The outlines of the attorney-client privilege and work-product doctrine are well-established. But how should they apply when an organizational client suffers a cybersecurity event or other intrusion that results in a data breach? Should information about the company’s security policies pre-breach and its post-breach response be given any enhanced protection? Under what circumstances?
The questions
Picture this: You’re travelling across U.S. borders, heading home from a client meeting abroad. However, unlike other trips, this time a Customs and Border Protection agent requests that you unlock and hand over for inspection your computer and cell phone — full of client confidential information. You’ve been concerned about this issue, and so you’ve
Whether you are in-house or outside counsel, your clients want the attorney-client privilege and/or work-product shield to apply to materials created as part of an internal corporate investigation. But the applicability of these doctrines is very fact-specific, and difficult facts can doom that desired outcome. That was the conclusion of the Washington, D.C. district court
Both in-house and outside counsel can learn valuable lessons from