Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

MVP program · Professional services

Minimum Viable Privacy Program for Law Firms

Minimum Viable Privacy gives a small firm its privacy and security foundations in one packaged year: gap review, core policies, essential safeguards, workshops and training, for $5,499 CAD annually. It exists for the sole practitioner or five-lawyer shop that just received its first client security questionnaire, or whose insurance renewal asked questions nobody could answer, and that has no appetite for hiring or for a sprawling consulting project.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The essentials a small practice must get right first

At one to ten lawyers there is no room for a program that covers everything thinly. The MVP concentrates on the handful of assets where failure is existential.

Intake and identification records

Client verification documents, ID scans and conflicts information collected at the start of every retainer are personal information the moment they arrive, and they deserve better than a shared inbox.

The one or two systems holding everything

Small firms typically run on a single practice-management platform plus email. Securing those two accounts properly delivers most of the available protection for the least effort.

Money moving through trust

Even a two-lawyer real-estate practice wires significant sums. Basic verification discipline and control over who can initiate payments are non-negotiable from day one.

A handful of busy people

With two to ten staff, one person's click is the firm's breach. The included training seats cover everyone who touches client information, receptionist included.

Regulatory map

Small firm, full-size obligations

None of the duties that apply to a national firm are waived for a boutique. The MVP is scoped so a small practice can meet them without a compliance department.

Strict confidence from the first client

The conduct rules' confidentiality duty binds a licensee identically whether the firm has three lawyers or three hundred, and it extends to how files are stored, sent and destroyed.

Primary source →

PIPEDA with no size threshold

A practice handling personal information in commercial activity is covered regardless of headcount, including the accountability, safeguards and breach provisions.

Read our guide →

Breach duties that ignore firm size

Reporting to the OPC where real risk of significant harm exists, notifying individuals as soon as feasible and keeping breach records apply to a sole practitioner exactly as written.

Primary source →

By-Law 7.1 record-keeping

Ontario's client identification and verification requirements generate documents that must be kept, organized and protected, a duty the gap review checks on day one.

Primary source →

What goes wrong

Why small firms cannot wait for a mature program

Attackers do not filter targets by lawyer count; automated attacks find whoever left a door open. For a boutique, three exposures dominate.

  • One mailbox equals the whole firm

    In a five-person practice, a single compromised email account exposes nearly every matter, every client and the payment flow at once. Concentration is the small firm's defining risk.

  • Nobody officially owns privacy

    When responsibility belongs to everyone it belongs to no one, and the questionnaire, the breach and the complaint all land on whoever is nearest. The MVP names an owner and gives them a structure.

  • Deals stalled at onboarding

    A corporate client's procurement process will not wait months while a firm assembles policies from scratch. Foundations built in advance keep the retainer moving.

  • The unencrypted laptop problem

    Small-firm devices travel to courthouses, cottages and coffee shops. Whether a stolen machine is an anecdote or a notification event depends on settings the MVP verifies early.

Our mvp program for law firms

What the MVP year includes for a small firm

A fixed package, sequenced so the highest-impact items land first and nothing depends on the firm hiring anyone.

Magazine Editors At Work
  1. Baseline gap review

    A structured look at how your intake, files, devices, vendors and habits compare against law society expectations and privacy statutes, producing a short, ranked list instead of a hundred-page report.

  2. Prioritized controls

    Directional recommendations on what to fix first, typically authentication, encryption, backups and payment verification, chosen for impact per hour of the firm's limited time.

  3. Core policy development

    The essential documents a small practice needs: confidentiality and acceptable use, retention basics, breach response steps and a client-facing privacy policy, drafted for your actual systems.

  4. Readiness assessment workshops

    Working sessions that prepare the firm for the situations that prompted the purchase, from completing a client questionnaire honestly to handling a suspected incident.

  5. Training with ten seats

    Role-appropriate privacy and security training with human-risk assessments for up to ten people, which covers the full roster of most firms this size.

  6. Twelve hours of coaching

    Expert time to spend where the year takes you: a vendor question, a tricky retention decision, a client's follow-up, or help implementing a recommended control.

How the engagement runs

A year of MVP in a small practice

  1. Step 1

    Review and rank

    The engagement opens with the gap review and a prioritized plan the partners can read in one sitting.

  2. Step 2

    Build the foundations

    Policies are drafted and the first controls implemented with coaching support, usually landing within the opening months of the term.

  3. Step 3

    Train and rehearse

    Staff complete training, and workshops rehearse the questionnaire and incident scenarios that matter most to your practice.

  4. Step 4

    Close the loop

    Remaining coaching hours handle what surfaced during the year, and the term ends with a clear picture of what maturity would look like next.

What it costs

MVP pricing for a small law firm

Minimum Viable Privacy is $5,499 CAD per year on a twelve-month term, covering the gap review, policy development, readiness assessment workshops, twelve hours of coaching and training with human-risk assessments for ten seats. There are no per-deliverable surprises; the package is the price.

Firms that outgrow it, by opening a Quebec office, facing heavy questionnaire volume or taking on institutional clients, typically graduate to the Virtual Privacy Office retainer, and the MVP's outputs carry straight into it. Book a demo to see whether the package fits your practice.

Law Firms: MVP program questions, answered

Five things, done properly: a named person accountable for privacy; a simple map of where client information lives; core policies covering confidentiality, acceptable use, retention and breach response; baseline safeguards, meaning MFA, encrypted devices and working backups; and trained staff. That set satisfies the accountability the statutes expect, gives the law society a coherent story, and holds up when a client asks what protects their file. It is exactly the scope the MVP delivers in its first months.

Institutional clients usually ask for written security and privacy policies, MFA and encryption in place, an incident response capability, evidence of staff training and a view of your key vendors. The MVP builds that foundation and rehearses the questionnaire in a workshop so answers are accurate rather than optimistic. Some sophisticated clients go further and request independent testing; when that happens, our penetration testing service bolts onto the same foundation rather than starting over.

The foundations, yes. The gap review, first controls and core policies are designed to land inside the opening quarter of the term, on a few hours a month from a partner and whoever runs your office, with no new headcount. What a quarter does not produce is maturity: training embeds over the following months, workshops rehearse scenarios as they arise, and the coaching hours absorb the questions a real year throws at a practice. That is why the package is annual rather than a sprint.

Four components across the twelve-month term: the baseline privacy gap review with prioritized recommendations; development of the core policy set; readiness assessment workshops; and privacy and security training with human-risk assessments for up to ten seats, plus twelve hours of expert coaching to apply wherever the firm needs them. It is deliberately a fixed, published price so a managing partner can approve it without a procurement exercise.

Three honest options. Firms whose risk profile is stable often renew and use the year to deepen what exists: refreshed training, updated policies, new coaching questions. Firms that grew, added offices or started fielding regular client reviews step up to the Virtual Privacy Office, where a designated privacy lead and monthly hours take over. And a firm that built internal capability can simply carry the program forward itself, since every deliverable, policy and assessment belongs to you.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.