UK GDPR and Data Protection for Legal Practice: A Practical Guide

A practical guide for lawyers and support staff on UK GDPR and DPA 2018 in legal practice, covering privilege, special category data, retention and breach reporting.

Learnsignal Education Team
8 min read
Updated

Every client file a law firm opens is also a data protection file. Names, addresses, financial records, health details, criminal history, family circumstances — client matters are often built on exactly the kind of personal data that UK GDPR and the Data Protection Act 2018 (DPA 2018) were designed to protect. For lawyers and support staff, getting this right is not just an IT or compliance department problem; it sits alongside professional conduct duties and client care obligations. This guide sets out the practical points that matter most in day-to-day legal practice across England & Wales, and flags where the law is currently changing.

UK GDPR and the DPA 2018: the basics for a law firm

UK GDPR is the retained, UK-specific version of the EU General Data Protection Regulation, and it works alongside the DPA 2018, which supplements it with UK-specific rules, exemptions and the framework the Information Commissioner's Office (ICO) — the UK's data protection regulator — uses to enforce compliance. Together they govern how a firm collects, stores, uses, shares and eventually deletes personal data about clients, opponents, witnesses and staff.

Three concepts matter most in a legal context:

  • Lawful basis — every use of personal data needs a lawful basis under Article 6 UK GDPR. For most client work this is "contract" (acting for the client) or "legitimate interests" (for example, conflict checks or file audits), not consent.
  • Data controller vs processor — a firm is normally the controller for client and matter data, meaning it carries the primary legal responsibility for how that data is handled, even where third parties (cloud storage providers, barristers, expert witnesses) also touch it.
  • Accountability — firms must be able to demonstrate compliance, not just achieve it. That means documented policies, training records and a clear audit trail, particularly around subject access requests and breaches.

One of the trickiest intersections in legal practice is between legal professional privilege (LPP) — the client's right to keep communications with their lawyer confidential — and an individual's right of access under UK GDPR to see personal data held about them.

The DPA 2018 provides a specific exemption: personal data that is subject to a claim of legal professional privilege (or, in Scotland, confidentiality of communications) is exempt from the right of access and several other data subject rights, to the extent that disclosure would be prevented by privilege. In practice this means:

  • A subject access request (SAR) from an opposing party, a former client, or a third party does not automatically require disclosure of privileged advice or litigation correspondence.
  • The exemption applies to the specific privileged material, not to a client's entire file — non-privileged personal data within the same file (contact details, administrative correspondence) generally still falls to be assessed against the request.
  • Firms should not assume privilege applies to everything simply because a matter is contentious; each document or category of data needs a considered assessment, and legally privileged material should be clearly identified and ring-fenced when responding to a SAR.

Getting SAR handling wrong — either over-disclosing privileged material or blanket-refusing a legitimate request — creates real risk, both regulatory and professional. Firms that regularly handle SARs should have a documented process for triaging requests, applying exemptions correctly, and recording the reasoning, since the ICO can and does ask organisations to justify a refusal.

Special category and criminal offence data in client files

Legal files routinely contain what UK GDPR treats as higher-risk categories of data:

  • Special category data under Article 9 — health information, for example in personal injury, clinical negligence, employment or family matters; also data revealing racial or ethnic origin, religious beliefs, trade union membership or sexual orientation, which can appear in discrimination or family law files.
  • Criminal offence data — details of criminal allegations, proceedings or convictions, common in criminal defence, family (safeguarding), and civil litigation touching on criminal conduct.

Both categories require an additional lawful condition on top of the normal Article 6 basis before they can be processed. For law firms, the most relevant condition is usually the "legal claims" condition — processing necessary for the establishment, exercise or defence of legal claims, or in connection with legal proceedings. Firms should be able to point to which condition applies for each matter type, and, for criminal offence data specifically, have regard to the additional DPA 2018 Schedule 1 conditions and any associated policy documentation the ICO expects controllers to maintain. This is an area worth building into onboarding and file-opening procedures, not something to work out retrospectively if a complaint arrives.

