ABA Data Breach Response Flowchart


Published: October 2018Click To View (PDF)

This flowchart describes the duties imposed on attorneys by the Model Rules of Professional Conduct following a data breach or cyberattack in which client information was compromised. It provides a stepwise process for attorneys to follow after the attack. The chart is based on the guidance published by the American Bar Association in Formal Opinion 483. Attorneys’ duties of competence, confidence, and to keep the client reasonably informed impose distinct, but overlapping, obligations following a breach.