Last updated: June 3, 2026
Texas attorneys already know Rule 1.05 covers client confidentiality. What fewer firms have worked through is where that obligation lands in practice — because it follows your data into every system that touches it. Case management, email, the cloud platform your firm adopted three years ago, the AI tool someone on staff started using last Tuesday. The State Bar’s ethics opinions address the headline questions: Opinion 680 covers cloud storage, Opinion 705 covers AI. Neither one tells you how to lock down a network, secure a client portal, or manage five years of archived matter files. That’s what this covers.
What Rule 1.05 actually requires from your IT setup
Rule 1.05 governs confidentiality, not technology. But your technology is where client information lives, so the rule reaches into every system that touches it. If someone gets unauthorized access to any of that, you’ve likely violated 1.05 — even if you never intended to share anything. The State Bar doesn’t distinguish between a deliberate disclosure and a breach that started with a phishing click or a vendor with weak security. Reasonable safeguards are required either way.
There’s a practical side benefit to taking this seriously: cyber insurance carriers now expect the same controls. MFA, endpoint protection, regular security training — most carriers won’t write a policy without them. Your ethics posture and your cyber-insurance application end up answering most of the same questions.
The vendor due diligence problem
Opinion 680 (September 2018) allows cloud services if you take “reasonable precautions in the adoption and use of cloud-based technology.” That sounds tidy until you have to actually implement it. When a firm asks us to vet a practice-management or document-automation tool, here’s what we check:
- A current SOC 2 Type II report — not Type I, not “we’re working on it”
- Clarity on where the data physically sits
- Encryption standards in writing, in transit and at rest
- A contractual clause stating the vendor won’t use your client data to train AI models or for marketing
- Cyber insurance on the vendor side, plus an obligation to notify you of a breach within a defined window
Most Austin-area firms don’t have someone in-house to run this review. If that’s your firm, the answer is usually an MSP that has done it for legal clients before. Otherwise you end up agreeing to terms nobody read on a tool a partner picked because they liked the demo.
Client portal security: a login screen isn’t enough
If you’re sharing documents with clients through a portal, every shared file is a potential disclosure point. A password alone doesn’t get you there. You need:
- Encryption in transit and at rest — TLS 1.2 or higher for transmission, AES-256 for storage
- Multi-factor authentication — default-on, no exceptions. Comment 8 to Rule 1.01 requires technological competence, and by 2026 MFA is the floor, not a bonus feature
- Granular access controls — clients see only their own matters, and access gets revoked the day representation ends
- Audit logs — you need to know who accessed what and when, for ethics compliance and for the day opposing counsel asks how a document was handled
- Automatic session timeout — 15 to 30 minutes of inactivity, then re-authenticate
We see Austin firms use consumer Dropbox accounts and bare Google Drive links to swap discovery documents. That’s a 1.05 problem waiting for a moment to arrive. If the link gets forwarded, if the client’s laptop is compromised, if the service updates its terms next quarter — you’ve lost control of confidential information. Your engagement letter should spell out how you’ll transmit confidential data and what the client needs to maintain on their end. Putting it in writing protects the client and gives you evidence of reasonable care if anything goes wrong.
Conflict checks and the data you tend to overlook
Your conflicts database holds confidential information: client names, opposing parties, adverse counsel, case types, the relationships between them. Most firms treat the conflicts tool as a back-office utility rather than a case-file-grade asset. It is a case-file-grade asset.
- Apply the same access controls and encryption you use for case files
- Audit access at least once a year — former employees keep database access months after they’ve left more often than you’d expect
- Document how conflicts actually get run; if the process involves emailed spreadsheets or screen-sharing on Zoom, it needs to change
- Integrate with your practice-management system rather than maintaining a second, less-secure copy of your client list elsewhere
If you’re on a standalone conflicts tool, keep it under the same security standards as everything else. Stop exporting client data to Excel files on individual laptops.
Retention and deletion: the part most firms avoid
Texas Rule 1.15(a) requires five-year retention of trust-account records — records of funds in your trust or escrow accounts (including IOLTA) and other client property the lawyer holds. Not client files generally. (If you’re reading older ethics opinions or articles that cite Rule 1.14, the substance is the same; the rules were renumbered when new Rules 1.10 and 1.18 took effect October 1, 2024.)
