The Case for Attorneys Controlling Their Own Data vs. Cloud-Based Case Management

Cloud-based case management platforms require attorneys to trust third-party vendors with some of their most sensitive client information — case strategies, client communications, and privileged analysis. On-device storage returns data sovereignty to the attorney, where it belongs.

Corrections and updates — 2026-07-12

ABA Formal Opinion 483: Corrected the description of Formal Opinion 483 (2018), which addresses lawyers' obligations after a data breach, not cloud computing generally. The earlier cloud-computing guidance is Formal Opinion 477R (2017). This post now cites both correctly.

Rule 1.1 (Competence): Updated to clarify that on-device architecture supports the duty of competence but does not by itself satisfy it. Competence under Rule 1.1 is an ongoing obligation that includes periodically reviewing security and backup practices.

Cloud vendor practices: Softened overbroad statements about cloud platform terms of service and data-disclosure practices. Vendor terms vary widely, and specific policies should be evaluated individually.

Data sovereignty — the concept that data is subject to the laws and governance of the entity that controls it — is a familiar concept in international privacy law. But for attorneys, data sovereignty has a much more immediate meaning: who has control over client case data, and what happens when someone else asserts control over it?

When an attorney stores case data in a cloud-based platform, they are not merely "storing data in the cloud." They are entering into a relationship with a third-party data processor that involves technical access, contractual terms, and potentially conflicting legal obligations. The attorney's control over the data is mediated by the platform's terms of service, its data retention policies, its security practices, and the legal regimes to which the platform is subject.

The Three Dimensions of Data Sovereignty

Data sovereignty for attorneys operates on three dimensions: legal control, technical control, and practical control. Depending on their architecture and terms, cloud platforms can reduce control in one or more of these dimensions.

Legal control refers to who has the legal right to access, delete, or transfer the data. When case data resides on a cloud platform's servers, the platform's terms of service govern access. Many platforms disclaim ownership of client data but necessarily process it for service delivery, and their terms may permit disclosure in response to legal process directed at the platform — sometimes without notice to the attorney, depending on the service's specific policies and applicable law. An attorney who stores privileged case data on a cloud platform may find that the platform, not the attorney, decides how to respond to a third-party subpoena, though notice obligations vary by jurisdiction and agreement.

Technical control refers to who has the technical ability to access the data. Some cloud platforms hold or can access keys needed to decrypt customer data, while end-to-end encrypted services are designed so the provider cannot decrypt it. Attorneys should verify each product's encryption design, key management, subprocessors, and feature-specific data flows rather than infer access from the word “cloud.”

Practical control refers to how easily the attorney can migrate data out of the platform. Vendor lock-in is a well-documented phenomenon in legal technology. Once an attorney has entered hundreds of cases with detailed notes, hearing dates, and document links into a platform, the cost — in time and risk — of migrating to another system can be prohibitive. Some platforms make data export easy; others impose technical or contractual barriers.

Data Sovereignty: Cloud vs. On-Device

Cloud platform: Legal control shared with vendor (terms of service, subpoena response). Technical control held by vendor (server-side encryption keys, infrastructure access). Practical control limited by export format, vendor lock-in, and subscription continuity.

On-device (e.g., Docketloom): The primary app data store remains under the attorney's device-level controls. Lawful process, device management, exports, and any enabled operating-system backup can still create additional access paths that the attorney must evaluate.

Why Data Sovereignty Matters for Solo and Small-Firm Attorneys

For solo practitioners and small firms — the primary audience for tools like Docketloom — data sovereignty is particularly important. Unlike large firms with dedicated IT security teams, contract counsel, and data governance policies, solo and small-firm attorneys often make technology decisions without the infrastructure to audit vendor security practices, review data processing agreements, or monitor vendor compliance with ethical obligations.

The ABA's opinions on technology competence establish a framework for evaluating cloud services. Formal Opinion 477R (2017) addressed the duty to secure client data when using cloud computing. Formal Opinion 483 (2018) addressed lawyers' obligations after a data breach, including notification duties. Together, they establish that attorneys using cloud services must "competently" select and use the technology, which includes understanding the provider's data security measures, data breach notification procedures, and data retention policies. For many solo practitioners, meeting this standard requires significant time investment that would be better spent on client work.

On-device case management can simplify this due diligence by removing an application-operated server from the primary data path. The attorney still must evaluate the app, device security, exports, operating-system backups, and any other enabled services. The attorney's existing duty of competence under Rule 1.1 is supported by local-only storage coupled with standard iOS device security — device passcode, biometric authentication, and iOS Data Protection encryption — but competence remains an ongoing obligation that includes periodically reviewing the device's security configuration and backup practices.

The Subscription Cost Angle

Data sovereignty also has a financial dimension. Cloud case management platforms typically charge monthly or annual subscription fees that increase over time. The attorney's access to their own data is contingent on continued payment. If the attorney stops paying — whether due to practice closure, retirement, or financial hardship — they may lose access to their case data entirely or face extraction fees.

With on-device case management, the data persists on the device regardless of subscription status. An attorney who has paid for the app (whether through a one-time purchase or during an active subscription period) retains access to their case data. The data sovereignty principle is reinforced by the economics: the attorney who controls the data does not pay rent on it.

This content is legal information, not legal advice. It does not create an attorney–client relationship and cannot substitute for consultation with a licensed attorney about your specific circumstances.

Enjoyed this post?