Blog · Compliance · September 23, 2026 · By Mike Parker

What the California State Bar Requires of Your Firm’s Technology

Technology competence has been part of a California lawyer’s duty of competence since 2021. The State Bar has also said how it applies to cloud storage and to data breaches, and the ABA has addressed AI tools. Here is what each source actually says, in plain English, and the checklist it adds up to for a small or midsize firm.

This is not legal advice. We are an IT and security provider, not a law firm. Every source below is linked so you can read it yourself, and your own ethics counsel has the final word on how it applies to your practice.

1. The duty of technology competence (Rule 1.1)

On March 22, 2021, California amended Comment [1] to Rule 1.1 of the Rules of Professional Conduct. The duty of competence now includes “the duty to keep abreast of the changes in the law and its practice, including the benefits and risks associated with relevant technology.”

That does not make every partner a technologist. It does mean that “we didn’t know email could be spoofed” or “we assumed the backup worked” is no longer a defense a firm can comfortably rely on. Competence can be supplied by people you hire, provided someone who understands the risk is actually looking at it.

Read the Rules of Professional Conduct at the State Bar →

2. Cloud storage and outside vendors (Formal Opinion 2012-184)

The State Bar’s standing committee on professional responsibility looked at a firm running its practice from the cloud and said it is permitted, with due diligence both when the vendor is chosen and for as long as it is used. Building on its earlier Formal Opinion 2010-179, the opinion points to six things to weigh:

  • The vendor’s credentials and track record.
  • Data security: encryption, passwords and access controls.
  • Where the data travels, including across state or national borders.
  • Your ability to supervise the vendor.
  • The contract terms, which should address confidentiality.
  • Periodic reassessment that the vendor still meets the standard.

The benchmark is blunt: the vendor’s policies and procedures should “at a minimum equal what Attorney herself would do.” That applies to your IT provider as much as to any document-storage service.

Read Formal Opinion 2012-184 (PDF) →

3. Data breaches (Formal Opinion 2020-203)

This is the opinion that matters most day to day. It sets out three duties:

  • Reasonable security, reached by a process. The opinion does not mandate specific tools. It asks for a fact-specific process to assess the risks, then put appropriate measures in place.
  • Monitoring and response. Lawyers must make reasonable efforts to monitor the technology and office resources connected to the internet, and act reasonably and promptly to stop a breach and limit the damage. The opinion encourages firms to have a breach response plan.
  • Telling the client. When a breach creates a reasonable risk to a current client’s interests, disclosure “must be made as soon as reasonably possible.” At a minimum, the client learns there has been unauthorized access to or disclosure of their information, or that it is reasonably suspected.

The opinion ties these duties to Rules 1.1, 1.4, 1.6, 5.1 and 5.3 and to Business and Professions Code section 6068(e). Rules 5.1 and 5.3 are the reminder that partners answer for the systems and the staff, not only for their own conduct.

Read Formal Opinion 2020-203 (PDF) →

4. AI tools (ABA Formal Opinion 512)

On July 29, 2024, the American Bar Association issued its first formal opinion on generative AI. For tools that learn from what is typed into them, it says “a client’s informed consent is required prior to inputting information relating to the representation.” It also says that general, boilerplate consent language in an engagement letter is not sufficient.

ABA opinions interpret the ABA Model Rules and do not bind California lawyers. They are widely read as persuasive, though, and California’s own confidentiality duty leads to the same practical answer: know which AI tools your people are using, and keep client information out of the ones that learn from it unless the client has agreed.

Read ABA Formal Opinion 512 (PDF) →

What it adds up to: a checklist for a small or midsize firm

  1. A written risk assessment, repeated at least once a year. It is the “process” Formal Opinion 2020-203 asks for, and it is the first thing you will want to show if anyone asks.
  2. A vendor file for everyone who holds client data: your IT provider, cloud storage, e-mail, billing. Credentials, security terms, where the data is kept, and the date you last reviewed each one.
  3. Someone watching the systems, including after hours. Monitoring is part of the duty, and attacks are timed for when the office is dark.
  4. Multi-factor sign-in, encryption and tested backups on every account and device that touches client files.
  5. A breach response plan that names who investigates, who decides, and who tells clients, so “as soon as reasonably possible” is a plan and not a scramble.
  6. An AI use policy that says which tools are approved and keeps client information out of tools that learn from it without informed consent.
  7. Staff training at least once a year, with phishing practice. Rules 5.1 and 5.3 make supervision part of the partners’ job.

Where we fit

We run the technical half of that list for Southern California law firms: the monitoring, the security controls, the backups, the vendor documentation and the evidence that shows it all happened. Legal work is priced on our Secure IT plan with a published 10% confidentiality uplift, because a firm needs the 24/7 security operations center, not just a help desk. The details are on our law firm IT page and every rate is on the pricing page.

The rules ask for a process and the evidence you follow it. That is something an IT provider can build with you, and something you can show.

Quick answers

Law firm technology rules, answered plainly

Do California lawyers have a duty of technology competence?

Yes. Comment [1] to Rule 1.1 of the California Rules of Professional Conduct, in effect since March 22, 2021, covers it. The duty of competence includes "the duty to keep abreast of the changes in the law and its practice, including the benefits and risks associated with relevant technology." A lawyer does not have to be a technologist, but has to understand the risks of the tools the practice runs on, or bring in someone who does.

Can a California law firm store client files in the cloud?

Yes. State Bar Formal Opinion 2012-184 allows it, with due diligence. The lawyer must look at the vendor's credentials, its data security, where the data travels, the lawyer's ability to supervise the vendor, and the contract terms, and must keep reviewing the arrangement. In the opinion's words, the vendor's policies should "at a minimum equal what Attorney herself would do."

Does a California lawyer have to tell clients about a data breach?

Yes, for current clients whose interests face a reasonable risk of harm. State Bar Formal Opinion 2020-203 says disclosure "must be made as soon as reasonably possible." At a minimum the client must be told that there has been unauthorized access to or disclosure of their information, or that it is reasonably suspected. Separate breach-notification statutes can also apply.

Can lawyers put client information into a public AI tool?

Not without care. ABA Formal Opinion 512 (July 29, 2024) says that for AI tools that learn from what is typed into them, "a client's informed consent is required prior to inputting information relating to the representation." It adds that boilerplate language in an engagement letter is not enough. ABA opinions are not binding in California, but California's own confidentiality duty points the same way.

What counts as reasonable security for a small law firm?

The State Bar deliberately does not name specific tools. Formal Opinion 2020-203 asks for a process: assess the risks, put measures in place that answer them, monitor the systems connected to the internet, and have a plan for responding to a breach. The measures have to fit the firm, which is why the process, and the evidence that you follow it, matters more than any single product.

See where your firm stands against the rules

A free 30-minute assessment with the owner: your current controls against the State Bar's expectations, and what it would take to close the gaps.

Book a Free 30-Minute IT Assessment