The General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) had direct effect in the UK between 25 May 2018 and 1 January 2021, but was extended and modified in its application to the UK by the Data Protection Act 2018. The Data Protection framework in the United Kingdom has since the country’s exit from the European Union been governed by the retained EU regulations (“UK GDPR”), supplemented by the Data Protection Act 2018, and (when enacted) the Data (Use and Access) Act 2025.
Adherence
The head of chambers, members, management, and employees of Serle Court are committed to compliance with all relevant UK and EU laws in respect of Personal Data, and the protection of the rights and freedoms of individuals whose information we collect and process in accordance with the GDPR. Serle Court and its representatives will naturally cooperate with the data protection regulator, the Information Commissioner’s Office (“ICO”) in the performance of its tasks as required.
Scope of regulations and policy
The GDPR and this policy apply to all of Chambers‘ Personal Data controlling and processing functions, including those performed on members’, clients’, employees’, applicants’ and suppliers’ Personal Data, and any other Personal Data we process from any source, whether digital or paper-based. Personal Data is any information relating to an identified or identifiable natural person.
This policy applies to all employees, permanent and temporary, including any agency and contract staff, and consultants to whom this policy will be provided. Any breach of the GDPR by employees to whom our disciplinary policy applies will be dealt with under that policy, and may also be a criminal offence, in which case the matter will be reported as soon as possible to the appropriate authorities.
It is also applicable to members when they are processing Chambers’ data on and behalf of Serle Court by virtue of their membership of Chambers. Chambers’ constitution contains a Data Processing Agreement between each member and chambers and provisions concerning the obligation on members to comply with Chambers’ policies, including this one.
This policy also applies to pupils, other trainees or secondees, and mini-pupils who may process member-controlled Personal Data. There is in place a living master Data Processing and Sharing Agreement between all members who supervise, and pupils and trainees. The contracts that regulate mini-pupils’ time in chambers also ensure GDPR compliance.
Partner organisations and third parties working with or for us which have or may have access to personal data we collectively or individually control or process, will be expected to adhere to all obligations imposed by Data Protection legislation. No third party may access Personal Data held by us without having first entered into an appropriate formal Data Processing Agreement which imposes on the third party obligations no less onerous than those to which we are committed, and which gives us the right to audit compliance with the Agreement.
Responsibility
Under the GDPR, organisations are required to appoint a Data Protection Officer where large-scale Processing of Special Category Data or Monitoring of Data Subjects takes place. As a set of chambers practising primarily in the area of commercial chancery law, Serle Court does not consider this precondition to be met.
In place of a DPO, Serle Court has nominated Kathryn Purkis, the Chambers Director, as Data Protection Lead (“DPL”). The DPL will act as the central point of contact on all matters relating to data protection in chambers and will have overall responsibility for day-to-day Data Protection activities. The DPL can be contacted at kpurkis@serlecourt.co.uk or on 0207 4007240.
Having a DPL in chambers does not obviate the general, personal responsibility that all members of chambers and staff have under the law to comply with the GDPR as Data Controllers or Data Processors.
Where this policy uses words and concepts defined in or by the GDPR, those definitions apply also to this policy. Such defined terms may be indicated by capitalisation.
This policy is predicated on the settled position that:
All processing of Personal Data will be conducted in accordance with the Data Protection Principles as set out in the GDPR and outlined below. Our policies and procedures are designed to ensure compliance with these Principles.
Personal data must be processed lawfully, fairly, and transparently.
Lawfully – we must and will identify a Lawful Basis before we can process Personal Data. We demonstrate our accountability under the GDPR by recording the Lawful Bases we rely upon in our Data Processed Register (each member has their own such Register and Chambers has its own separate one). The Lawful Bases are:
Fairly – in order for processing to be fair, we have to make certain information available to Data Subjects. This applies whether the Personal Data was obtained directly from Data Subjects or from other sources.
Transparently – the GDPR includes rules on giving privacy information in Privacy Notices to Data Subjects when collecting their Personal Data. These rules are detailed and specific, placing an emphasis on making Privacy Notices understandable and accessible. Such information must and will be communicated by the Data Controller to the Data Subject in an intelligible form using clear and plain language. Accordingly, Chambers has its own Privacy Notice (with Data Processed Register and Data Retention and Disposal Policy annexed) which is to be read in conjunction with this Policy, and each member of chambers has a Privacy Notice which sets out their individual assessment of their Lawful Basis for Processing.
