Legal & Professional Services
Client confidentiality and bar association requirements
Law firms and professional services organizations handle confidential client information under professional responsibility obligations. Thalorin supports legal sector compliance with security controls addressing client confidentiality, matter management, and the increasing cybersecurity expectations of sophisticated clients.
The State Bar of California replaced its November 2023 generative AI guidance in 2026, at the request of the California Supreme Court, to deal with agentic systems that initiate tasks and sequence work without being prompted. The guidance created no new duty. It restated the existing ones — competence, confidentiality, communication and candor — and observed that the more autonomy a system is given, the more supervision the lawyer owes. That is the shape of professional regulation: the obligations are old and stable, and what moves is the object they attach to.
Three authorities reach the same file. State rules of professional conduct, each a local variant of the ABA Model Rules, are enforced by a disciplinary body. Outside counsel guidelines are enforced by the client, through audit and non-payment, and routinely specify hosting locations, subcontractor limits and notification windows shorter than any statute. And where a firm prepares tax returns, the FTC Safeguards Rule at 16 CFR Part 314 applies: IRS Publication 5708 states that tax and accounting professionals are financial institutions under the Gramm-Leach-Bliley Act regardless of size.
Reasonableness is the part practitioners underestimate. Model Rule 1.6(c) requires reasonable efforts to prevent unauthorised access to information relating to a representation, and access alone is not a violation where those efforts were made. The comment on acting competently to preserve confidentiality lists the factors: the sensitivity of the information, the likelihood of disclosure without additional safeguards, their cost and difficulty, and how far they impair the representation. It then adds that a client may require special measures, or consent to forgo them. The standard varies matter by matter.
The applicable standard is set per matter, so the matter is what Thalorin holds. Controls and evidence bind to the matter and to the client guidelines that imposed them, an ethical screen is an access state with a date rather than a memorandum, and a security questionnaire is answered from the control state the firm operates. When a lateral arrival or a closed file changes who may see what, the entitlement moves with the matter and is recorded where a challenge would look.
Organizations face significant compliance challenges
Outside counsel guidelines outrank firm policy
Sophisticated clients impose security terms per engagement — hosting locations, subcontractor restrictions, notification windows measured in hours. They are negotiated separately and audited separately, so a single firm-wide baseline answers none of them completely.
A standard that changes per matter
Rule 1.6(c) is judged on factors including the sensitivity of the information and the burden of additional safeguards, and the comment lets a client demand more or consent to less. Two matters in one firm can owe genuinely different measures.
The tax practice is a financial institution
A practice that prepares returns falls under the FTC Safeguards Rule regardless of size, importing a qualified individual, a written risk assessment, encryption, multi-factor authentication and a 30-day notification duty into a partnership otherwise governed by bar rules.
Screens that exist only on paper
The screening path in Rule 1.10 turns on facts: timely isolation from the matter, no share of the fee, written notice to the affected former client. A screen in a memorandum that the document system does not enforce is hard to evidence.
How Thalorin helps
Client confidentiality controls
Bind each safeguard to the Rule 1.6(c) factor it answers — sensitivity, likelihood of disclosure, cost, burden on the representation — so the firm can show the judgement it made, not just a policy that exists.
Matter-based access control
Treat the matter, not the practice group, as the unit of authorisation. Access is granted against the matter record, so a lateral arrival, a closed file or a new screen changes entitlements where the rules reason about them.
E-discovery security
Carry the protective order and any Federal Rule of Evidence 502(d) clawback order alongside the review environment, so custodian collections, vendor access and disposition are evidenced against the order that governs them.
Professional responsibility compliance
Track state adoptions of the Model Rules and the guidance layered on top of them, including the State Bar of California's 2026 practical guidance on generative AI, against the tools the firm has actually deployed.
Client security assessments
Answer outside counsel guidelines and client questionnaires from live control state, mapping each client's clauses to the controls that satisfy them rather than re-deriving the answer for every engagement.
Conflict wall implementation
Implement the screen as an access control and a record at once: timely isolation, no fee apportionment, and the written notice to the affected former client that the rule requires.
Legal & Professional Services: common questions
Is an ethical screen enough if the screened lawyer can still open the file?
No. The screening path depends on facts a firm must show: that the lawyer was timely screened from the matter, that no part of the fee was apportioned to them, and that written notice went to the affected former client. Where the document management system still grants access, the screen is an intention rather than a state — and it is the state that gets examined on a disqualification motion. State variants differ, too: Ohio closes the path entirely where the arriving lawyer had substantial responsibility.
Does the FTC Safeguards Rule apply to a law firm?
It depends on the activity, not the professional licence. The Rule reaches any institution whose business is an activity financial in nature or incidental to one; the examples in 16 CFR 314.2 include an accountant or other tax preparation service, an entity providing real estate settlement services, and a real or personal property appraiser. A firm with a tax, settlement or appraisal practice should assume the Rule reaches it. IRS Publication 5708 treats tax and accounting professionals as covered regardless of size.
What do we do when a client's security terms conflict with our own standard?
Record which regime governs which matter. The comment to Rule 1.6 anticipates exactly this: a client may require special security measures the rule does not, or give informed consent to forgo measures that would otherwise apply. That makes the firm-wide baseline a floor rather than an answer, and it makes the mapping from a client's clauses to the controls that satisfy them the artifact worth maintaining — because it is what an audit, and a dispute, will ask for.
Can we put client documents into a generative AI tool?
Not into a tool whose confidentiality, security and data retention behaviour you have not established, and generally not without informed client consent where material risks exist. The State Bar of California's guidance is explicit that inputs, including prompts and uploaded files, can leak through the product, and that agentic systems configured to reach into firm systems raise the exposure again. State rules differ, so the controlling text is your own jurisdiction's, read alongside the client's guidelines.
Is a SOC 2 report enough to answer a client's security questionnaire?
Rarely on its own. A SOC 2 report describes a system and a selection of trust services criteria over a period; outside counsel guidelines ask matter-level questions — which people can reach this matter, where the data physically sits, which subcontractors touch it, how fast you will tell us. Both can be produced from the same control state, but the report answers the entity question and the guidelines answer the engagement one. The SOC 2 capability page covers the report itself.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Legal & Professional Services.
See how one evidence artifact satisfies Legal & Professional Services requirements alongside every other framework you carry.