Compliance

E-Signature for Law Firms in Ontario: LSO Client ID Rules

· 4 min read

Ontario law firms are adopting e-signatures for retainer agreements, closing documents, and correspondence with clients. But the Law Society of Ontario (LSO) has specific client identification and verification (ID&V) rules that exist separately from any e-signature tool. Understanding how the two fit together matters before you roll out digital signing across your practice.

E-signatures don't replace LSO client identification duties

Under the LSO's By-Law 7.1 and the Rules of Professional Conduct, lawyers and paralegals in Ontario must identify and, in certain cases, verify their clients before providing legal services. This obligation is about knowing who your client is and confirming that identity with reliable documentation. Signing a document electronically does not satisfy this requirement on its own.

An e-signature platform confirms that a specific email address or phone number completed a signing session and captures a timestamped audit trail. It does not, by itself, confirm that the person behind that inbox is who they claim to be under LSO rules. Firms need a separate, documented ID&V process, whether that's an in-person meeting, a video call with government ID review, or another method permitted under the by-law.

Where e-signature tools fit in the workflow

Once client identification is handled through your firm's compliant process, e-signature tools are useful for the actual execution of documents: retainer agreements, engagement letters, real estate closing packages, and settlement documents. The signature itself is one step in a larger chain of custody that starts with knowing your client.

  • Complete client ID&V per LSO By-Law 7.1 before sending documents for signature.
  • Use the e-signature platform to capture consent, timestamps, and signer actions during execution.
  • Keep the identification records and the signed document records together in your file, even if they live in different systems.
  • Review LSO guidance periodically since ID&V rules and acceptable methods have been updated over time.

What to look for in an e-signature tool for a law practice

Law firms handle sensitive client information, so the platform you choose should give you a clear, defensible record of what happened during signing, not just a signed PDF.

Audit trail and proof of integrity

A usable audit trail should show who received the document, when they opened it, what they clicked or typed, and when they signed. VG·Sign generates a SHA-256 hash of the final signed PDF and keeps an append-only audit log tied to that document. If anyone alters the file after signing, the hash no longer matches, which gives you a straightforward way to demonstrate the document hasn't been changed since execution.

Where your client data is processed

Ontario clients, particularly in regulated matters, sometimes ask where their information is stored. With VG·Sign, envelope content, meaning the documents, form data, and signatures, is stored and processed in the Montreal region: the database and file storage run on Supabase in AWS's ca-central-1 zone, and the application servers run on Vercel's yul1 region. That keeps the core processing in Canada.

It's worth being precise with clients about the exceptions. Email and SMS notifications, along with payment processing, go through US-based providers. The completion email that gets sent when a document is fully signed includes the signed PDFs as attachments, so that specific step crosses the border. If a client asks whether their data ever leaves Canada, the honest answer is that most of it stays in Montreal, but notification delivery involves US infrastructure.

Retention and access for client files

Law firms typically need to retain signed documents for years under professional conduct rules and limitation periods. Confirm that whatever platform you use lets you export signed documents and audit logs in a format you can archive in your own document management system, independent of the vendor's retention policy.

Practical steps for Ontario firms adopting e-signature

  1. Document your firm's client identification and verification procedure separately from your signature workflow.
  2. Choose an e-signature tool with a clear audit trail and document integrity proof, such as a SHA-256 hash of the final PDF.
  3. Confirm where the vendor stores and processes document content, and ask specifically about any cross-border data flows for email or payment services.
  4. Train staff to complete ID&V steps before sending a document for signature, not after.
  5. Keep signed documents and their audit trails as part of your permanent client file.

If you're evaluating options beyond the big US platforms, it's worth comparing pricing and data handling directly.

For a side-by-side look at how VG·Sign compares to larger US-based platforms on pricing and data residency, see our Docusign alternative comparison .

Plans and per-envelope costs for small and mid-size firms are listed on our pricing page .

An e-signature confirms how a document was signed. Client identification confirms who you're actually working for. Ontario firms need both, handled as separate steps.

Frequently asked questions

Does e-signature software satisfy LSO client identification requirements?
No. E-signature platforms record who completed a signing session and provide an audit trail, but they don't independently verify a person's identity under LSO By-Law 7.1. Firms still need their own client identification and verification process, separate from the signing tool.
Is client data processed in Canada with VG·Sign?
Envelope content, including documents and signature data, is stored and processed in the Montreal region using Supabase on AWS ca-central-1 and Vercel's yul1 servers. Email, SMS, and payment providers are US-based, and the completion email that attaches the signed PDF crosses the border at that step.
Can a signed PDF be proven unaltered later?
VG·Sign generates a SHA-256 hash of the final signed PDF along with an append-only audit log. If the file is changed after signing, the hash won't match, which gives you evidence the document is intact since execution.
Are there Canadian laws that apply to e-signatures in Ontario?
Ontario's Electronic Commerce Act and federal PIPEDA provide general context for electronic signatures and personal information handling. This is background information only, not legal advice, and firms should consult qualified counsel for their specific obligations.

This article is for general information only and is not legal advice. For advice on your specific situation, consult a qualified professional.