Augmented Justice and DPR: The Importance of Technology Engagement Rules from the Outset of the Process
10 August 2026
Private dispute prevention and resolution processes (DPR) play an important role in the administration of justice. They are based on a simple but fundamental principle: enabling parties to prevent a potential dispute or resolve an existing one within a framework that is more flexible, confidential, efficient and tailored to their circumstances, before turning to the courts.
This principle is all the more relevant in a context where organizations and individuals seek efficient, proportionate, and pragmatic solutions to their disagreements.
Artificial intelligence (AI) technologies, collaborative platforms, document analysis and review tools, drafting assistants, videoconferencing environments, and digital case management solutions, among others, nevertheless add a layer of complexity that requires parties and professionals to reassess the measures needed to preserve the confidentiality of these processes.
DPR processes increasingly take place in a digital environment in which technological tools assist the parties, their counsel and the neutral third parties involved. This evolution is contributing to the emergence of a form of “augmented justice,” in which technology can support preparation, negotiation, mediation or arbitration by accelerating analysis, facilitating the management of large volumes of information, structuring exchanges, and supporting decision-making and dispute management—without replacing human judgment.
The increasing integration of digital tools into these processes raises an important governance question: how should the use of these tools be governed so as to preserve the confidentiality of communications, the protection of personal information, professional secrecy and settlement privilege?
Traditional Principles, New Risks
The Code of Civil Procedure provides that parties must consider private DPR before referring a matter to the courts and that such processes are selected by mutual agreement. This procedural autonomy allows the parties not only to choose the process best suited to their dispute, but also to define its practical parameters, including the arrangements governing communications, confidentiality and document management. [1]
Confidentiality, however, is the pillar that becomes most vulnerable when technological tools are integrated into the process. Article 4 of the Code of Civil Procedure provides that parties who enter into a private PDR process, together with the third party assisting them, undertake to preserve the confidentiality of anything said, written or done in the course of the process, subject to their agreement or to any specific provisions of law.
This confidentiality creates a protected space in which parties can openly discuss their interests, risks and potential avenues for settlement without fear that those communications will later be used against them in subsequent litigation. This protection is reinforced by settlement privilege, whose purpose is precisely to foster frank and constructive discussions aimed at reaching a settlement.
Once technology is introduced, the question is no longer simply whether the parties wish to preserve confidentiality. It is also necessary to determine whether the tools being used actually allow them to do so.
The Risk Is Not AI Itself, but the Absence of Governance
In a PDR context, technological tools may be used at many stages of the process, by the parties, their counsel and neutral third parties alike: transcribing meetings, organizing documents, conducting research, translating, preparing summaries, analyzing documents, developing settlement scenarios or managing communications among participants.
These tools can increase the efficiency of the process. Their use nevertheless raises significant concerns when the parties have not agreed from the outset on, among other things, the rules governing their use, the circulation of information, data retention and the security measures surrounding them. The risks are amplified where the selected tools do not provide adequate safeguards with respect to cybersecurity, confidentiality and data governance.
The main concerns relate to loss of control over exchanged information, understanding data flows involving technology providers, and preserving the confidentiality that is one of the fundamental characteristics of PDR. These issues may arise, for example, where a platform retains data longer than necessary, where information is disclosed to third-party service providers, where data-processing parameters are insufficiently documented or difficult to understand, or where it becomes difficult to determine the extent to which an artificial intelligence tool contributed to an analysis or to the production of an output.
These risks take on particular importance when a dispute involves personal information or other sensitive information, such as health information, financial information, information relating to employees, clients or family members, information concerning children, income information, family circumstances, trade secrets, strategic information or business strategies.
Regulatory considerations add a further layer to these concerns. Organizations participating in a PDR process remain subject to their obligations regarding the protection of personal information.
In Québec, the Act respecting the protection of personal information in the private sector requires businesses, among other things, to implement security measures appropriate to ensuring the protection of personal information that is collected, used, disclosed, retained or destroyed, taking into account such factors as its sensitivity, the purposes for which it is used, its quantity, its distribution and the medium on which it is stored.[2]
Before even considering whether an artificial intelligence tool may be used in a dispute-resolution process, the parties should ask themselves whether they have the governance mechanisms, security measures and necessary authorizations required to disclose, process and adequately protect the information involved.
The issue, therefore, is not so much the technology itself as the absence of a clear framework for determining which tools may be used, for what purposes, under what conditions, with what security measures, and with what degree of transparency toward the other participants. It is precisely from this perspective that technology rules of engagement become so important.
Technology Engagement Rules: An Essential Preliminary Step
The parties should establish technology rules of engagement at the outset of the DPR process. These rules should not be treated as a mere administrative box-checking exercise; they should form part of the very architecture of the process.
The objective is twofold: to preserve the integrity of the process and to prevent the use of a technological tool from itself becoming a source of dispute.
Such rules should address, in particular, the following matters:
Authorized and Prohibited Tools
Identify the platforms, software and AI tools that may be used, and expressly prohibit open or public tools that do not provide adequate assurances regarding the confidentiality of submitted information.
Permitted Uses
Simply identifying an authorized tool is not sufficient; its use must also be governed. A tool might, for example, be authorized to summarize public documents while being prohibited from analyzing confidential communications, draft settlement offers or sensitive information.
