ABA Model Rule 1.6 and Cloud Storage: What Solo Attorneys Need to Know
Most solo attorneys use at least one cloud service that touches client information — practice management, email, file storage, or all three. Most have also never read the ethics analysis that applies to that choice. This isn’t a scare piece: no jurisdiction categorically forbids cloud tools. But the rules do put the burden on you, not your vendor, and it’s worth understanding exactly what you signed up for.
The rule itself
Model Rule 1.6(a) is the confidentiality rule everyone knows: a lawyer shall not reveal information relating to the representation of a client without informed consent. The part that matters for technology came in 2012, when the ABA added paragraph (c):
A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
Two things about that sentence deserve attention. First, it covers unauthorized access — not just disclosures you make, but breaches that happen to you. Second, “reasonable efforts” is a duty of process, not outcome. You won’t be disciplined merely because a sophisticated attacker got through, but you can be on the hook if you never made serious efforts to prevent it.
Comment [18] to the rule lists the factors that determine whether your efforts were reasonable: the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost and difficulty of employing safeguards, and whether those safeguards would impair your ability to represent the client. In other words: a criminal defense file and a routine commercial lease do not call for identical treatment, and the analysis is yours to make.
The competence duty makes it unavoidable
The same 2012 amendments added Comment [8] to Rule 1.1, the competence rule: lawyers must keep abreast of “the benefits and risks associated with relevant technology.” Many jurisdictions have adopted that language or related technology requirements; because adoption changes over time, check the current LawSites tech-competence tracker and your own jurisdiction’s rules.
Put the two rules together and the conclusion is hard to escape: “I didn’t really understand where my client files were stored” is not a defense. If you use a cloud tool, understanding its risks is itself an ethical obligation.
What “reasonable efforts” looks like with a cloud vendor
State bar opinions have consistently permitted cloud storage — but nearly all of them condition it on the lawyer exercising reasonable care in selecting and supervising the vendor. In practice, that means you should be able to answer questions like these about any tool that holds client data:
- Where is the data stored, and who can access it? Vendor employees? Subcontractors? In what countries?
- Is it encrypted at rest and in transit — and who holds the keys? If the vendor holds the keys, the vendor (and anyone who compromises the vendor) can read your files.
- What do the terms of service actually say? Some consumer-grade tools claim broad licenses to use uploaded content, or reserve the right to change terms unilaterally.
- What happens when there’s a breach? How quickly will they notify you? (Remember, under ABA Formal Opinion 483, you may have your own duty to notify affected clients.)
- Can you get your data out? In what format, and does it survive the vendor being acquired or shutting down?
If a vendor can’t or won’t answer these in writing, that fact is itself part of your reasonableness analysis.
The risk is not hypothetical
The ABA’s Cybersecurity TechReport found that 29% of responding firms reported having experienced a security breach — and another 19% didn’t know whether they had. Solo and small firms consistently reported the weakest safeguards: only 19% of firms with fewer than ten lawyers had an incident response plan, and only about a third of solos carried cyber insurance.
Law firms are attractive targets precisely because they concentrate other people’s secrets. A solo immigration or criminal defense practice may hold information more sensitive than anything at a Fortune 500 company, protected by a fraction of the security budget.
A simpler way to shrink the analysis
Here’s the part most ethics articles skip: every factor in the Comment [18] analysis gets easier when there’s no third party in the picture at all. Client data kept on hardware you control — encrypted, backed up, physically in your office — removes the vendor’s employees, subprocessors, terms of service, and breach history from your confidentiality equation entirely. The analysis doesn’t disappear (your own laptop can be stolen too, so disk encryption and backups still matter), but it becomes an analysis about your practices, which you can actually control.
That’s not an argument that cloud tools are unethical — they aren’t, and for many practices the convenience genuinely serves clients. It’s an argument that where client data lives is a decision, one the rules require you to make deliberately. Local-first software is a legitimate answer to that decision, and for the most sensitive practice areas, arguably the cleanest one.
Whichever way you decide, decide on purpose. Your clients assumed you would.
This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction — consult yours.