Every regulated profession that holds client confidences, notaries, lawyers, and others, carries a duty of professional secrecy. It is one of the oldest promises in professional life: what a client tells you, and what you hold for them, stays private. Yet the tool most offices use to move that information every day, ordinary email, was never built to keep a secret.
Why email undermines secrecy
Standard email is not encrypted end to end. A message passes through and rests on several servers, and it exposes metadata such as sender, recipient, and subject line even when the body is protected. Copies linger in multiple inboxes indefinitely, and once you press send you cannot recall the message or see who opened it. None of that is visible to you, which is exactly why the risk goes unnamed. The exposure is real even when nothing appears to go wrong.
Secrecy is about reasonable measures
A duty of secrecy is not only about intent. It is about taking reasonable steps to keep information confidential. When a confidential document sits in plaintext across several mail servers, it becomes harder to say that reasonable steps were taken. Encryption and access control are how you close that gap, and how you can show you closed it.
What to do instead
- Encrypt on the device. Use a tool that encrypts the file before it leaves your computer, so no one in the middle can read it.
- Split the link from the passphrase. Send the secure link one way and the passphrase another, so no single channel exposes the document.
- Set an expiry and revoke when done. Confidential files should not live in an inbox forever.
Where Privatt fits
Send encrypts each file on your device and shares it as a passphrase-protected link, with no account needed for the recipient. You can expire it, cap how many times it is opened, and revoke access at any time. Secrecy stops depending on hoping an inbox stays private.
This article is general information, not legal advice.