Guide

The Law Society of Ontario’s technology expectations, explained for small firms

Legal I.T. services from DASTech ConsultingRelated serviceLegal I.T.See the service

The Law Society of Ontario expects every licensee to be technologically competent, to keep client information confidential and secure, and to properly supervise the staff and vendors who handle that information. These are not a separate “IT rule” bolted onto practice. They flow directly from the existing duties of competence, confidentiality, and supervision in the Rules of Professional Conduct, applied to the tools a modern firm actually uses every day: your email, your practice management software, your cloud storage, and your backups.

Before you read on

This guide is general information about technology practice, not legal advice. It reflects what we see doing hands-on IT work with Canadian law firms, and it does not account for your firm’s particular circumstances. Confirm any specific obligation with your own counsel or with the Law Society directly before you act on it.

For a small or solo firm without a dedicated IT department, that can feel like a moving target. This guide breaks the expectations down in plain language, maps each one to a single concrete control you can put in place, and shows where a technology partner fits.

What the Law Society actually expects

The Law Society does not publish a checklist of approved products or a minimum encryption standard. Instead, it holds you to professional duties that now clearly include the technology side of practice.

Rule 3.1-1 of the Rules of Professional Conduct defines what a competent lawyer is, and Rule 3.1-2 is the competence rule itself. The commentary to Rule 3.1-2 is where technology comes in: a lawyer should develop an understanding of, and an ability to use, technology relevant to the nature and area of their practice, and should understand the benefits and risks of that technology given the duty to protect confidential information. The Law Society adopted the Federation of Law Societies Model Code commentary on this point, amended in the fall of 2019.

The duty of confidentiality in Rule 3.3-1 requires you to hold in strict confidence, at all times, all information concerning the business and affairs of the client acquired in the course of the professional relationship. There are four exceptions: the client authorizes disclosure, disclosure is required by law or by a tribunal, disclosure is required by the Law Society, or the rules otherwise permit it. Everything else stays confidential, which by extension means protecting it wherever it is stored or transmitted. And the supervision rules in Chapter 6 make you responsible for the non-licensee staff acting on your behalf.

Read together, four practical expectations emerge:

  1. Technological competence. You should understand the tools you use and the risks that come with them.
  2. Confidentiality. Client information must stay private, in transit and at rest.
  3. Safeguarding client data. Files must survive hardware failure, ransomware, and human error.
  4. Supervising staff and vendors. Everyone who touches client data, inside your firm or at a third party, has to meet the same standard you do.

These duties also tend to line up with privacy law obligations, which run in parallel to the Rules of Professional Conduct rather than replacing them. Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice. If a breach of security safeguards does occur under PIPEDA, the reporting threshold is whether the breach creates a “real risk of significant harm” to an individual, judged on the sensitivity of the information involved and the probability that it will be misused. Significant harm is defined broadly there: bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. Where the threshold is met, you report to the Privacy Commissioner and notify the affected individuals as soon as feasible after determining that a breach occurred. Separately, organizations must keep a record of every breach, whether or not it meets that threshold, and retain those records for 24 months. Client legal data sits at the sensitive end of the scale, so the threshold is easier to cross than firms expect.

The four expectations, mapped to one control each

You do not need to solve everything at once. The most useful thing a small firm can do is attach one clear, testable control to each expectation. Here is a starting map.

Law Society expectation What it means in plain terms One concrete control to put in place
Technological competence (commentary to Rule 3.1-2) Understand the tools you use and where the risks are Keep a simple inventory of your software and cloud services, note what client data each one holds, and get basic training on the ones that matter
Confidentiality (Rule 3.3-1) Keep client information private, in transit and at rest Turn on encryption plus multi-factor authentication (MFA) on every account that touches client data, with no exceptions for convenience
Safeguarding client data Do not lose the file to failure, theft, or ransomware Run automated, versioned backups and actually test a restore on a schedule, so you know the backup works before you need it
Supervising your own staff (the supervision rules in Chapter 6) Your team follows the same rules you do Apply least-privilege access (people see only the files they need) and run short, regular security awareness training
Supervising vendors and third parties Cloud and IT providers handle data properly on your behalf Do written due diligence before you sign, and keep a signed agreement covering data location, breach notification, and access
Retention and secure disposal Keep records as required, then dispose of them safely Set a retention schedule and use secure deletion or drive destruction when files reach end of life

Retention is the row firms most often guess at, and it is one of the few places where the Law Society does give you a number. LSO By-Law 9, which governs financial transactions and records, requires trust records to be kept for ten years plus the current year, and the book of duplicate cash receipts to be kept for at least the six years preceding the most recent fiscal year end. Whatever storage or backup system you choose has to be able to hold and produce those records over that span, which rules out a laptop that gets replaced every three years.

