Regulatory information
Privacy notice
How Taylor Lewis Solicitors uses and protects your personal data. Effective 25 May 2018.
Taylor Lewis Solicitors, Bingham House, Pendre, Cardigan, Ceredigion, Wales, SA43 1JU.
UK data privacy and data protection law changed significantly on 25 May 2018. The General Data Protection Regulation (GDPR) is a positive step towards you having more control over how your data is used and how you are contacted by us.
If you are an individual, your rights under the GDPR include:
- the right to be informed
- the right of access
- the right to rectification
- the right to erasure
- the right to restrict processing
- the right to data portability
- the right to object
- rights in relation to automated decision-making and profiling.
The changes also help to better protect your personal data, and we have updated our privacy notice to reflect them.
We use your personal data to help us provide an excellent client service, which includes tailoring the information we share with you so that it is relevant, useful and timely. We will respect your privacy and work hard to ensure we meet strict regulatory requirements. We will not sell your personal data to third parties. We will provide you with easy ways to manage and review your marketing choices if you receive direct marketing communications from us.
We are a firm regulated by the Solicitors Regulation Authority (SRA). As you might expect, we are already subject to strict rules of confidentiality, and keeping your information private and secure is part of the fabric and culture of our firm.
Please help us keep your data secure by carefully following any guidance and instructions we give you — for example, about communicating bank account details and transferring funds to us.
We are sometimes obliged to share your personal data with external authorities without notifying you, for example as required by anti-money laundering and counter-terrorist financing legislation. In all other cases we will be transparent, and we will explain why we are requesting your data and how we are using it.
Lawful bases for processing your data
The law states that we may use personal information only if we have a proper and lawful reason to do so. This includes sharing it with others outside the firm, for example an auditor of a relevant quality standard. We must have one or more of these reasons:
- Contract: the processing is necessary for a contract we have with an individual, or because they have asked us to take specific steps before entering into a contract.
- Legal obligation: the processing is necessary for us to comply with the law (not including contractual obligations).
- Legitimate interests: the processing is necessary for our legitimate interests or those of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. A legitimate interest is when we have a business or commercial reason to use your information.
- Consent: the individual has given clear consent for us to process their personal data for a specific purpose.
How we use your personal data, and why
| Use of your personal data | Our reasons | Our legitimate business interest |
|---|---|---|
| Opening, progressing, closing, archiving and storing a matter or case file | Contract; legitimate interest; legal obligation | Fulfilling your instructions (the retainer); complying with regulations and the law |
| Direct marketing to you | Legitimate interest | Keeping our records up to date, working out which of our services may interest you and telling you about them; providing information on changes in the law and inviting you to contact us for advice |
| Making and managing client payments; managing fees, charges and interest due to clients; collecting and recovering money owed to us | Contract; legitimate interest; legal obligation | Keeping accounts systems up to date; complying with the SRA Accounts Rules and other regulations; effective and efficient management of a sustainable business |
| Detecting, investigating, reporting and seeking to prevent financial crime; managing risk for us and our clients; complying with laws and regulations that apply to us; responding to complaints and seeking to resolve them | Contract; legitimate interest; legal obligation | Developing and improving how we deal with financial crime, including suspected money laundering, and complying with our legal obligations in this respect; complying with regulations that apply to us; being efficient about how we fulfil our legal and contractual duties |
| Running our business in an efficient and proper way, including managing our financial stability, business capability, planning, communications, corporate governance and audit | Legitimate interest; legal obligation | Complying with the SRA Accounts Rules, Code of Conduct and other regulations; being effective and efficient; allowing external consultants, advisers and auditors to inspect files |
| Exercising our rights and complying with obligations set out in agreements or contracts | Legitimate interest; legal obligation | Complying with contractual requirements, for example for the provision to clients of public funding by public bodies |
Special categories and criminal convictions data
In addition to our lawful bases for processing personal data, we rely on further conditions in Schedule 1, Part 3 of the Data Protection Act 2018 for processing these types of data. The primary condition we rely on is known as “legal claims”, which is met if the processing:
- is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings),
- is necessary for the purpose of obtaining legal advice, or
- is otherwise necessary for the purposes of establishing, exercising or defending legal rights.
