The LSBC Cloud Computing Checklist: What BC Law Firms Must Do Before Moving to the Cloud
The Law Society of British Columbia updated its Cloud Computing Checklist to version 4.0 in January 2023. It contains over 80 due diligence items across nine categories. We've read the whole thing so you don't have to — here's what actually matters for your firm.
Why this checklist exists
Cloud computing offers real benefits to lawyers: access to software without capital outlays, remote access to your data, and offloaded maintenance. But when you place client data in the hands of third parties, you take on security, privacy, and regulatory obligations that don't disappear just because the data left your office.
The LSBC checklist is built to help you perform due diligence before moving data to the cloud — and to revisit that due diligence periodically, because cloud technologies and the legal landscape around them keep evolving.
"Due diligence is not a one-and-done proposition, because new technologies develop, new opportunities arise, and new risks can manifest."
— Law Society of British Columbia, Cloud Computing Checklist v4.0
The CLOUD Act: why it matters now
One development the LSBC specifically flags is the US CLOUD Act (Clarifying Overseas Use of Lawful Data Act). It's already operative in the United States, and Canada and the US are negotiating an agreement to make it reciprocally enforceable.
If your cloud provider is US-based or has US operations, US law enforcement could potentially compel access to your client data — even if that data is stored in Canada. The LSBC strongly encourages lawyers to familiarize themselves with the legislation, especially if your clients' activities could be of interest to US government or law enforcement agencies.
Key takeaway
If you're using a US-headquartered cloud provider (Microsoft 365, Google Workspace, Dropbox, etc.), your client data may be subject to US lawful access. Canadian-controlled cloud infrastructure eliminates this exposure.
Part A: First steps — read before you click
Before signing up for anything, the LSBC wants you to actually read the fine print:
The LSBC notes that vendor marketing claiming "law society compliance" is not a substitute for your own due diligence. A cloud product designed for lawyers may have been built with professional obligations in mind, but you still need to verify.
Part B: Law Society compliance — non-negotiable
This section applies to all lawyers, regardless of practice area. The key requirements:
Records and audit requirements
Reporting obligations
Part C: Security and risk management
The LSBC identifies four pillars of data security: firewall, encryption, password protection, and physical security. Your cloud provider should address all four.
The checklist also raises the question of private cloud vs. public cloud. A private cloud — internally hosted within your corporate firewall, under your IT team's control — removes concerns about external control over client data and regulatory compliance.
Part D: Compliance — where your data lives matters
This is where the CLOUD Act and cross-border data issues come into focus. The LSBC wants you to know:
Encryption guidance
The LSBC recommends that the lawyer or law firm be the sole owner of the encryption key, not the cloud provider. Encrypting data before sending it to the cloud reduces risk. While encryption at rest and in transit is the gold standard, some legal software providers don't encrypt at rest — discuss this with your provider and make an informed decision.
Part E: Due diligence — what if things go wrong?
The checklist asks you to plan for failure scenarios before they happen:
Parts F–I: Client implications, IT, reliability, and cost
The remaining sections cover client consent, technical integration, uptime, and fees. Key points:
Client implications
IT considerations
Reliability
Fees and cost
What this means for your firm
The checklist is thorough — sometimes overwhelmingly so. But the core message is simple: you remain responsible for your client's data regardless of where it's stored or who is hosting it.
If you're a BC law firm considering a move to the cloud (or reviewing your current cloud setup), here are the questions that matter most:
- Where does the data physically live? If it's in a US data centre, the CLOUD Act applies.
- Who controls the encryption keys? You should, not the provider.
- Can you get your data out? In a usable format, on short notice, without exorbitant fees.
- Are you complying with Rules 10-3 and 10-4? These are non-negotiable for every lawyer.
- Have you documented your due diligence? If the Law Society asks, you need to show your work.
How Cloud Collective helps
We work with BC law firms to navigate exactly these requirements. Our managed IT and cloud migration services are designed with LSBC compliance in mind:
- Canadian-hosted infrastructure — your client data stays in Canada, no CLOUD Act exposure.
- Encryption you control — you hold the keys, not us and not a foreign provider.
- Local backups and safe-harbour copies — your data is backed up independently of your cloud provider.
- Documented due diligence — we provide the documentation you need to show LSBC compliance.
- Disaster recovery planning — tested RPO and RTO targets, business continuity plans.
If you're reviewing your firm's cloud setup or planning a migration, book a free IT assessment or contact us — we'll walk you through the checklist items that apply to your practice.
The full LSBC Cloud Computing Checklist v4.0 is available on the Law Society of British Columbia website. For practice advice relating to these issues, contact the LSBC practice advisors at practiceadvice@lsbc.org.
This article is for informational purposes and does not constitute legal advice. Law firms should consult with the Law Society's practice advisors for guidance specific to their practice.