After the session as guest speaker at the first Global Council for Responsible AI Isle of Man chapter event on 5 August 2026, I had a few follow up questions from guests. Amongst them, one relates to legal privilege. The question about use of AI systems and its impact on legal privilege is still unsettled law, but a few points are still worth making at this stage. Not legal advice.
TL;DR
Confidentiality and privilege are different things. Where exactly the boundary falls in a given file is a question for advice, not for a rule of thumb.
The rights are the client’s. The Isle of Man Law Society’s summary: “Privilege is the right of the client and may only be waived by the client.” Under Rule 3.5.1 of the Advocates’ Practice Rules 2024, only the client, legislation or a court can waive or override confidentiality. But a lawyer can waive privilege in the conduct of litigation, and that does not cure the breach.
Ask what you are pasting, not whether the prompt is privileged. Privilege attaches to communications, written ones and drafts included, but generally not to pre-existing documents or to facts (Ventouris v Mountain).
Follow the SRA’s line from its 17 August warning notice. Both free and paid AI systems may pose risks. What matters is “the provider’s terms, settings and technical architecture”: client data in a secure environment, not accessed by unauthorised third parties, not used for training unless explicitly authorised, not retained longer than necessary.
And be wary of privilege checklists, this one included.
What is Legal Privilege?
Legal professional privilege protects confidential communications from disclosure. It covers communications between clients and their lawyers, material evidencing those communications, and in some circumstances communications between clients or lawyers and third parties.
It is old and it is fundamental. The right has stood for some four centuries. English law treats it both as a fundamental common law right and as a human right. Lord Taylor’s formulation in R v Derby Magistrates’ Court, ex parte B [1996] AC 487 remains the clearest statement of why:
“a man must be able to consult his lawyer in confidence, since otherwise he might hold back half the truth. The client must be sure that what he tells his lawyer in confidence will never be revealed without his consent. Legal professional privilege is thus much more than an ordinary rule of evidence, limited in its application to the facts of a particular case. It is a fundamental condition on which the administration of justice as a whole rests.”
Privilege arises in two ways. They are parts of a single integral privilege, but they have different characteristics and conditions.
Legal advice privilege applies to confidential communications between a lawyer and a client, made for the sole or dominant purpose of giving or receiving legal advice. It also covers communications forming part of what the courts call a “continuum of communications”, aimed at keeping client and lawyer informed so that advice may be sought and given as required (Balabel v Air India [1988] Ch 317; Three Rivers (No 6) [2005] 1 AC 610). The scope of “legal advice” is broad. It is not confined to telling the client the law. It extends to advice about what should prudently and sensibly be done in the relevant legal context (Three Rivers (No 6); Civil Aviation Authority v R (Jet2.com Ltd) [2020] EWCA Civ 35). It does not require litigation. It lasts indefinitely.
Litigation privilege applies to confidential communications between lawyers or their clients and third parties, made for the sole or dominant purpose of conducting existing or reasonably contemplated litigation that is adversarial rather than investigative. It is wider in who it covers and narrower in when it applies.
The position under Isle of Man law
The Isle of Man Law Society published A Summary of Legal Professional Privilege under Isle of Man Law and its Application to In-House Lawyers. It recognises the same two heads. Advice privilege attaches to communications between a lawyer in his professional capacity and his client where they are (a) confidential and (b) made for the purposes of seeking or giving legal advice. Litigation privilege attaches to communications that are (a) confidential, (b) made after litigation has been commenced or contemplated, and (c) made for the sole or dominant purpose of such litigation.
There is also a statutory definition in section 13 of the Police Powers and Procedures Act 1998. It covers communications between a professional legal adviser and his client, or a person representing the client, made in connection with the giving of legal advice; communications between such an adviser, client or representative and any other person made in connection with or in contemplation of legal proceedings and for the purposes of such proceedings; and items enclosed with or referred to in such communications. Items held with the intention of furthering a criminal purpose are excluded.
This will be familiar, and deliberately so. Privilege is one of the major common law concepts on which Manx law tracks the English position. There is no reason to think our courts or our profession intend to depart from it.
Two features of the summary are worth drawing out.
On what privilege attaches to, the summary says:
“Legal professional privilege is a substantive rule of law, not a mere procedural rule of evidence. Privilege only relates to ‘communications’, not to other documents, or to any information per se.”