For closed client files, the five-year norm isn’t from any single rule. It comes from extending the trust-account retention period by analogy, malpractice-carrier guidance, and Texas statutes of limitations on most claims against lawyers. Ethics Opinion 627 (2013) walks through the principles for deciding when destruction is permitted but explicitly declines to set a bright-line number of years. The State Bar’s own published guidance is clear that no rule mandates a minimum retention period for closed client files. The five-year practice is right; the rule everyone cites isn’t the rule that actually requires it.
Retention creates ongoing confidentiality obligations either way. Every backup tape, archived inbox, and old laptop in a closet is a 1.05 risk until it’s either secured or destroyed.
What a compliant retention strategy looks like
You need a documented schedule: what gets kept, how long, where, who can access it, and how it’s destroyed when the clock runs out. For electronic records:
- Encrypted backups with restore procedures you’ve actually tested — a backup and recovery plan that’s never been verified is just a checkbox
- A defined process for wiping devices before disposal or redeployment
- Annual review of archived matters so you’re not retaining everything forever by default
- Destruction certificates for both paper and electronic records
Firms with more than one office need the policy applied everywhere. We’ve walked into firms where the main office had tight controls and the satellite location had years of paper files in an unlocked storage room. Same firm, same client data, very different exposure. Retention also runs into e-discovery. If you become a defendant, you need to identify and preserve relevant records quickly — which means knowing what you have and where it lives before the litigation hold lands.
AI tools and Opinion 705: what you can and can’t outsource
Opinion 705 (February 2025) covers generative AI. You’re allowed to use these tools. You’re still responsible for the work product, and you still can’t expose client information to a vendor in a way that breaks Rule 1.05.
- Document review AI — acceptable if the vendor doesn’t retain your data or use it for training, and if you verify the output rather than treating it as final
- Contract analysis tools — same conditions, plus confirming the tool isn’t quietly missing material provisions
- Generative AI for drafting — higher risk unless you’re on an enterprise tier with terms equivalent to a BAA, and you’re editing the output rather than shipping it
Opinion 705 doesn’t ban AI. It requires the same competence and confidentiality standard that applies to everything else you do with client information. You need to know how the tool works, what it does with your data, and whether it would pass the same vendor review you’d run on any other platform.
For most small and midsize firms in Austin and Central Texas, the safer pattern right now: don’t paste client information into public AI tools, and use AI mainly for research and templates rather than live client matters. When you’re ready to go further, work with an IT partner who can vet the vendor and put the right agreements in place. That’s part of what our IT consulting and vCIO work covers for legal clients.
Most Austin law firms we talk to don’t have anyone in-house to run a proper IT security review. If your firm is in that spot, we can help — no pressure, no obligation. We work with legal clients across Central Texas on exactly these issues.
Sources and further reading
Texas Disciplinary Rules of Professional Conduct
Rule 1.01 — Competent and Diligent Representation (including Comment 8 on technological competence)
Rule 1.05 — Confidentiality of Information
Rule 1.15 — Safekeeping Property (formerly Rule 1.14; renumbered when Rules 1.10 and 1.18 took effect October 1, 2024)
Professional Ethics Committee Opinions
Opinion 680 (September 2018) — Cloud-based storage and software systems
Opinion 705 (February 2025) — Generative AI in the practice of law
Opinion 627 (April 2013) — Retention and disposition of client files
State Bar of Texas resources
State Bar of Texas AI Toolkit
“Save or Shred: The Ethics of Destroying Closed Client Files” (Texas Bar Journal)
“Practice Tips Regarding File Retention and Destruction”
Technology and vendor terms
Microsoft Products and Services Data Protection Addendum (DPA)
Texas Supreme Court Misc. Docket No. 19-9016 — adopting Comment 8 to Rule 1.01
Texas Supreme Court Misc. Docket No. 24-9054 — October 2024 amendments and rule renumbering (PDF)
Current consolidated Texas Disciplinary Rules of Professional Conduct (effective March 7, 2025) (PDF)