Confidentiality, privilege and the ethical walls that protect it
In 2012, a paralegal at a major firm working on a large merger accidentally sent a batch of privileged strategy memos to opposing counsel instead of co-counsel. The mistake took eleven seconds to make and months to litigate. Courts had to decide whether attorney-client privilege, the legal protection that shields confidential communications between a lawyer and client from disclosure, had been permanently waived. That single email nearly unraveled the confidentiality architecture around a deal worth billions.
This is not a rare horror story. It is the everyday risk that law firm compliance infrastructure exists to manage. This lesson covers the rules, the regulators, and the practical mechanics of the "ethical wall" (also called a "screen" or "cone of silence") that firms build to keep privileged information contained when lawyers switch firms, firms take on conflicting clients, or teams work adjacent matters for competitors.
The legal foundation: privilege and confidentiality are not the same thing
Two distinct concepts get conflated constantly, and the difference matters for compliance design.
Attorney-client privilege is an evidentiary rule. It lets a client refuse to disclose, and prevents others from compelling disclosure of, confidential communications made for the purpose of getting legal advice. It belongs to the client, not the lawyer, and the client can waive it, sometimes accidentally (as in the email example above).
Duty of confidentiality is a broader ethical obligation. In the US it comes from ABA Model Rule 1.6 (American Bar Association Model Rules of Professional Conduct), adopted with variations by every state bar. It covers essentially all information relating to representation, not just privileged communications, and it survives even if privilege is lost or was never established. In England and Wales, the equivalent obligation sits in the SRA Standards and Conduct (Solicitors Regulation Authority) rules on confidentiality.
Waiving privilege in litigation is damaging. Breaching confidentiality is a disciplinary matter that can end a license. Firms build compliance systems to protect against both, but the mechanisms overlap only partially.
Why ethical walls exist: the conflicts-of-interest problem
Ethical walls exist because of conflict of interest rules, primarily ABA Model Rule 1.7 (current client conflicts) and Rule 1.9 (duties to former clients). The core rule: a firm generally cannot represent a client whose interests are directly adverse to another current client, and it cannot use confidential information from a former client against that client in a related matter.
The practical trigger scenarios:
- Lateral hires: a partner moves from Firm A to Firm B and previously worked on a matter now adverse to a Firm B client.
- Merging firms: two firms combine and discover overlapping representations on opposite sides of the same deal.
- Same-firm conflicting engagements: one practice group represents a company in an acquisition while another group represents a shareholder suing that company.
Rule 1.10 in most US jurisdictions allows firms to avoid imputed disqualification (where one lawyer's conflict is presumed to taint the whole firm) by screening the conflicted lawyer, essentially quarantining them from the matter, notifying affected clients, and documenting the screen. That quarantine is the ethical wall.
What an ethical wall actually requires in practice
An ethical wall is not a metaphor, it is an operational control system. A properly built wall includes:
- Access restrictions in document management systems: matters get tagged so the screened lawyer's login cannot open specific files. Firms use systems like iManage or NetDocuments with matter-level permissioning.
- Physical and communication separation: screened lawyers are excluded from meetings, distribution lists, and shared drives related to the matter.
- Written notice and certification: the screened individual signs an acknowledgment; affected clients are often notified, sometimes required under state rules.
- Conflicts database checks: before any lateral hire or new matter intake, firms run the new person and new matter against a centralized conflicts database covering all current and former clients, adverse parties, and related entities.
- Ongoing audit: general counsel or a conflicts committee periodically reviews screens to confirm they are holding, especially on long-running matters.
A useful primer on how this operates day to day comes from the ABA's own guidance: ABA Model Rules of Professional Conduct, Rule 1.10.
Who enforces this, and what happens when walls fail
Enforcement in the US is decentralized. There is no single federal "law firm regulator." Instead:
- State bar associations (e.g., the State Bar of California, the New York State Bar) license lawyers and discipline them for confidentiality and conflicts violations, up to disbarment.
- Courts rule on privilege waiver and disqualification motions case by case; a judge can disqualify an entire firm from a matter if a screen is found inadequate.
