Certix

Legal services

Data protection for
law firms

Law firms process data relating to clients, non-client third parties, and special category data (criminal records, health data) under the protection of professional secrecy, which coexists with GDPR obligations.

Art. 10

GDPR — criminal data

Art. 9

GDPR — health data

5 years

civil limitation period

24 h

personalised proposal

Sector challenges

General obligations for law firms

Data of non-client third parties

A case file may contain data relating to the opposing party, witnesses and expert witnesses who have no contractual relationship with the firm. GDPR applies to this data as well and requires a legal basis for its processing.

Professional secrecy and GDPR

The lawyer's duty of confidentiality prevails against third-party requests, but it does not exempt the firm from documenting the processing of data or from informing its own clients.

Cloud-based legal software

Providers of cloud-based case management, billing and communications systems may act as data processors. The precise legal relationship depends on each provider's terms and conditions and must be verified and documented.

Health data in case files

In family law, personal injury, incapacity or succession matters, health data may appear. This is a special category subject to enhanced protection.

Criminal data in case files

Art. 10 GDPR restricts the processing of data relating to criminal offences. In the context of legal defence, such processing is permissible, but it requires additional security measures.

Retention of closed files

Once a matter is concluded, data cannot be retained indefinitely. The firm must define retention periods and a procedure for deletion or blocking.

External DPO

Is a Data Protection Officer (DPO) mandatory for a law firm?

As a general rule, law firms are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each firm's processing activities. Each case requires individual analysis.

Irrespective of legal obligation, many corporate clients and data processing agreements require the firm to have an identified data protection contact. Certix can assume this role as a standalone service.

Most common legal bases in a law firm

Art. 6.1.b GDPR

Performance of the legal services contract with the client.

Art. 6.1.f GDPR

Legitimate interests — processing of third-party data in the context of litigation.

Art. 6.1.c GDPR

Legal obligation — retention of tax documentation.

Art. 9.2.f GDPR

Establishment, exercise or defence of legal claims — health and criminal data in case files.

Art. 10 GDPR

Criminal data — solely within the scope of legal defence activities.

The service

What is included in the data protection service for your firm

Record of Processing Activities

RoPA (Record of Processing Activities) tailored to the firm: clients, case files, employees, third parties in litigation and external processors.

Information clauses

First- and second-layer texts for the legal services contract and web forms.

Privacy policy and legal notice

Web documentation for the firm's website, including the contact form and private client area.

Data Processing Agreements (DPA)

DPAs for cloud-based legal software, messaging services, electronic signature platforms and other suppliers.

Data breach protocol

Procedure for detecting and notifying incidents within 72 hours.

Data subject rights management

Procedure for handling requests from clients and third parties, taking into account the nuances arising from professional secrecy.

Document management platform

Access to a private platform with all documents and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO (where applicable)

As a general rule, law firms are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each firm's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your firm?

Tell us the size of the firm and your practice areas. Proposal in under 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in law firms

Is professional secrecy in law firms compatible with GDPR?

Yes. Professional secrecy and GDPR are compatible frameworks. The lawyer's duty of confidentiality prevails over access or information requests from third parties, but it does not exempt the firm from meeting the documentary obligations of GDPR: records of processing activities, data processing agreements, and information clauses for its own clients.

How long must a law firm retain client files?

LOPDGDD does not set a generic retention period for law firms. The retention period must be determined by reference to potential liabilities arising from the professional relationship (civil limitation period: up to 5 years) and tax regulations (4 years). Once the relevant periods have elapsed, data must be blocked or deleted.

Can a law firm process data relating to the opposing party in litigation?

The processing of data about non-client third parties in the context of legal proceedings may rely on the legitimate interests of the controller (art. 6.1.f GDPR) or, for special categories, on the establishment, exercise or defence of legal claims (art. 9.2.f GDPR). Collection must be limited to what is strictly necessary and, as a general rule, the data subject must be informed. This information is indicative; procedural case law is complex and each situation requires individual analysis.

Is cloud-based legal software a data processor?

As a general rule, providers of cloud-based case management or legal billing software may act as data processors when they process data on the firm's instructions. The exact legal relationship depends on each provider's terms and conditions; it is advisable to verify this and, where confirmed, formalise the corresponding agreement and check the location of the data.

Can all lawyers in a firm access every client file?

Not necessarily. Access to files must be restricted to staff with a direct role in the matter. The firm must define access profiles and maintain a log of who accesses which data. In firms with multiple partners and differentiated practice areas, cross-access to files from other areas must be justified and documented.

Do files containing criminal or health data require additional measures?

Yes. Data relating to criminal offences (art. 10 GDPR) and health data (art. 9 GDPR) are categories with enhanced protection. In the context of a law firm, the processing of such data in case files is covered by the legal defence of the client, but it requires additional security measures: encryption, restricted access, and access logs.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Legal services

GDPR compliance
for your firm.

An expert analyses your practice and proposes the most appropriate solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.