safeguarding client info and file retention

72
Safeguarding Client Information and File Retention Requirements Michael Downey Downey Law Group LLC August 2017

Upload: downey-law-group-llc

Post on 29-Jan-2018

53 views

Category:

Law


0 download

TRANSCRIPT

Page 1: Safeguarding Client Info and File Retention

SafeguardingClientInformationandFileRetentionRequirements

MichaelDowneyDowneyLawGroupLLC

August2017

Page 2: Safeguarding Client Info and File Retention

SafeguardingClientInformation

2

Page 3: Safeguarding Client Info and File Retention

3

1/8/17, 9(45 PMChinese Nationals Charged With Hacking Firms to Steal M A Info | The American Lawyer

Page 1 of 2http://www.americanlawyer.com/printerfriendly/id=1202775530918

NOT FOR REPRINT

Click to Print or Select 'Print' in your browser menu to print this document.

Page printed from: The American Lawyer

Chinese Nationals Charged With HackingFirms to Steal M&A InfoMark Hamblett, The Am Law Daily

December 27, 2016

Three Chinese nationals face federal charges for allegedly hacking into two major U.S. law firms ina scheme to trade on information about imminent mergers and acquisitions.

U.S. Attorney Preet Bharara of the Southern District of New York announced Tuesday that IatHong, Bo Zheng and Hung Chin have been charged with infiltrating the servers of two law firms in2014 and 2015 and accessing nonpublic information about pending deals. According to Bharara'soffice, the information was used in trades that reaped roughly $4 million in illegal profits.

The indictment unsealed Tuesday does not name the law firms, which are referred to as Law Firm1 and Law Firm 2. According to the charges, Law Firm 1 advised Intel Corp. on its 2015 acquisitionof Altera Corp. for $16.7 billion and represented a company that was in deal talks with InterMuneInc., which sold to Roche AG in 2014 for $8.9 billion.

The second major law firm advised Pitney Bowes Inc. in the 2015 acquisition of New York-based e-commerce company Borderfree, the indictment states.

Based on those details the two firms appear to be Weil, Gotshal & Manges and Cravath, Swaine &Moore, firms where cyberbreaches previously were reported. Weil represented Intel in the Alterabuy and Cravath is identified in securities filings as Pitney Bowes lead deal counsel.

Representatives of both firms, reached Tuesday, declined to comment.

"This case of cyber meets securities fraud should serve as a wake-up call for law firms around theworld: you are and will be targets of cyber hacking, because you have information valuable towould-be criminals,” Bharara said.

In addition to infiltrating the two firms, Bharara said the defendants went after at least five other lawfirms between March and September 2015, trying to get unauthorized access to the firms' networksand servers on over 100,000 occasions.

Page 4: Safeguarding Client Info and File Retention

4

Page 5: Safeguarding Client Info and File Retention

5

Page 6: Safeguarding Client Info and File Retention

6

Page 7: Safeguarding Client Info and File Retention

7

Page 8: Safeguarding Client Info and File Retention

DUTYofConfidentiality

8

Page 9: Safeguarding Client Info and File Retention

Duty ofConfidentiality– Rule4-1.6

Alawyershallnotrevealinformationrelatingtotherepresentationofaclientunlesstheclientgivesinformedconsent,thedisclosureisimpliedlyauthorizedinordertocarryouttherepresentation,orthedisclosureispermittedbyRule4-1.6(b).

9

Page 10: Safeguarding Client Info and File Retention

DutyofConfidentiality– MissouriRule4-1.6

• Informationfromanysource

• Relatingtorepresentation

• Limiton"revelation"• Limiton"use"inRule

4-1.8

Client

Mediareports Opposingcounsel

Pleadings

Adverseparty

Thirdparty

Lawyer

10

Page 11: Safeguarding Client Info and File Retention

TheMythofPrivacy

"Therecanbenoreasonableexpectationofprivacyinatweetsentaroundtheworld."

Peoplev.Harris(N.Y.Crim.Court2012)

11

Page 12: Safeguarding Client Info and File Retention

Internetvs.Privacy:"HelpfulVenndiagram"

ByDavidHoffman,availableathttp://bit.ly/bqU5vU

TheInternet Privacy

12

Page 13: Safeguarding Client Info and File Retention

13

Page 14: Safeguarding Client Info and File Retention

ProtectingInformationModel Rule1.6(c):"Alawyershallmakereasonableeffortstopreventtheinadvertentorunauthorizeddisclosureof,orunauthorizedaccessto,informationrelatingtotherepresentationofaclient."

