Monday, January 5, 2015

Technology Affects a Lawyer’s Duty to Protect Confidential Information


Q:       How does a lawyer handle my confidential information?
A:        A lawyer must “act competently to safeguard information relating to the representation of a client,” according to Model Rule 1.6, which governs attorneys’ ethical practices. Today, a lawyer must understand how cloud computing works in order to competently comply with this obligation. With any cloud or virtual online storage hosting of client data, your lawyer should enter into a Service Level Agreement (SLA) that dictates how client data and files are kept secure. The law office should use firewalls and data encryption to further ensure that a client’s data is kept confidential.

Q:       Does my lawyer have to follow any standards to safeguard my confidential information?
A:        Anyone who has Federal Taxpayer Information (FTI) must follow standards set by the Internal Revenue Service (Regulation 1075). This regulation provides guidelines and procedures not only for computer use but also for storing and destroying physical files containing FTI. While this regulation is probably “over kill” for the average law office, it is an excellent guide for law firms to follow. For example, law offices should have written policies regarding remote access to their computer systems and for the use of thumb drives. Internet use by employees on computers housing client’s information should be regulated and monitored.

Q:       Should my attorney’s law office employees be allowed to work remotely with my client data?
A:        If there is a proper system in place, this may be acceptable, as long as the employee always adheres to your attorney’s profession obligations. You may want to question your attorney about the firm’s plan for protecting your client information at all times. For example, you might ask your attorney: Will any of your staff members work on the firm’s laptop or their home computers? Is the firm’s computer or external storage device password protected? Do staff members work on files remotely and email them to the office? There are many ways a law firm can address these concerns by using various encryption options. These options are now standard on most word processing programs and .pdf files, but the encryption only works if a password is sent by separate email to the person receiving the information.

Q:       How can my attorney avoid a data breach like those I’ve heard about in the news?
A:        If Target, Home Depot, celebrity iCloud accounts, and many others can experience a data breach, then so can your attorney. Forty-three percent of companies have experienced a data breach in the last year according to USA Today, and that is likely a conservative estimate, since many data breaches are not reported. Your attorney may not be able to avoid a data breach, but a law office that expects to be hacked is more likely to provide office policies addressing confidential information, including safeguards for hardware and software. Your attorney and staff should be trained on cyber and physical security of confidential client information. Whether using the Cloud, a smartphone or the office paper shredder, your attorney has a duty to competently safeguard your information.

Q:       I’ve seen the paper shredder at my attorney’s office. That’s a good sign I’m protected, right?
A:        Maybe, but if your attorney opens up the shredder and you can still read anything on the scraps, then your documents may as well have been crumbled into balls and thrown away. At a minimum, a paper shredder must cross-cut, diamond-cut or pulverize documents. If your attorney uses a third-party vendor to dispose of your confidential documents, then your attorney must be familiar with that company’s policies and procedures for disposal. Your attorney’s duty to you not only extends to his or her employees, but also to any third-party vendors the firm may use.

Q:       Should I send information to my attorney through Instant Message, Facebook, or Instagram?
A:        You cannot expect your attorney to safeguard your information when you submit it through an unsecure platform. Your attorney’s law office likely spends time and money to understand every aspect of the proper storage, transmission and destruction of your client information. Law offices must also train support staff and third-party vendors on the firm’s best practices. If you open the door for a data breach, however, none of your attorney’s safeguards will protect your information.

This “Law You Can Use” column was provided by the Ohio State Bar Association. It was prepared by Dayton attorney Gregory M. Gantt. Articles appearing in this column are intended to provide broad, general information about the law. Before applying this information to a specific legal problem, readers are urged to seek advice from an attorney.

Labels: , ,

Monday, November 5, 2012

Technology and Social Media Raise New Challenges with Confidential Information



Q:        How has the treatment of confidential information changed since the Internet explosion?
A:        While confidential information is as old as the first secret, the computer revolution of the last couple of decades has raised many questions about how the law addresses ownership and use of confidential information. Life-changing new technology has forced us to determine how the old legal rules apply to new situations. Today, people have easier access to more information than ever before, and most of that information exists in a highly mobile form. As a result, it is much more difficult to protect confidential information today than in the past, so it is more important than ever to take appropriate steps to protect information and avoid the legal problems that result from disclosures of confidential information.

Q:        What kinds of confidential information are affected by the technological changes?
A:        Anything that a person or company might not want somebody else to know has been affected, including such important categories of confidential information as business trade secrets, medical records and student records. Since virtually all information is created and/or stored electronically, anything that a company or an individual might like to keep confidential is subject to new challenges raised by Internet accessibility.

Q:        What is a trade secret?
A:        A trade secret is a form of confidential information recognized by statute in Ohio (and all states in one form or another). In short, trade secrets have value because of the very fact that they are kept confidential. For example, the owner of the formula for a soft drink will go to great lengths to make sure that formula is kept secret, since it is the crown jewel of the business. If the formula were to become known by those outside the business, the company would stand to lose a lot of money because the recipe for creating the drink’s distinctive taste would be available to its competitors. That is a trade secret.

Q:        How has technology affected trade secrets law?
A:        Because the formula referenced above almost certainly exists electronically, it could, in a split second, be emailed or posted on the Internet and become available to millions of people. Such a disclosure could cripple the business. For example, the formula could inadvertently be shared by an employee who leaves a mobile device such as a laptop, an iPhone or a flash drive in an insecure location.
            In light of these new challenges, the owner of information involving trade secrets must take appropriate steps to protect the information. In particular, the owner of the information must determine how to limit the physical locations of the information in all forms, electronic and otherwise.

Q:        If, as an employee of a company, I’ve developed a list of LinkedIn contacts or Twitter followers, who owns that contact list?
A:        If the list has been developed as part of your employment, then the employer will likely want to retain ownership and has strong grounds for doing so. The more complicated situations involve situations where some of the contacts relate to your employment and some do not, or where some of the contacts pre-date your employment. In order to avoid future misunderstandings, it is wise for both sides to specifically spell out as much as possible what each expects regarding ownership of contact information developed through the Internet.

Q:        If I have business contact information on my personal smartphone, don’t I own it?
A:        Not necessarily. This is the “BYOD” (bring your own device) issue that is currently receiving attention among employers. An employer may maintain trade secret protection for information located on an employee’s personal device. Both the employer and the employee should, therefore, plan for how to handle the situation where the device is lost. For example, there are programs that enable remotely “wiping” the device of data if it cannot be located.
            As an employee, you should not assume you have free rein to use job-related information on your smartphone. Such an assumption could lead to unwanted legal problems for you. 

This “Law You Can Use” column was provided by the Ohio State Bar Association. It was prepared by attorney Bill Nolan of the Columbus office of Barnes & Thornburg LLP. Articles appearing in this column are intended to provide broad, general information about the law. Before applying this information to a specific legal problem, readers are urged to seek advice from an attorney.

Labels: , , , , ,