Disclosure of AI Use
A distinction should be drawn between internal use and use affecting the common process.
An AI tool used by a party on its own documents to prepare its position may form part of that party’s strategy. By contrast, disclosure should be mandatory where the tool processes information originating from the other party or from the neutral third party, where its outputs are presented or relied upon in the process, or where the neutral third party uses the tool.
Processing of Personal Information
Where personal information is involved, the parties should confirm the categories of information being exchanged, the purposes for which it will be processed, applicable security measures, restrictions on disclosure, retention periods, and the procedures governing its destruction or return.
Anonymization or De-identification
Where possible, personal information should be anonymized, de-identified or minimized before being processed by a technological tool.
The Barreau du Québec also notes, in its resources concerning generative AI, that such tools raise significant concerns regarding the protection of personal information, fairness and transparency in legal processes.[3]
Data Security and Hosting
The information-security practices of technology providers should be subject to appropriate due diligence, including access controls, encryption, data hosting, data-retention practices, the use of subcontractors and incident management.
A provider’s reputation or the widespread use of its platform is not a substitute for diligent risk assessment.
Traceability of Technological Interventions
The parties should be able to document the use of AI where it generates a summary, analysis or proposal, without compromising the parties’ protected strategies.
Human Validation
No AI-generated output should be treated as a legal or factual conclusion without human review.
The Barreau du Québec has emphasized that generative AI presents risks and limitations requiring its careful, responsible use in a manner consistent with professional obligations. [4]
Incident Management
The parties should establish procedures for responding to any confidentiality or security incident involving a technological tool, including notification, suspension of use, corrective measures, preservation of evidence, notification of affected individuals and coordination with applicable legal obligations.
Such plans should be tested periodically and adjusted accordingly, both internally and with technology providers. Providers’ contractual notification and cooperation obligations should likewise be aligned with the parties’ own incident-response plans.
Effect on Confidentiality and Privilege
The parties should specify that the use of a technological tool does not constitute a waiver of the confidentiality of the process or of settlement privilege, subject to the limitations imposed by law and to any express agreement between them.
A Contractual and Operational Approach
In practice, technology rules of engagement could be incorporated into a PDR protocol, a mediation agreement, an arbitration clause, a confidentiality undertaking or a procedural agreement.
They should be tailored to the nature of the dispute, the sensitivity of the information involved, the parties’ level of technological sophistication and the role of the neutral third party.
For businesses, the issue is also operational. Legal, IT, cybersecurity, compliance and privacy teams should be involved where a dispute concerns sensitive data or makes significant use of technological tools.
PDR can no longer be approached solely as an isolated legal exercise. It is becoming an area of integrated risk management at the intersection of law, technology governance and business strategy.
Governance standards and frameworks can also serve as useful reference points. Although generally voluntary, these frameworks can help organizations structure their internal controls, assess the risks associated with the technologies they use and define their contractual expectations toward technology providers.
Examples include the ISO/IEC 27001 series on information security, ISO/IEC 42001 on artificial intelligence management systems, the NIST Cybersecurity Framework and AI Risk Management Framework and, by way of comparison, the European Union’s Artificial Intelligence Act, several of whose governance principles may inform organizational best practices.
Practical Recommendations
To preserve the integrity of a PDR process, the parties should, at a minimum, where these measures are not already incorporated into their governance practices:
- Conduct due diligence on technology tools being used.
- Confirm compliance applicable with privacy legislation.
- Establish technology rules of engagement from the start.
- Limit the use of personal information to what is strictly necessary.
- Prohibit the use of open or unsecured tools for confidential or sensitive information;
- Document permitted uses and applicable restrictions.
- Provide for an obligation to disclose the use of AI where it may influence the process;
- Maintain human review of AI-generated outputs.
- Provide for contractual requirements concerning confidentiality, security, retention, and destruction measures.
- Incorporate an incident management mechanism.
Conclusion
Technology now plays a significant role in private dispute prevention and resolution processes.
AI digital tools can improve the efficiency of proceedings, facilitate exchanges between the parties and enhance access to certain dispute-resolution mechanisms. Their use, however, brings increased responsibilities in relation to confidentiality, information security and data governance.
In the context of PDR, confidentiality cannot be taken for granted. It depends, among other things, on informed technology choices, an adequate understanding of the risks associated with the tools being used, and the establishment of clear expectations among participants.
The reputation of a platform or the popularity of an artificial intelligence tool is no substitute for the due diligence required in each matter.
Establishing technology rules of engagement at the outset of the process is, in this respect, a prudent practice for reconciling innovation with the protection of communications. By establishing a framework for the use of technology, parties can better preserve the trust, decisional autonomy and confidentiality that lie at the heart of PDR.
When properly integrated, technology can support the objectives pursued through these processes. When poorly controlled, however, it may instead undermine the trust and confidentiality that are essential conditions of their success.
References
[1] Code of Civil Procedure, CQLR c. C-25.01, arts. 1-7.
[2] Act Respecting the Protection of Personal Information in the Private Sector, CQLR c. P‑39.1, s. 10.
[3] Barreau du Québec, Generative Artificial Intelligence – Practical Guide for Responsible Use, 2025.
[4] Barreau du Québec, Generative Artificial Intelligence – Practical Guide for Responsible Use, 2025.