Jurono Magazine

Client Portal or Email? Which Channel Is Best for Which Type of Law Firm Communication?

Client portal or email? This comparison shows which channel is truly best suited for documents, inquiries, and sensitive content in law firms.

August 10, 202611 min readJurono Editorial TeamClient Portal or Email: Law Firms
JEJurono Editorial TeamJurono Magazine
Next step

Check which Jurono starting point fits your firm.

See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.

The correct answer is rarely “only the client portal” or “only email.” For law firms, a combined channel model usually makes the most sense: brief, low-sensitivity coordination via email; confidential documents, larger data sets, and version-controlled collaboration via a controlled exchange channel. The key factors are the need for protection, the complexity of the process, and whether information can later be reliably assigned to a specific client.

A portal is not automatically secure just because it’s called a portal. And email is not automatically prohibited. Professional regulations and data protection laws do not require a specific product category, but rather organizational and technical measures commensurate with the risk. The law firm therefore does not have to choose between two camps, but must determine which channel is intended for which process.

Why the “either/or” question is misleading

Email is well-established in the day-to-day operations of a law firm; it is fast and accessible to clients without requiring additional login credentials. Appointment confirmations, brief follow-ups, or updates on a case’s status can be communicated smoothly via email. At the same time, email is a weak working medium: attachments are sent multiple times, replies are scattered across inboxes, subject lines change, and incorrect autocomplete suggestions can lead to the wrong recipient address.

A client portal can consolidate documents, messages, and responsibilities in one place. Access rights can often be controlled more precisely; outdated attachment versions and long distribution lists can be avoided. However, this creates new friction: clients must understand invitations, manage login credentials, and pay attention to notifications. Without a clear onboarding process, the portal becomes just another channel, while the actual work continues to be handled via email.

The productive decision, therefore, is not “Which medium will prevail?” but “Which task should be handled via which standard channel?”

Professional Law

Section 43a(2) of the Federal Lawyers’ Act (BRAO) obligates attorneys to maintain confidentiality. Section 2(2) of the BORA specifies, with regard to day-to-day law firm operations, that organizational and technical measures necessary to protect client confidentiality must be risk-appropriate and reasonable for the legal profession. Technical measures must, to the extent that data protection law applies, comply with its requirements; other technical measures must be state-of-the-art.

The current BORA also stipulates: An electronic communication channel that poses risks to confidentiality is permitted in any case if the client consents. Consent may be presumed under the conditions specified in § 2(2) BORA if the client proposes or initiates the channel and continues to use it after receiving at least a general risk disclosure.

This does not constitute authorization for arbitrary use of email. The need for protection, the specific circumstances of each case, and the concrete implementation remain decisive. Nor does it mean, however, that a client portal is always mandatory under professional law.

Data Protection

Art. 5(1)(f) of the GDPR requires processing to be carried out with appropriate security measures. Article 32 of the GDPR links the selection of technical and organizational measures to, among other things, the state of the art, implementation costs, the nature, scope, context, and purposes of the processing, as well as the likelihood and severity of potential risks.

Here, too, the legal situation is not dictated by a product’s label. A poorly configured portal with broad default permissions, weak account recovery, and unclear data flows may be unsuitable. A well-secured email process may be appropriate for certain communications. In the case of particularly sensitive content or increased risk, additional protective measures—including end-to-end encryption or a suitable secure exchange channel—may be required. The specific assessment depends on the individual case.

The Federal Office for Information Security (BSI) clearly distinguishes between transport encryption and end-to-end encryption. Transport encryption protects individual segments of the transmission; end-to-end encryption protects the content between the endpoints. Law firms should therefore not only ask whether a provider mentions “encryption,” but also which data is protected from whom at which stage.

The 4K Matrix for Channel Selection

For small and medium-sized law firms, a decision matrix with four criteria is often sufficient. It translates abstract risks into a working rule.

1. Criticality of the Content

How sensitive are the message and attachments? A routine appointment scheduling email typically has different protection requirements than health data, criminal case files, ID copies, extensive personnel files, or a transaction that has not yet been made public. The higher the criticality, the stronger the case for a controlled communication channel with appropriate access and encryption measures.

