By Jason Da Silva, Principal Consultant, DASTech Consulting · Last updated: May 2026
Related serviceLegal I.T.See the service →The Law Society of Ontario expects every licensee to be technologically competent, to keep client information confidential and secure, and to properly supervise the staff and vendors who handle that information. These are not a separate “IT rule” bolted onto practice. They flow directly from the existing duties of competence, confidentiality, and supervision in the Rules of Professional Conduct, applied to the tools a modern firm actually uses every day: your email, your practice management software, your cloud storage, and your backups.
This guide is general information about technology practice, not legal advice. It reflects what we see doing hands-on IT work with Canadian law firms, and it does not account for your firm’s particular circumstances. Confirm any specific obligation with your own counsel or with the Law Society directly before you act on it.
For a small or solo firm without a dedicated IT department, that can feel like a moving target. This guide breaks the expectations down in plain language, maps each one to a single concrete control you can put in place, and shows where a technology partner fits.
The Law Society does not publish a checklist of approved products or a minimum encryption standard. Instead, it holds you to professional duties that now clearly include the technology side of practice.
Rule 3.1-1 of the Rules of Professional Conduct defines what a competent lawyer is, and Rule 3.1-2 is the competence rule itself. The commentary to Rule 3.1-2 is where technology comes in: a lawyer should develop an understanding of, and an ability to use, technology relevant to the nature and area of their practice, and should understand the benefits and risks of that technology given the duty to protect confidential information. The Law Society adopted the Federation of Law Societies Model Code commentary on this point, amended in the fall of 2019.
The duty of confidentiality in Rule 3.3-1 requires you to hold in strict confidence, at all times, all information concerning the business and affairs of the client acquired in the course of the professional relationship. There are four exceptions: the client authorizes disclosure, disclosure is required by law or by a tribunal, disclosure is required by the Law Society, or the rules otherwise permit it. Everything else stays confidential, which by extension means protecting it wherever it is stored or transmitted. And the supervision rules in Chapter 6 make you responsible for the non-licensee staff acting on your behalf.
Read together, four practical expectations emerge:
These duties also tend to line up with privacy law obligations, which run in parallel to the Rules of Professional Conduct rather than replacing them. Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice. If a breach of security safeguards does occur under PIPEDA, the reporting threshold is whether the breach creates a “real risk of significant harm” to an individual, judged on the sensitivity of the information involved and the probability that it will be misused. Significant harm is defined broadly there: bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. Where the threshold is met, you report to the Privacy Commissioner and notify the affected individuals as soon as feasible after determining that a breach occurred. Separately, organizations must keep a record of every breach, whether or not it meets that threshold, and retain those records for 24 months. Client legal data sits at the sensitive end of the scale, so the threshold is easier to cross than firms expect.
You do not need to solve everything at once. The most useful thing a small firm can do is attach one clear, testable control to each expectation. Here is a starting map.
| Law Society expectation | What it means in plain terms | One concrete control to put in place |
|---|---|---|
| Technological competence (commentary to Rule 3.1-2) | Understand the tools you use and where the risks are | Keep a simple inventory of your software and cloud services, note what client data each one holds, and get basic training on the ones that matter |
| Confidentiality (Rule 3.3-1) | Keep client information private, in transit and at rest | Turn on encryption plus multi-factor authentication (MFA) on every account that touches client data, with no exceptions for convenience |
| Safeguarding client data | Do not lose the file to failure, theft, or ransomware | Run automated, versioned backups and actually test a restore on a schedule, so you know the backup works before you need it |
| Supervising your own staff (the supervision rules in Chapter 6) | Your team follows the same rules you do | Apply least-privilege access (people see only the files they need) and run short, regular security awareness training |
| Supervising vendors and third parties | Cloud and IT providers handle data properly on your behalf | Do written due diligence before you sign, and keep a signed agreement covering data location, breach notification, and access |
| Retention and secure disposal | Keep records as required, then dispose of them safely | Set a retention schedule and use secure deletion or drive destruction when files reach end of life |
Retention is the row firms most often guess at, and it is one of the few places where the Law Society does give you a number. LSO By-Law 9, which governs financial transactions and records, requires trust records to be kept for ten years plus the current year, and the book of duplicate cash receipts to be kept for at least the six years preceding the most recent fiscal year end. Whatever storage or backup system you choose has to be able to hold and produce those records over that span, which rules out a laptop that gets replaced every three years.
Notice that none of these controls are exotic. MFA, tested backups, and written vendor agreements are ordinary practices. What the Law Society expects is that a firm handling other people’s confidential legal matters actually has them in place and can show it.
Large firms absorb these obligations through in-house IT and information security teams. A three-lawyer practice in a strip mall does not have that, yet it holds exactly the same duty to the client. That gap is where most of the real risk sits.
A few patterns we see often at smaller firms:
The good news is that closing these gaps is affordable and mostly a one-time setup with light ongoing maintenance. You do not need an enterprise budget. You need someone to configure the controls correctly and keep an eye on them.
A practical sequence for a small firm looks like this:
This is the model behind fractional IT: you get the coverage of an IT department sized and priced for a small firm, without a full-time hire. Our fractional IT service for small businesses is built for exactly this range of roughly 5 to 80 seats, and our legal IT service for law firms applies that same coverage specifically to the Law Society expectations above.
DASTech Consulting is a genuine Clio Partner, which means we work day to day inside the practice management platform many Ontario firms already run. That matters because the Law Society’s expectations are not abstract for us. We configure the confidentiality, backup, and access controls directly in the tools your practice depends on, rather than handing you a generic security template and walking away.
For a concrete example of what compliant, well supervised technology change looks like, see our Heeney Lawyers cloud migration case study. We moved the firm to the cloud in 90 days with zero downtime and 100 percent MFA coverage across every account, which maps directly onto the confidentiality and supervision expectations in the table above.
If you are not sure where your firm stands, the fastest path is a short conversation. You can reach us through the contact page and we will reply within one business day. None of this needs to be daunting. It needs to be done once, correctly, and then maintained.
No. The Rules of Professional Conduct are written as professional duties rather than as a product list: competence under Rule 3.1-2 and its commentary, confidentiality under Rule 3.3-1, and supervision of non-licensee staff under Chapter 6. You choose the tools, but you are responsible for making sure they actually protect client information.
Yes. The commentary to Rule 3.1-2 says a lawyer should develop an understanding of, and an ability to use, technology relevant to the nature and area of their practice, and should understand the benefits and risks of that technology given the duty to protect confidential information. The Law Society adopted that commentary from the Federation of Law Societies Model Code, amended in the fall of 2019. In practice it means knowing what your tools do with client data and where the weak points are.
Largely, yes, because you cannot delegate away the duty of confidentiality in Rule 3.3-1. The supervision rules in Chapter 6 cover the non-licensee staff and services acting on your behalf, which is why written due diligence and a signed agreement covering breach notification and data location matter so much. If PIPEDA applies to your firm, you will also have your own record keeping and, where the harm threshold is met, reporting obligations after a vendor breach.
Multi-factor authentication on every account that touches client data, with no exceptions. It is low cost, fast to deploy, and blocks the most common way client information gets stolen: a compromised password.
Yes. Fractional IT gives a small firm the coverage of an IT department at a fraction of the cost of a full-time hire. Our legal IT service is designed to put the Law Society's expectations in place and keep them maintained.