Legal professionals collaborating with AI analytics on screen and laptops

Last updated: June 3, 2026

Texas attorneys already know Rule 1.05 covers client confidentiality. What fewer firms have worked through is where that obligation lands in practice — because it follows your data into every system that touches it. Case management, email, the cloud platform your firm adopted three years ago, the AI tool someone on staff started using last Tuesday. The State Bar’s ethics opinions address the headline questions: Opinion 680 covers cloud storage, Opinion 705 covers AI. Neither one tells you how to lock down a network, secure a client portal, or manage five years of archived matter files. That’s what this covers.

What Rule 1.05 actually requires from your IT setup

Rule 1.05 governs confidentiality, not technology. But your technology is where client information lives, so the rule reaches into every system that touches it. If someone gets unauthorized access to any of that, you’ve likely violated 1.05 — even if you never intended to share anything. The State Bar doesn’t distinguish between a deliberate disclosure and a breach that started with a phishing click or a vendor with weak security. Reasonable safeguards are required either way.

There’s a practical side benefit to taking this seriously: cyber insurance carriers now expect the same controls. MFA, endpoint protection, regular security training — most carriers won’t write a policy without them. Your ethics posture and your cyber-insurance application end up answering most of the same questions.

The vendor due diligence problem

Opinion 680 (September 2018) allows cloud services if you take “reasonable precautions in the adoption and use of cloud-based technology.” That sounds tidy until you have to actually implement it. When a firm asks us to vet a practice-management or document-automation tool, here’s what we check:

  • A current SOC 2 Type II report — not Type I, not “we’re working on it”
  • Clarity on where the data physically sits
  • Encryption standards in writing, in transit and at rest
  • A contractual clause stating the vendor won’t use your client data to train AI models or for marketing
  • Cyber insurance on the vendor side, plus an obligation to notify you of a breach within a defined window

Most Austin-area firms don’t have someone in-house to run this review. If that’s your firm, the answer is usually an MSP that has done it for legal clients before. Otherwise you end up agreeing to terms nobody read on a tool a partner picked because they liked the demo.

Client portal security: a login screen isn’t enough

If you’re sharing documents with clients through a portal, every shared file is a potential disclosure point. A password alone doesn’t get you there. You need:

  • Encryption in transit and at rest — TLS 1.2 or higher for transmission, AES-256 for storage
  • Multi-factor authentication — default-on, no exceptions. Comment 8 to Rule 1.01 requires technological competence, and by 2026 MFA is the floor, not a bonus feature
  • Granular access controls — clients see only their own matters, and access gets revoked the day representation ends
  • Audit logs — you need to know who accessed what and when, for ethics compliance and for the day opposing counsel asks how a document was handled
  • Automatic session timeout — 15 to 30 minutes of inactivity, then re-authenticate

We see Austin firms use consumer Dropbox accounts and bare Google Drive links to swap discovery documents. That’s a 1.05 problem waiting for a moment to arrive. If the link gets forwarded, if the client’s laptop is compromised, if the service updates its terms next quarter — you’ve lost control of confidential information. Your engagement letter should spell out how you’ll transmit confidential data and what the client needs to maintain on their end. Putting it in writing protects the client and gives you evidence of reasonable care if anything goes wrong.

Conflict checks and the data you tend to overlook

Your conflicts database holds confidential information: client names, opposing parties, adverse counsel, case types, the relationships between them. Most firms treat the conflicts tool as a back-office utility rather than a case-file-grade asset. It is a case-file-grade asset.

  • Apply the same access controls and encryption you use for case files
  • Audit access at least once a year — former employees keep database access months after they’ve left more often than you’d expect
  • Document how conflicts actually get run; if the process involves emailed spreadsheets or screen-sharing on Zoom, it needs to change
  • Integrate with your practice-management system rather than maintaining a second, less-secure copy of your client list elsewhere

If you’re on a standalone conflicts tool, keep it under the same security standards as everything else. Stop exporting client data to Excel files on individual laptops.

Retention and deletion: the part most firms avoid

Texas Rule 1.15(a) requires five-year retention of trust-account records — records of funds in your trust or escrow accounts (including IOLTA) and other client property the lawyer holds. Not client files generally. (If you’re reading older ethics opinions or articles that cite Rule 1.14, the substance is the same; the rules were renumbered when new Rules 1.10 and 1.18 took effect October 1, 2024.)

For closed client files, the five-year norm isn’t from any single rule. It comes from extending the trust-account retention period by analogy, malpractice-carrier guidance, and Texas statutes of limitations on most claims against lawyers. Ethics Opinion 627 (2013) walks through the principles for deciding when destruction is permitted but explicitly declines to set a bright-line number of years. The State Bar’s own published guidance is clear that no rule mandates a minimum retention period for closed client files. The five-year practice is right; the rule everyone cites isn’t the rule that actually requires it.

Retention creates ongoing confidentiality obligations either way. Every backup tape, archived inbox, and old laptop in a closet is a 1.05 risk until it’s either secured or destroyed.

What a compliant retention strategy looks like

You need a documented schedule: what gets kept, how long, where, who can access it, and how it’s destroyed when the clock runs out. For electronic records:

  • Encrypted backups with restore procedures you’ve actually tested — a backup and recovery plan that’s never been verified is just a checkbox
  • A defined process for wiping devices before disposal or redeployment
  • Annual review of archived matters so you’re not retaining everything forever by default
  • Destruction certificates for both paper and electronic records

Firms with more than one office need the policy applied everywhere. We’ve walked into firms where the main office had tight controls and the satellite location had years of paper files in an unlocked storage room. Same firm, same client data, very different exposure. Retention also runs into e-discovery. If you become a defendant, you need to identify and preserve relevant records quickly — which means knowing what you have and where it lives before the litigation hold lands.

