Sovereign Cloud for Law Firms: SRA Compliance and Client Confidentiality

For UK law firms, client confidentiality is a regulatory duty, not a preference. Paragraph 6.3 of the SRA Codes requires the affairs of current and former clients to be kept confidential. And where your cloud provider is incorporated determines which government can compel access to those files. Sovereign cloud for law firms keeps client data under UK law only.

Quick facts

  • The duty: paragraph 6.3 of the SRA Codes of Conduct – keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.
  • The overlooked risk: SRA guidance treats cloud storage as outsourcing, and warns that clients may not realise their information can end up considered in a foreign jurisdiction.
  • The legal exposure: US-headquartered providers are subject to the US CLOUD Act – client files can be compelled without a UK court order and without notification.
  • The operational lesson: the November 2023 cyber attack on legal IT provider CTS disrupted around 80 UK firms through a single supplier.
  • The structural fix: a UK-incorporated sovereign cloud provider keeps client data governed exclusively by UK law.

Why does data sovereignty matter for law firms?

A law firm’s data is not ordinary business data. Case files, correspondence, and instructions carry two layers of protection that most industries never deal with. The first is the professional duty of confidentiality owed to every current and former client. The second is legal professional privilege, which attaches to advice and litigation material. Both assume the firm controls who can see the information.

Cloud hosting does not weaken either protection by itself. However, it does add a question most firms never ask: which country’s law governs the company holding the files? A UK data centre is not the same as UK legal control. That distinction between residency and sovereignty is covered in full in our guide to what UK sovereign cloud hosting is. For a law firm, the short version is simple. A US-owned provider’s London servers remain within reach of US legal process.

Key takeaway: Client confidentiality and privilege assume the firm controls access to its files. If the provider holding them answers to a foreign government, that control has a gap in it. The location of the servers does not close it.

What do the SRA rules require for cloud and outsourcing?

Paragraph 6.3 of the SRA Codes of Conduct requires you to keep the affairs of current and former clients confidential. The only exceptions are where disclosure is required or permitted by law, or where the client consents. The duty attaches to all information received in connection with the retainer. Crucially, it does not expire when the matter closes.

The SRA’s confidentiality guidance is explicit that outsourcing includes any arrangement for storing data with a third party via the cloud. It also points firms to National Cyber Security Centre guidance for assessing whether a cloud provider is secure enough to protect client data. Additionally, the same guidance carries a warning that goes to the heart of the sovereignty question. Clients may not have agreed or understood that their confidential information could be considered by an unregulated third party – and in certain cases, in a foreign jurisdiction.

Three practical consequences

  • The firm remains responsible. Moving files to a cloud provider does not move the confidentiality duty. If the provider fails, the regulatory exposure is the firm’s.
  • Due diligence is expected, not optional. The SRA expects firms to satisfy themselves that suppliers meet appropriate security standards. Firms must also be able to evidence that assessment.
  • Jurisdiction is part of the assessment. A provider whose corporate structure exposes client files to foreign legal process is a fact the firm needs to have considered. It must also be able to justify it.

The Law Society’s cloud computing practice note reinforces the same position. Cloud brings real benefits, but firms are expected to navigate the risks deliberately rather than discover them later.

Does legal professional privilege protect files from the US CLOUD Act?

No – and this is the point many firms miss. Legal professional privilege is a protection under UK law. It binds UK courts and UK authorities. However, it does not bind US authorities acting under US law against a US company.

The US CLOUD Act lets American authorities compel US-headquartered cloud providers to disclose customer data regardless of where it is stored. That includes files sitting in a London data centre. The demand is served on the provider, not the firm. It does not require a UK court order. It can also be accompanied by non-disclosure requirements, meaning the firm may never know its client files were produced. We cover the mechanics in full in our guide to the US CLOUD Act and UK data sovereignty.

