Attorney-Client Privilege and On-Device Data: Why Cloud Case Management Is Risky
Every cloud case management platform introduces a third party with technical access to privileged client information. ABA Model Rule 1.6 and the Kovel doctrine create a framework that every attorney should understand before choosing a case management tool.
The attorney-client privilege is the cornerstone of confidential legal representation. Codified in federal common law and state evidence codes across the United States, it protects confidential communications between attorney and client from compelled disclosure. Yet the rise of cloud-based practice management tools has introduced a vulnerability that many attorneys do not fully appreciate: every third-party platform with access to case data is a potential waiver of privilege.
ABA Model Rule 1.6 requires attorneys to "make reasonable efforts to prevent the inadvertent or unauthorized disclosure of or unauthorized access to information relating to the representation of a client." This duty of confidentiality extends beyond the attorney-client privilege itself — it covers all information relating to a client's representation, regardless of whether it would be protected by the privilege in litigation. The rule applies to technology choices, including case management software.
When an attorney stores case data in a cloud platform, the analysis under both Rule 1.6 and the privilege doctrine turns on a single question: does the third party's access to the data create a waiver of privilege, and if not, what reasonable efforts has the attorney made to protect client confidences?
The Kovel Doctrine and Third-Party Access
The seminal case on third-party access to privileged communications is United States v. Kovel, 296 F.2d 918 (2d Cir. 1961). In Kovel, the Second Circuit held that communications through an accountant who was retained to help the attorney understand the client's financial records remained privileged because the accountant was "necessary" to enable the attorney to provide legal services. The privilege extension applied because the accountant functioned as a translator of client information — not as an independent service provider.
Courts have extended the Kovel reasoning to experts such as translators, investigators, and forensic accountants whose work is essential to the attorney's ability to render legal advice. The key limitation is that the third party must be necessary to the representation, not merely convenient. A cloud case management platform that stores case notes, hearing dates, and client communications is almost certainly not "necessary" in the Kovel sense — it is a tool the attorney chooses to use, not a translator without whom the attorney cannot understand the client.
State Bar Ethics Opinions on Cloud Computing
Several state bar associations have issued ethics opinions addressing attorneys' use of cloud computing. The general trend is permissive but conditioned on reasonable care. California Bar Formal Opinion 2010-179, one of the earliest, concluded that attorneys may use cloud computing if they take "reasonable precautions" to protect client confidentiality. The opinion specifically requires attorneys to review the provider's security measures, data encryption practices, and terms of service.
The Florida Bar's Ethics Opinion 06-1 (2006), reaffirmed in subsequent guidance, similarly holds that attorneys may store client data on third-party servers provided they exercise due care in selecting the vendor and ensuring the vendor's security measures are adequate. New York State Bar Association Opinion 842 (2010) and Pennsylvania Bar Association Opinion 2010-05 reached similar conclusions.
The common thread across these opinions is that attorneys bear the burden of evaluating their technology vendors' security practices. For a solo practitioner without dedicated IT support, this due diligence burden is substantial — and continuing, because vendor practices change over time.
ABA Formal Opinion 477 (2017) provides guidance on the "reasonable efforts" standard for protecting client confidentiality when using technology. Factors include: the sensitivity of the information, the probability of disclosure, the cost of additional security measures, the difficulty of implementing safeguards, and the extent to which safeguards affect the attorney's ability to represent the client. Comment [18] to Rule 1.6 specifically notes that factors to consider include "the nature of the attorney-client relationship and the involvement of third parties."
The On-Device Alternative
On-device case management eliminates the third-party access question entirely. When case data is stored exclusively on the attorney's device using a local persistence framework, there is no vendor server, no vendor employee with technical access, and no cloud infrastructure that can be subpoenaed or breached. The attorney's duty of confidentiality under Rule 1.6 is satisfied by the architectural choice of local-only storage, combined with standard device-level security — passcode, biometric authentication, and iOS Data Protection encryption at rest.
This is not merely a theoretical distinction. Consider a subpoena scenario: when a cloud vendor receives legal process for an attorney's case data, the vendor must respond. The attorney may not receive timely notice and may not have standing to object in the vendor's jurisdiction. With on-device architecture, the data resides only on the attorney's device. Any legal process must be directed at the attorney, who can assert privilege directly.
The Burden of Vendor Diligence
ABA Formal Opinion 483 (2018) specifically addresses lawyers' use of cloud computing. It confirms that attorneys may use cloud services but must exercise "competent" selection and ongoing monitoring. This includes understanding the provider's data security, breach notification procedures, data retention and destruction policies, and the jurisdiction where data is stored. The opinion also notes that the attorney must reasonably believe the provider's conduct will comply with the attorney's ethical obligations.
For many solo practitioners, this level of vendor diligence is neither practical nor sustainable. Evaluating a cloud provider's SOC 2 reports, reviewing their data processing agreements, understanding their subcontractor relationships, and monitoring their evolving privacy policies requires time and expertise that most solo attorneys do not have. On-device architecture eliminates this burden because there is no vendor to evaluate.
An attorney who chooses on-device case management does not need to review vendor security audits, analyze whether a third-party processor is "necessary" under Kovel, or worry about a vendor's data breach exposing client confidences. The data is on the attorney's device, protected by the same security the attorney already relies on for their phone, tablet, and computer. The architecture itself satisfies the duty of confidentiality.
This content is legal information, not legal advice. It does not create an attorney-client relationship and cannot substitute for consultation with a licensed attorney about your specific circumstances.