Legal services
Data protection for
law firms
Law firms process data relating to clients, non-client third parties, and special category data (criminal records, health data) under the protection of professional secrecy, which coexists with GDPR obligations.
Art. 10
GDPR — criminal data
Art. 9
GDPR — health data
5 years
civil limitation period
24 h
personalised proposal
Sector challenges
General obligations for law firms
Data of non-client third parties
A case file may contain data relating to the opposing party, witnesses and expert witnesses who have no contractual relationship with the firm. GDPR applies to this data as well and requires a legal basis for its processing.
Professional secrecy and GDPR
The lawyer's duty of confidentiality prevails against third-party requests, but it does not exempt the firm from documenting the processing of data or from informing its own clients.
Cloud-based legal software
Providers of cloud-based case management, billing and communications systems may act as data processors. The precise legal relationship depends on each provider's terms and conditions and must be verified and documented.
Health data in case files
In family law, personal injury, incapacity or succession matters, health data may appear. This is a special category subject to enhanced protection.
Criminal data in case files
Art. 10 GDPR restricts the processing of data relating to criminal offences. In the context of legal defence, such processing is permissible, but it requires additional security measures.
Retention of closed files
Once a matter is concluded, data cannot be retained indefinitely. The firm must define retention periods and a procedure for deletion or blocking.
External DPO
Is a Data Protection Officer (DPO) mandatory for a law firm?
As a general rule, law firms are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each firm's processing activities. Each case requires individual analysis.
Irrespective of legal obligation, many corporate clients and data processing agreements require the firm to have an identified data protection contact. Certix can assume this role as a standalone service.
Most common legal bases in a law firm
Art. 6.1.b GDPR
Performance of the legal services contract with the client.
Art. 6.1.f GDPR
Legitimate interests — processing of third-party data in the context of litigation.
Art. 6.1.c GDPR
Legal obligation — retention of tax documentation.
Art. 9.2.f GDPR
Establishment, exercise or defence of legal claims — health and criminal data in case files.
Art. 10 GDPR
Criminal data — solely within the scope of legal defence activities.
The service
What is included in the data protection service for your firm
Record of Processing Activities
RoPA (Record of Processing Activities) tailored to the firm: clients, case files, employees, third parties in litigation and external processors.
Information clauses
First- and second-layer texts for the legal services contract and web forms.
Privacy policy and legal notice
Web documentation for the firm's website, including the contact form and private client area.
Data Processing Agreements (DPA)
DPAs for cloud-based legal software, messaging services, electronic signature platforms and other suppliers.
Data breach protocol
Procedure for detecting and notifying incidents within 72 hours.
Data subject rights management
Procedure for handling requests from clients and third parties, taking into account the nuances arising from professional secrecy.
Document management platform
Access to a private platform with all documents and electronic signature.
Ongoing support
Unlimited queries. Updates in response to regulatory changes.
External DPO (where applicable)
As a general rule, law firms are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each firm's processing activities. Each case requires individual analysis. Separate contract.
Do you need a proposal for your firm?
Tell us the size of the firm and your practice areas. Proposal in under 24 hours.
FAQ
Frequently asked questions about data protection in law firms
Is professional secrecy in law firms compatible with GDPR?
Yes. Professional secrecy and GDPR are compatible frameworks. The lawyer's duty of confidentiality prevails over access or information requests from third parties, but it does not exempt the firm from meeting the documentary obligations of GDPR: records of processing activities, data processing agreements, and information clauses for its own clients.
How long must a law firm retain client files?
LOPDGDD does not set a generic retention period for law firms. The retention period must be determined by reference to potential liabilities arising from the professional relationship (civil limitation period: up to 5 years) and tax regulations (4 years). Once the relevant periods have elapsed, data must be blocked or deleted.
Can a law firm process data relating to the opposing party in litigation?
The processing of data about non-client third parties in the context of legal proceedings may rely on the legitimate interests of the controller (art. 6.1.f GDPR) or, for special categories, on the establishment, exercise or defence of legal claims (art. 9.2.f GDPR). Collection must be limited to what is strictly necessary and, as a general rule, the data subject must be informed. This information is indicative; procedural case law is complex and each situation requires individual analysis.
Is cloud-based legal software a data processor?
As a general rule, providers of cloud-based case management or legal billing software may act as data processors when they process data on the firm's instructions. The exact legal relationship depends on each provider's terms and conditions; it is advisable to verify this and, where confirmed, formalise the corresponding agreement and check the location of the data.
Can all lawyers in a firm access every client file?
Not necessarily. Access to files must be restricted to staff with a direct role in the matter. The firm must define access profiles and maintain a log of who accesses which data. In firms with multiple partners and differentiated practice areas, cross-access to files from other areas must be justified and documented.
Do files containing criminal or health data require additional measures?
Yes. Data relating to criminal offences (art. 10 GDPR) and health data (art. 9 GDPR) are categories with enhanced protection. In the context of a law firm, the processing of such data in case files is covered by the legal defence of the client, but it requires additional security measures: encryption, restricted access, and access logs.
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Legal services
GDPR compliance
for your firm.
An expert analyses your practice and proposes the most appropriate solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.