Secure document intake for law firms: a practical workflow
A practical workflow for receiving allowed client documents, limiting access and moving required records into the matter file.
A law firm should treat document intake as a controlled transfer into the matter, not as a new place to keep the matter file. Ask for defined documents through one approved route, restrict review to the assigned team, move required records into the practice or document-management system and delete the temporary submission.
This workflow can suit ordinary client intake when the service permits the documents. It is not suitable by default for criminal-case material, children's information, health evidence or other restricted categories.
Decide the destination before requesting a file
Every request should name the matter task and the document's final destination. A broad request such as "send all relevant correspondence" invites clients to upload more than the lawyer needs and leaves the intake team to classify it later.
Use a matter intake map:
| Intake item | Purpose | Reviewer | Approved matter destination | Temporary copy ends |
|---|---|---|---|---|
| Engagement document | Confirm agreed scope and authority | Responsible lawyer or onboarding team | Matter-opening record | After approved transfer |
| Company document | Confirm a named corporate fact for the matter | Assigned lawyer or paralegal | Matter file or verified register note | After review and required transfer |
| Contract or correspondence | Advise on the specified issue | Assigned matter team | Document-management system | After import and filing check |
| Identity evidence | Complete a separately defined client due-diligence step | Authorised compliance team | Approved verification or compliance system | As soon as the check and required record are complete |
| Evidence from another person | Assess a defined issue and source | Named lawyer | Matter file with source and provenance note | After approved transfer |
Add matter-specific rows instead of treating this as a universal list. Confirm whether the firm needs the whole document, selected pages, an original or only a verified fact. Intake should never be the only copy of a record the firm must preserve.
Tell the client what the link is for
The request should identify the firm and matter in a way the client recognises, while keeping the email subject free of sensitive facts. Explain:
- The exact file or pages requested
- The purpose of the request
- The team or role that can review it
- The accepted formats and deadline
- The expected deletion timing for the temporary copy
- Where the firm's privacy information is available
- Which categories must not be sent through that route
- Who to contact when the client is unsure
Do not ask the client to put a dispute, diagnosis, alleged offence or transaction value in the filename. A receipt should not list filenames or document contents.
The general document request template can be adapted to a matter. Review the final wording against the firm's engagement terms and local professional duties.
Match the communication method to the matter
Email may be reasonable for some routine lawyer-client communication, while a particular document or matter needs stronger precautions. The answer depends on sensitivity, client instructions, known threats, contractual duties and the rules that apply to the lawyer.
The American Bar Association's Formal Opinion 477R says lawyers generally may use internet communication after making reasonable efforts to prevent inadvertent or unauthorised access, but stronger precautions may be required by the information, agreement or law. It interprets US ABA Model Rules, not rules for every jurisdiction.
The Solicitors Regulation Authority's confidentiality guidance explains the duty for SRA-regulated firms and points firms assessing cloud services to security guidance. Use the rules for the firm's jurisdiction.
A portal can keep working attachments out of personal mailboxes and allow active access to be withdrawn. It does not decide whether a lawyer has met a confidentiality, privilege, disclosure or preservation duty.
Separate matter access from firm seniority
A partner outside the matter does not need automatic access to its documents. A billing administrator may need the matter number without seeing the submission. A temporary paralegal may need access for a fixed period.
Use named accounts and assign access by task. Separate:
- Viewing the submitted pages
- Printing or downloading an original
- Changing the deletion date
- Deleting a submission
- Inviting or removing workspace members
When the software offers only workspace-wide review, keep membership to the smallest group that works across those matters. Do not create a shared "litigation" or "intake" login. Review access after departures, matter closure and suspected compromise. The least-privilege checklist includes a full process.
Verify through a separate control
An upload portal is not client identity verification. Possession of a link or access to an email account does not prove who the sender is. A scan of an identity document does not prove that the document is genuine or belongs to the person using the page.
Client due diligence, conflict checks, authority checks, signatures and source-of-funds work each need an approved process. A portal may receive a permitted input, but it does not complete the check. Verify new payment details through a separate trusted route.