14

Page 15: Safeguarding Client Info and File Retention

15

WhatAre"Reasonable"Protections?

Page 16: Safeguarding Client Info and File Retention

EvaluationofSafeguards• Factorstobeconsideredindeterminingthereasonableness

ofthelawyer’seffortsinclude,butarenotlimitedto,– thesensitivity oftheinformation– thelikelihoodofdisclosureifadditionalsafeguardsarenot

employed– thecost ofemployingadditionalsafeguards– thedifficulty ofimplementingthesafeguards (and)– theextenttowhichthesafeguardsadverselyaffectthelawyer’s

abilitytorepresentclients(e.g.,bymakingadeviceorimportantpieceofsoftwareexcessivelydifficulttouse)

16

Page 17: Safeguarding Client Info and File Retention

Rule1.6(c)– TwoMoreCaveats• Aclientmayrequirethelawyertoimplementspecialsecurity

measuresnotrequiredbythisRuleormaygiveinformedconsenttoforgosecuritymeasuresthatwouldotherwiseberequiredbythisRule.

• Whetheralawyermayberequiredtotakeadditionalstepstosafeguardaclient’sinformationinordertocomplywithotherlaw,suchasstateandfederallawsthatgoverndataprivacyorthatimposenotificationrequirementsuponthelossof,orunauthorizedaccessto,electronicinformation,isbeyondthescopeoftheseRules.

17

Page 18: Safeguarding Client Info and File Retention

WhereIstheData?

18

Page 19: Safeguarding Client Info and File Retention

The"Cloud"

19

Page 20: Safeguarding Client Info and File Retention

"DataFarms"

20

Page 21: Safeguarding Client Info and File Retention

TermsofServiceGoogleDocs(8/2017)

21

Page 22: Safeguarding Client Info and File Retention

SecureCommunications

• WhatsApp• Apple-AppleiMessagetexting(blue,notgreen)

• FaceTime

22

Page 23: Safeguarding Client Info and File Retention

BeatingSecurity

23

Page 24: Safeguarding Client Info and File Retention

InternetAccess

24

Page 25: Safeguarding Client Info and File Retention

25

Page 26: Safeguarding Client Info and File Retention

PrivatePublic

26PKI

EmailEncryption

Page 27: Safeguarding Client Info and File Retention

27

“AlawyergenerallymaytransmitinformationrelatingtotherepresentationofaclientovertheInternet withoutviolatingtheModelRulesofProfessionalConductwherethelawyerhasundertakenreasonableeffortstopreventinadvertentorunauthorizedaccess…

Page 28: Safeguarding Client Info and File Retention

28

…However,alawyermayberequiredtotakespecialsecurityprecautionstoprotectagainsttheinadvertentorunauthorizeddisclosureofclientinformationwhenrequiredbyanagreementwiththeclientorbylaw,orwhenthenatureoftheinformation requiresahigherdegreeofsecurity.”

Page 29: Safeguarding Client Info and File Retention

SevenConsiderations1. Understandthethreat

2. Understandhowclientinformationistransmittedandstored

3. Understandandusereasonablesecuritymeasures

4. Determinehowclientinformationshouldbeprotected

5. Labelclientinformationconfidential

6. Trainaboutinformationsecurity

7. Conductduediligenceontechnology

29

Page 30: Safeguarding Client Info and File Retention

30

“Thus,theuseofunencryptedroutineemailgenerallyremainsanacceptable methodoflawyer-clientcommunication.However,cyber-threatsandtheproliferationofelectroniccommunicationsdeviceshavechangedthelandscapeanditisnotalwaysreasonabletorelyontheuseofunencryptedemail.”

Page 31: Safeguarding Client Info and File Retention

Attorney-ClientPRIVILEGE

31

Page 32: Safeguarding Client Info and File Retention

Attorney-ClientPrivilege

• Confidential• communications• betweenanattorneyandhis[orher]client• concerningtherepresentationoftheclient• areprotectedbytheattorney-clientprivilege.

Diehlv.FredWeber,Inc. (Mo.App.E.D.2010)

32

Page 33: Safeguarding Client Info and File Retention

DUTYofConfidentiality– Rule4-1.6

Client

Court Filings

Real Estate Records

Newspaper

Depositions

Pleadings

Opposing Party

Lawyer

Page 34: Safeguarding Client Info and File Retention

Attorney-ClientPrivilege

• Confidential• communications• betweenanattorneyandhis[orher]client• concerningtherepresentationoftheclient• areprotectedbytheattorney-clientprivilege.