That is not a statement about medium. A communication can be in writing. Written communications are the paradigm case, and the drafts and documents generated in the course of communicating advice can form part of the communication rather than sitting outside it. That is the continuum point again.
What it restates is the orthodox rule that privilege does not attach to pre-existing documents or to facts. A document does not become privileged merely by being gathered into a lawyer’s file, or by being attached to a privileged communication (Ventouris v Mountain [1991] 1 WLR 607). A fact does not become privileged merely because you told your lawyer about it. The principle is common to both jurisdictions, and the exception in caselaw would likely equally apply: a selection of documents assembled by a lawyer may be privileged where it betrays the trend of the advice (Lyell v Kennedy (No 3)).
On agency, advice privilege “will also protect communications by or with an agent of the lawyer or client if that agent was appointed for the purpose of communicating with the other in order to seek or to give legal advice”. Litigation privilege extends to communications with agents of either. Again, the orthodox position. Agency is how a person other than lawyer and client comes inside the protection.
But the key statement of the general position is this one:
“Privilege is the right of the client and may only be waived by the client.”
The Manx professional materials say the same, adding that the right survives the client’s death. So does the English guidance. So does Derby Magistrates itself: privilege endures unless and until the client waives it. It is a right, not of lawyers or the legal profession, but of clients, whether individuals or corporates. On this, as on most of it, the two jurisdictions speak with one voice.
Confidentiality is not privilege
This distinction gets somewhat obfuscated in commentaries and summaries posted online. Confidentiality and privilege are separate concepts. Confidentiality prevents an advocate from disclosing any information relating to a client without the client’s consent. Privilege allows a lawyer to withhold specific information that they would otherwise be obliged to disclose, in court proceedings for example.
They differ in more than one aspect.
Scope. Confidentiality covers all information relating to a client, whatever its source and whatever its subject matter. Privilege covers only communications satisfying one of the two tests above. The categories are therefore different sizes. Everything in the file is confidential. Only some of it will be privileged.
I would resist going further than that. It is tempting to produce a tidy list of things that are supposedly “confidential but never privileged”: client identity, the fact of the retainer, billing information. Such lists are not safe. Whether any particular item is privileged is fact-sensitive, and material that looks administrative can attract protection where disclosing it would reveal the substance of advice sought or given. The reliable proposition is the narrow one. Confidentiality is wider than privilege. Working out where the boundary falls in a given file is a question for advice, not for a rule of thumb.
Direction. Confidentiality is a duty the professional adviser owes. It restrains them from disclosing. Privilege is a right the client holds. It entitles the client to withhold material from a court, regulator or opponent who could otherwise compel production.
Source. On the Island the confidentiality duty is expressed in Rule 3.5.1 of the Advocates’ Practice Rules 2024:
“Subject to any exceptions provided under the law, an advocate must maintain client confidentiality. This duty is not terminated by the passage of time. Where appropriate an advocate must also supervise his employees or consultants to ensure that they keep client matters confidential. Only the client, primary or secondary legislation, or a competent court can waive or override (as the case may be) the duty of confidentiality. The duty, howsoever arising, does not apply to information about any crime a client indicates that they will, or intend to, commit.”
Privilege, by contrast, is founded in the common law, with statutory definitions adopted for particular purposes.
Who can release it. Under Rule 3.5.1, only the client, legislation, or a competent court can waive or override confidentiality. And as we will see, only the client is entitled to waive privilege.
The relationship between them. Confidentiality is a precondition of privilege. Privileged material is necessarily confidential. Confidential material is not necessarily privileged. So when confidentiality goes, privilege may go with it. The reverse does not hold. The two questions also arise at different times. The confidentiality question arises the moment information leaves your control. The privilege question arises later, usually if someone tries to compel production.
Note also the supervision limb in Rule 3.5.1. The duty extends to supervising employees and consultants so that they keep client matters confidential. That obligation was drafted with human beings in mind. It reads rather differently in a year when the “assistant” processing your client’s file is neither an employee nor a consultant.
For many of the guests at the GCRAI event, the distinction is the practical point. Trust administrators, compliance officers, accountants and corporate service providers hold enormous quantities of confidential client information. Privilege will arise for a much smaller part of it. If they paste a client file into a consumer chatbot, the confidentiality question arises immediately and unavoidably. Sometimes the issue is both confidentiality and privilege.