We would normally also rely on another condition in Schedule 1, Part 3 of the Act known as “consent”: due to the nature of these types of data, we would obtain your consent before processing them.
Our reason for processing data may be in connection with Schedule 1, Part 2 of the Act, condition 18 — safeguarding of children and of individuals at risk — where the processing is necessary for the purposes of (a) protecting an individual from neglect or physical, mental or emotional harm, or (b) protecting the physical, mental or emotional well-being of an individual; and where (a) in the circumstances, consent to the processing cannot be given by the data subject; (b) in the circumstances, we cannot reasonably be expected to obtain the consent of the data subject; or (c) the processing must be carried out without the consent of the data subject because obtaining it would prejudice the provision of the protection.
Due to the nature of these data types, we also comply with Schedule 1, Part 4 of the Data Protection Act, which requires us to have an appropriate written policy explaining our security procedures and data retention periods, and to retain this policy and produce it to the Information Commissioner on request. Our policy is set out in the firm’s Information Management & Security Policy.
Types of personal data we process
| Type of personal information | Description |
|---|---|
| Financial | Your bank account details and your financial status and information |
| Contact information | Where you live and how to contact you |
| Socio-demographic | Details about your work or profession, nationality, etc. |
| Transactional | Details about payments to and from your bank accounts |
| Contractual | Details about the services we provide to you |
| Behavioural | Details about how you use our services |
| Communications | What we learn about you from letters, emails and conversations between us |
| Social relationships | Your family, friends and other relationships |
| Open data and public records | Details about you in public records such as the Land Registry, and information about you that is openly available on the internet |
| Documentary data | Details about you stored in documents in different formats, or copies of them — for example your passport, driving licence or birth certificate |
| Special types of data | Racial or ethnic origin; religious or philosophical beliefs; trade union membership; genetic and biometric data; health data including gender; criminal convictions and offences. We will only collect and use these if the law allows or requires us to do so. |
| Consents | Any permissions, consents or preferences you give us, such as how you want us to contact you |
| National identifier | A number or code given to you by a government to identify you, such as a National Insurance number |
| Legal Aid application and bill | Information required to submit an application for public funding and to claim our fees under any legal aid certificate issued to you |
Sources of data
| Data | Source | Purpose |
|---|---|---|
| Data you give us when you instruct us to advise or act for you | You | To decide whether to accept your instructions and to progress your matter |
| Data you give us by letter, phone, email and other documents | You | To decide whether to accept your instructions and to progress your matter |
| Data you give us when you visit our website, or via a messaging service or social media | You | To deal with your query or request and to contact you if appropriate |
| Data you give us during interviews | You | To advise and represent you, and to communicate with other solicitors and third parties on your behalf |
| Data you give us in client surveys | You | To improve our services and respond to any expressions of dissatisfaction |
| Data provided by referrers and introducers | Referrers | To contact you, decide whether to accept your instructions and progress your matter |
| Fraud prevention agencies | Agency | To comply with the law and regulations and carry out client due diligence checks |
| Estate agents | Agents | To act on your behalf in a land transaction |
| Other solicitors | Solicitor firms | As part of an exchange of information to progress the matter and advise you |
| Public bodies such as HMRC, HM Treasury, local authorities, the Land Registry, Land Charges Registry, Probate Registry, Legal Aid Agency, police, CPS, courts service and other government departments | Public body | To advise you and progress your matter, and to prevent fraud and money laundering |
| Your GP or other medical professional | Doctor | To obtain appropriate medical reports |
| The Legal Aid Agency | LAA | Under our contractual obligations we receive “shared data” from the LAA if your matter is legally aided |
Who we share your data with
Subject to the SRA Code of Conduct and the requirements of client confidentiality, we may share your personal information with:
- lawyers or other organisations on the other side of a matter or case
- barristers or experts we instruct
- the courts and other tribunals
- your personal representatives or attorneys
- auditors
- lenders
- estate agents, IFAs, referrers, etc.
