Law Firms Cloud Computing October 2026 8 min read

The LSBC Cloud Computing Checklist: What BC Law Firms Must Do Before Moving to the Cloud

The Law Society of British Columbia updated its Cloud Computing Checklist to version 4.0 in January 2023. It contains over 80 due diligence items across nine categories. We've read the whole thing so you don't have to — here's what actually matters for your firm.

Why this checklist exists

Cloud computing offers real benefits to lawyers: access to software without capital outlays, remote access to your data, and offloaded maintenance. But when you place client data in the hands of third parties, you take on security, privacy, and regulatory obligations that don't disappear just because the data left your office.

The LSBC checklist is built to help you perform due diligence before moving data to the cloud — and to revisit that due diligence periodically, because cloud technologies and the legal landscape around them keep evolving.

"Due diligence is not a one-and-done proposition, because new technologies develop, new opportunities arise, and new risks can manifest."
— Law Society of British Columbia, Cloud Computing Checklist v4.0

The CLOUD Act: why it matters now

One development the LSBC specifically flags is the US CLOUD Act (Clarifying Overseas Use of Lawful Data Act). It's already operative in the United States, and Canada and the US are negotiating an agreement to make it reciprocally enforceable.

If your cloud provider is US-based or has US operations, US law enforcement could potentially compel access to your client data — even if that data is stored in Canada. The LSBC strongly encourages lawyers to familiarize themselves with the legislation, especially if your clients' activities could be of interest to US government or law enforcement agencies.

Key takeaway

If you're using a US-headquartered cloud provider (Microsoft 365, Google Workspace, Dropbox, etc.), your client data may be subject to US lawful access. Canadian-controlled cloud infrastructure eliminates this exposure.

Part A: First steps — read before you click

Before signing up for anything, the LSBC wants you to actually read the fine print:

Read the cloud provider's click-through agreement — yes, the whole thing.
Review the Service Level Agreement (SLA).
Review the privacy and confidentiality agreement.

The LSBC notes that vendor marketing claiming "law society compliance" is not a substitute for your own due diligence. A cloud product designed for lawyers may have been built with professional obligations in mind, but you still need to verify.

Part B: Law Society compliance — non-negotiable

This section applies to all lawyers, regardless of practice area. The key requirements:

Records and audit requirements

Electronic records must be capable of meeting Law Society auditing and investigation standards (Rule 10-3).
Records must be printable in a comprehensive format, accessible read-only, and exportable to an acceptable electronic format.
Metadata associated with electronic records must be available to the Law Society on demand.
Trust ledger, bank reconciliations, and master billings must be maintained in hard copy or PDF.
All records must show creation dates, edit dates, and preserve all metadata.
Records must be retained for a minimum of 10 years from the final accounting transaction.

Reporting obligations

If you lose custody or control of records, a written report must go to the Executive Director (Rule 10-4(2)).
Report to the Lawyers Indemnity Fund where required (Rule 3-39, BC Code section 7.8).
If you're the victim of a data breach, immediately report to your cyber insurer.
Have a plan to give the Law Society access to passwords if they need to retrieve documents (e.g. acting as custodian).

Part C: Security and risk management

The LSBC identifies four pillars of data security: firewall, encryption, password protection, and physical security. Your cloud provider should address all four.

Has the cloud provider had any security breaches? Are you satisfied with their response?
Is your data encrypted both in transit and at rest? If not at rest, can you add your own encryption?
Is your data "safe-harboured" — backed up with a separate third party in case your cloud provider goes down?
Can you maintain a local backup of your data?
Has the provider had independent third-party security audits? How often?
If the provider ceases business, how long will it take to get your data out and into another system?
Do you have a disaster recovery / business continuity plan?

The checklist also raises the question of private cloud vs. public cloud. A private cloud — internally hosted within your corporate firewall, under your IT team's control — removes concerns about external control over client data and regulatory compliance.

Part D: Compliance — where your data lives matters

This is where the CLOUD Act and cross-border data issues come into focus. The LSBC wants you to know:

Where are the servers? Multiple locations? Who has access? What laws apply?
Is data staying within BC? Within Canada? If it leaves Canada, what laws apply?
You must comply with PIPA (BC), PIPEDA (federal), and FIPPA where applicable.
If data goes outside Canada, you must notify clients and obtain consent.
Your privacy policy must list countries where data is collected, used, or disclosed.
Consider a private cloud for sensitive data that cannot leave the jurisdiction.

Encryption guidance

The LSBC recommends that the lawyer or law firm be the sole owner of the encryption key, not the cloud provider. Encrypting data before sending it to the cloud reduces risk. While encryption at rest and in transit is the gold standard, some legal software providers don't encrypt at rest — discuss this with your provider and make an informed decision.

Part E: Due diligence — what if things go wrong?

The checklist asks you to plan for failure scenarios before they happen:

Can you terminate the service? At what cost? What if a breach occurs?
Is your data available after termination? For how long? In what format?
Can your data be fully sanitized from the provider's systems after termination?
Does the SLA transfer ownership of your data? (Rule 10-3(4) requires that ownership of records must not pass to another party.)
Have you compared the cloud product against non-cloud alternatives?
Have you documented your due diligence and kept a copy for later reference?

Parts F–I: Client implications, IT, reliability, and cost

The remaining sections cover client consent, technical integration, uptime, and fees. Key points:

Client implications

Best practice: get informed consent from clients to store their data in the cloud — in writing, in your retainer agreement.
Notify existing clients if you're moving to cloud-based storage, especially if data goes outside Canada.

IT considerations

Does the cloud application integrate with your existing office systems?
Do you have sufficient bandwidth for acceptable performance?
Test with dummy data before committing.
Can the provider handle capacity spikes from rapid growth?
What are the backup systems? Where are they located? How often?

Reliability

What is the provider's uptime history? (Gold standard: 99.999%.)
Can you operate offline if the system goes down?
Are uptime guarantees and penalties spelled out in the SLA?

Fees and cost

What are setup fees, monthly fees, and usage/bandwidth fees?
How often can the provider increase fees? Is there a cap?
Can the provider cut off access to your data for non-payment?
Compare total cost of cloud vs. non-cloud alternatives (present value calculation).

What this means for your firm

The checklist is thorough — sometimes overwhelmingly so. But the core message is simple: you remain responsible for your client's data regardless of where it's stored or who is hosting it.

If you're a BC law firm considering a move to the cloud (or reviewing your current cloud setup), here are the questions that matter most:

  1. Where does the data physically live? If it's in a US data centre, the CLOUD Act applies.
  2. Who controls the encryption keys? You should, not the provider.
  3. Can you get your data out? In a usable format, on short notice, without exorbitant fees.
  4. Are you complying with Rules 10-3 and 10-4? These are non-negotiable for every lawyer.
  5. Have you documented your due diligence? If the Law Society asks, you need to show your work.

How Cloud Collective helps

We work with BC law firms to navigate exactly these requirements. Our managed IT and cloud migration services are designed with LSBC compliance in mind:

If you're reviewing your firm's cloud setup or planning a migration, book a free IT assessment or contact us — we'll walk you through the checklist items that apply to your practice.

The full LSBC Cloud Computing Checklist v4.0 is available on the Law Society of British Columbia website. For practice advice relating to these issues, contact the LSBC practice advisors at practiceadvice@lsbc.org.

This article is for informational purposes and does not constitute legal advice. Law firms should consult with the Law Society's practice advisors for guidance specific to their practice.