Personal data can only be collected for specific, explicit, and legitimate purposes.
The data we obtain for these specified, explicit and legitimate purposes must and will not be used for a purpose that is incompatible with those set out in Chambers’ Data Processed Register, as the Data Subjects may reasonably expect. Nor will it be further processed in a manner incompatible with those purposes.
Personal data must be adequate, relevant, and limited to what is necessary for processing.
We cannot and do not collect information that is not strictly necessary for the purpose for which it is obtained.
Personal data must be accurate and, where necessary, kept up to date.
Every reasonable step must and will be taken to ensure that any Personal Data that is inaccurate is erased or corrected without delay. Data that is stored by us must and will be reviewed and updated as necessary: no data should be kept unless it is reasonable to assume that it is accurate.
Personal data must be kept in a form such that the Data Subject can be identified only as long as is necessary for processing.
We must and will only hold Personal Data for as long as we need it, in line with Chambers’ Data Retention and Disposal Policy.
Personal data must be processed in a manner that ensures appropriate security of that personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
The GDPR includes provisions that promote Accountability and Governance. These complement the GDPR’s Transparency requirements discussed below. Accountability requires us to demonstrate that we comply with the GDPR Principles.
As regards Principle 6 in particular we implement technical and organisational measures which are both digital and physical. More detail on Chambers’ digital technical and organisational measures (of which members also avail or may avail) may be found in our Information Security Policy Suite and our AI Governance Policy and Procedures. We have also adopted operational techniques such as Data Protection Impact Assessments, ensuring Data Protection “By Design”, clear breach notification procedures and comprehensive incident response plans.
The Good Governance measures with which we comply include regular reviewing of our GDPR suite of policies and regular training to ensure that members, pupils and staff are aware of their regulatory obligations and how best to discharge them, and regular reviewing and tightening of digital security.
The GDPR provides the following rights for individuals in relation to their Personal Data, which may be briefly explained as follows:
Data Subjects may make Subject Access or other Subject Rights Requests relating to their Personal Data. Where the Data Subject has been involved in a case with a member of Chambers, it may be that such Personal Data is being processed and controlled both by Chambers and the member and co-ordination of response will be necessary.
Chambers’ Subject Rights Request Policy describes how Chambers will ensure that our response to any requests made of Chambers complies with the requirements of the GDPR. Members may wish to utilise the approach in this Policy for their own purposes.
Under this policy, the DPL is responsible for responding to requests to Chambers for information from Data Subjects within one calendar month. This can be extended for up to a further two months for complex requests in certain circumstances. If we decide not to comply with the request, the DPL will respond to the Data Subject to explain our reasoning and inform them of their right to complain to the ICO and seek judicial remedy.
Data Subjects also have the right to complain to us about the processing of their personal data, and the handling of a Subject Rights Request: we have a separate Data Complaints Policy. They can also pursue this complaint to the ICO.
Consent is a critical concept under the GDPR. We understand ‘consent’ as follows: a specific, informed and unambiguous indication of the Data Subject’s agreement to the processing of personal data relating to them given by an express statement or a clear, affirmative act.
Consent must be explicitly and freely given:
The Data Subject can withdraw Consent at any time.
Consent will not be inferred from non-response to a communication: a Data Controller must be able to demonstrate that consent, where necessary, was obtained for the processing operation.
For Sensitive Personal Data, explicit written consent of Data Subjects will be obtained unless an alternative Legitimate Basis for processing exists.
As neither Chambers nor members provide services to children under the age of 13, there is no question of parental or custodial authorisation needing to be obtained.
Serle Court processes (as Controller) a wide range of Personal Data, including Special Category data and, very occasionally, criminal convictions, as part of its business as a set of Chambers. It may also process Personal Data as part of the client file when acting as Data Processor for members.
The following types of Data may be processed in either such capacity:
In particular, any of the above categories of data may be processed by Chambers as Data Controller if you make a complaint under our Complaints Policy and provide such information as part of it.
