\n\n

An interesting book by Dave Eggers came out several years ago called The Circle. It was later made into a mediocre movie, but the book has become considerably more disturbing with time.

The essence of the book was the drip-by-drip loss of privacy, symbolized by the loss of integrity of the main character. She goes to work for a big tech company and stands idly by as more and more private information about people becomes public, piece by piece. By the end of the book, she has wholesale bought into the company philosophy: “All that happens must be known.”

Sounds a little creepy but there is some truth to her story: we don’t notice the loss of privacy that happens gradually. And we accept more and more intrusions by entities that can get anything and everything about us and do God knows what with it. 

My Driver’s License and a Bottle of Wine

Here’s an example. I go to the store to buy a bottle of wine. I’m asked for an ID by a clerk who looks young enough to be my granddaughter, even though I’m clearly over 21. They don’t want just any ID. They want my driver’s license. Apparently, my passport, a document issued by the United States government that allows me to enter foreign countries, isn’t quite good enough to buy a $14 bottle of Cabernet without managerial intervention.

Why? They can easily and quickly scan the back of the license to confirm that I’m legal. No fuss, no muss. But think about it. Once scanned, that scan goes somewhere. Where? I don’t know. Who has it? Don’t know. How long will they keep it and what can they do with it? You got me. How protected from theft is it? Hmm.

Think there is really nothing to worry about here? Think again. A recent report from KrebsOnSecurity revealed that the FBI is now investigating an identity theft service on the dark web. That service is selling the digital scans of more than 150 million driver’s licenses from people in the United States and Canada. It appears that the scans were obtained by a hack of a widely used identity verification company based in Louisiana that most of us never heard of. There are reports that a Russian cybercrime forum is now offering access to digital scans as well. 

It’s not just scans of licenses used to buy a cheap bottle of wine

It’s not just scans of licenses used to buy a cheap bottle of wine. Rent a car: scan. Check in a hotel: scan. Buy some marijuana from a licensed dispensary: scan. See a doctor: scan. What the hell happens to all those scans? 

Here’s another example. The security camera vendor, Flock, now reportedly operates roughly 120,000 license plate readers across some 49 states. These cameras don’t just see and record your license plate. They can also make passive searches and potentially reconstruct where vehicles have been. And guess what? There have been reports of police officers using Flock searches to look up and stalk exes and romantic interests. 

So What?

It all sounds so innocent and even beneficial. Scan your license because it’s safer and quicker. Let a camera read your plate because it catches criminals. Store the information so it can be used later. Just in case. Now that you have it, why not connect the information or share it? 

Now, someone–anyone (the government, your employer) can access your information. Where you’ve been. What you’ve done

Now, someone–anyone (the government, your employer) can access your information. Where you’ve been. What you’ve done. Whether you’ve bought marijuana. How many bottles of wine you bought last month. And don’t think for a moment that some of those entities won’t hesitate to sell that information every chance they get. 

And that’s just the good guys. As the KrebsOnSecurity article shows, bad guys can get all this information as well. Do we have any idea how secure all these entities with all this information really are? 

So what you say? Here’s the so what. What if you can’t get a job because the records show that you visited a legal marijuana dispensary in another state. Or you’re a woman arrested in Texas for getting an abortion in Illinois, where it’s legal, because a scan shows you visited a clinic there. Or your insurance carrier ups your automobile premiums because of where you’ve been, what you’ve bought, or what you have done.

Or someone finds out your car is repeatedly outside an oncologist’s office. Or a divorce lawyer’s office. Or a political organization. Or somebody else’s house.

It’s a slippery slope, my friends, and it’s dangerous

Welcome to The Circle. It’s a slippery slope, my friends, and it’s dangerous. 

I Get It, But What Does It Have to Do with Lawyers? 

So Embry, you don’t like having to show your license when you buy a bottle of wine, but what does this have to do with lawyers? After all, isn’t that what this blog is supposed to be about?

