice change.
Primary references
- ABA Model Rule 1.6
- ABA Model Rule 1.1, Comment 8
- ABA Formal Opinion 483: Lawyers’ Obligations After an Electronic Data Breach
This article offers general information, not legal or ethics advice. Check the rules and opinions that apply in your jurisdiction.
This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction—consult yours.