Encrypting email in Outlook or Gmail protects privileged communications from some risks and not others, depending on the plan, the setting used and who holds the encryption keys. Encryption supports the confidentiality that privilege depends on, but whether an email keeps attorney-client privilege turns on the facts and law rather than on an encryption setting. This post compares the built-in Microsoft and Google options against ABA guidance and against the questions regulated clients put to their law firms.

Is regular email safe for privileged attorney-client communications?

Regular email can be acceptable for many client communications. ABA Formal Opinion 477R says a lawyer “generally may transmit information relating to the representation of a client over the internet without violating the Model Rules of Professional Conduct where the lawyer has undertaken reasonable efforts to prevent inadvertent or unauthorized access.” The qualifier matters, and sensitive matters raise the bar.

The same opinion continues: “However, a lawyer may be required to take special security precautions to protect against the inadvertent or unauthorized disclosure of client information when required by an agreement with the client or by law, or when the nature of the information requires a higher degree of security.” Privileged strategy, health records, deal terms and government contract data are the kinds of material where that sentence can apply.

Model Rule 1.6(c) frames the duty as “reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.” Comment [18] lists what goes into reasonableness, including “the sensitivity of the information” and “the likelihood of disclosure if additional safeguards are not employed.”

What does Microsoft 365 encryption do for a law firm?

Microsoft Purview Message Encryption lets a firm send encrypted messages from Outlook. Recipients outside Microsoft 365 “can read and reply to encrypted messages on the web through your web browser.”

Purview Message Encryption uses the Azure Rights Management service, and Microsoft says that letting Microsoft manage the root key for that service “is the default setting and recommended best practice for most organizations.” Mail stored in Exchange Online is likewise encrypted with Microsoft-managed keys by default, with Customer Key as the customer-managed option. The practical questions for a firm are which plan it is on, whether staff apply encryption consistently, how clients experience the web portal step, and who controls the keys.

What does Google Workspace encryption do for a law firm?

Google Workspace client-side encryption (CSE) adds encryption to files and email that Google says “Google servers and third parties can’t decrypt.” It is available only on certain editions: Google lists Frontline Plus, Enterprise Plus, Education Standard and Education Plus. Most small firms on Business editions would need to change edition to use it.

Without CSE, Google encrypts Workspace data at rest and Google manages cryptographic keys on behalf of its customers. That is standard for hosted email and does not make Gmail unsuitable, but it does mean the provider’s systems can process the content. If your client asks “can your email provider read our data?”, the answer depends on the configuration.

Why does key custody matter for privileged email?

Key custody matters because whoever holds the keys can decrypt the content. If the provider holds them, a breach of the provider, an insider, or a legal demand served on the provider can reach privileged messages. If only the firm and its clients hold the keys, then the provider cannot hand over readable message contents or files.

Two client-driven rules make this concrete. A firm that is a HIPAA business associate (one that handles protected health information, or PHI, for a healthcare client) must have a business associate agreement (BAA) with any vendor that maintains or transmits PHI for it (45 CFR 164.308(b)(2)), and its client will ask what that vendor can see. Clients regulated by the New York Department of Financial Services (DFS) must keep guidelines for third-party service providers that address, “to the extent applicable,” multi-factor authentication and “use of encryption as required by section 500.15 to protect nonpublic information in transit and at rest” (23 NYCRR 500.11(b)). A law firm with access to the client’s nonpublic information meets its definition of a third-party service provider (500.1(s)).

How do the options compare for privileged email?

The options differ on three points that matter for privileged email: which plan includes encryption, how an outside client reads the message, and who can decrypt stored content. Standard hosted email leaves the keys with the provider; customer-held key options and end-to-end encryption change that.

QuestionStandard Outlook or GmailMicrosoft Purview Message EncryptionGoogle WorkspacePreVeil
Who can decrypt stored contentProvider manages keysProvider unless BYOK is set upDepends on configurationOnly senders and recipients; keys on user devices
Supports 164.312(e)(2)(ii) transmission encryption (addressable)In transit onlyYes, when appliedYes, on supported editionsYes, end to end
Supports ABA Op. 477R “special security precautions”Depends on the matterYes, when appliedYes, when appliedYes

How does PreVeil protect privileged client email?

PreVeil encrypts message contents, attachments and files end to end inside Outlook, Gmail and Apple Mail, so privileged email stays in the tools lawyers already use. Keys are generated and held on each user’s device. Clients read and reply for free from their browser, and their replies stay encrypted.

PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices. PreVeil uses FIPS 140-3 validated cryptographic modules, and the Business plan includes activity logs in the admin console. PreVeil offers a BAA with law firms to protect PHI.

The guide to law firm security obligations for regulated clients covers each client obligation in more depth, and the PreVeil for law firms page has more information.

Frequently asked questions

Is Outlook encryption end-to-end encrypted?

Microsoft Purview Message Encryption encrypts messages with keys Microsoft manages by default. Whether Microsoft can access content depends on how keys are configured.

Is Gmail end-to-end encrypted?

Google’s client-side encryption is only available on select plans – free personal accounts and normal Google Workspace plans do not offer this.

What do clients mean when they ask if our email provider can read their data?

Clients asking this want to know about key custody: whether the provider holds keys that could decrypt stored or transmitted content. BAAs, NYDFS vendor policies and questionnaires raise the same point.

Can PreVeil read privileged email?

Never. The encryption keys stay on users’ devices, so PreVeil cannot access or decrypt message contents, attachments or files.

Sources

Talk to PreVeil about privileged email

A demo shows PreVeil inside Outlook or Gmail and how it answers a client’s question about who can read the firm’s email. Request a demo