What if we’re a law firm?
Attorney-client privilege has no expiration date. Neither does a client’s expectation that what they told you stays told to you.
That single property puts a law firm’s material in the same category this resource identifies as the worst case for any business: information whose value to somebody else survives a decade in storage. Trade secrets earn that description because secrecy itself is the asset. Privileged communications earn it for the same structural reason.
The profession’s own habits compound it. Litigation holds preserve exactly the material with the longest damage horizon, and matter files routinely outlive the matter, the client relationship, and sometimes the firm.
Not legal advice
This is general education rather than advice on professional obligations. What your rules of professional conduct require of you is a determination for your own counsel and your bar.
The short version:
- Privilege has no expiry, which makes privileged material structurally identical to a trade secret.
- Litigation holds preserve the highest-value material, so the profession’s own discipline works against deletion here.
- Your duty of technological competence already reaches this, in most jurisdictions, without anything new being written.
- The material an opponent would most value is exactly what’s most retained: strategy, internal assessments, settlement positions.
- Most of your cryptography belongs to vendors, since firms buy document management, email, and e-discovery rather than build it.
- Small firms are in a genuinely simpler position, because the whole estate is a vendor list.
Why is privileged material the worst case?
Because 3 properties stack, and few other categories carry all 3.
It never expires. A privileged communication from 2026 remains privileged indefinitely, and the underlying facts frequently remain damaging for as long as the client or the matter has consequences. A settlement position, an internal assessment of a client’s exposure, or a candid note about a witness does not become harmless with age.
It’s concentrated. A matter file gathers the client’s secrets, the firm’s assessment of them, and the strategy built on both, in one place. The Guide describes communications archives as the densest single target in any organization because they concentrate everything else, and a law firm’s files are that concentration by design.
It’s deliberately preserved. Litigation holds suspend deletion precisely for the material most worth having. Retention schedules keep matter files for years past closure. Deletion is the cheap protection available to every other organization, and a firm under hold is frequently forbidden from using it.
What do our own obligations already require?
More than most firms have connected to this, and none of it is new.
Most U.S. jurisdictions have adopted a duty of technological competence, requiring lawyers to keep abreast of the benefits and risks of relevant technology. Confidentiality duties require reasonable efforts to prevent unauthorized disclosure of client information. Neither names cryptography, and both are the kind of general standard that a court later interprets against whatever was publicly known at the time.
That’s the relevant mechanism. The replacement standards were finalized on August 13, 2024, and multiple governments have published dated retirement schedules for the old ones. Those facts are public, dated, and easy to establish after the fact.
Source: NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024, nist.gov.
A firm arguing in 2032 that nobody could have known is arguing against the public record. What “reasonable efforts” required in 2026 will be assessed with the benefit of that record.
What is actually at risk in a firm?
| Category | Why it’s exposed | How long it stays damaging |
|---|---|---|
| Matter files and work product | Concentrates the client’s secrets and the firm’s assessment of them | Indefinitely for many matters |
| Privileged communications | Privilege makes them valuable precisely because they were never meant to be seen | Indefinitely |
| Settlement and negotiation positions | Reveals a client’s true valuation of their own exposure | Beyond the matter, into every future negotiation |
| Internal investigations | Frequently the most sensitive material a firm ever holds | Indefinitely |
| Client intellectual property | Firms hold what clients hold, in patent, licensing, and transactional work | No expiry, per the client’s own trade-secret position |
| Deal and diligence rooms | Concentrated, time-sensitive, and retained afterward | Sharp initially, and the file persists |
| Client personal data | Immigration, family, criminal, and employment matters | The client’s lifetime |
The immigration, family, and criminal categories deserve separate emphasis. Those clients frequently sit in the population where exposure is a safety question rather than a commercial one. See If you are a high-risk person.
What can a firm actually control?
Less than it would like, and the honest accounting is useful.
Most firms buy their technology rather than build it. Document management, email, practice management, e-discovery platforms, and secure file transfer are vendor products, which means the cryptography inside them is on somebody else’s release schedule. That’s the same position most organizations are in, and it makes the vendor question the central one.
What a firm does control:
- Which vendors it uses, and what it asks them at renewal.
- Its retention schedule, within what the rules and holds permit.
- Where the genuinely sensitive material lives, and whether it’s segregated.
- What it tells clients about how their material is handled.
What are the 6 things worth doing?
Ordered by value, and none of them require a technology program.
- Ask your document management and email vendors for a dated post-quantum commitment. These 2 hold most of what matters. The letter template at What if we are a small business works unchanged.
- Identify the matters where exposure would still be damaging in 15 years. For most firms this is a minority of files, and knowing which ones is the whole prioritization exercise.
- Review retention against what the rules actually require, rather than what habit has preserved. Material kept because nobody decided to stop is exposure the firm chose to carry.
- Treat email as the weak channel, because it largely is. For genuinely sensitive client contact, a modern encrypted channel is better protected today.
- Decide what you tell clients. Sophisticated clients, particularly in regulated industries, will start asking. A firm with an answer is in a better position than one improvising.
- Put it in front of whoever owns risk at the firm, framed as a confidentiality-duty question rather than an IT question. That’s the framing that gets it resourced.
Does this differ by firm size?
Substantially, and small firms have the easier problem.
A large firm faces the same estate problem as any large organization: many systems, acquisitions, legacy platforms, and a genuine inventory challenge. The work is real and it looks like What is technically happening to our systems.
A small firm or solo practice has almost everything in 4 or 5 vendor products. That’s an inventory you can write on one page, and it makes the vendor question tractable in a way it isn’t for a firm of 2,000. The small-business page applies almost directly. See What if we are a small business.
Questions people ask
Is privileged material really comparable to a trade secret? Structurally, yes. Both derive their value from remaining secret and neither has an expiration date, which is the property that makes stored data worth collecting.
Does the crime-fraud exception or waiver change the analysis? Those affect whether privilege attaches, rather than how long the underlying material stays damaging. An adversary reading a file is unaffected by whether privilege would have been sustained.
Litigation holds prevent us from deleting. What then? Then deletion isn’t available and prioritization matters more. Identify which held material would still be damaging in 15 years and make sure it sits in the best-protected systems you have.
Do our professional rules require us to do anything specific? No rule names cryptography. The duties of competence and confidentiality are general standards, and how they apply here is a question for your counsel and your bar.
Should we tell clients? Increasingly, sophisticated clients will ask first. Having a considered answer is better than being asked without one.
What about our e-discovery vendors? They hold concentrated, litigation-relevant material. They belong at the top of the vendor question list alongside document management.
Is any of this urgent for a small practice? The vendor questions are worth a morning. Beyond that, the useful frame is knowing which of your matters have a 15-year damage horizon.
Where to go next
- What of our company data is at risk covers the 9 data families and their lifetimes.
- What if we are a small business applies almost directly to a small practice.
- What can I not fix myself covers the vendor question in depth.
- If you are a high-risk person covers clients whose exposure is a safety question.
- For Business Leaders MOC is the full business route.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.