For the purposes of record-keeping and HR, Chambers also processes such data for Members, employees and applicants for pupillage, mini-pupillage and work experience, or tenancy.
We recognise that where Special Category Data or Criminal Offence Data is processed, both a Lawful Basis and a Processing Condition are required to be identified and that in certain cases there may be further legal obligations to comply with, all of which are set out in the GDPR.
Chambers’ Privacy Notice and the Data Processed Register appended to it set out more detail on the categories and purposes of data processed.
All Personal Data processed by Chambers is provided directly to us by:
All chambers’ data collection forms (electronic and paper-based), including data collection requirements in new information systems, must and will include a fair processing statement or a link to our Privacy Notice and be approved by the DPL.
Employees are required to notify the Head of People and EDI of any changes in their personal circumstances which may require personal records to be updated.
The DPL is responsible for ensuring that appropriate procedures and policies are in place to keep Personal Data accurate and up to date, taking into account the volume of data collected, the speed with which it might change and any other relevant factors.
The DPL is responsible for making appropriate arrangements where third-party organisations may have been passed inaccurate or out-of-date Personal Data to inform them that the information is inaccurate and/or out of date and is not to be used to inform decisions about the individuals concerned; and for passing any correction to the Personal Data to the third party where this is required.
All Personal Data should be accessible only to those with prior authorisation to use it. All Personal Data should be kept secure, and Personal Data kept on chambers systems by members or staff is held securely in accordance with our Information Security Policy Suite.
No less than annually the DPL will carry out a risk assessment reviewing all the circumstances of our data controlling and processing operations.
In determining the appropriateness of all technical and organisational security measures, the DPL will consider the extent of possible damage or loss that might be caused to individuals (e.g. staff, clients or members) if a security breach occurs, the effect of any security breach on our organisation itself, and any likely reputational damage, including the possible loss of client trust.
Personal Data of which Chambers is Data Controller should never be removed from Chambers’ systems if held electronically, and if held physically, it should only be removed from Chambers’ premises if legitimate processing requires it, and then returned for secure retention or disposal.
Processing of Personal Data ‘off-site’ or otherwise than using chambers’ managed IT systems presents a potentially greater risk of loss, theft, or damage to that data. The precautions that should be taken by different users are set out in our Information Security Policy Suite.
All employees are responsible for ensuring that any Personal Data that we hold and for which they are responsible is kept securely.
Disclosure of data in response to a Subject Rights Request is dealt with under paragraph 6 of this policy and under our Subject Rights Request Policy.
Our staff and members exercise caution when asked to share Personal Data held on another individual to any third party. If necessary the DPL will perform a Data Protection Impact Assessment before chambers proceeds with data sharing.
We must and will ensure that Personal Data is not disclosed to unauthorised third parties, such as family members, friends, and, in certain circumstances, government bodies or the Police.
Otherwise, if we share Personal Data with third parties it will only be on basis of a formal Data Sharing Agreement or when we have a legal obligation to do so.
It is our intention in time to create a Third Party Data Sharing Register which lists any Data Sharing Agreements or Data Processing Agreements that Chambers has in place.
Members will have their own Data Retention and Disposal policies.
Chambers shall and does not keep Personal Data in a form that permits identification of Data Subjects for a longer period than is necessary in relation to the purpose(s) for which the data was originally collected.
The retention period for each category of personal data is set out in chambers’ Retention and Disposal Policy, which is also appended to our Privacy Notice.
Personal data will be retained in line with this policy and, once its retention date is passed, it must and will be securely destroyed as that policy provides.
On at least an annual basis, our DPL will review the retention dates of all the Personal Data controlled by chambers and will identify any data that is no longer required. This data will be securely archived, deleted or destroyed in line with our Retention and Disposal Policy and any data cleanse will be duly documented.
Where personal data is archived it will be minimised and password-protected in order to protect the identity of the Data Subject in the event of a Data Breach.
The DPL must and will specifically approve any data retention that exceeds the retention periods defined in our Retention and Disposal Policy, and must ensure that the justification is clearly identified and recorded.
We may store data for longer periods if the Personal Data is to be processed solely for statistical purposes, subject to the implementation of appropriate technical and organisational measures to safeguard the rights and freedoms of the Data Subject. Any such retention must and will be approved in advance by the DPL.
Under GDPR, transfers of personal data outside of the European Economic Area can only be made if specific safeguards exist.
No employee is authorised to transfer Chambers’ controlled Personal Data internationally. Chambers stores and backs up its Data only to servers in the UK and EU.
If Chambers as Data Processor for any of its members transfers data outside of the European Economic Area at their direction, it will rely on the Impact Assessment of the member in question and that they have satisfied themselves that the relevant conditions laid down in the GDPR are complied with by themselves and the recipient.
We have established a Data Processed Register that records for Chambers-controlled data:
The Responsible Person for all Chambers data is ultimately the DPL, who will ensure the currency of data held in accordance with the Retention and Disposal Policy and who will act on requests for rectification, erasure, restriction and portability.
Members as Data Controllers are responsible for creating and maintaining their own Data Processed Registers.
Chambers’ Data Processed Register is also appended to our Privacy Notice.
Serle Court operates strict confidentiality measures and a “Need to Know” approach to client file access. Chambers will only process Personal Data from client files where the relevant member has granted access thereto. Where there are Members acting on opposing sides of a matter this is flagged in our systems and established Information Barrier processes will operate. For further information on access controls please refer to chambers’ Information Security Policy Suite and our Deputy Practice Director who has responsibility for the configuration of our case management software, Lex.
These issues are dealt with in Chambers’ Information Security Policy Suite which is available on request.
Chambers takes a proactive approach to preventing data breaches and not simply reacting if or when they occur. All members and staff should be and are vigilant to circumstances which pose a risk to Personal Data.
Where any member, pupil or staff member becomes aware of any risk to Personal Data, or to a data breach or the possibility thereof, they should report this to the DPL as soon as reasonably practicable using the Internal Breach Reporting Form. All identified risks should be reported to the DPL’s email address. High risks may warrant a telephone call. Although (as noted below) members will carry the reporting obligation for a data breach in respect of data they control, they should still complete this form because it is possible that Chambers needs to know (a) as processor of their data and (b) in case the risk or breach possibility in question requires a response from Chambers.
Risks to data, and possible data breaches, may arise in any circumstances where the data might be accessed without authority, processed unlawfully, damaged, lost or destroyed. The following should be flagged along with any other equivalent circumstances or concerns:
Data Protection breaches involving pupils or staff will be actioned within 72 hours in accordance with the Serle Court Data Protection Breach Procedure, which sets out guidance on when a report should be made to the ICO and how to go about it, and when to inform affected individuals. The Breach Procedure also mandates the maintenance of a Breach and Near Miss Register.
Where any new central software, system, practice or process is proposed, Chambers through the DPL or other delegate will carry out an initial risk assessment to identify any potential risks inherent in the proposal and its implications for the processing of Personal Data. Our AI Governance Policy mandates this for the adoption of any new AI tool for use in Chambers Microsoft 365 tenancy.
If any processing (in particular by using new technologies, and taking into account the nature, scope, context and purposes of the processing) is likely to result in a heightened risk to the rights and freedoms of living natural persons, we shall, prior to the processing, carry out or cause to be carried out a Data Protection Impact Assessment of the envisaged processing operations and document any steps proposed in mitigation using the Serle Court Risk Assessment and DPIA Template. All DPIAs will be overseen and reviewed by the DPL.
Where as a result of a DPIA it is clear that we are about to commence processing of Personal Data that could cause damage and/or distress to the Data Subjects, the decision as to whether or not we may proceed must be referred to the DPL and/or the Tech and/or the Management Committee, as appears appropriate, for approval to proceed.
The DPL shall, if there are significant concerns, either as to the potential damage or distress, or the quantity of data concerned, refer to the ICO for guidance and advice.
All staff as part of their onboarding, and at least annually, complete role-specific GDPR training, taking into account the extent of the data processing they are involved in and the scope of their duties. New staff will not be permitted access to live Client File data until such training is completed.
| Date Reviewed | Reviewed By | Updates & Changes | Date Of Next Review |
|---|---|---|---|
| June 2026 | CD | AI; Complaints | 2029 |