Annual Partners

Member Login

The Philadelphia Lawyer


Posted on: Aug 4, 2022

By Daniel J. Siegel

Would a lawyer leave a client file lying around in his office where anyone could see it? Of course not.

Would a lawyer agree to disclose client information to third parties who are unrelated to the firm or the client? Of course not.

Suppose a lawyer was going to court and brought a client’s file with her. In the file were the name, address, phone number and Social Security number of the client. Before going to the courthouse, she stopped for lunch. Would a lawyer take out the file and leave it on the restaurant table for anyone who walks by to peruse? Of course not. 

These questions sound ridiculous.  

They are not. In fact, lawyers probably do this all the time – electronically, or with their smartphones. In this column, I will address ethical issues relating to smartphones and tablets, and offer some ways to address them. 

I have previously written about the dangers of just clicking on the “I Agree” checkbox for the “Terms of Service” for many software programs and websites. One website, visualcapitalist.com, has analyzed these documents, calculating that the terms of service for Microsoft, Apple, Zoom, Slack, Uber, and Twitter were 15,260, 7,314, 6,891, 5,782, 5,658 and 5,633 words long, respectively. The site also produced a graphic highlighting the length of these documents. https://www.visualcapitalist.com/terms-of-service-visualizing-the-length-of-internet-agreements/.  

Considering that the average adult reads about 200 to 250 words per minute, it takes a long time to read one of those documents. 

Virtually everything electronic has a terms of service box that users routinely “agree” to without considering what they are agreeing to. For example, AOL and Yahoo! free email, which are now owned by the same company, agree that they are giving the company “a license to use and distribute your content.” In other words, lawyers who use AOL and Yahoo free email permit the company to use and distribute their content, including the content of and attachments to email. Users of other companies’ services, especially free technology products, often grant the vendors similar licenses to use the subscribers’ content without limitation. 

Smartphone users do the same thing. When installing an app on a smartphone, users generally agree to the app’s terms of services without even considering what information the apps collect and use. If you don’t know the type of information apps can, and do, collect, view the permissions you have granted for your phone’s apps.  

On Android phones, for example, the apps permission manager shows which apps can access everything on the devices from the calendar to camera to contacts to files and media to location to SMS, and more. On iPhones, the app privacy report shows the permissions you granted to various apps. 

In other words, your smartphone’s apps can access files and contact information, which may include “information relating to representation of a client,” the type of information Pennsylvania Rule of Professional Conduct 1.6 requires attorneys to protect. In the past, when authors and speakers addressed the privacy concerns raised by smartphone apps, most readers and listeners nodded, and went about their business as usual. 

The days of ignoring the need to keep “information relating to representation of a client” confidential may finally be coming to an end. On April 8, 2022, the New York State Bar Association Committee on Professional Ethics issued Opinion 1240 addressing the “duty to protect client information stored on a lawyer’s smartphone.”  

The New York State Bar Opinion is a game changer because it finally applies the teeth of Rule 1.6 to smartphones and by analogy other technology. The Opinion concludes that “If ‘contacts’ on a lawyer’s smartphone include any client whose identity or other information is confidential under Rule 1.6, then the lawyer may not consent to share contacts with a smartphone app unless the lawyer concludes that no human being will view that confidential information, and that the information will not be sold or transferred to additional third parties, without the client’s consent.” 

Although New York’s version of Rule 1.6 differs in its definition of the information that attorneys must protect, the Opinion’s analysis and conclusion apply equally to Pennsylvania attorneys. 

The Opinion explains that contacts stored on a smartphone commonly include information such as email addresses, work or residence addresses, phone numbers, birthdates, and “the lawyer’s relationship to the contact.” It further noted that “social media apps may seek access to this information to solicit more users to their platforms … to establish links between users and enhance the user experience [or] to sell products or services.” 

The Opinion then explains that because clients’ names themselves constitute confidential information, “a lawyer must make reasonable efforts to prevent the unauthorized access of others to those names, whether stored as a paper copy in a filing cabinet, on a smartphone, or in any other electronic or paper form. To that end, before an attorney grants access to the attorney’s contacts, the attorney must determine whether any contact – even one – is confidential within the meaning of Rule 1.6(a). A contact could be confidential because it reflects the existence of a client-attorney relationship which the client requested not be disclosed or which, based upon particular facts and circumstances, would be likely to be embarrassing or detrimental to the client if disclosed.” 

Finally, the Opinion lists “relevant factors a lawyer should consider in determining whether any contacts are confidential are:  

“(i) whether the contact information identifies the smartphone owner as an attorney, or more specifically identifies the attorney’s area of practice (such as criminal law, bankruptcy law, debt collection law, or family law);  

“(ii) whether people included in the contacts are identified as clients, as friends, as something else, or as nothing at all; and  

“(iii) whether the contact information also includes email addresses, residence addresses, telephone numbers, names of family members or business associates, financial data, or other personal or non-public information that is not generally known.” 

This advice applies equally to lawyers in Pennsylvania and to lawyers throughout the county. Periodically, Google and Apple will remove apps that violate their privacy policies, including apps that improperly access the types of information referred to in the New York Opinion. The Opinion makes clear, however, that lawyers cannot rely on vendors to monitor their ethical obligations. What should lawyers do in response to this guidance? 

First, lawyers should require lawyers and support staff that may store information subject to Rule 1.6 to encrypt all data on their devices. 

Second, lawyers should review smartphones, tablets, iPads, and other devices on which they store information to determine which apps have been given permission to potentially access information that falls under the ambit of Rule 1.6. 

Third, lawyers should revoke permissions that were granted to apps that have no need to access protected information. 

Fourth, lawyers should evaluate, limit and/or prohibit, as appropriate, their offices’ policies relating to the types of Rule 1.6 information that attorneys and support staff store on their devices. In many cases, there is little or no need to store client information on the devices. 

Finally, firms should require lawyers and support staff who download files relating to clients to restrict access to the files and to delete the files from their devices promptly. 

As a practical matter, there is generally little need for lawyers to regularly store information relating to the representation of a client on their phones and tablets. Within the context of New York’s ethics opinion, it is now time for Pennsylvania lawyers to re-examine how and what they store on smartphones and other mobile devices, and to limit that data to assure confidentiality. 

Daniel J. Siegel, a member of the Editorial Board of The Philadelphia Lawyer, is the principal of the Law Offices of Daniel J. Siegel, LLC, and chair of the Pennsylvania Bar Association Legal Ethics Committee. He provides ethical and disciplinary guidance to other attorneys, and can be reached at dan@danieljsiegel.com. 

Subscribe to Bar News: