This is not legal advice. We are an IT and security provider, not a law firm. Every source below is linked so you can read it yourself, and your own ethics counsel has the final word on how it applies to your practice.
1. The duty of technology competence (Rule 1.1)
On March 22, 2021, California amended Comment [1] to Rule 1.1 of the Rules of Professional Conduct. The duty of competence now includes “the duty to keep abreast of the changes in the law and its practice, including the benefits and risks associated with relevant technology.”
That does not make every partner a technologist. It does mean that “we didn’t know email could be spoofed” or “we assumed the backup worked” is no longer a defense a firm can comfortably rely on. Competence can be supplied by people you hire, provided someone who understands the risk is actually looking at it.
Read the Rules of Professional Conduct at the State Bar →
2. Cloud storage and outside vendors (Formal Opinion 2012-184)
The State Bar’s standing committee on professional responsibility looked at a firm running its practice from the cloud and said it is permitted, with due diligence both when the vendor is chosen and for as long as it is used. Building on its earlier Formal Opinion 2010-179, the opinion points to six things to weigh:
- The vendor’s credentials and track record.
- Data security: encryption, passwords and access controls.
- Where the data travels, including across state or national borders.
- Your ability to supervise the vendor.
- The contract terms, which should address confidentiality.
- Periodic reassessment that the vendor still meets the standard.
The benchmark is blunt: the vendor’s policies and procedures should “at a minimum equal what Attorney herself would do.” That applies to your IT provider as much as to any document-storage service.
Read Formal Opinion 2012-184 (PDF) →
3. Data breaches (Formal Opinion 2020-203)
This is the opinion that matters most day to day. It sets out three duties:
- Reasonable security, reached by a process. The opinion does not mandate specific tools. It asks for a fact-specific process to assess the risks, then put appropriate measures in place.
- Monitoring and response. Lawyers must make reasonable efforts to monitor the technology and office resources connected to the internet, and act reasonably and promptly to stop a breach and limit the damage. The opinion encourages firms to have a breach response plan.
- Telling the client. When a breach creates a reasonable risk to a current client’s interests, disclosure “must be made as soon as reasonably possible.” At a minimum, the client learns there has been unauthorized access to or disclosure of their information, or that it is reasonably suspected.
The opinion ties these duties to Rules 1.1, 1.4, 1.6, 5.1 and 5.3 and to Business and Professions Code section 6068(e). Rules 5.1 and 5.3 are the reminder that partners answer for the systems and the staff, not only for their own conduct.
Read Formal Opinion 2020-203 (PDF) →
4. AI tools (ABA Formal Opinion 512)
On July 29, 2024, the American Bar Association issued its first formal opinion on generative AI. For tools that learn from what is typed into them, it says “a client’s informed consent is required prior to inputting information relating to the representation.” It also says that general, boilerplate consent language in an engagement letter is not sufficient.
ABA opinions interpret the ABA Model Rules and do not bind California lawyers. They are widely read as persuasive, though, and California’s own confidentiality duty leads to the same practical answer: know which AI tools your people are using, and keep client information out of the ones that learn from it unless the client has agreed.