2. Coordination Needs

Is only a single piece of information being transmitted, or are multiple people working on documents and different versions? As soon as drafts, attachments, and follow-up questions circulate through multiple rounds of review, the email inbox quickly becomes an unofficial document management system. In this context, a centralized process may be more important than the medium used for transmission.

3. Contextual Alignment

Can the information be unambiguously assigned to the correct case, the correct person, and the correct processing status? A message may be delivered securely from a technical standpoint but still get lost within the organization. Anyone who regularly moves attachments from personal inboxes into case files should treat this assignment as a separate selection criterion.

4. Continuity

What happens during vacation, staff changes, lost login credentials, or the end of a case? The chosen channel must allow for substitution, revocation of access rights, export, and a traceable handover. A portal without regulated notifications and recovery is just as problematic as a case history stored only in a single person’s mailbox.

Which Channel Is Right for Which Law Firm Situation?

A sensible internal policy might look like this:

Law Firm SituationTypical Standard ProcedureWhat Else to Consider?
Appointment confirmation or request for a callbackEmailInclude as few client details as possible in the subject line
Notification that new documents are availableEmail notification, content in a secure areaNotification must not reveal any sensitive details
Copies of ID, health data, personnel filesControlled upload or secure exchange channelVerify permissions, deletion, and recipients
Multiple draft and attachment versionsCase-specific workspaceMake version, approval status, and responsibility visible
Brief technical inquiry without an attachmentDepending on security requirements: email or secure channelCheck context and recipient before sending
Time-sensitive instructionsAgreed-upon channel plus explicit confirmation of receiptDo not rely solely on an automatic notification
Case closure and file handoverDefined export and handover processClarify completeness, format, and deletion policy

This table is not a blanket legal assessment. It serves as a starting point for a firm-specific policy that takes into account the practice area, client base, data types, and technical environment.

Three Typical Missteps

The portal is implemented, but email remains the de facto process

The law firm provides an upload feature but continues to accept all attachments via email as well. Employees save files manually, clients use either method depending on their preference, and no one knows which version is authoritative. The problem here is not a lack of technology, but a lack of enforceability.

Every message is forced into the “most secure” channel

Maximum security without regard for usability can lead to workarounds. If a harmless question about an appointment can only be answered after logging in, multi-factor authentication, and multi-step navigation, participants may resort to private or informal channels. Security must take the actual workflow into account.

“Encrypted” Replaces Provider Verification

A product description says little about roles, protocols, deletion, subcontractors, data export, or recovery. Before making a selection, law firms should document the actual data flow and responsibilities. The article GDPR in Law Firms: Practical Checkpoints for New Tools offers a more in-depth assessment framework.

Implementing a Channel Model in Five Steps

1. Analyze Actual Communication

Select twenty typical workflows from a two-week period: receipt, follow-up, document request, draft, approval, and completion. Note what content was sent, how many people were involved, where documents were stored, and at which points follow-up calls were necessary or reordering was required.

2. Classify Processes Rather Than Tools

Categorize the cases according to the four Cs: criticality, coordination, context dependency, and continuity. Only then should you compare technical solutions. This helps you avoid a feature list that has no connection to the firm’s day-to-day operations.

3. Define a Standard and Exceptions

Formulate a brief channel policy: What can be sent via email under normal circumstances? What content belongs in a secure communication channel? Who makes the decision in cases of doubt? How is client consent or a differing preference taken into account? What applies in urgent situations?

4. Consider Transitions

The communication process doesn’t begin only after a case is accepted. Structured initial information and documents are already created during the intake. The comparison contact form or digital intake shows how data can be captured for the next decision. Afterward, it should be clear how the process transitions into ongoing communication without requiring re-entry of data. Media breaks otherwise occur precisely at this transition point.

5. Pilot the System with a Case Type

Select a common, repeatable case type and test the model for four weeks. Measure not only messages sent, but also misclassifications, follow-up inquiries, duplicate attachments, search times, and user acceptance. Only then is it worth expanding the system.