Diehlv.FredWeber,Inc. (Mo.App.E.D.2010)

34

Page 35: Safeguarding Client Info and File Retention

Attorney-ClientPrivilege

Client Lawyer

Renditionof

LegalServices

35

Page 36: Safeguarding Client Info and File Retention

"Necessary"Agents– Kovel

Client Lawyer

Agent

36

Page 37: Safeguarding Client Info and File Retention

JointRepresentation

Client1 Client2

Lawyer

37

Page 38: Safeguarding Client Info and File Retention

DeBoldv.Case (8th Cir.BAP2005)

“Whentwoormorepersons,eachhavinganinterestinsomeproblem,jointlyconsultanattorney,theirconfidentialcommunicationswiththeattorney,thoughknowntoeachother,willofcoursebeprivilegedinacontroversyofeitherorbothoftheclientswiththeoutsideworld,thatis,withpartiesclaimingadverselytobothoreitherofthosewithintheoriginalcharmedcircle.”

38

Page 39: Safeguarding Client Info and File Retention

JointDefense/CommonInterestPrivilege

39

Client1 Client2

Lawyer1 Lawyer2

Page 40: Safeguarding Client Info and File Retention

Attorney-ClientPrivilege

CommonInterest

40

Page 41: Safeguarding Client Info and File Retention

AdverseinBusinessTransaction

Seller

Buyer

41

Page 42: Safeguarding Client Info and File Retention

SharedInterestinEvaluatingLawsuit

Seller

Buyer

Plaintiff

42

Page 43: Safeguarding Client Info and File Retention

WorkProductProtection– MORule56.01(b)(3)

• SubjecttotheprovisionsofRule56.01(b)(4),apartymayobtaindiscoveryofdocumentsandtangiblethingsotherwisediscoverableunderRule56.01(b)(1)andpreparedinanticipationoflitigationorfortrialbyorforanotherpartyorbyorforthatotherparty'srepresentative,includinganattorney,consultant,surety,indemnitor,insurer,oragent,onlyuponashowingthatthepartyseekingdiscoveryhassubstantialneedofthematerialsinthepreparationofthecaseandthattheadversepartyisunablewithoutunduehardshiptoobtainthesubstantialequivalentofthematerialsbyothermeans.Inorderingdiscoveryofsuchmaterialswhentherequiredshowinghasbeenmade,thecourtshallprotectagainstdisclosureofthementalimpressions,conclusions,opinions,orlegaltheoriesofanattorneyorotherrepresentativeofapartyconcerningthelitigation.

43

Page 44: Safeguarding Client Info and File Retention

Rule56.01(b)(3)Parsed

§ [A]partymayobtaindiscoveryofdocumentsandtangiblethingsotherwisediscoverableunderRule56.01(b)(1)and

§ preparedinanticipationoflitigationorfortrial§ byorforanotherpartyorbyorforthatotherparty'srepresentative,

includinganattorney,consultant,surety,indemnitor,insurer,oragent,§ onlyuponashowing

– thatthepartyseekingdiscoveryhassubstantialneedofthematerialsinthepreparationofthecaseand

– thattheadversepartyisunablewithoutunduehardshiptoobtainthesubstantialequivalentofthematerialsbyothermeans.

44

Page 45: Safeguarding Client Info and File Retention

FRCPRule26(b)(3)(A)Parsed• DocumentsandTangibleThings.• Ordinarily,apartymaynotdiscover• documentsandtangiblethingsthat• arepreparedinanticipationoflitigationorfortrial• byorforanotherpartyoritsrepresentative(includingthe

otherparty'sattorney,consultant,surety,indemnitor,insurer,oragent)

45

Page 46: Safeguarding Client Info and File Retention

Work-ProductProtection

Alawyer'sinvolvementisnotrequired

46

Page 47: Safeguarding Client Info and File Retention

Attorney-ClientPrivilege

Work-ProductProtection

47

Page 48: Safeguarding Client Info and File Retention

OpinionWorkProduct– FullProtection

§ Inorderingdiscoveryof[workproduct]whentherequiredshowinghasbeenmade,thecourtshallprotectagainstdisclosureofthementalimpressions,conclusions,opinions,orlegaltheoriesofanattorneyorotherrepresentativeofapartyconcerningthelitigation.