Waiver, and loss: three different routes
With the concepts established, I can turn to the actual discussion this piece intended to cover, which came from a question on how one’s use of AI could lead to the end of legal privilege. The ways privilege comes to an end are distinct from one another, and worth taking separately. Since the right to assert privilege is the client’s, it is the client who is entitled to waive it. But a lawyer conducting litigation can, without reference to the client, act in a way that waives the client’s privilege. The classic example is allowing an opponent to inspect a privileged document. And separately from waiver altogether, privilege may simply be lost if confidentiality is lost.
So there are three distinct ways privilege ends.
The client waives it. Expressly or impliedly, generally or on a limited basis.
The lawyer waives it in the conduct of litigation. Note the confinement. This concerns the lawyer’s ostensible authority in running the case.
Confidentiality is lost, because the material has entered the public domain.
Route 2 deserves emphasis, because it corrects a common shorthand. It is tempting to say that a lawyer can only ever breach privilege, never waive it, since the right belongs to the client. That is too neat. A lawyer conducting litigation can, without reference to the client, do something that waives the client’s privilege.
What follows, and matters more practically, is that the two concepts are not alternatives. That a lawyer’s act was effective against the opponent to waive the client’s privilege says nothing about whether the lawyer was entitled to do it as between lawyer and client. A waiver that was inadvertent or outside the client’s instructions may still be a breach of duty.
An adviser pasting a client letter into a chatbot at their desk is not route 1. It is some distance from route 2, which concerns the conduct of proceedings. If privilege is affected at all, it seems most likely to be by route 3. Loss of confidentiality has its own body of law.
Whether privilege survives a disclosure depends on whether the material retains its confidential nature. Confidentiality is generally understood as a prerequisite for privilege, and it will have been lost if the communications have entered the public domain. Two things follow. First, “the public domain” is a legal term of art, and its content is for the courts to interpret, case by case. Second, the threshold is demanding. Confidentiality is not necessarily lost merely because privileged communications have been made available online. The Singapore Court of Appeal so held in Wee Shuo Woon v HT S.R.L. [2017] SGCA 23, where privileged emails obtained by hacking and uploaded to WikiLeaks were found to retain their confidential character.
The limited waiver cases point the same way. Disclosure for a limited purpose is not treated as a general waiver, provided the material is not in fact made public. The test is what actually happened, not what the terms theoretically permit. But the limitation has to be a real one. In FM Capital Partners Ltd v Marino [2017] EWHC 3700 (Comm), a company disclosed an investigation report to a defendant ahead of a disciplinary hearing without imposing any express restriction on its use, and was held to have waived privilege in it. Silence about permitted use is not neutral.
Then there is the principle that is likely the most relevant to the AI question. Privileged material can be shared outside the organisation, not merely circulated within it, provided it is shared under a duty of confidentiality, express or implied. That principle is illustrated in Gotha City v Sotheby’s [1998] 1 WLR 114, where legal advice shared with the auction house from which a disputed painting had been bought retained its privilege. There was no express duty of confidence on the recipient, and the court proceeded on the basis that obligations of confidentiality were implied. The everyday application is the sharing of privileged advice with a client’s other professional advisers. An implied duty may suffice. An express one is better. That is the frame within which the AI question should be asked.
What the Upper Tribunal said
The case that prompted the question from guests is UK and R (on the application of Munir) v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC), published this February. Most commentary calls it Munir. It is one judgment disposing of two unrelated cases, joined under the Hamid jurisdiction, being the inherent power of a court to hold the lawyers before it to proper professional standards.
Ms Munir’s case is about supervision, and its holding generalises well beyond the legal profession. A supervisor who fails to ensure a junior’s work is free of AI hallucinated citations is likely to be more culpable than a lawyer who fails to check their own, because the supervisor fails the tribunal, the public, the client and the junior’s development at once.
The privilege observation comes from the other case. An accredited immigration adviser explained that he had been putting draft client letters and Home Office decision letters into ChatGPT, to improve the former and summarise the latter. At paragraph 21 the Tribunal observed:
“to put client letters and decision letters from the Home Office into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege, and thus any regulated legal professional or firm that does so would, in addition to needing to bring this to the attention of their regulator, be advised to consult with the Information Commissioner’s Office. Closed source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks.”