Data retention: how long should a file be kept?

There is no single statutory retention period for client files, which is precisely why firms need their own documented retention policy rather than an informal "keep everything" habit. Retention decisions should weigh:

  • Relevant limitation periods (generally six years for most contract and tort claims under the Limitation Act 1980, longer for some categories such as claims by minors or under seal).
  • Professional indemnity insurance requirements, which often push firms towards longer retention for higher-risk matter types.
  • Regulatory and anti-money laundering record-keeping obligations, which run alongside — and sometimes independently of — data protection considerations.
  • The UK GDPR storage limitation principle: data should not be kept "just in case" indefinitely once the purpose for holding it has passed, so a retention schedule needs a clear, defensible end point and a mechanism for secure destruction.

Good practice is a written retention schedule by matter type, applied consistently, with periodic reviews of archived files rather than a one-off policy that is never revisited.

Breach reporting: the basics

A personal data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data — this covers everything from an email sent to the wrong recipient to a stolen laptop or a ransomware attack. Under UK GDPR, where a breach is likely to result in a risk to individuals' rights and freedoms, the firm must notify the ICO without undue delay, and in any event within 72 hours of becoming aware of it where feasible. Where the risk is high, affected individuals must also be told directly.

For a law firm, common breach scenarios include misdirected correspondence containing client or third-party personal data, unauthorised access to case management systems, and lost devices. Because deadlines run from when the firm becomes aware of the breach — not when it happened — having a simple, well-understood internal escalation process (who to tell, how quickly, and who decides on ICO notification) matters more than a lengthy policy document nobody has read. The exact thresholds and notification mechanics are detailed in current ICO guidance, which is worth checking directly given it is periodically updated.

The Data (Use and Access) Act 2025: what's changing

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent in 2025 and reforms parts of the UK's data protection framework, including elements of the DPA 2018 and the wider UK GDPR regime. Its provisions are being brought into force in phases rather than all at once, with the ICO publishing guidance as each tranche takes effect — reported changes include adjustments to complaints handling, cookie consent rules, and aspects of automated decision-making and international transfers. Because commencement is phased and guidance is still being issued, firms should treat any specific claim about "what has changed" with caution and check the ICO's dedicated DUAA pages for the current, matter-specific position before relying on it in client advice or internal policy updates.

Practical takeaways for firms

Embedding good data protection practice in a legal team is mostly about consistency: know which lawful basis applies to each type of processing, flag special category and criminal offence data at file opening, apply the LPP exemption deliberately rather than reflexively, follow a written retention schedule, and rehearse the breach escalation process before it is needed. Building this into induction and ongoing training — alongside related risk areas such as payment diversion fraud risk in law firms and professional ethics and client care obligations — helps make data protection part of normal file management rather than a separate compliance exercise bolted on afterwards.

FAQ

Does legal professional privilege override a subject access request entirely?

No. The DPA 2018 exemption applies to the specific data that is genuinely privileged, not to an entire file. Non-privileged personal data within the same matter — such as basic contact or administrative details — generally still needs to be assessed against the request.

Who is the data controller when a firm instructs counsel or an expert witness?

In most cases the firm remains the controller for the client relationship and file, while counsel or an expert acts as a separate controller for their own professional judgment and records, or in some cases a processor depending on the arrangement. Firms should be clear about this in engagement terms.

Is the Data (Use and Access) Act 2025 fully in force now?

It received Royal Assent in 2025 but its provisions are commencing in stages, with the ICO issuing guidance as each part takes effect. Always check the ICO's current DUAA guidance rather than assuming a reform is already live.

How long should we keep a closed client file?

There is no single fixed period in law. Firms should set their own retention schedule based on limitation periods, insurance requirements and regulatory obligations, and apply it consistently rather than retaining files indefinitely.

Data protection competence is now a core part of legal professionalism, not a side issue for the IT team — and it is a subject regularly covered in Learnsignal's CPD courses for legal professionals.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Legal CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans