Skip to content

Resources/Canadian data sovereignty

Law society guidance on storing client files in the cloud

Reviewed

No Canadian law society forbids cloud storage of client information, and none has for a long time. What they consistently require is that the lawyer, not the vendor, owns the decision, and that the lawyer can explain it. The guidance across provinces converges on a short list of questions.

The duty has not changed, only the venue

Confidentiality is a professional obligation that predates every tool you use. Storing a file with a third party does not delegate the duty; it adds a party you now have to be satisfied about. Law society guidance across the country frames cloud use the same way: permitted, provided the lawyer exercises reasonable due diligence in selecting the provider, understands the arrangement, and reviews it periodically.

That framing is why a vendor cannot hand you an approval. There is no approved-provider list to appear on. There is a standard of care that you meet or do not.

What the due-diligence lists have in common

  1. Where is the data stored, and where are the backups?
  2. Who has access, including provider staff, and how is that access controlled and logged?
  3. Is the data encrypted in transit and at rest, and who holds the keys?
  4. What happens if the provider fails, is acquired, or is bought by a company in another country?
  5. Can you get your data out in a usable form, on demand and at termination?
  6. What is the provider's policy on responding to legal process, and will they tell you when they receive it?

That last question is worth dwelling on, because it is the one where the answers vary most and where a client would most want you to have asked.

Why jurisdiction is a sharper question for lawyers

For most professionals, foreign legal reach is a privacy problem. For a lawyer it is also a privilege problem. If a foreign order is served on a provider rather than on you, the client's file can be produced through a process the client never sees, in a forum where the privilege analysis is not the one you would have made, and possibly without you being told in time to assert anything.

This is why "who owns the company holding it" matters more in a legal practice than the datacentre address does. A provider incorporated in Canada, holding files in Canada, can still be compelled, but by a Canadian court, on a record you can see and contest.

Separate the collection channel from the file system

A great deal of risk sits in intake, before anything reaches your document management system: the ID photo texted to a paralegal, the disclosure package emailed as forty attachments, the mortgage file dropped in a shared folder that three people still have a link to.

A dedicated collection channel with per-matter checklists, expiring links, malware scanning, and an audit record narrows that window. It is not a DMS and should not pretend to be one. Its job is to get documents from the client to you cleanly, and then to stop holding them.

Say it in the engagement letter

Clients rarely object to secure electronic handling; they object to finding out about it later. A short paragraph naming how documents will be exchanged, roughly where they will be held, and how long you will keep them turns a possible complaint into an informed instruction. It also forces you to answer the questions above for yourself before a client asks them.

General information about how these rules work, not legal advice. The obligations that apply to your practice depend on your province, your regulator, and the information you hold.

Related reading

Ready to try it on your next intake? See how it works.

Law society guidance on storing client files in the cloud - ReceiveVault