A law firm’s obligations around client information are more demanding than what most businesses face. The duty of confidentiality is broad, it survives the end of representation, and it does not diminish because the information happened to be stored somewhere convenient.
Most firms use software that holds this information without having examined what the arrangement actually involves.
What the obligation requires in practice
Bar guidance has converged on a workable position over the past decade. Using third-party technology to store client information is permissible, provided the attorney takes reasonable steps to understand and mitigate the risks.
Reasonable steps means something. Knowing where the data resides. Understanding who at the vendor can access it and under what circumstances. Having a view on the vendor’s security practices. Knowing what happens if the relationship ends. Being prepared for a breach.
Most firms selected their software on features and price, which is normal and not sufficient by itself.
The questions worth asking about any system holding client data
Who can see it? Not just within the firm. Vendor support staff frequently have access for troubleshooting. That may be entirely reasonable and you should know it is the case.
Where does it live? Data location can matter for certain matters and certain clients, particularly where cross-border considerations exist.
What happens at termination? How long do you have to export. What comes out. Whether the vendor deletes what remains and whether they will confirm it.
Is the data used for anything else? Increasingly relevant with AI features. Some platforms train models on customer data by default. For a law firm this deserves a specific answer, not an assumption.
What is the breach commitment? How quickly you would be notified, with what detail. You may have notification obligations of your own that depend on theirs.
How complete is export? Matter records without the attached documents, communications and notes is a fraction of the file. Discovering this during a migration is a bad time to discover it.
Where firms are typically most exposed
Not in the practice management system, which is usually the most carefully chosen.
Email. Most confidential client communication lives in mailboxes with retention settings nobody has reviewed and access that may extend further than intended.
Consumer file sharing. Documents shared through personal accounts because it was faster in the moment. This happens in every firm and appears in none of the policies.
Intake tools and website forms. Someone describing their legal problem in a web form has created confidential information, often before any relationship exists. Where does that submission go, who receives it, and how long is it kept.
AI tools used informally. An attorney pasting matter facts into a general-purpose assistant to help draft something. The terms of that service now govern that information. This is the newest exposure and the least examined.
What owning the system changes
For firms that build their own layer, the calculation shifts rather than simply improving.
What you gain: access control designed for your firm’s actual structure rather than the vendor’s roles. Retention that matches your obligations instead of running indefinitely by default. Audit logging you define. Export that is not a feature but simply access to your own database. Certainty that nothing is being used for a secondary purpose.
What you take on: security is now your responsibility. Encryption, patching, backups that have been tested by restoring them, access review when staff leave. A vendor was doing this, adequately or not. Now the firm is.
This is genuinely a trade rather than an upgrade. A firm that builds its own system and neglects it is in a worse position than one using a well-maintained platform. A firm that builds and takes the responsibility seriously is in a better one.
A practical review
This does not require a project. It requires an afternoon.
List every system holding client information. Practice management, email, storage, intake, billing, anything with AI features, anything anyone uses informally.
For each, answer the six questions above. Where you cannot answer, that is the finding.
Then note which systems hold information the firm would struggle to reconstruct, and what the export from each actually contains.
Most firms complete this and find two or three items worth addressing, usually in the informal tools rather than the main platform. That is a manageable list, and having it is a meaningfully better position than not having looked.
If you are evaluating what your firm controls and whether building your own layer makes sense, get in touch. We build systems for law firms with these obligations designed in from the start.
Frequently asked questions
Is using cloud software a confidentiality problem?
Not inherently. Bar authorities across states have generally accepted cloud storage of client information provided the attorney exercises reasonable care in selecting the vendor and understands the terms. The obligation is diligence, not avoidance.
What should a firm actually check in a vendor agreement?
Where data is stored, who can access it, what happens on termination, how quickly and completely you can export, whether the vendor uses your data for any secondary purpose, and their breach notification commitments. Most firms have never read for these specifically.
Does building custom software make confidentiality easier or harder?
Different, not automatically better. You gain control over access, retention and export. You take on responsibility for security that a vendor was handling. Whether that is an improvement depends entirely on whether the firm treats it seriously.