Skip to content

Compliance

Data protection housekeeping for law firms

Firms hold unusually sensitive personal data and unusually little structure around it. Five areas that repay attention.

Justina Morkūnaitė

Editorial Lead

·8 min read

Law firms occupy an awkward position in data protection. They advise on it constantly, and they hold some of the most sensitive personal data anyone handles — health records in personal injury, financial detail in matrimonial work, criminal allegations, immigration status — usually in a file structure that grew organically over twenty years.

The compliance work that follows is not exotic. It is housekeeping, and it concentrates in five places.

1. Retention, decided rather than defaulted

Most firms keep everything. The reasoning is understandable: limitation periods are long, negligence claims arrive late, and nobody wants to be the person who destroyed the file that would have answered the allegation.

But "keep everything forever" is a decision that has never been made explicitly, and it is difficult to defend as a retention policy. The workable approach is to set periods by matter type, driven by the relevant limitation period plus a defined margin, plus any regulatory requirement that applies to the practice area — and then to be able to show the reasoning.

Two refinements make the policy survivable. First, separate the file from the correspondence around it: the closed matter file and eleven years of scheduling emails do not need the same treatment. Second, build in a review point rather than automatic destruction for categories where a live claim might exist. A policy that destroys something needed for a defence will not be followed for long.

2. Access control that reflects how you actually work

Confidentiality obligations are professional as well as statutory, and both point at the same control: people should reach the matters they work on, not every matter in the firm.

The typical position is a shared drive where anyone can open anything, on the basis that everyone is subject to the same duties. That may be professionally tolerable and is still a weak position. It makes an insider incident unconstrained, it makes ethical walls difficult to operate credibly, and it makes any breach assessment start from the worst case, because nothing narrows what could have been reached.

Matter-level permissions, with genuine walls where a conflict requires them and logging of who opened what, changes the posture significantly. The logging matters as much as the restriction: being able to state what a compromised account could reach, and what it actually opened, is the difference between a contained incident and an unbounded one.

3. Know your sub-processors — all of them

Firms often assume that because they are controllers of client data, the processor analysis is somebody else's problem. It is not. Every supplier that touches personal data on the firm's behalf sits in the chain: practice management, document storage, transcription, e-discovery, translation, secure disposal, the barrister's clerk's scheduling system.

Two questions are worth asking of each. Where is the data processed, and what does the contract actually say about international transfers? And what happens at the end of the relationship — deletion on what timescale, from backups too?

The exercise usually turns up two or three arrangements nobody remembered signing. That is the point of doing it.

4. Data subject requests where privilege is in play

Requests to a firm are harder than requests to an ordinary business, because the material is entangled with privilege, with confidentiality owed to other people, and frequently with the requester being an opposing party who has noticed that a subject access request is cheaper than disclosure.

The workable answer is process, not judgement under time pressure. Decide in advance who receives requests and how they are logged. Establish the routine for identifying material that is exempt or that contains third-party data, and record the reasoning for each exclusion at the time. Set an internal deadline comfortably inside the statutory one, because the search itself is the slow part.

The recurring failure is not refusing to disclose something. It is being unable, months later, to explain on what basis a document was withheld.

5. Records that would satisfy a stranger

Accountability requires being able to demonstrate compliance, and demonstration means documents. The record of processing activities, the lawful-basis analysis for each category, the retention schedule, the assessment of higher-risk processing, the training log, the breach register — including incidents assessed as not notifiable, with the reasoning.

The test to apply is whether someone with no knowledge of your firm could read the file and understand what you do with personal data and why. Records written for an audience that already knows the answers tend not to be records at all.

Where to start

If the whole list is daunting, start with the sub-processor inventory. It is finite, it takes a day or two, it feeds directly into the record of processing and the retention policy, and it almost always surfaces something that needs attention this quarter rather than next year.


This article is general commentary on data protection practice in legal services. It is not legal advice and does not address the requirements of any particular jurisdiction or regulator.

GDPRData protectionRiskLaw firms

A note on this article. Lexoria is a fictional company and this post is original editorial content written for a demonstration website. It is general commentary, not legal advice, and no lawyer–client relationship arises from reading it.

More from the blog

Operations

What document automation actually returns

The business case for automating drafting is usually built on the wrong number. Here is the arithmetic that survives contact with a real firm.

·7 min read

Book a demo

See Lexoria against your own matters.

A 40-minute walkthrough with someone who has actually practised. We will use your matter types, not a canned demo file.

No card required EU-hosted DPA available on request