48

Page 49: Safeguarding Client Info and File Retention

WaiverofPrivileges

§ MarthaStewartisbeinginvestigatedforinsidertrading

§ StewartprepareschronologyofeventsaroundImClonestocksale– Stewartsendschronologytoherlawyers– Stewartthensendschronologytoherdaughter

§ Isattorney-clientprivilegewaived?§ Iswork-productprotectionwaived?

49

Page 50: Safeguarding Client Info and File Retention

Waiver

§ Attorney-ClientPrivilege– Expresswaiver– At-issuewaiver– Disclosure

• WorkProduct– Expresswaiver(byclientorfirm)

– At-issuewaiver– Disclosure– whereinconsistentwithpurposeorlitigationadvantage

50

Page 51: Safeguarding Client Info and File Retention

Crime-FraudException

• Key– communicationsarenot(really)forthepurposeofgivingorreceivinglegaladvice,buttocommitacrime

• USv.Williams(8th Cir.2013)– defendantaskedlawyertosmugglecellphoneintoprison

51

Page 52: Safeguarding Client Info and File Retention

AccessingThird-PartyInformation

52

Page 53: Safeguarding Client Info and File Retention

53

Rule4-4.4RespectForRightsOfThirdPersons

(a)Inrepresentingaclient,alawyershallnotusemeansthathavenosubstantialpurposeotherthantoembarrass,delay,orburdenathirdperson,orusemethodsofobtainingevidencethatviolatethelegalrightsofsuchaperson.

(b)Alawyerwhoreceivesadocumentrelatingtotherepresentationofthelawyer'sclientandknowsorreasonablyshouldknowthatthedocumentwasinadvertentlysentshallpromptlynotify thesender.

Page 54: Safeguarding Client Info and File Retention

54

InadvertentProduction

• OldRule– recipientofmetadata– Notify producingpartyofproductionofprivilegedinformation

– Refrain fromreviewingprivilegedinformation– Abide byproducingcounsel'sinstruction– atleastuntilacourtordersotherwise

Page 55: Safeguarding Client Info and File Retention

55

NewRule4-4.4(b)

Alawyerwhoreceivesadocumentrelatingtotherepresentationofthelawyer'sclientandknowsorreasonablyshouldknowthatthedocumentwasinadvertentlysentshallpromptlynotifythesender.

Page 56: Safeguarding Client Info and File Retention

InreEisenstein (Mo.4/5/2016)• EisensteinrepresentedHusbandindivorce• HusbandaccessedWife'semailwithoutpermission,andgave

EisensteindocumentsincludingquestionsWife'sattorneyhadpreparedfordirectexamination

• EisensteindidnotproducethedocumentsreceivedfromWife'semail,untilgivingthemtoopposingcounselasexhibitsduringtrial

56

Page 57: Safeguarding Client Info and File Retention

ConsequencesinEisenstein

• Eisensteinwasfoundtohaveusedimproperlyobtainedinformation(violatingRule4-4.4)andconcealingdocumentswithevidentiaryvalue(violatingRule4-3.4)

• Eisensteinreceivedanindefinite(minimum6month)suspension

57

Page 58: Safeguarding Client Info and File Retention

ImproperAccess– Rule4-4.4(a)

• Inrepresentingaclient,alawyershallnotusemeansthathavenosubstantialpurposeotherthantoembarrass,delay,orburdenathirdperson,orusemethodsofobtainingevidencethatviolatethelegalrightsofsuchaperson.

58

Page 59: Safeguarding Client Info and File Retention

WhyImproper

• Illegal– maybeincriminatingclient– Evidencemaybebarred– Lawyermaybedisqualified

• Permitted– mayusedocuments

59

Page 60: Safeguarding Client Info and File Retention

FileRetention

60

Page 61: Safeguarding Client Info and File Retention

FileOwnership

• “Theclient’sfilesbelongtotheclient,nottotheattorneyrepresentingtheclient.Theclientmaydirectanattorneyorfirmtotransmitthefiletonewlyretainedcounsel.”InthematterofCupples,952S.W.2d226,234(Mo.banc1997).