It is the first time an English tribunal has addressed AI and privilege, which is why it travelled so far so fast.
Its status is worth being clear about. The Tribunal’s own language is “we also observe”. Therefore, in lawyer speak, this is strictly obiter. The point appears to not be in issue between any parties. It arose from an adviser’s candid account of his working habits in a professional conduct hearing. Herbert Smith Freehills Kramer’s note on the case records, with characteristic restraint, that “it is not clear what submissions were made on this issue”, and adds that the point “will no doubt receive further detailed analysis and judicial consideration in due course”. That seems right.
The SRA’s Latest Misuse of AI Warning Notice
The warning notice was published on 17 August and addressed to all firms and individuals the SRA regulates. It repays close reading, and not only for its content.
The notice cites the Upper Tribunal decision. What is noteworthy to me is what it quotes, and how the notice proceeds. It reproduces one clause, expressly attributed as the Tribunal’s observation: that to put client letters and Home Office decision letters into an open source AI tool “is to place this information on the internet in the public domain”. It does not adopt the reasoning as its own. It does not repeat the open-source and closed-source distinction, and it endorses no named product.
Then, in its own voice: “Using AI tools in this way will likely breach client confidentiality and as a result, legal professional privilege may be permanently waived and unable to be recovered.”
And then it proposes alternative criteria:
“Both free to use and paid for AI systems may pose risks to client confidentiality. Depending on the provider’s terms, settings and technical architecture, information entered into AI systems may be stored, retained or used to improve the tool.”
The SRA’s warning effectively says, without contradicting anyone, that price tier and brand are not the variable. Terms, settings and technical architecture are. A paid tool can be unsafe. And it gives a usable standard:
“Client information should only be entered into AI systems where appropriate contractual, technical and organisational safeguards are in place to protect confidentiality. Firms and solicitors should satisfy themselves that client data remains within a secure environment, is not accessed by unauthorised third parties, is not used to train AI models except where explicitly authorised and appropriate to do so, and is not retained longer than necessary.”
The SRA has taken the Tribunal’s concern entirely seriously, restated it in terms a compliance officer can apply, and left the doctrinal question where it belongs, with the courts. The SRA has clearly been grappling with related clarification questions lately, and it shows.
Note too what the SRA’s standard has in common with the Sotheby’s principle. “Appropriate contractual, technical and organisational safeguards” is the regulator’s way of saying what the common law has said for years: shared under a duty of confidentiality, express or implied, and better express than implied.
So how would you design a prompt flow that preserves confidentiality?
This was also a follow up question from guests. Most of the answer for now seems to be procurement rather than law.
Start with architecture. The question is not how a model is licensed but where the processing happens. A model run on your own or on dedicated infrastructure keeps the material inside your environment. Open weights are usually what makes that possible, but they are not themselves the safeguard: an open-weight model called through someone else’s API sends client material out to a third party just as any other hosted service does. Self-hosting is the highest-assurance option, and the most operationally demanding.
Two other approaches would in principle let material stay protected while the computation happens elsewhere. Confidential computing keeps data encrypted in memory during processing, inside hardware enclaves the provider cannot read into. Homomorphic encryption would allow computation on encrypted data without decrypting it at all. Both are technically possible. Confidential computing is available from some providers, though not yet in ordinary use for professional work of this kind. Homomorphic encryption remains far too slow for language models. This is an area where the position could change quickly.
With any hosted service, each prompt is a separate transmission of whatever it contains, to be processed on someone else’s systems. That much is a matter of fact. What it means legally is a further question, and the fact of transmission does not answer it. Confidential material can be shared with an outside party under a duty of confidence without the duty being breached or the client losing privilege. This is Sotheby’s applied to a vendor: your provider should be in the same position as the client’s other professional advisers, outside the firm but bound. So everything turns on the terms for your specific deployment. The terms that matter likely include the exclusion of training rights, a defined retention period with deletion that reaches logs and backups, no review of prompts by the provider’s own staff or contractors, named and bound sub-processors, express confidentiality obligations, encryption, and tenant isolation, meaning that your material is kept partitioned from that of the provider’s other customers. Training rights are the single most important of these. The SRA’s formulation is the standard: client data not used to train “except where explicitly authorised and appropriate to do so”.
