By Carole J. Buckner, member, LACBA Professional Responsibility and and Ethics Committee; Dean, St. Francis School of Law; and President, Buckner Law Corp. The opinions expressed are her own.

Many ethics opinions have deemed cloud computing permissible when “reasonable,” but numerous data breaches and hacking incidents put confidential client information in the cloud at risk.1 Data breaches in California grew by 600% in 2013.2 Exchanges between the ABA and the U.S. National Security Agency (NSA) concerning the attorney-client privilege highlight the risk of government intrusion via technology.3 National Security Letters (NSLs) issued by the Federal Bureau of Investigation (FBI) allow the government to obtain records from Internet, banking, and telephone companies, while barring the companies' disclosure.4 Device manufacturers improve encryption,5 which the government reportedly circumvents.6 Fourteen percent of law firms responding to an ABA survey experienced a data breach or theft.7 In this environment, what are a lawyer’s ethical obligations concerning cloud computing?

Without getting overly technical, “the ‘cloud’ is ‘merely a fancy way of saying stuff’s not on your [own] computer.’”8 Your clients’ information is stored in the “cloud” if you use software as a service (SaaS), a third-party vendor to provide data storage or backup for your computer systems, or many popular forms of e-mail. 9

Attorneys have a duty to preserve the secrets of their clients10 and arguably a duty of “compu-tence.”11 While cloud computing generally is permissible when reasonable,12 where an attorney using any technology is “aware that others have access to the client’s electronic devices or accounts and may intercept or be exposed to confidential client information, then such technology should not be used in the course of the representation.”13

In California, ethics analysis focuses on the duties of confidentiality14 and competence,15 and a laundry list of due diligence factors.16 California lawyers have a duty “to keep clients reasonably informed of significant developments in matters with regard to which the attorney has agreed to provide legal services,”17 including significant developments relating to the representation.18

ABA rules require that lawyers consult with clients about the means by which the client’s objectives will be accomplished,19 explaining matters to the extent reasonably necessary to facilitate informed decision-making by clients.20 Ethics opinions from other jurisdictions (not binding in California) reference a lawyer’s duty to safeguard client property and a lawyer’s duty of supervision.21 Many ethics opinions recognize that security measures become obsolete over time, requiring periodic review.22

Given data instability and a deficit of effective regulation,23 how should lawyers address cloud computing with their clients? First, lawyers should carefully evaluate cloud services.24 A lawyer should make “appropriate disclosures” and obtain client consent to the technology.25 Lawyers should follow any express instructions from clients directing that confidential information not be stored or transmitted via the Internet.26 In addition, “the greater the sensitivity of the information, the less risk an attorney should take with technology.”27 Lawyers should advise clients regarding the security measures they are using and obtain informed consent, especially for highly sensitive information.28 In ESI-intensive litigated matters, economics may favor use of cloud technology but not without risks.29 To obtain informed consent, lawyers should advise clients of the risks and the alternatives.30 Clients should also be told how an unauthorized disclosure of confidential information will be handled.31 For example, the loss of a computer must be reported under data breach disclosure laws.32 

Because data breaches can occur from hacking and malware, physical loss or theft of unencrypted devices, unintentional errors, and intentional misuse by insiders,33 law firms should implement suitable policies as well as vendor security programs to protect against loss of data to contractors.34

Consider the client: Some may have specialized concerns based on political or geographic considerations, or the nature of their particular business.35 Lawyers may need to advise such clients in greater detail regarding cloud services and provide clients with the opportunity to modify or enhance data security.36 Some clients may decide not to use cloud computing; others may employ additional security measures.37

Avoiding the cloud altogether may be best for some. Sensitive trade secrets may not be appropriate for cloud storage.38 In-person meetings with foreign clients may be preferable to digital communication.39 Use of prepaid phones for attorney-client communications should be considered.40For sensitive matters, a stand-alone computer not connected to the Internet may be preferable.41 Cloud storage may not be suitable where client documents are subject to permanent preservation obligations.42

Lawyers should consider how the cloud vendor holding client data responds to government or judicial attempts to require disclosure.43 Cloud computing may diminish a client’s ability to protect client information from government surveillance, since a cloud provider has less incentive than a law firm would to protect against government intrusion.44

Taking these matters into careful consideration, lawyers can fulfill their ethical obligations to their clients in connection with data in the ominous cloud.

LACBA's Professional Responsibility and Ethics Committee welcomes new inquiries from LACBA members regarding ethical issues or concerns about professional responsibilities. The identity of the inquirer is kept confidential within the committee. The committee, however, does not publish formal opinions that are the subject of any pending litigation involving the inquirer. If you have an ethical question that you would like the committee to consider, you can mail your written inquiry to Los Angeles County Bar Association, Professional Responsibility and Ethics Committee, P.O. Box 55020, Los Angeles, CA 90055-2020, or e-mail your inquiry marked “Confidential” to Member Services at msd@lacba.org.