Yes, and the blind loss of privacy really affects us.

Use of Platforms

First, countless lawyers are using AI these days. We are feeding enormous quantities of information into systems because it seems so convenient and harmless. We put client documents into an AI platform, entire discovery databases into another, recorded meetings into transcription services, email into AI assistants, geolocation data into analytic systems, client intake systems into CRMs, voice recordings, biometrics, browsing behavior, location information, and metadata. We even let an AI tool record our Zoom calls and make notes about what was said.

We do all this trusting that these systems, into which we’re placing all this information, are safe and secure. That they won’t do us or our clients any harm. Just like we trusted that Louisiana company (which we didn’t know existed) to safeguard our digital scans.

But that information is not ours. It belongs to our clients who trusted us with it. And we have obligations to protect it and secure it. “All that happens must be known,” is anathema to what we do. For us, it’s exactly the opposite. Everything that can be known doesn’t mean it should be known. That is the bedrock principle of privilege. 

It’s part of our duty to ask, before we turn over information:

– What’s going to happen to it?

– Where is it stored?

– For how long?

– Who else has access?

– Is it combined with other information?

– What happens if the company is acquired?

– What happens if it gets hacked?

And we need to be doubly cautious about the terms and conditions of the platforms we use. You know, the ones written by 14 lawyers in eight-point type that nobody on earth has ever read. We have a responsibility to make sure that those terms and conditions don’t jeopardize the confidential information. And that any changes in them don’t compromise the protection of that information.

We need to look at ourselves in the mirror as well.

The Man in the Mirror

And of course, we need to look at ourselves in the mirror as well. We collect a significant amount of information, personally identifiable information, and sensitive information. We house this information digitally within the bowels of the law firms in which we practice and in our own records. Or with our cloud provider. Medical records. Financial records. Trade secrets. Family secrets. You name it. How secure are we? Are we sure our cloud provider is protecting our clients’ privacy? Do we know? 

Our Clients

Clients are using this stuff too. We also have a responsibility to caution our clients as well about their use of technology. To not willy-nilly provide sensitive information to third parties. To not put sensitive information about their case or claim on a platform where the information can become public. To not say things for which they may be later sorry.

Some lawyers include a provision in their representation agreements that the client will not use AI to talk about their matter. That’s all well and good, but I think we have an obligation to explain to our clients why we–and they–need provisions like that. To get them to think about the information that they put into the digital soup and what could be done with it. 

Yes, God Help Us, There Are Ethics Rules

I know. We all roll our eyes at the mention of ethical rules. But here’s something important. Under Model Rule 1.6, our duty is not merely to protect privileged communication or confidential information. It’s broader. It’s to protect information relating to the representation of the client. 

And Comment 18 to Rule 1.6 and ABA Formal Opinion 477R require us to competently safeguard client information against unauthorized access by third parties. And inadvertent and unauthorized disclosure by us. 

More recently, ABA Formal Opinion 512 provides that before we input information into AI tools, we better understand the risks. Things like how the information is used and whether it might be disclosed or accessed by others. 

Our Duty to Our Clients

We can talk a lot about formal ethical rules and opinions till our eyes glaze over, but our real obligation is more fundamental. We are supposed to protect our clients. We are supposed to protect our clients’ privacy. They come to us precisely because they need somebody they could trust with things they may not want the rest of the world to know. It’s that trust that makes us different than someone who just wants to buy a bottle of wine.

Yeah, we have to entrust parts of what we do to third parties. We can’t realistically practice without cloud providers, email systems, document management platforms, and e-discovery vendors. But we can’t do that without knowing the risks and being reasonably sure the information is protected.

So the next time you hand over your license to be scanned, think about what’s happening. Think about your loss of privacy. Think about your client’s loss of privacy. Think about making sure that when you or your client hand over confidential information, it will be reasonably and competently protected by whoever gets it. 

Everything that happens should not be known. It’s our job to keep it that way.