GDPR Compliance for UK Law Firms: A Practical Guide
Practical UK GDPR compliance guide for solicitors — lawful basis, data subject rights, privacy notices, breach reporting, and ICO expectations for law firms in 2025.
Obiter Editorial Team
Published 15 March 2025
UK GDPR compliance remains one of the most misunderstood areas of law firm management, and not just among smaller practices. Many firms ticked a box in 2018 when the GDPR came into force, updated their privacy notice, appointed a data protection lead, and have not revisited the subject substantively since. That approach is no longer adequate. The Information Commissioner’s Office has moved from raising awareness to active enforcement, and the nature of data processing in a modern law firm has changed materially since 2018 — particularly with the introduction of AI tools, cloud storage, and electronic client communication platforms.
This guide covers the practical compliance requirements that UK law firms must satisfy in 2025: from the basic principles through the specific obligations most likely to be the subject of regulatory scrutiny, to the practical steps for building a compliance framework that is genuinely sustainable rather than just documented.
The Legal Framework
UK GDPR and the Data Protection Act 2018
The UK left the EU’s data protection framework at the end of the Brexit transition period. UK GDPR — the UK’s retained version of the EU GDPR, incorporated into domestic law via the Data Protection Act 2018 — is now the operative framework. The UK has additionally enacted the Data Protection and Digital Information Act (now in force following Royal Assent in 2025), which makes targeted adjustments to the UK GDPR framework while preserving its overall structure and principles.
For practical purposes, UK GDPR closely mirrors EU GDPR. The seven data protection principles — lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability — apply identically. The rights of data subjects, the obligations on data controllers, and the accountability requirements are substantively the same.
The ICO is the UK supervisory authority. The maximum fine is £17.5 million or 4% of global annual turnover, whichever is higher — the same penalty framework as EU GDPR. In practice, ICO fines against law firms have been in the range of £10,000 to £100,000+ for smaller incidents, with larger penalties reserved for more serious failures. The reputational and operational cost of an ICO investigation is often greater than the financial penalty itself.
The intersection with SRA regulation
The SRA’s duty of confidentiality — enshrined in paragraph 6.3 of the Code of Conduct for Solicitors — is distinct from but complementary to UK GDPR. A breach of UK GDPR in a law firm is almost always also a potential breach of the SRA’s confidentiality rules. An ICO investigation into a law firm data breach is therefore likely to be accompanied by, or trigger, SRA scrutiny.
Firms should not treat SRA compliance and UK GDPR compliance as separate programmes. They share the same underlying objective — protecting client information — and should be managed through an integrated framework.
Lawful Basis for Processing
Every processing activity in a law firm must be based on one of the six lawful bases under UK GDPR Article 6. Getting this right is fundamental, because the lawful basis determines what data subject rights apply and what justification the firm can offer if its processing is challenged.
The bases most relevant to law firms
Contract (Article 6(1)(b)) — processing that is necessary for the performance of a contract with the data subject, or to take steps at their request prior to entering a contract. For law firms, this covers processing a client’s personal data to perform legal services under the retainer.
Legal obligation (Article 6(1)(c)) — processing required by law. Anti-money laundering (AML) obligations under the Money Laundering Regulations 2017 require firms to collect, verify, and retain client due diligence data. Firms do not need client consent to process data for AML purposes — it is a legal requirement.
Legitimate interests (Article 6(1)(f)) — processing that serves a genuine interest of the controller or a third party, provided that interest is not overridden by the data subject’s rights. This is the appropriate basis for many operational activities that are not directly required by law or contract: business development, internal risk management, conflict checking, and maintaining records of former clients for reference purposes. A documented legitimate interests assessment (LIA) should be completed for reliance on this basis.
Consent (Article 6(1)(a)) — consent is often the default choice for organisations unsure of their lawful basis, but it is frequently the wrong choice for law firms. Consent must be freely given, specific, informed, and unambiguous. It must be as easy to withdraw as to give. For processing that is genuinely necessary to deliver legal services, contract or legal obligation is the correct basis — seeking consent suggests the firm could perform the services without the processing, which is misleading.
