Firm Practice, Client Data And Professional Boundaries

Kritika Krishnamurthy

3 Sept 2026 11:40 AM IST

  • Firm Practice, Client Data And Professional Boundaries

    On the Tug of War Nobody Admits, the WhatsApp Group Nobody Talks About, and the Client Caught in the Middle

    Listen to this Article

    It starts with a general counsel receiving a WhatsApp message from a lawyer they have worked with closely for three years. The message is warm. It references shared history: a deal they navigated together, a difficult negotiation that went well, the easy shorthand that develops between professionals who have worked through hard problems side by side. It feels, on first reading, like friendship. On closer examination, it is the opening move in a business development campaign, and the general counsel is the bounty prize.

    The lawyers making that WhatsApp call are not, in most cases, acting from malice. Many of them genuinely believe the relationship is theirs. They were the face of the firm in every meeting. The idea that the relationship belongs to the institution rather than to them feels, from where they sit, like an abstraction at best and an injustice and often we have heard a 'joke' at worst.

    The Technology Era Changed the Boundaries. Nobody Updated the Rules.

    Legal practice has always involved the movement of lawyers between firms. A generation ago, when a lawyer changed firms, the data of the client relationship stayed largely where it was: in firm files, in firm correspondence, in institutional systems that a departing professional could not carry out the door in a briefcase. The relationship might follow the lawyer. The personal data could not.

    That world no longer exists, and the profession has not fully reckoned with what replaced it. The personal data of the client relationship now lives in places that no firm fully controls and no exit protocol adequately addresses. It lives in WhatsApp groups created for a specific matter that persist, quietly, long after the matter concludes. It lives in mobile contact lists populated with numbers shared in the course of professional engagement. It lives in Teams channels, shared drives, email threads, and cloud-based platforms that exist simultaneously within and beyond firm infrastructure. It is distributed, portable, and in most firms, entirely ungoverned.

    When Teams Move: The Client Caught in the Middle

    The individual lawyer departure is a manageable governance challenge for a firm with adequate protocols in place. The team departure is something else. When a group of lawyers leaves simultaneously to join a competitor or establish their own practice, they move as an institutional unit, carrying between them the collective client knowledge, relationship history, and data accumulated over years of shared professional engagement. Most of this does not come within the ambit of the definition of 'personal data' under the Digital Data Protection Act, 2023. All of it comes within the definition of 'confidential information' of non-disclosure agreements chambers or law firms sign when onboarding the client serviced by the departing advocate.

    For the client, this creates a situation of genuine complexity that nobody asked them to navigate. They receive communications from multiple parties simultaneously: the firm asserting continuity of relationship, the departing team asserting the primacy of personal connection, the new firm offering a fresh start. They are being asked to make a decision about their legal representation in the middle of someone else's professional dispute, using information that all sides are presenting in their own interest.

    The client shared their contact details, their matter history, and their commercial thinking for a specific professional purpose. That data now travels between institutions without their knowledge, enabling conversations they did not initiate, serving interests they have not endorsed. The lawyers involved in those conversations are not, for the most part, aware of any wrongdoing. They are operating within what the culture of the profession has long treated as acceptable. That cultural acceptance is precisely the problem.

    The Draconian Employer Dilemma

    The moment a firm implements data governance policies- restricting personal device usage for professional communications, requiring firm-managed platforms, establishing protocols around client contact data and matter WhatsApp groups, the same objection surfaces, almost without variation. This is surveillance. This is distrust. We are not that kind of employer.

    It is worth sitting with that objection, because it has genuine weight. Legal practice is built on professional relationships, and professional relationships require a degree of personal trust that institutional frameworks can feel like they undermine. A lawyer who has spent three years building a client relationship does feel a personal stake in it.

    And yet. The same lawyers who resist these frameworks in a law firm operate without objection within the data governance frameworks of the organisations they advise. A lawyer seconded to a technology company accepts, as a condition of that engagement, that their device usage will be governed, their communications will be logged, their access to client data will be role-limited, and their departure will trigger a systematic review of the data they hold. They experience this as professional normalcy. They have never once described a technology company as a draconian employer for expecting it.

    The resistance in law firms is habitual rather than principled. It reflects an assumption embedded in the culture of legal practice for decades: that the professional autonomy of the lawyer extends to the data of the client relationship. That assumption made a kind of sense in the world of the first paragraph of this article, where a senior consciously gifted a client relationship to a departing professional. In a world where client data lives on personal devices and in ungoverned WhatsApp groups, it has become the justification for something considerably different.

    Every Other Sector Resolved This. Law Has Not

    The data governance problem Indian law firms are navigating was navigated and resolved by every other knowledge-intensive sector over the past two decades. Banking, financial services, technology, pharmaceuticals, consulting: every industry in which professionals hold sensitive client data and move between employers has developed frameworks for managing the tension between individual professional mobility and institutional data protection. The legal profession remains the exception, and the question of why is worth examining.

    The principle that emerged as the baseline standard across these sectors is what the technology industry calls zero trust: the architectural assumption that access to sensitive data is never granted by default, always verified by institutional necessity, always logged and auditable, and always bounded by the scope of the role that justified it. Access does not persist beyond the role. Data does not travel with the individual. The institutional framework, rather than individual discretion, determines what is held, by whom, and for how long.

    A bank does not allow a relationship manager to take client contact data when they resign. A consulting firm does not allow a departing partner to retain access to client engagement records. A pharmaceutical company does not allow a medical affairs professional to carry clinical data to a competitor. The professionals working within these frameworks do not experience them as distrust. They experience them as the baseline expectation of serious institutional work. The data belongs to the institution. That is not a contested point in any of these sectors.

    The legal profession's resistance to the same conclusion is rooted, in part, in the story the profession tells about itself: that relationships are personal, that loyalty is individual, that the client follows the lawyer because the lawyer earned them. That story was honourable in the world that gave rise to it. The question is whether it still describes the world accurately, or whether it has become the mythology that makes a different kind of behaviour feel acceptable.

    The DPDP Act 2023: Rights That Nobody Is Explaining

    The general counsel sitting in the middle of this tug of war is a data principal under the Digital Personal Data Protection Act, 2023, with rights that most Indian law firms are not yet equipped to honour.

    Client contact information, including names, phone numbers, email addresses, organisational data constitutes personal data within the meaning of the Act. The obligations it creates around consent, purpose limitation, data minimisation, and security safeguards apply to law firms as data fiduciaries in precisely the same manner as they apply to any bank, technology company, or healthcare provider. The fact that legal practice has historically operated outside formal data governance frameworks does not exempt it from the Act's requirements. It means only that the compliance gap is wider than in sectors that have had longer to prepare.

    Personal data collected for the purpose of providing legal services cannot be processed for purposes outside that mandate without the client's consent. A lawyer who uses client contact information, matter communications, or relationship data obtained during employment to solicit business for a competing firm is processing personal data outside the scope of the purpose for which it was collected. The client whose data has been used in this manner has recourse under the Act that most of them do not yet know exists. Enforcement will mature. The firms that have not built compliant data governance frameworks are accumulating exposure that will become progressively more difficult and more expensive to address.

    For general counsel advising their organisations on the selection of external legal advisors, this regulatory dimension bears directly on their own compliance obligations. The question of whether a law firm has adequate data governance frameworks is no longer a matter of professional preference. It is a question of whether engaging that firm, and sharing client data with it, creates obligations that the organisation's own compliance framework requires it to address.

    What the Client Deserves to Know

    The client who receives the WhatsApp message from the departing lawyer is being offered something that is presented as a continuation of a relationship and perhaps a discount for continued same quality of service. It was generated within an institutional context, using institutional resources, for institutional purposes. It is personal data which the law firm should protect if nothing else as a mitigation of legal and contractual risk.

    Clients can and do choose to follow lawyers to new firms. Professional relationships are human, and the trust accumulated between a client and a lawyer over years of difficult work is real and worth something. The question is not whether that trust is legitimate. The question is whether the data that enabled the continuation of the relationship travelled with the client's knowledge, through lawful means, or whether it was quietly assumed as a professional entitlement that nobody ever explicitly granted.

    Ending the Tug of War

    The seniors I described in the opening paragraph did not need data governance policies to act with integrity. The culture of the profession they practised in made integrity the default. Client relationships were passed on openly, with full transparency, because the senior had decided that was the right thing to do and had the standing to make it so. Nobody had to argue about who owned the data, because the data lived in institutional systems and the transition was made consciously.

    The culture of the profession has not kept pace with the technology that changed where client data lives. A WhatsApp group created for a matter, a mobile contact list populated during an engagement, a shared drive that exists outside firm systems: these are not edge cases. They are the texture of how legal work is actually conducted in India today. And the clients who trusted their firms, their data, and their relationships to institutions are bearing the cost of a gap the profession has not yet decided to close.

    The firms that address this now, that build the governance frameworks the technology era requires. They are acknowledging that the world changed. The only question is how long the legal profession takes to acknowledge it too. The client in the middle of the tug of war did not ask to be there. They asked for legal advice. They deserve an institution that treats that request, and everything it generated, with the seriousness and quiet dignity it has always warranted.

    Ms. Kritika Krishnamurthy, is the Founding Partner at AK & Partners, a technology-first boutique law firm based in New Delhi. As AK & Partners completes a decade as a law firm, we are launching a thought leadership series that brings a young, outsider's perspective to a centuries-old profession. Through this series, the author hopes to examine the legal profession not only as it is practised, but also as it is lived by a new generation of lawyers and professionals navigating changing expectations, evolving work cultures, and the realities of modern practice. AK & Partners holds ISO 27001 (Information Security Management) and ISO 42001 (AI Management Systems) certifications. The views expressed are those of the author in a personal professional capacity and do not constitute legal advice.

    Next Story