Stop Sending Client Files to AI Tools Before Asking These Data Residency Questions
AI-assisted, reviewed by Adam Elias. This post was drafted with AI under Adam's editorial rules and published under his name. It is commentary, not legal advice. Verify any rule or citation against the primary source before you rely on it. Published August 2, 2026. Reviewed August 2, 2026.
There's a question almost no solo attorney asks before subscribing to an AI tool, and it's not about price or features. It's: where does my client's data actually go?
The answer matters more than most NJ practitioners realize. When you upload a contract, a deposition summary, or a client intake form to a cloud-based AI platform, that data doesn't just sit on your computer. It travels to a server, gets processed by a model, and is potentially retained by a vendor operating under terms of service you accepted without redlining a single clause. For attorneys in New Jersey, that workflow implicates confidentiality obligations that don't care whether you understood the vendor's infrastructure.
This isn't a scare piece. Most reputable legal AI vendors take security seriously. But "reputable" and "configured correctly for your practice" are two different things, and the gap between them is where ethics problems grow.
What Data Residency Actually Means
Data residency refers to the physical or legal jurisdiction where your data is stored and processed. Some AI vendors operate on servers based in the United States. Others use globally distributed infrastructure, which means a document you upload in Newark could be processed on a server in Ireland or Singapore. That matters for two reasons.
First, foreign data storage can trigger different legal regimes. If your client is involved in litigation and their data sits on a server subject to EU law, you now have a complexity most solo practitioners are not equipped to manage.
Second, and more practically, NJ RPC 1.6 requires reasonable measures to prevent unauthorized disclosure of client information. The word "reasonable" does the heavy lifting there. The New Jersey Supreme Court's Comment to RPC 1.6 explicitly notes that lawyers must consider the sensitivity of information when choosing transmission methods. An AI vendor whose data processing happens across unpredictable jurisdictions is not obviously a "reasonable" choice for sensitive matters, unless you've done the diligence to document why you believe it is.
SOC 2 and Why It's the Floor, Not the Ceiling
You'll hear vendors tout SOC 2 Type II compliance as a signal that they're serious about security. It's a meaningful credential. A SOC 2 Type II report means an independent auditor evaluated the vendor's security controls over a period of time, not just a snapshot. That's worth something.
But it doesn't answer your specific questions. A SOC 2 report tells you the vendor has controls in place. It doesn't tell you whether your data is used to train their AI model, how long it's retained after your session ends, who within the vendor's organization can access it, or what happens to it if the company is acquired.
Before you upload a single client file, you want written answers to those four questions. If the vendor's website doesn't answer them, ask your sales contact in writing. If they can't or won't answer, treat that as relevant information.
The Business Associate Agreement Problem
If any of your clients are covered entities or business associates under HIPAA, such as a medical practice, a healthcare provider, or an insurer, you already know you need Business Associate Agreements with your own vendors. What some attorneys miss is that their AI tool vendor may need to be part of that chain too.
If you're running a personal injury practice and you upload medical records to an AI tool to draft a demand letter, and that vendor has no BAA with you, you have a gap. The AI vendor is handling protected health information without the contractual framework HIPAA requires. That's your problem, not theirs.
Getting a BAA signed is not complicated. Many major vendors offer them, sometimes automatically at certain subscription tiers, sometimes only if you ask. The point is you have to ask, and you have to ask before the data moves.
A Practical Approach for NJ Solo Firms
The goal isn't to avoid AI tools. It's to use them with enough specificity that if the NJ Office of Attorney Ethics ever had a question about your vendor choices, you could point to a documented process.
Start with a short vendor intake checklist you run before subscribing to any new AI tool. It should cover, at minimum: where data is stored and processed, whether the vendor uses customer data for model training (and whether you can opt out), retention periods, SOC 2 or equivalent audit status, whether a BAA is available, and what their breach notification process looks like.
Keep a copy of the vendor's data processing agreement or privacy policy as it existed when you signed up. Vendors update these. If you have the original version, you have a record.
Then, map that vendor against the types of matters you handle. A tool that's appropriate for drafting non-sensitive commercial correspondence may not be the right choice for family law intake documents or criminal defense work. The sensitivity of the matter should inform how tightly you vet the infrastructure behind the tool.
None of this takes more than an hour per vendor. It's the kind of due diligence that RPC 1.1's competence requirement has always expected attorneys to apply to the tools they use, even before AI was part of the conversation. The technology changed. The obligation didn't.
Get the weekly roundup
New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.