AI tools and Opinion 705: what you can and can’t outsource

Opinion 705 (February 2025) covers generative AI. You’re allowed to use these tools. You’re still responsible for the work product, and you still can’t expose client information to a vendor in a way that breaks Rule 1.05.

  • Document review AI — acceptable if the vendor doesn’t retain your data or use it for training, and if you verify the output rather than treating it as final
  • Contract analysis tools — same conditions, plus confirming the tool isn’t quietly missing material provisions
  • Generative AI for drafting — higher risk unless you’re on an enterprise tier with terms equivalent to a BAA, and you’re editing the output rather than shipping it

Opinion 705 doesn’t ban AI. It requires the same competence and confidentiality standard that applies to everything else you do with client information. You need to know how the tool works, what it does with your data, and whether it would pass the same vendor review you’d run on any other platform.

For most small and midsize firms in Austin and Central Texas, the safer pattern right now: don’t paste client information into public AI tools, and use AI mainly for research and templates rather than live client matters. When you’re ready to go further, work with an IT partner who can vet the vendor and put the right agreements in place. That’s part of what our IT consulting and vCIO work covers for legal clients.

Most Austin law firms we talk to don’t have anyone in-house to run a proper IT security review. If your firm is in that spot, we can help — no pressure, no obligation. We work with legal clients across Central Texas on exactly these issues.

Get a free IT assessment

Does Rule 1.05 require me to encrypt all client emails?

Not all of them. Rule 1.05 asks for reasonable safeguards, which scale with the sensitivity of the information. Routine scheduling and general correspondence over standard email is generally fine. Financial records, medical information, trade secrets, anything privileged or particularly damaging if leaked — those go through encrypted email or a secure portal.

Can I use Microsoft 365 or Google Workspace for client files?

Yes, on the business or enterprise tiers, with appropriate data-protection terms in place. Microsoft’s Products and Services Data Protection Addendum and Google’s equivalent agreements cover the baseline. Consumer versions don’t give you the confidentiality protections you need. You also need MFA enabled, retention policies configured, and a hard process for revoking former employees’ access on day one of their departure. If your firm handles healthcare-client matters under HIPAA, you’ll need a Business Associate Agreement on top of the standard DPA.

What happens if my vendor has a data breach?

You’re still on the hook under Rule 1.05. But if you did real due diligence picking the vendor and your contract requires prompt breach notification, you have something concrete to point to when explaining what you did. You’ll also need to notify affected clients, alert your malpractice carrier, and possibly report to the State Bar depending on what happened. Vendor selection and contract terms do a lot of quiet work for you in that scenario.

Do I need to tell clients I’m using cloud storage?

Opinion 680 doesn’t require upfront disclosure, but it’s worth including a short paragraph in your engagement letter explaining that you use cloud-based systems and what security measures are in place. Some clients will have objections, and you want to surface those before you’ve started storing their files. Government clients and clients in regulated industries may require explicit written consent.

How long do I need to keep email related to closed matters?

Emails that are part of the client file — substantive communications, strategy discussions, document exchanges — should be retained as part of the file. Texas doesn’t mandate a specific retention period for client files. The common practice is five years after the matter closes, which aligns with most Texas statutes of limitations on claims against lawyers and matches the Rule 1.15(a) trust-account retention period. Administrative messages can follow a shorter schedule. What matters is having a written policy and applying it consistently.

Can I let clients access files through Dropbox or Google Drive links?

Only on business-grade accounts with security controls enabled: password protection on shared links, expiration dates, access logs, encryption at rest. Consumer-grade file sharing with permanent public links is not a reasonable safeguard under 1.05. For most firms, a real client portal with granular access controls is the cleaner long-term answer.

Does safemode IT work with Austin-area law firms on IT compliance?

Yes. We work with legal clients across Central Texas on vendor vetting, endpoint security, MFA deployment, cloud configuration, and backup/retention strategies. If your firm needs a security review that’s grounded in what Rule 1.05 and the State Bar opinions actually require, reach out through our IT consulting page or call 512-761-7652.

Sources and further reading

Texas Disciplinary Rules of Professional Conduct
Rule 1.01 — Competent and Diligent Representation (including Comment 8 on technological competence)
Rule 1.05 — Confidentiality of Information
Rule 1.15 — Safekeeping Property (formerly Rule 1.14; renumbered when Rules 1.10 and 1.18 took effect October 1, 2024)

Professional Ethics Committee Opinions
Opinion 680 (September 2018) — Cloud-based storage and software systems
Opinion 705 (February 2025) — Generative AI in the practice of law
Opinion 627 (April 2013) — Retention and disposition of client files

State Bar of Texas resources
State Bar of Texas AI Toolkit
“Save or Shred: The Ethics of Destroying Closed Client Files” (Texas Bar Journal)
“Practice Tips Regarding File Retention and Destruction”

Technology and vendor terms
Microsoft Products and Services Data Protection Addendum (DPA)
Texas Supreme Court Misc. Docket No. 19-9016 — adopting Comment 8 to Rule 1.01
Texas Supreme Court Misc. Docket No. 24-9054 — October 2024 amendments and rule renumbering (PDF)
Current consolidated Texas Disciplinary Rules of Professional Conduct (effective March 7, 2025) (PDF)