Privilege and the agency exception
Attorney-client privilege attaches to confidential communications made for the purpose of obtaining legal advice, and disclosure to a third party can defeat it. The usual answer for a transcription vendor is that the disclosure falls within the agency exception: a vendor engaged by counsel to assist in the representation is treated as within the circle of confidentiality, in the same way a paralegal or an expert is.
What makes that work is the engagement, not the technology. A vendor retained under terms that identify them as assisting counsel, bound to confidentiality, and instructed not to disclose, is in a materially different position from a consumer tool used by a lawyer with a credit card and a click-through licence. The terms are doing the work.
Protective orders and sealed material
A protective order may restrict disclosure of produced material to specified categories of people - counsel of record, experts, sometimes a defined list - and uploading that material to a vendor is a disclosure. Whether the vendor falls within a permitted category depends on the order's wording, and the obligation to get that right sits with the firm.
Sealed material is stricter still. Where a court has sealed a filing or a transcript, sending it to a vendor without checking the sealing order is a risk taken on behalf of a client who did not agree to it. This is the step most often skipped, because the material arrives as an audio file like any other and nothing about it announces its status.
- Check whether the protective order defines who may receive the material
- Check whether sealing terms restrict disclosure at all
- Confirm the vendor is engaged under terms that place them within counsel's circle
- Confirm whether subcontractors or model providers also receive the audio
- Ask whether the vendor serves other parties in the same matter
The conflict nobody checks
A transcription vendor large enough to serve many firms may already be handling material for the other side of your matter. There is no mechanism that surfaces this, because nobody asks and the vendor has no duty to volunteer it. For most matters it is immaterial; in a high-stakes one it is the kind of fact that is uncomfortable to discover later.
The question is simple to put and rarely put: do you currently hold material for any other party in this matter, and what separates it from ours? A vendor that can answer that has thought about it.
What we do, specifically
Material is scoped to the organisation that uploaded it and to the matter it was filed in - every query filters on both, and access is logged. Audio is not used to train models. Deletion is available on request with confirmation rather than as an assurance. We will sign a confidentiality agreement and can state in writing that we are engaged to assist counsel, which is the provision that matters for the agency analysis.
What we cannot do is tell you whether your protective order permits disclosure to us, or whether sealed material may be sent. Those are determinations for counsel on the terms of the specific order, and a vendor claiming otherwise is offering an opinion it is not qualified to give.
Supervision is a professional obligation, not a procurement one
Model Rule 5.3 makes a lawyer responsible for the conduct of nonlawyer assistance, including an outside vendor, where the lawyer orders or ratifies the conduct or fails to take reasonable remedial action. That framing matters because it means the obligation is not discharged by signing whatever the vendor offers - it requires some judgement about whether the arrangement is adequate.
In practice "reasonable efforts" means knowing where material goes, who can reach it, and what happens when the engagement ends. A firm that cannot answer those questions about its own vendor has not met the standard, however good the vendor turns out to be. The standard is about the firm's diligence rather than the vendor's competence.
Three questions worth asking about an incident
Most confidentiality discussions concern prevention, and the more revealing questions are about what happens afterwards. Will the vendor notify you of a breach, within what period, and does that commitment appear in the contract rather than in a policy page they can revise?
Then: can they tell you which of your files were affected? A vendor without per-file access logging can only tell you that something happened somewhere, which is not enough to meet a client-notification obligation. And finally, what survives termination - is your material returned, destroyed, or retained under terms you did not negotiate?
These are answerable in writing and rarely asked. A vendor that answers them specifically has thought about the failure case, which is more informative than any security page.
- Breach notification: committed in the contract, with a stated period
- Per-file access logs, so an incident can be scoped rather than described
- Return or destruction of material on termination, confirmed
- Whether subcontractors are bound to the same obligations
Sources
- Fed. R. Civ. P. 26(c) (protective orders)
- Model Rules of Prof'l Conduct r. 1.6 (confidentiality of information)
- Model Rules of Prof'l Conduct r. 5.3 (responsibilities regarding nonlawyer assistance)
Verified 19 September 2026.
The regulatory information on this page is general background compiled from public primary sources, not legal or compliance advice. Requirements change and vary by jurisdiction and by court. Verify current rules with the relevant authority or your own counsel before relying on them.