A law firm's duty of confidentiality does not end at the paper file. It lives on every device that held a client's matter. Document shredding deals with the paper; it does nothing for the client data sitting on a retired laptop, server or photocopier. This guide explains what law firms are actually obliged to do when they dispose of IT, and why privilege depends on getting it right.
A law firm must ensure that client data on retired IT is destroyed beyond recovery, to a recognised standard, with a record to prove it, because the duty of confidentiality and legal professional privilege that attach to client information do not lapse when a device is switched off. Under the Australian Solicitors' Conduct Rules, a solicitor must keep client information confidential, and under the Privacy Act 1988 personal information must be destroyed or de-identified once it is no longer needed. On a device, meeting both means certified wiping or physical destruction with a certificate, not a factory reset and not the paper shredder. This is exactly what IT disposal for law firms is built to deliver.
There is a blind spot in how many firms think about confidential disposal. Shredding paper files is well understood and diligently done; the retired laptop, the decommissioned server, the photocopier going back on a lease, are treated as IT to be cleared, not as confidential client material to be destroyed. Yet those devices often hold far more client data than the paper ever did. This guide covers where client data hides in a firm's IT, what confidentiality and privilege actually require at disposal, why the photocopier is the most overlooked risk of all, and what compliant destruction looks like.
A law firm's confidential information is spread across far more devices than the document management system.
| Equipment | Why it holds privileged client data |
|---|---|
| Servers & document management | The central store of matters, advice, correspondence and trust records; the highest-risk items, destroyed and certified drive by drive |
| Solicitor laptops & workstations | Draft advice, briefs, email and local copies of matter files; caches and files remain until wiped |
| Photocopiers & scanners | Internal hard drives store an image of everything scanned, copied or faxed, including affidavits, contracts and client identity documents |
| Mobile phones & tablets | Email, matter apps and messages; check for account locks before collection |
| Backup media & old drives | Historic backups can hold years of closed matters that are easy to forget and rich in privileged material |
| Networking & access systems | Switches and access control retaining configuration and staff or visitor data |
The pattern is that privilege travels with the data, not the document. A brief that was shredded in hard copy may still exist as a scan on the photocopier's drive, an email on a laptop, and a file on a backup tape. Disposing of the paper while overlooking the devices leaves the confidential material exactly where it is easiest to lose. A firm that takes confidentiality seriously has to extend the same rigour it applies to paper across every data-bearing device it retires.
The confidentiality risk appears at predictable moments. Recognising them is how a firm gets ahead of it rather than discovering a gap later.
Replacing solicitor laptops, workstations and servers is the most common trigger, and the batch usually holds a broad cross-section of current and recent matters.
The single most overlooked moment. A multifunction device is handed back to a finance company at lease end with its drive, and its stored images of client documents, intact.
Relocating or refurbishing a practice clears networking, servers and old equipment to a deadline, all of it potentially holding privileged material.
Combining firms, or a departing partner, duplicates and displaces equipment, and the retired estate can carry the confidential matters of multiple practices.
Store rooms accumulate backup media and old drives holding years of closed matters, rich in privileged material and easy to forget until an audit or a move surfaces them.
This is the wedge most firms have not closed. The document-destruction contract covers the files; it does nothing for the devices.
A firm with a diligent paper-shredding programme can still have an open confidentiality gap the size of its entire IT estate. The two are complementary, not interchangeable: paper destruction handles the documents, certified data destruction handles the devices, and a firm needs both to close the loop on client confidentiality. The distinction matters because the search terms and the vendors overlap; a "document destruction" or "secure shredding" company is usually handling paper, and the data-bearing devices need a certified IT disposal process with its own data destruction and per-device certificates.
Two duties converge on the same outcome: client data on a retired device must be destroyed beyond recovery, and it helps to be able to prove it was.
A solicitor's duty of confidentiality is a cornerstone of the Australian Solicitors' Conduct Rules: a solicitor must not disclose confidential client information, and must take reasonable steps to keep it secure. That duty does not expire when a matter closes or a device is retired; confidential material remains confidential, and legal professional privilege can attach to it indefinitely. Alongside this sits the Privacy Act 1988, whose Australian Privacy Principle 11 requires an entity to destroy or de-identify personal information once it is no longer needed, and to take reasonable steps to protect it from unauthorised access. For a law firm, a retired device holding client matters engages both: the professional duty of confidentiality and the statutory duty under the Privacy Act.
Neither duty prescribes a specific destruction method, but both point to the same practical standard: the data must be rendered unrecoverable, and reasonable steps must be demonstrable. On modern storage that means certified wiping to a recognised standard such as NIST 800-88, or physical destruction where a drive cannot be verifiably wiped, with a certificate recording that it was done. The certificate is what turns "we cleared the device" into evidence a firm can produce if a client, a regulator, or the other side ever asks how confidential material was handled. You can read more on protecting personal information at the OAIC, and on the duty of confidentiality via your state law society.
Firms must retain certain client and trust records for set periods, and privilege may require keeping some material indefinitely. So archive what you are required or advised to keep to your current systems before the old hardware is destroyed. The disposal handles the device and its residual data; your file-retention and trust-account obligations govern what must be kept elsewhere. Confirm the archive is complete, then destroy with confidence.
A confidentiality breach from a retired device is not just a data-protection failure; it is a professional one. Figures from named sources.
For most businesses, a data breach is a regulatory and reputational problem. For a law firm it is that and something more: a failure of the confidentiality that clients rely on and that privilege depends on. A single retired laptop or an un-wiped photocopier that surfaces with a client's matter on it is not only a notifiable breach under the Privacy Act, it is a breach of the professional duty at the heart of the relationship, and the damage to client trust outlasts any fine. Set against that, certified destruction with a certificate for every device is a small and obvious cost. The question a firm should ask before it retires any IT is not "how do we get rid of this", but "can we show the client data on it was destroyed".
Four things turn a firm's IT disposal into one that protects client confidentiality and can be evidenced.
Not just computers: servers, backups, phones and the photocopiers and scanners whose drives store matter documents. The scope is everything that ever held client data.
Certified wiping to NIST 800-88 for reusable equipment, and physical shredding for drives that cannot be verifiably wiped, with solid-state media handled by a matched method.
Every asset logged at collection and tracked to destruction, so there is never a window in which a device holding privileged material is unaccounted for.
Item-level proof recording what was destroyed and how, reconcilable to your asset register, so the firm can show exactly how any device was handled.
Where a firm would prefer that data never leaves the premises before it is destroyed, on-site data destruction can be arranged so drives are destroyed at your office and only then removed for recycling. Either way a certificate is issued for every device, so the choice comes down to your risk preference, not the standard of proof.
If there is one device to remember, it is the one nobody thinks of as a computer.
Almost every office photocopier and multifunction device made in the last two decades contains an internal hard drive, and that drive stores an image of the documents it processes. In a law firm, that means the machine has quietly retained a copy of a great deal of what has passed through it: affidavits, contracts, briefs, client identity documents, correspondence. When the copier reaches the end of its life or, more commonly, is returned at the end of a lease, that drive leaves the building with the firm's confidential material still on it, unless it is wiped or destroyed first. Lease returns are the particular trap, because the device is handed back to a finance company as a matter of routine, with no thought given to the data it holds.
The fix is simple once the risk is recognised: treat the copier exactly like any other data-bearing device. Before it is returned or retired, its drive is wiped to standard or physically destroyed and certified, the same process applied to the servers and laptops. A certified disposal partner handles the copier in the same collection as the rest of the IT, so nothing is overlooked and the firm holds a certificate covering the machine that would otherwise have been its biggest confidentiality gap.
The questions firms ask most about disposing of IT that held client matters.
No. A document-shredding or secure-destruction service handles paper: files, printouts and archive boxes. It does nothing for the client data on retired laptops, servers, backups, phones and photocopiers, which often hold far more confidential material than the paper did. Firms need both: paper destruction for the documents, and certified data destruction for the devices, each with its own proof.
Two main duties. The Australian Solicitors' Conduct Rules require a solicitor to keep client information confidential and take reasonable steps to secure it, a duty that does not lapse when a matter closes. The Privacy Act 1988, through Australian Privacy Principle 11, requires personal information to be destroyed or de-identified once no longer needed. On a retired device, both point to destroying the data beyond recovery and being able to show reasonable steps were taken.
Usually yes. Most photocopiers and multifunction devices contain an internal hard drive that stores an image of documents scanned, copied or faxed, which in a firm includes affidavits, contracts and identity documents. Lease returns are the common trap: the machine is handed back with its drive intact. Before it is returned or retired, the drive should be wiped or destroyed and certified.
No. A factory reset or deleting files leaves the underlying data recoverable with freely available tools. To protect privileged client material, the storage must be securely wiped to a recognised standard such as NIST 800-88, or physically destroyed, with a certificate confirming it was done. That is the step that meets the reasonable-steps test and gives the firm evidence if it is ever questioned.
Yes. Where a firm prefers that data never leaves the premises before destruction, on-site data destruction can be arranged so drives are destroyed at your office and only then removed for recycling. Otherwise devices are collected under a documented chain of custody and destroyed at the facility. Either way a certificate is issued for every device.
Retain what you are required or advised to keep, including trust records and any material subject to privilege, by archiving it to your current systems before the old hardware is destroyed. The disposal handles the device and its residual data; your file-retention and trust-account obligations govern what must be kept elsewhere. Confirm the archive is complete, then destroy the equipment with confidence.
See how ITC destroys client data on retired IT for law firms, to a recognised standard, with the chain of custody and per-device certificates that let you show confidentiality was protected right to the end.
Evidence for your auditor
Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.