IT Compliance for Ontario Law Firms: What You Have to Prove
August 20, 2026

For most small and mid-sized Ontario law firms, compliance doesn’t arrive as a regulator at the door. It arrives as an email.
A corporate client is about to send you something sensitive, and their procurement or infosec team wants a security questionnaire filled in first. Thirty or forty questions about encryption, access control, backups, retention, incident response. It has a deadline, it’s attached to work you’ve already won, and nobody in the firm knows the answers off the top of their head.
That’s the moment most firms discover the real gap. It usually isn’t that the security is bad. It’s that nobody can prove it.
The gap is evidence, not software
We see the same pattern in professional practices often enough that it’s worth stating plainly: an office that would pass a security review on the substance can still struggle to answer the questionnaire, because the answers live in people’s heads and in settings nobody has written down.
Multi-factor authentication is probably on. Can you say when it was turned on, who it covers, and which accounts are exempt? Backups probably run. When did someone last restore from one to check? Access is probably reasonable. Can you produce a list of who can reach the document management system, and show that the articling student who left in March can’t?
Every one of those is a two-minute answer if somebody keeps the record, and a two-week scramble if nobody does. The technology is rarely the bottleneck. The paperwork is.
What actually applies to an Ontario firm
There’s a lot of loose talk about which rules bind a law firm’s technology. Four things genuinely matter, and one commonly cited item mostly doesn’t.
Your professional obligations come first. The Law Society of Ontario’s Rules of Professional Conduct put confidentiality of client information at the centre of practice, and that duty doesn’t change because the file is a PDF instead of a folder. Nothing in your IT setup is allowed to make that duty harder to meet.
Client identification and verification, under By-Law 7.1. You have to identify clients and, for certain transactions, verify their identity. There are three permitted methods for an individual and you pick one: examining an authentic government-issued photo identification document, the credit file method (matching against a Canadian credit file that has existed for at least three years), or the dual process method (two reliable, independent sources).
This became a technology question on January 1, 2024, when the Law Society’s temporary pandemic measure — which had allowed virtual verification without authenticating the document — ended. If you are not in the client’s physical presence and you are relying on the photo ID route, you now need a process that establishes the document is genuine, which in practice means authentication technology rather than a scan emailed over and eyeballed. The other two methods remain available precisely because they don’t involve examining a document at all. The Law Society doesn’t endorse or approve any particular product, which leaves both the choice and the record of having done it properly with you.
Financial records and cash, under By-Law 9. This is the one with a body that will actually turn up and ask you to produce something. By-Law 9 sets out the financial records a practice has to keep and for how long, restricts how much cash you may accept on a client matter, and a Law Society spot audit expects those records to be produced — including records kept electronically. If your document management or accounting system lives in the cloud, “can we get it out, in readable form, going back the required number of years” is a question worth answering before somebody else asks it.
PIPEDA, the federal privacy law, applies to personal information your firm handles in the course of commercial activity. Its relevance here is mostly practical: it sets the expectation that you safeguard personal information appropriately, and it’s the framework behind the breach-notification obligation if things go wrong.
And the one that usually gets miscited: FINTRAC. You will see IT vendors list FINTRAC obligations alongside a law firm’s compliance requirements. For financial services firms that’s fair. For a law firm acting in its capacity as legal counsel it isn’t.
In Canada (Attorney General) v Federation of Law Societies of Canada, 2015 SCC 7, the Supreme Court struck down the application of the money-laundering regime’s client identification and record-keeping obligations, and its law-office search powers, to lawyers and law firms — the search provisions under section 8 of the Charter, and the record-keeping obligations under section 7, because they were incompatible with the lawyer’s duty of commitment to the client’s cause. Lawyers had already been removed from the reporting requirements by regulation years earlier. What binds you instead is the Law Society’s own client identification and verification rules under By-Law 7.1, and its cash-handling restrictions under By-Law 9.
Two caveats, because they’re where the simple version breaks. The carve-out follows the capacity you’re acting in: a practice that also carries on a separately regulated activity — real estate or mortgage brokerage, say — can still be a reporting entity in that capacity. And if you’re in-house at a bank or a dealer, your employer’s FINTRAC obligations are very much your problem; they simply aren’t obligations of a legal practice as such.
Worth watching rather than acting on: Bill C-2, introduced in June 2025, proposes — as introduced — a general prohibition on accepting cash at or above $10,000 in the course of a business or profession, broadly and without regard to reporting-entity status, which is why it would reach legal practices. As at August 2026 it has not been enacted. If a provider is pitching you FINTRAC reporting compliance for a law practice today, though, that’s a reasonable signal they’re working from a template written for somebody else.
The four things a security review will actually ask about
Client questionnaires vary in length and almost never in substance. Nearly all of them want evidence in four areas.
Access. Who can reach client files, how they authenticate, and what happens the day someone leaves. Multi-factor authentication everywhere is the baseline answer. The harder half is offboarding — being able to show that departures are handled the same way every time, not remembered.
Encryption. Data at rest and in transit. Full-disk encryption on laptops matters more than it sounds, because the realistic loss event for a small firm isn’t a sophisticated intrusion, it’s a bag left in a car.
Backup and retention. Not whether backups exist, but whether they’ve been restored recently, how far back they go, and how they line up with your file-retention obligations. A backup nobody has tested is a plan, not a control.
Logging and incident response. Whether you’d know something happened, and what you’d do in the first hour. This is the one small practices most often have nothing written for, and it’s the one a client’s security team pushes hardest on — because an office that can’t detect a problem also can’t tell them about it. Note too that PIPEDA requires you to keep a record of every breach of security safeguards for two years, whether or not it was serious enough to report. That’s a filing obligation rather than a technical one, and it’s exactly the kind of thing that doesn’t exist until somebody decides to create it.
Wire fraud is the threat behind the questionnaire
It’s worth being clear about why corporate clients started asking. Legal practice sits on top of trust accounts and closing funds, which makes it a standing target for payment-redirection fraud — a convincing email, at the right moment in a transaction, with new banking details.
That’s also why email authentication does more for a firm’s real risk than most security spending. If your domain can be convincingly impersonated, an attacker doesn’t need to break into anything. You can check where your domain stands with our free Email Spoofing Check — it takes under a minute and needs no signup.
Where to start
If a questionnaire is already sitting in your inbox, answer it honestly, including the gaps. Procurement teams are used to “not yet, here’s the plan”; they are much less forgiving of an answer that turns out to be wrong.
If one isn’t, the useful first step is an inventory rather than a purchase: what you have, who can reach it, what’s backed up, what’s logged, and where the written version of all that lives. Most firms find they’re in better shape than they feared on the technology and worse than they hoped on the documentation — which is the cheaper of the two problems to fix.
How Canopytech can help
We’re a GTA-based IT partner with over 40 years of combined experience, and we work with professional practices where confidentiality isn’t a preference but an obligation. That means access control and offboarding you can evidence, tested backups, email authentication that blocks impersonation of your domain, and written documentation you can hand to a client’s security team without rewriting it each time.
We support professional practices across Toronto and the wider GTA. If a client security review or a Law Society requirement has put your technology under a spotlight, book a free 30-minute consultation or call 647.478.8449.
This article is general information for Ontario practices, current as at August 2026. It is not legal advice, and it is not a substitute for your own reading of the Rules of Professional Conduct or By-Laws 7.1 and 9. This is a regime being actively amended — check the date before relying on any of it.