Special category data
Law firms frequently process special category data under Article 9 — health information in personal injury or clinical negligence cases, information about criminal convictions in criminal defence work, political opinions and religious beliefs in immigration and asylum matters. Special category data requires both a lawful basis under Article 6 and a condition under Article 9.
For legal services, the most commonly applicable Article 9 condition is “establishment, exercise or defence of legal claims” (Article 9(2)(f)), which covers the processing necessary to conduct litigation or provide legal advice in connection with actual or potential proceedings. Document the basis for each category of special category data processing in your data inventory.
Building Your Compliance Framework
The Records of Processing Activities (ROPA)
Article 30 of UK GDPR requires data controllers to maintain a record of processing activities. The ROPA is the foundation of any compliance framework — it documents what personal data you process, for what purpose, on what lawful basis, for how long, and who has access to it.
For a law firm, the ROPA will typically include processing activities in categories including: matter management and client work, AML and CDD, HR and staff management, marketing and business development, financial accounting, and supplier management. Each activity should be documented with the relevant data categories, retention periods, and third-party recipients (including technology suppliers as data processors).
A ROPA that has not been updated since 2018 will not reflect the firm’s current processing — it will miss cloud systems introduced since then, AI tools, electronic verification platforms, and remote working arrangements. Treat the ROPA as a live document, reviewed at least annually.
Privacy notices
Your privacy notice must accurately describe what you do with personal data. A notice that describes manual processing when the firm has moved to cloud infrastructure, or that does not mention AI-assisted drafting tools that process client emails, is inaccurate and potentially misleading.
Review your privacy notice against your ROPA annually. Ensure it covers: identity of the controller and DPO (if one is appointed); the purposes and legal bases for all processing; data subject rights and how to exercise them; retention periods; third-party recipients and whether data is transferred outside the UK; and contact information for the ICO.
Data subject rights
UK GDPR creates six enforceable rights for individuals whose data you process. The most commonly exercised in the legal context are:
Right of access (SAR) — the right to receive a copy of all personal data held about a data subject. Law firms receive subject access requests from clients, former clients, and occasionally opposing parties or former employees. You must respond within one month of receipt. Searches must cover email, the practice management system, physical files, and any other system that might hold the person’s data.
Right to erasure — the right to have personal data deleted. This right is not absolute — AML record-keeping obligations under the Money Laundering Regulations 2017 override it for the required retention period. Similarly, data retained pursuant to a legal obligation (court orders, limitation periods) cannot be erased on request. Document your basis for declining erasure requests carefully.
Right to rectification — the right to have inaccurate data corrected. This is straightforwardly appropriate for errors in contact details or biographical information.
Data breach response
A personal data breach must be reported to the ICO within 72 hours if it is likely to result in a risk to individuals’ rights and freedoms. This threshold — “likely to result in a risk” — is lower than many firms realise. A misdirected email containing a client’s personal data, an unsecured laptop containing matter files, or a ransomware attack encrypting a client database all meet this threshold.
Maintain a breach register documenting all incidents, assessed against the notification threshold. Even breaches that fall below the notification threshold must be recorded. A firm that has not reported a notifiable breach because it was not aware of the notification obligation faces a more serious regulatory position than one that reports promptly.
Supplier due diligence
Every technology supplier that processes personal data on the firm’s behalf — practice management providers, AML verification services, cloud storage, email platforms, AI drafting tools — is a data processor under UK GDPR. You must have a data processing agreement (DPA) in place with each, and you must document them in your ROPA.
Review existing supplier DPAs to confirm they include the mandatory clauses under Article 28: processor must act only on controller instructions; processor must maintain security; processor must assist with data subject rights requests; processor must notify of breaches; processor must return or delete data on contract end; processor must allow audits.
Obiter is designed with UK GDPR compliance built in — it acts as a data processor on the firm’s behalf, processes client data within the UK, maintains complete audit logs of all AI activity, and provides a data processing agreement that satisfies Article 28 requirements. For firms concerned about the data protection implications of AI tools handling client email and matter data, Obiter provides the documentation and transparency needed to satisfy both ICO expectations and SRA governance standards.
Topics:
Ready to reclaim 12+ hours a week?
See how Obiter handles your legal admin so you can focus on advising clients.