The prompt is also not the only place client material goes. Where a system retrieves from your own documents to answer a question, an arrangement usually called retrieval-augmented generation, those documents are first indexed into a store that sits outside the prompt flow. That store is a persistent copy of client material, and it needs the same analysis as the inference endpoint rather than being treated as plumbing. Fine-tuning goes further still: material used to adapt a model is absorbed into its weights and cannot straightforwardly be deleted afterwards. Both are common in legal deployments, and both sit outside a terms review that looks only at what happens to a prompt.
Retention needs a qualification. Shorter is not automatically better, because other duties can pull the other way. Storage limitation under data protection law points toward deletion. The EU AI Act points the other way for anyone within its reach, requiring providers and deployers of high-risk systems to keep automatically generated logs for at least six months (Articles 19 and 26(6)). Professional file-retention obligations, anti-money laundering record-keeping and litigation holds can require preservation for far longer. The regimes are reconcilable, but not by instinct. The question is not how little you can retain. It is whether the period you have settled on is deliberate, and defensible against each duty that applies to you.
The FM Capital point applies with equal force to vendor terms. What the contract does not restrict, it may be taken to permit. And distinct from what a provider will choose to do is what it can be made to do. Data held by US providers is reachable under the CLOUD Act wherever it is stored. It is not only a US question. Article 7 of China’s National Intelligence Law requires organisations to support and cooperate with state intelligence work, and Article 35 of the Data Security Law obliges them to cooperate with security organs collecting data, with none of the published process or transparency reporting that has grown up around the US regime. The point is not that one jurisdiction is uniquely dangerous. It is that compelled access is a feature of the legal system your provider sits in, and it survives whatever the contract says. Worth separating from the question of where a model came from: running open weights of any origin on your own infrastructure involves no provider to compel, while a hosted service does, wherever it is based. That matters for various professional work here, however good the commercial terms.
That much you can specify, procure and audit. The harder question is not about the tooling at all. It is what you are pasting. Privilege attaches to that material, or does not, by ordinary principles, before any tool is involved.
Ventouris held that pre-existing documents obtained by a solicitor for the purposes of litigation do not thereby attract litigation privilege. That is not authority that a third party’s document can never be privileged in any configuration. A selection of documents assembled by a lawyer may be protected where the selection itself would betray the trend of the advice (Lyell v Kennedy (No 3)). There is also an unresolved body of law about the status of copies of unprivileged originals.
Why any of this matters, when the material is confidential either way, is that only privilege protects against compulsion. Where material is confidential but not privileged, an upload may breach a duty owed to the client, but a court or regulator could always have required its production in any event. Where the material is privileged and the upload is found to have destroyed confidentiality, the client loses the ability to resist that production. The first is a wrong done to the client. The second hands something to the other side.
Two shorter points on the lawyer’s own working material. Advice a client obtains from a chatbot instead of from a lawyer does not attract advice privilege. Litigation privilege is a different question, so material a client prepares for the dominant purpose of contemplated proceedings may still qualify. More importantly, advisers should expect to receive AI-prepared client drafts carrying no advice privilege at all, and to have to say so. And the converse does not follow either. Using an AI tool does not create privilege where none would otherwise arise, and a lawyer’s involvement does not supply it. Whether material is privileged turns on the ordinary tests, as summarised above.
Nor is “it involves a third party and litigation is contemplated” always a safe harbour, as the Commercial Court illustrated in June. In Uber London Ltd v White [2026] EWHC 1610 (Comm), communications between a firm of solicitors and a litigation funder were held not to attract litigation privilege. Proceedings were genuinely in contemplation. The documents would not have existed but for the prospective claim. But the dominant purpose was enabling the funder to decide whether to fund, and, adopting Hollander’s formulation, “obtaining funding cannot sensibly be regarded” as conducting litigation. Dominant purpose is a demanding filter, applied to the reason each document came into existence. Sophisticated parties with first-rate representation can get it wrong.
So the practical answer to the design question may look something like this. Whether a privilege claim is ultimately available for any given prompt may be genuinely uncertain. The confidentiality analysis always applies, and it is the one you can control by procurement. Design for confidentiality and privilege looks after itself. Design assuming privilege will save you, and you may find that for a good deal of the material there was never any privilege there to save you with.
