GDPR and Data Protection for UK Law Firms
A practical guide to GDPR and data protection for UK law firms; what the law requires and how to comply.
A practical guide to GDPR and data protection for UK law firms; what the law requires, where firms commonly fall short, and how to build a compliance process that doesn't slow down the practice.
GDPR compliance is one of those topics that generates anxiety disproportionate to its actual difficulty. The principles are clear. The requirements are documented. The challenge for law firms is not understanding what to do; it's building the processes that ensure it actually happens across every matter, every client interaction, and every document.
This guide covers the UK GDPR (as retained and amended post-Brexit) and the Data Protection Act 2018, with practical guidance for law firms.
The legal framework
UK law firms are subject to:
- UK GDPR; the retained version of the EU General Data Protection Regulation, applicable in the UK post-Brexit
- Data Protection Act 2018; the UK's implementing legislation, which supplements the UK GDPR
- SRA Code of Conduct; requires firms to handle client data in compliance with the law
The UK GDPR applies to any firm that processes personal data; which means every UK law firm, because every firm holds client names, addresses, identity documents, financial information, and case details.
Key principles
The UK GDPR is built on seven principles:
- Lawfulness, fairness, and transparency; you must have a lawful basis for processing personal data, process it fairly, and be transparent about what you're doing
- Purpose limitation; you must only use data for the purposes for which it was collected
- Data minimisation; you must only collect the data you actually need
- Accuracy; data must be accurate and kept up to date
- Storage limitation; you must not keep data longer than necessary
- Integrity and confidentiality; data must be held securely
- Accountability; you must be able to demonstrate compliance
For law firms, the most challenging principles are usually storage limitation (how long to keep client files) and integrity/confidentiality (how to store and transmit data securely).
Lawful basis for processing
Law firms typically rely on one of several lawful bases:
- Contract; processing is necessary to provide the legal services the client has instructed
- Legal obligation; processing is necessary to comply with a legal obligation (e.g., AML record-keeping, SRA requirements)
- Legitimate interests; processing is necessary for the firm's legitimate business interests (e.g., marketing, business development); provided it doesn't override the client's rights
For most legal work, the lawful basis is contract or legal obligation; the firm is processing data to provide the services the client has instructed, or to comply with regulatory requirements.
Special category data
Law firms often process "special category data"; data that is more sensitive and has additional protections. This includes:
- Information about a client's health (e.g., personal injury claims, medical negligence)
- Information about a client's criminal record (e.g., criminal defence work)
- Information about a client's sexual orientation or sex life (e.g., family law)
- Racial or ethnic origin (e.g., immigration work)
To process special category data, the firm must have both a lawful basis AND an additional condition under Article 9 of the UK GDPR. For law firms, this is typically:
- Legal claims; processing is necessary for the establishment, exercise, or defence of legal claims
- Substantial public interest; processing is necessary for reasons of substantial public interest
The firm must document which condition it is relying on for each type of matter.
Client privacy notice
Every firm must provide clients with a privacy notice; a document that explains:
- Who the firm is and how to contact them
- What personal data the firm collects
- Why the firm collects it (the lawful basis)
- Who the firm shares it with (e.g., barristers, expert witnesses, Checkboard for KYC)
- How long the firm keeps it
- What rights the client has (access, rectification, erasure, restriction, portability, objection)
- How to complain to the ICO
The privacy notice should be provided at or before the point of client onboarding. Many firms include it in the client care letter pack or provide it as a standalone document.
Data security
The "integrity and confidentiality" principle requires firms to hold data securely. For law firms, this means:
Technical measures
- Encryption; all client data should be encrypted at rest (on the firm's servers or in the cloud) and in transit (when emailed or transferred)
- Access controls; staff should only have access to data they need for their work. SharePoint provides per-matter access control, which is essential for conflict management
- Multi-factor authentication; all systems holding client data should require 2FA
- Secure email; large or sensitive documents should be sent through a secure channel, not as plain email attachments
- Mobile device management; if staff access client data on phones or laptops, those devices should be managed and encryptable remotely
Organisational measures
- Staff training; all staff should receive data protection training at induction and annually
- Data protection policies; the firm must have documented policies on data handling, breach response, and subject access requests
- Data protection officer; firms that carry out large-scale processing of special category data must appoint a DPO. Most law firms are not required to appoint one, but many choose to designate a data protection lead
- Breach response plan; the firm must have a plan for responding to personal data breaches, including notification to the ICO within 72 hours for notifiable breaches
Data retention
The "storage limitation" principle requires firms not to keep personal data longer than necessary. For law firms, this means having a file retention policy that specifies:
- How long each type of file is kept (e.g., conveyancing files 6 years, litigation files 6-15 years depending on the limitation period)
- What happens at the end of the retention period (destruction, return to client, or indefinite retention for specific reasons)
- How the policy is enforced (who decides when a file is destroyed, and how is this recorded)
The SRA does not specify a minimum retention period; but the Limitation Act 1980 implies that files should be kept at least as long as the limitation period for any potential claim. See our limitation dates guide for the relevant periods.
Subject access requests
Clients (and others) have the right to request access to their personal data. The firm must:
- Respond within 1 month (can be extended by 2 months for complex requests)
- Provide a copy of the personal data held
- Explain the purposes for which it is being processed
- Provide it free of charge (unless the request is manifestly unfounded or excessive)
Law firms should have a process for handling subject access requests; including identifying the requester, searching for the data, and reviewing it for legal professional privilege before disclosure.
Data sharing
Law firms share client data with:
- Barristers and expert witnesses; sharing case documents for the purpose of the matter
- Third-party providers; Checkboard for KYC, TM Group for searches, court filing systems
- Opposing solicitors; sharing documents in litigation (subject to privilege)
- Accountants and auditors; sharing financial information for billing and compliance
Each sharing arrangement should be documented, and the firm should ensure that third parties handle the data in compliance with the UK GDPR. For regular third parties, a data sharing agreement is good practice.
Common compliance gaps
- No privacy notice; or a privacy notice that hasn't been updated since 2018
- No data retention policy; files kept indefinitely "just in case"
- No breach response plan; the firm doesn't know what to do if a breach happens
- No access controls; every fee earner can see every matter
- No subject access request process; the firm has never received one and has no process for when it does
- Inadequate staff training; training was done once and never refreshed
Where OrdoLux fits
OrdoLux is built on Microsoft 365 and SharePoint, which means client data is stored in the firm's own Microsoft tenancy; with the security, encryption, and access controls that Microsoft provides. Each matter has its own SharePoint folder with per-matter access control, and the audit trail records who accessed what and when.
OrdoLux also includes Checkboard for KYC and AML (with results filed to the matter, not stored in a separate system), mandatory 2FA across the platform, and SRA-compliant accounting that maintains the audit trail required for regulatory reporting.
See all features or book a demo.
Limited offer
6 months free — founding firm access
We're inviting a small number of UK law firms to join OrdoLux as founding customers. Full platform access, completely free for 6 months. No credit card. No catch. When we have enough firms on board, this offer closes.
Apply for founding access →Try OrdoLux — legal case management software built for UK solicitors
Matter management, time capture, billing and AI tools in one platform. Rolling monthly, no lock-in, £50 + VAT per user.
Book a free demo Learn more