The scenario to consider

For a law firm, the scenario is concrete. A client matter touches a US investigation, and the firm’s files are held with a US-owned provider. Privileged material is then compelled through the provider under US process. The privilege argument happens – if it happens at all – in a US forum, after the fact, without the firm in the room. As a result, the only way to keep that scenario structurally impossible is for the provider to have no US legal nexus.

Legal professional privilege shown as protection that applies within UK jurisdiction only
Legal professional privilege binds UK courts and authorities only – it does not prevent disclosure compelled under US law.

Key takeaway: Privilege is a UK legal protection. It travels only as far as UK jurisdiction does. If client files are held by a US-owned provider, their protection from US process depends on US law – not on privilege.

What did the CTS attack teach the legal sector?

In November 2023, a cyber attack hit CTS, a managed IT provider serving the UK legal sector. Around 80 law firms were left unable to access case files or complete transactions. Conveyancing was hit hardest. Completions stalled, clients were left in limbo between homes, and firms resorted to manual workarounds while restoration took weeks. There is no suggestion CTS was at fault. In fact, that is precisely the lesson: a single supplier incident became the sector’s problem overnight.

Two conclusions for IT procurement

  • Supplier due diligence is a confidentiality and continuity issue, not an IT formality. Commentary at the time noted that firms rarely ask where their supplier’s servers are located, or what security measures protect them. However, these are exactly the questions the SRA expects firms to be asking.
  • Recovery capability matters as much as prevention. A firm’s ability to keep serving clients through an incident depends on its provider’s disaster recovery. That means a defined recovery point, a tested failover, and infrastructure that is as protected as the primary environment. This is the case for sovereign DRaaS: recovery infrastructure under the same UK jurisdiction and security standards as the live systems. It carries a 1-second recovery point objective through continuous replication.
Law firm business continuity depending on its supplier's tested disaster recovery
The November 2023 CTS attack disrupted around 80 UK law firms through a single supplier.

What should a law firm look for in a cloud provider?

The SRA does not publish a provider checklist. However, its confidentiality guidance, the NCSC guidance it points to, and the lessons of the last few years converge on the same set of questions:

Key requirements law firms should check before choosing a cloud hosting provider
Six questions law firms should ask a cloud provider: jurisdiction, certifications, encryption and access logging, tested recovery, UK-based staff, and exit terms.
RequirementWhy it mattersWhat to ask
UK jurisdiction – incorporated and operatedDetermines which government can compel access to client filesIs there a foreign parent company anywhere in the structure?
ISO 27001 and Cyber Essentials PlusIndependent evidence for the due diligence file the SRA expectsAre certificates current and independently audited?
Encryption at rest and in transit, role-based accessThe technical backbone of the paragraph 6.3 dutyWho holds the encryption keys? Are access logs auditable?
Tested DR with defined RPO and RTOContinuity through a supplier incident – the CTS lessonWhat is the recovery point? When was failover last tested?
UK-based support staffNo foreign personnel with access to client dataWhere are the engineers who can touch our environment?
Clear exit and data return termsThe firm must keep control of client data through any changeWhat is the notice period and the data return process?

How does BlackBox support law firms?

BlackBox Hosting is a UK-incorporated sovereign cloud provider operating from Tier 3+ data centres in London, with no foreign parent company. Client files hosted with BlackBox are governed exclusively by UK law and are not subject to the US CLOUD Act. The sovereign cloud platform is built for exactly the material law firms hold: case files, document management systems, and communication tools. Additionally, everything is protected by encryption, granular access controls, and multi-factor authentication, in line with SRA, Bar Council, and ISO 27001 confidentiality requirements.

  • Certified to ISO 27001, ISO 22301, ISO 20000-1, ISO 9001, ISO 14001, ISO 14068-1:2023, CSA STAR Level 2, and Cyber Essentials Plus – the audit evidence a due diligence file needs.
  • 24/7/365 UK-based engineers – no offshore support with access to client environments.
  • Sovereign DRaaS with a 1-second recovery point objective – continuity through the kind of incident that stopped 80 firms in 2023.
  • 99.999% network uptime guarantee from Tier 3+ UK facilities, and G-Cloud listed on the Crown Commercial Service Digital Marketplace.