Notice that none of these controls are exotic. MFA, tested backups, and written vendor agreements are ordinary practices. What the Law Society expects is that a firm handling other people’s confidential legal matters actually has them in place and can show it.

Why this lands harder on small firms

Large firms absorb these obligations through in-house IT and information security teams. A three-lawyer practice in a strip mall does not have that, yet it holds exactly the same duty to the client. That gap is where most of the real risk sits.

A few patterns we see often at smaller firms:

  • MFA is on for the lawyers but not the assistants. Attackers target the least protected account, and a legal assistant’s mailbox often holds just as much confidential material.
  • Backups exist but have never been restored. A backup you have not tested is a hope, not a control. Ransomware frequently encrypts the backup too if it is left connected.
  • Vendor relationships are handshake deals. The cloud storage or email service was chosen years ago with no written agreement about where data lives or what happens after a breach.
  • Old devices leave the office with data still on them. A retired laptop sold or donated without a secure wipe is a confidentiality incident waiting to be discovered.

The good news is that closing these gaps is affordable and mostly a one-time setup with light ongoing maintenance. You do not need an enterprise budget. You need someone to configure the controls correctly and keep an eye on them.

How to close the gap without hiring an IT department

A practical sequence for a small firm looks like this:

  1. Inventory first. List every place client data lives: email, practice management, document storage, local drives, and phones. You cannot protect what you have not mapped.
  2. Lock the front door. Enforce MFA everywhere and confirm encryption is on for email, storage, and any laptop hard drive.
  3. Prove your backups. Move to automated backups with version history and run a test restore. Write down the date you last restored successfully.
  4. Tighten access. Give each person the minimum access they need and remove accounts the moment someone leaves.
  5. Paper your vendors. Collect written agreements from your key technology providers covering security, data location, and breach notice.
  6. Train the humans. Most incidents start with a click. Short, regular training does more than any single piece of software.

This is the model behind fractional IT: you get the coverage of an IT department sized and priced for a small firm, without a full-time hire. Our fractional IT service for small businesses is built for exactly this range of roughly 5 to 80 seats, and our legal IT service for law firms applies that same coverage specifically to the Law Society expectations above.

Where DASTech fits, as a Clio Partner

DASTech Consulting is a genuine Clio Partner, which means we work day to day inside the practice management platform many Ontario firms already run. That matters because the Law Society’s expectations are not abstract for us. We configure the confidentiality, backup, and access controls directly in the tools your practice depends on, rather than handing you a generic security template and walking away.

For a concrete example of what compliant, well supervised technology change looks like, see our Heeney Lawyers cloud migration case study. We moved the firm to the cloud in 90 days with zero downtime and 100 percent MFA coverage across every account, which maps directly onto the confidentiality and supervision expectations in the table above.

If you are not sure where your firm stands, the fastest path is a short conversation. You can reach us through the contact page and we will reply within one business day. None of this needs to be daunting. It needs to be done once, correctly, and then maintained.

FAQ

Common questions.

Does the Law Society of Ontario require lawyers to use specific security software?

No. The Rules of Professional Conduct are written as professional duties rather than as a product list: competence under Rule 3.1-2 and its commentary, confidentiality under Rule 3.3-1, and supervision of non-licensee staff under Chapter 6. You choose the tools, but you are responsible for making sure they actually protect client information.

Is technological competence really part of a lawyer's professional duty?

Yes. The commentary to Rule 3.1-2 says a lawyer should develop an understanding of, and an ability to use, technology relevant to the nature and area of their practice, and should understand the benefits and risks of that technology given the duty to protect confidential information. The Law Society adopted that commentary from the Federation of Law Societies Model Code, amended in the fall of 2019. In practice it means knowing what your tools do with client data and where the weak points are.

Am I responsible if my cloud vendor has a data breach?

Largely, yes, because you cannot delegate away the duty of confidentiality in Rule 3.3-1. The supervision rules in Chapter 6 cover the non-licensee staff and services acting on your behalf, which is why written due diligence and a signed agreement covering breach notification and data location matter so much. If PIPEDA applies to your firm, you will also have your own record keeping and, where the harm threshold is met, reporting obligations after a vendor breach.

What is the single most valuable control for a small firm to start with?

Multi-factor authentication on every account that touches client data, with no exceptions. It is low cost, fast to deploy, and blocks the most common way client information gets stolen: a compromised password.

Can a small firm meet these expectations without hiring full-time IT staff?

Yes. Fractional IT gives a small firm the coverage of an IT department at a fraction of the cost of a full-time hire. Our legal IT service is designed to put the Law Society's expectations in place and keep them maintained.