Multistate Professional Responsibility Examination (MPRE)Client ConfidentialityHard

A lawyer is representing a start-up company in a patent application. The lawyer uses a third-party, cloud-based data storage service to store all client files, including highly sensitive intellectual property information. The terms of service for the cloud provider state that the provider may access and use aggregated, anonymized data for service improvement. The lawyer has not obtained explicit informed consent from the client for this specific data storage method. Is the lawyer's conduct ethically permissible?

  1. AYes, because the data is anonymized and aggregated, it does not reveal specific client information.
  2. BYes, as long as the lawyer reasonably believes the cloud service's security measures are adequate.
  3. CNo, because any use of a third-party cloud service for client data is inherently a breach of confidentiality.
  4. DNo, because the lawyer has not obtained the client's informed consent for using a third-party cloud service for sensitive data.
Show answer & explanation

Correct answer: D. No, because the lawyer has not obtained the client's informed consent for using a third-party cloud service for sensitive data.

A lawyer must make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation. This includes using technology. When using third-party services, especially for sensitive data, a lawyer must ensure adequate security and often needs to obtain informed consent from the client, particularly if there's any risk of access by the third party, even if 'anonymized' or 'aggregated.' The mere possibility of access, even for service improvement, necessitates client awareness and consent for sensitive data.

Why the other options are wrong

  • A. Even if anonymized and aggregated, the initial access and processing by a third party, particularly for sensitive IP, generally requires client consent or a clear understanding of the risks.
  • B. Adequate security is necessary, but it does not negate the need for informed consent when using third-party services that may involve some level of access or processing of sensitive data.
  • C. Using cloud services is not inherently a breach, but it requires due diligence, reasonable security measures, and often informed consent, especially for sensitive information.

Cloud Storage & Confidentiality

Lawyers using cloud-based services for client data must take reasonable steps to ensure confidentiality, including assessing the provider's security and obtaining informed consent from the client, especially for sensitive information or if the provider has any access to the data.

  • Reasonable efforts to protect client data required.
  • Assess security of third-party providers.
  • Informed consent often required for sensitive data or third-party access.
  • Duty applies even if data is anonymized/aggregated by provider.

Memory trick: Cloudy storage needs client's knowledge.

More Client Confidentiality questions