Perhaps, then, a matter for the engagement letter. Only the client can waive privilege. Under Rule 3.5.1, only the client, legislation or a court can waive or override confidentiality. An engagement letter that sets out which categories of AI tooling may be used, for what tasks, and on what terms as to confidentiality, converts an unauthorised disclosure into an authorised and limited one. That reflects settled good practice for limited waivers generally: record in writing the terms on which the disclosure is permitted, and the specific purposes for which it is given. FM Capital shows what happens when no limit is specified. It is the cheapest control available.
A caution about the foregoing
Having set out a procurement standard and a good deal of doctrine, I should say plainly what the exercise is and is not worth.
Privilege is a genuinely difficult area. It is riddled with distinctions and potential exceptions like the rest of the common law: sole versus dominant purpose, who counts as the client, whether the adviser counts as a lawyer, which communications fall inside a continuum and which sit outside it, when a third party is an agent, when confidentiality has been lost, when a waiver is limited and when it is collateral. Uber v White is a useful reminder that these are not academic refinements. It took a Commercial Court judgment to resolve whether documents that would never have existed but for a prospective claim were made for the purpose of conducting it, and the parties had excellent lawyers on both sides.
So I would be sceptical of any attempt, including my own, to reduce this to a rule set that lets someone decide, unaided, whether a particular use of an AI tool is safe. Summaries of privilege written to enable technology adoption tend to be of limited value precisely where they are most needed: at the margins, on the facts of an actual file. What is set out above is a way of structuring a conversation with people who will look at your circumstances. It is not a substitute for that conversation, and nothing here is legal advice.
There is a version of this article that ends with a neat table. I have not written it, because I do not think one exists that would be safe to rely on. What I would rather leave you with is a sense of which questions matter, what an England and Wales legal regulator has actually said, and enough of the shape of the law to know when you have reached the edge of what a checklist can tell you.
Parting Thoughts to the Weekend
I mulled over these follow up questions over multiple weekends, and will close this particular one with a few last remarks.
The AI questions are being litigated elsewhere first. Privilege is one of the major common law concepts on which the Manx and English positions align, and nothing in the local materials suggests an intention to diverge. English decisions are persuasive here rather than binding. But the AI cases are reaching the English courts first, and the Upper Tribunal’s observation will likely be tested there before it is tested here, so that is where to watch. On AI specifically, the Isle of Man Law Society has not issued guidance, and the Information Commissioner’s has been signalled but is not yet published. The questions are arriving faster than the guidance.
The Isle of Man Information Commissioner. The Upper Tribunal in UK and R (Munir) v SSHD suggested consulting the Information Commissioner’s Office. In a Manx setting that is the Isle of Man Information Commissioner, under the Applied GDPR. If client material has gone into a consumer tool, the questions are familiar. Is this a personal data breach? Is it reportable? Was there ever a data protection impact assessment? The Island’s Data Protection Maturity Survey in February found only 8% of AI-using organisations believed they were processing personal data at all.
The law will develop, probably soon, and with better argument than a conduct hearing could provide. In the meantime the useful answer does not depend on how it develops, which is fortunate, because none of us can currently say. And for most people here it will not turn on privilege at all, but on the confidentiality duty, which is the live obligation whether or not privilege is ever in play. The question to ask before pasting anything into a prompt box is the one I closed the talk with: would I do this if the client were watching?
If the answer is anything other than an immediate yes, that is not a signal to consult a checklist. It is a signal to ask someone.
AIOM · Artificial Intelligence of Mann · theaiom.im
Sources. Publicly available: Isle of Man Law Society, A Summary of Legal Professional Privilege under Isle of Man Law and its Application to In-House Lawyers; SRA Warning Notice, Misuse of AI (17 August 2026); Advocates’ Practice Rules 2024, r.3.5.1; Police Powers and Procedures Act 1998, s.13; UK and R (on the application of Munir) v SSHD (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC); Uber London Ltd v White [2026] EWHC 1610 (Comm); Wee Shuo Woon v HT S.R.L. [2017] SGCA 23; and the authorities cited throughout, all of which are reported and can be read in full.
The Law Society of England and Wales practice note on legal professional privilege is available to members only. I have drawn on it for orientation, but the propositions above are stated from the underlying authorities rather than from the note, so that readers without access can check the source material for themselves. The same approach is taken to the Isle of Man Bar Examinations ethics materials.
Nothing here is legal advice.