61

Page 62: Safeguarding Client Info and File Retention

Retention– OrdinaryClientRecords

Rule4-1.22

62

Page 63: Safeguarding Client Info and File Retention

SixYears– UnlessWrittenConsent• Alawyershallsecurelystoreaclient'sfileforsixyearsaftercompletionor

terminationoftherepresentationabsentotheragreementbetweenthelawyerandclientthroughinformedconsentconfirmedinwriting.Suchinformedconsentconfirmedinwritingmaybemadebetweenthelawyerandtheclientatanypointduringthesixyearsaftercompletionorterminationoftherepresentation.Iftheclientdoesnotrequestthefilewithinsixyearsaftercompletionorterminationoftherepresentation,thefileshallbedeemedabandonedbytheclientandmaybedestroyed.

• ThesixyearclientfileretentionrequirementshallapplytoallclientfileswherethecompletionorterminationoftherepresentationoccursonorafterJuly1,2016.AllclientfileswherethecompletionorterminationoftherepresentationoccurspriortoJuly1,2016,shallbegovernedbythepreviouslyrequired10years.

63

Page 64: Safeguarding Client Info and File Retention

BewareSpoliation• AlawyershallnotdestroyafilepursuanttothisRule4-1.22if

thelawyerknowsorreasonablyshouldknowthat:(a)alegalmalpracticeclaimispendingrelatedtotherepresentation;(b)acriminalorothergovernmentalinvestigationispendingrelatedtotherepresentation;(c)acomplaintispendingunderRule5relatedtotherepresentation;or(d)otherlitigationispendingrelatedtotherepresentation.

64

Page 65: Safeguarding Client Info and File Retention

KeepItemsWith“IntrinsicValue”

• Itemsinthefilewithintrinsicvalueshallneverbedestroyed.

• AlawyerdestroyingafilepursuanttothisRule4-1.22shallsecurelystoreitemsofintrinsicvalueordeliversuchitemstothestateunclaimedpropertyagency.Thefileshallbedestroyedinamannerthatpreservesclientconfidentiality.

65

Page 66: Safeguarding Client Info and File Retention

RememberWhatYouDestroy• AlawyerdestroyingafilepursuanttothisRule4-1.22shall

maintainthewrittenrecordoftheclient'sconsentofdestructionforatleastsixyearsaftercompletionorterminationofemployment.Clientfiles,exceptforitemsofintrinsicvalue,maybemaintainedbyelectronic,photographic,orothermediaprovidedthatprintedcopiescanbeproduced.Theserecordsshallbereadilyaccessibletothelawyer.

66

Page 67: Safeguarding Client Info and File Retention

Dissolution– MustProtectRecordsUpondissolutionofalawfirm,thelawyersshallmakereasonablearrangementsforthemaintenanceofclientfiles.Uponthesaleofalawpractice,thesellershallmakereasonablearrangementsforthemaintenanceofclientfiles,whichincludeswrittennoticetoaclientastothelocationoftheclient'sfile.

67

Page 68: Safeguarding Client Info and File Retention

Retention– TrustAccountRecords

Rule4-1.15(f)

68

Page 69: Safeguarding Client Info and File Retention

SixYears– NoMatterWhatCompleterecordsofclienttrustaccountsshallbemaintainedandpreservedforaperiodofatleastsixyearsafterthelaterof:

(1) terminationoftherepresentation,or

(2) thedateofthelastdisbursementoffunds.

Clienttrustaccountrecordsmaybemaintainedbyelectronic,photographic,orothermediaprovidedthattheyotherwisecomplywithRules4-1.145to4-1.155andthatprintedcopiescanbeproduced.Theserecordsshallbereadilyaccessibletothelawyer.

69

Page 70: Safeguarding Client Info and File Retention

RequiredTrustAccountDocumentation(Missouri)

(1) receiptanddisbursementjournals

(2) client-specificledgers

(3) feeagreementsandsimilardocuments

(4) accountingstatementsshowingdisbursementsmade

(5) billsandexpensessenttoclients

(6) disbursementrecords

(7) check-bookregistersandbankstatementsortheequivalents

(8) electronictransferrecords

(9) accountreconciliations

(10)credit-cardtransactioninformation

70

Page 71: Safeguarding Client Info and File Retention

Dissolution– MustProtectRecords

Upondissolutionofalawfirmorofanylegalprofessionalcorporation,thepartnersshallmakereasonablearrangementsforthemaintenanceofclienttrustaccountrecords.Uponthesaleofalawpractice,thesellershallmakereasonablearrangementsforthemaintenanceofclienttrustaccountrecords.

71

Page 72: Safeguarding Client Info and File Retention

MichaelDowneyDowneyLawGroupLLC

(314)961-6644(844)961-6644tollfree

[email protected]

ThankYou