- organisations that we introduce you to
- HM Revenue and Customs
- the government, both central and devolved
- fraud prevention agencies, including the National Crime Agency
- the SRA and other regulators
- ID checking organisations.
Automated decision-making
We do not use automated decision-making systems. All decisions relating to you and your matter are made by a person.
Personal data we use
We typically use the following types of personal data: your name; date of birth; home address; contact details such as phone numbers and email addresses; bank details and account information; medical information (where applicable); employment details; and data that identifies you by cookies when you use our website.
Sending data outside the European Economic Area
Unless you instruct us in a matter or case that involves an international element, we do not normally send your personal data outside the EEA. If we do, we will seek your consent, explain the risks to you, and talk to you about potential safeguards depending on the country involved.
If you refuse to provide personal data we request
If you refuse to provide the information requested, it may cause delay, and we may be unable to continue to act for you or complete your matter.
Marketing information
We may from time to time send you letters or emails about changes in the law and suggestions about actions you might consider in the light of that information — for example, reviewing your Will. We will send you this marketing information either because you have consented to receive it or because we have a “legitimate interest”.
You have the right to object and to ask us to stop sending you marketing information by contacting us at any time. You can of course change your mind and ask us to send the information again.
How long we keep your personal information
We are legally obliged to keep certain information for at least five years, and typically store your file for six years before destroying it. In some cases, for example Legal Aid matters, we are obliged to keep your files for longer; this period will be set out in our closing letter to you. We will store Wills and other documents indefinitely. We will keep your name and personal contact details on our database until you tell us that you would like them removed, for example where you have changed solicitor.
How to get a copy of your personal information
If you wish to access your personal data, please write to: Alan Lewis, Data Protection Supervisor, Taylor Lewis Solicitors, Bingham House, Pendre, Cardigan, Ceredigion, Wales, SA43 1JU.
Telling us if your personal information is incorrect
If you think any information we hold about you is incomplete or wrong, you have the right to ask us to correct it. Please contact us as above.
Other rights
You also have the right to erasure, the right to restrict processing, and the right to data portability. You have the right to ask us to delete (erase) or stop using your data if there is no longer any need for us to keep it (for example, under a legal obligation).
In terms of data portability, subject to any lien we may have for non-payment of fees, we will comply promptly (where permitted) with your request to transfer your physical paper file to another solicitor on receipt of your signed consent. If your file is in electronic format, we will take reasonable steps to export it in a “portable format” where possible, so that your new solicitor can upload it to their system. As many different IT systems are used by the legal profession, we cannot guarantee that we can provide data in a compatible format.
Consent
In some cases the GDPR requires us to obtain your explicit consent — for example, to process information about racial or ethnic origin; political opinions; religious or similar beliefs; trade union membership; physical or mental health or condition; sexual life; the commission or alleged commission of any offence; or any proceedings for an offence, their disposal, or the sentence of any court. Where acting for you involves processing such data we will seek your explicit consent, for example when we plan to obtain your medical records.
You have the right to withdraw your consent by contacting us as above. However, if you do so, we may not be able to progress your case or continue to act for you.
How to complain
If you are unhappy about how we are using your personal data, you can complain to us using the contact information above. You also have the right to complain to the Information Commissioner’s Office (ICO). Details of how to raise a concern with the ICO are on its website: ico.org.uk/concerns.
Updating this notice
We will, from time to time, update this privacy notice to reflect emerging ICO guidance, the requirements of data protection law and any other relevant changes in the law or regulations.