Check content before choosing this route
Legal matters routinely contain information that a general intake service does not accept. A family file may contain children's data. Employment or injury evidence may contain health information. Criminal and regulatory matters may contain allegation or conviction data. Identity checks may use biometric comparison. A bundle may also contain passwords, private keys or complete payment-card details.
Sunset Docs does not authorise children's data, criminal-conviction data, special-category data, biometric data used for unique identification, full payment-card data, credentials or secrets unless separately agreed in writing. Do not use the standard workspace for those materials. Choose a system and contract approved for the category, or request a narrower allowed document when professional and legal requirements permit.
This restriction applies even if the firm has a lawful reason to hold the information. Lawfulness at the firm does not change what a particular processor has agreed to handle.
Before adopting a portal, use the 15-question evaluation checklist to check data categories, providers, access and deletion.
Preserve privilege and evidence outside the intake portal
Whether a communication or document is privileged depends on the facts and applicable law. A "privileged" label does not decide the issue, and use of a portal does not create privilege.
The responsible lawyer should decide what enters the matter file, how its source is recorded and whether metadata or the original format must be preserved. A rendered preview may not preserve everything needed for evidence or disclosure.
When the original is required, transfer it directly to the approved matter system, confirm the transfer and remove the local working copy. Do not download every submission because one matter might need an original.
The NIST file-exchange guidance notes different encryption, third-party storage and tampering risks. Assess the transfer, temporary processing and final matter system.
Close intake as part of matter administration
Use the following completion check:
- Confirm that the submission matches the request and matter.
- Reject or isolate unexpected files under the firm's procedure.
- Record the source, date and reviewer where required.
- Transfer the required record to the document-management or practice system.
- Confirm that the official copy is complete and readable.
- Remove exceptional downloads from local and shared folders.
- Delete the active intake copy or leave its documented deletion date unchanged.
- Keep only the minimal intake audit information the firm has decided it needs.
Do not delete material subject to a preservation duty or legal hold. The firm should move it into the controlled record system first and apply the hold there. A temporary upload service is not a legal-hold repository or permanent archive.
Sunset Docs schedules every allowed submission for deletion and supports earlier deletion. Its view-only mode avoids delivering the original file to the browser during ordinary review, but it cannot prevent screenshots, photographs, printing or transcription. Malware scanning and validation reduce risk but do not prove authenticity or catch every harmful file. The Security page describes the controls and limits.
A client request template
Please upload the following document for {matter reference} using our intake page:
{upload_link}
We need {exact document or pages} to {specific matter purpose}. {role or matter team} will review it. Please submit it by {date} in {formats}.
The temporary intake copy is scheduled for deletion {timing}. Any document that must form part of the matter record will be transferred to our approved system under the firm's retention policy and privacy information at {link}.
Do not use this link for health information, children's data, criminal-case material, biometric identification, full payment-card data, passwords or secret keys. Contact {firm contact} for an approved route if the document contains any of these.
Frequently asked questions
Does a secure portal make a document privileged?
No. Privilege depends on the communication, purpose, parties and applicable law. A portal is a transfer and review tool, not a legal determination.
Can a firm send every client the same upload link?
A stable firm page can be useful, but each request should still identify the matter purpose, allowed documents, reviewer and deletion timing. Consider whether the service's access model separates matters adequately for the firm.
Can support staff review all new submissions?
Only if their assigned task requires the document contents. Receipt triage can often use a submission status or matter reference without opening every file.
Is the upload receipt proof of who sent the file?
No. It records that a submission occurred through the available route. It does not establish identity, authority, authenticity or chain of custody by itself.
Can Sunset Docs hold the complete matter file?
No. It is temporary intake, not a document-management system, backup, evidence repository, legal-hold platform or permanent archive. Required records must move to the firm's approved system before expiry.
What should happen when a client uploads restricted information by mistake?
Stop ordinary review, restrict further access, follow the firm's incident and provider procedures and avoid creating more copies. Contact the provider through its approved support or privacy route without emailing the document again. The firm should obtain legal or professional advice where the circumstances require it.