“A law firm’s whole value rests on clients being able to speak freely. The moment a foreign government can reach those files without a UK court ever being involved, that promise has an asterisk on it. Sovereignty removes the asterisk.”

– Matt Burden, Founder & Managing Director, BlackBox Hosting

Key takeaway: The SRA expects firms to know where client data is, who can access it, and under what law. Sovereign cloud is the only hosting model that answers all three questions with ‘the UK’. Structurally, not contractually.

FAQ: Cloud hosting and SRA compliance

Is cloud hosting allowed under SRA rules?

Yes. The SRA does not prohibit cloud computing – its guidance treats it as outsourcing. The firm remains fully responsible for client confidentiality. It is also expected to carry out and evidence due diligence on the provider’s security and suitability.

Does the SRA require client data to be stored in the UK?

There is no explicit residency mandate. However, the confidentiality duty, UK GDPR obligations, and SRA guidance on foreign jurisdictions all point the same way. Foreign legal exposure is difficult to justify in a due diligence assessment, particularly for privileged material.

Can US authorities access client files held with a US cloud provider?

Yes. Under the US CLOUD Act, American authorities can compel a US-headquartered provider to disclose data regardless of where it is stored – including files in UK data centres. This can happen without a UK court order, and potentially without the firm being notified.

Does legal professional privilege protect files from the CLOUD Act?

No. Privilege is a protection under UK law and binds UK courts and authorities. It does not bind US authorities acting under US law against a US company. As a result, protection from foreign process has to come from the provider’s jurisdiction, not from privilege.

What certifications should a law firm’s cloud provider hold?

ISO 27001 is the baseline for independently audited information security. Cyber Essentials Plus demonstrates UK government-backed security controls. CSA STAR Level 2 and ISO 22301 (business continuity) strengthen the due diligence file further. Certificates should be current and independently verified, not self-attested.

What happens if our IT provider suffers a cyber attack?

The 2023 CTS incident showed the answer depends on decisions made before the attack. Ask three things. Does the provider have tested disaster recovery? What recovery point and recovery time does it commit to in the service agreement? And is the failover environment as protected as the primary one? Firms should get these commitments in writing.

Is sovereign cloud more expensive than public cloud for a law firm?

Not necessarily. Sovereign providers typically use fixed monthly pricing with no consumption penalties or egress fees. For the steady, compliance-sensitive workloads law firms run, that often works out more predictable – and frequently cheaper – than hyperscaler billing.

#main-content .dfd-content-wrap {margin: 0px;} #main-content .dfd-content-wrap > article {padding: 0px;}@media only screen and (min-width: 1101px) {#layout.dfd-portfolio-loop > .row.full-width > .blog-section.no-sidebars,#layout.dfd-gallery-loop > .row.full-width > .blog-section.no-sidebars {padding: 0 0px;}#layout.dfd-portfolio-loop > .row.full-width > .blog-section.no-sidebars > #main-content > .dfd-content-wrap:first-child,#layout.dfd-gallery-loop > .row.full-width > .blog-section.no-sidebars > #main-content > .dfd-content-wrap:first-child {border-top: 0px solid transparent; border-bottom: 0px solid transparent;}#layout.dfd-portfolio-loop > .row.full-width #right-sidebar,#layout.dfd-gallery-loop > .row.full-width #right-sidebar {padding-top: 0px;padding-bottom: 0px;}#layout.dfd-portfolio-loop > .row.full-width > .blog-section.no-sidebars .sort-panel,#layout.dfd-gallery-loop > .row.full-width > .blog-section.no-sidebars .sort-panel {margin-left: -0px;margin-right: -0px;}}#layout .dfd-content-wrap.layout-side-image,#layout > .row.full-width .dfd-content-wrap.layout-side-image {margin-left: 0;margin-right: 0;}