- In the UK, the SRA regulates solicitors and can fine firms or individuals; the Legal Services Board oversees SRA and other approved regulators.
- In the EU, confidentiality intersects with GDPR (General Data Protection Regulation) when client data includes personal data of EU residents, adding a second, separate compliance layer with its own breach notification duties (72 hours to the relevant Data Protection Authority).
Real consequence example: courts have disqualified entire firms from multibillion-dollar matters after finding a lateral hire's ethical wall was set up too late or too loosely, meaning the firm loses the client relationship, the fees, and often faces malpractice exposure. This is a business risk, not just a professional one, which is why large firms now run dedicated "conflicts and risk" departments led by a General Counsel or Chief Risk Officer, separate from the practicing lawyers.
Cross-border complexity for global firms
Multinational firms and matters add layers:
- In-house counsel privilege is treated inconsistently. US privilege generally extends to in-house lawyers; in the EU, following the *Akzo Nobel* ruling by the Court of Justice of the European Union (CJEU, 2010), in-house counsel communications are not privileged under EU competition law investigations because in-house lawyers are not considered sufficiently independent from their employer.
- Data residency and privilege collide when firms store documents in cloud systems spanning jurisdictions; a subpoena valid in one country may not respect privilege protections recognized in another.
- Firms operating across US and EU matters often need dual-track privilege logs, one built for US discovery standards, one accounting for the narrower EU in-house counsel exception.
Vérification des acquis
1. Why does the accidental disclosure of privileged memos to opposing counsel create such a serious legal problem?
2. A firm loses a court battle and privilege over a set of documents is ruled waived. Under the concept of duty of confidentiality, what happens next?
3. A lawyer moves to a new firm that represents a party adverse to one of the lawyer's former clients. What is the primary purpose of building an 'ethical wall' in this situation?
4. Select ALL correct answers about how attorney-client privilege differs from the duty of confidentiality.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers about situations where ethical walls are typically used in law firm compliance practice.
Sélectionnez toutes les réponses correctes.
Building the compliance muscle: what firms actually do
Real-world implementation, beyond the rulebook:
- Conflicts checks are mandatory intake gates. No new matter or lateral hire proceeds without clearing the conflicts database, run by a dedicated conflicts counsel role.
- Screens are documented, dated, and time-stamped, because if litigation challenges the wall later, the firm needs to prove exactly when the screen went up relative to when the lateral hire started.
- Technology enforces what policy states. Document management permissions, not just memos, are what actually stop access. A wall that exists only on paper does not survive scrutiny in a disqualification motion.
- Training is recurring, not one-time. Bar rules in most US states require Continuing Legal Education (CLE) hours, and ethics/professional responsibility credits are typically mandatory within that requirement.
- Malpractice insurers increasingly require documented conflicts systems as a condition of coverage, turning an ethical obligation into an insurance underwriting requirement too.
🎬 [VIDEO: "Attorney-Client Privilege Explained" — youtube.com — a concise walkthrough of how privilege works, what waives it, and why the rule differs from confidentiality obligations, useful for non-lawyers navigating this vertical]
Key Takeaways
- Privilege and confidentiality are legally distinct: privilege is an evidentiary shield the client controls and can waive (even accidentally); confidentiality is a broader ethical duty under rules like ABA Model Rule 1.6 that survives regardless.
- Ethical walls are the practical tool for managing conflicts under ABA Rules 1.7, 1.9, and 1.10, screening a conflicted lawyer through access controls, notice, documentation, and audit rather than turning down the whole firm.
- Enforcement is fragmented across state bars, courts, and (internationally) bodies like the SRA and Legal Services Board, with courts able to disqualify an entire firm if a wall is judged inadequate.
- Cross-border matters add real complexity: EU competition law strips privilege from in-house counsel communications (per the CJEU's *Akzo Nobel* decision), unlike the US default, so global firms need jurisdiction-specific privilege strategies.
- Technology, not policy language, is what actually enforces a wall: matter-level permissioning in document management systems is the operational backbone that turns an ethics rule into an enforceable control.