Questions a Client Portal Must Answer Before Selection

A sound decision requires more than just a demo. In particular, verify the following:

  • How are data transmission, stored data, and—where applicable—content protected?
  • What roles, access rights, and multi-factor authentication methods are in place?
  • Are activities and changes logged in a traceable manner?
  • How do invitations, notifications, and account recovery work?
  • What data do subprocessors see, and where is it processed?
  • How can client data be fully exported and access terminated?
  • How are retention and deletion rules implemented in practice?
  • Can clients use the system on standard devices without barriers?

These questions do not automatically distinguish between statutory minimum requirements and voluntary quality features. However, they do reveal whether a system is a good fit for a firm’s specific risk and process landscape. Law firms can find a broader basis for decision-making in the Law Firm Software Comparison for Everyday Use.

The Jurono Perspective: Communication as Part of the Client Workflow

Jurono does not view digital case intake and subsequent processing as isolated silos. It is precisely this connection that is relevant when deciding which communication channels to use: Information should not only arrive securely but also be structured to follow the correct case file and next step in the workflow.

Which communication channels and security measures are suitable for a specific law firm must be assessed based on actual usage. Jurono does not replace professional or data protection assessments. However, a demo allows you to walk through your own process—from initial contact to an editable case structure—and compare it with current email practices.

Conclusion: A channel model is more valuable than a commitment to a single channel

Email remains practical for simple, less complex coordination. A controlled, case-specific communication channel proves its worth when content is sensitive, documents are numerous, processing statuses are relevant, or multiple parties are involved.

The viable solution is therefore a documented channel model: risk-appropriate, understandable to employees, and usable by clients. Anyone who first reviews twenty real-world cases using the 4K matrix will quickly recognize whether a portal solves a specific process problem or merely creates another inbox.

This article is intended for general organizational and technical guidance and does not constitute individual legal advice. Professional and data protection requirements must be reviewed for specific applications.

Sources

  1. German Federal Bar Association – “Code of Professional Conduct for Attorneys (BORA), Version dated December 1, 2025,” published in the current version as of December 1, 2025, https://www.brak.de/fileadmin/02_fuer_anwaelte/berufsrecht/033-BORA_Stand_01.12.2025.pdf, Retrieved: August 10, 2026. Supporting statement: Section 2 of the BORA requires risk-appropriate and reasonable organizational and technical measures and governs consent to high-risk communication channels.
  2. Federal Ministry of Justice / Federal Office of Justice – “Section 43a BRAO – Fundamental Duties,” current version of the law, https://www.gesetze-im-internet.de/brao/__43a.html,, accessed August 10, 2026. Supporting statement: attorneys’ statutory duty of confidentiality.
  3. European Union, EUR-Lex – “Regulation (EU) 2016/679,” April 27, 2016, in particular Art. 5(1)(f) and Art. 32, https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:02016R0679-20160504,, accessed August 10, 2026. Supporting statement: Integrity and confidentiality, as well as risk-based security of processing.
  4. Federal Office for Information Security – “Email Encryption,” no publication date specified, https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Informationen-und-Empfehlungen/Onlinekommunikation/Verschluesselt-kommunizieren/E-Mail-Verschluesselung/e-mail-verschluesselung_node.html,, accessed August 10, 2026. Supporting statement: technical distinction between transport encryption and end-to-end encryption.
  5. Federal Bar Association, Friederike Schoettle – “Lawyers’ Communication via Email – Only Encrypted?”, BRAK-Mitteilungen 2018, https://www.brak.de/fileadmin/01_ueber_die_brak/schoettle-brak-mitt.-2018-118.pdf,, accessed August 10, 2026. Supporting statement: technical classification of email communication and the question of a general obligation to use end-to-end encryption; cited only as supplementary information due to the legal status as of 2018.
JE

Jurono Editorial Team

August 10, 2026

Turn magazine insight into a concrete starting point

Evaluate Jurono the privacy-compliant way

See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.