This policy summarises the key points about how Elliott Duffy Garrett collects, uses and discloses personal data and ensures compliance with the GDPR and Data Protection Act.
Clients should read this policy alongside the Terms and Conditions of Engagement that we issue to you.
means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The Firm is the Data Controller of all Personal Data relating to our staff and Personal Data used in our business for our own commercial purposes;
Any living individual who is the subject of Personal Data;
means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person and includes data held electronically or in a Relevant Filing System;
means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
any paper filing system or other manual filing system which is structured so that information about an individual is readily accessible according to specific criteria;
Data that relates to racial or ethnic origin of the data subject, political opinions, religious beliefs or other beliefs of a similar nature, trade union membership, physical or mental health or condition, sex life or sexual orientation, genetic data and biometric data.
Data in relation to criminal offences and proceedings is not included in the definition of Special Categories of Data but similar safeguards will apply in relation to processing such data;
The Firm is the data controller of the personal data we process and therefore is responsible for ensuring our systems, processes, suppliers and staff comply with data protection laws in relation to the information we handle.
All staff must abide by this policy and our Data Protection Policy when handling personal data and must take part in any required data protection training. Any breach will be taken seriously and may result in disciplinary action.
The Firm has adopted the principles below to govern our use, collection and disclosure of personal data. Data will be:
As a Firm the type of data we collect and process falls into one of the following categories:
Personal data will only be processed where one of the following conditions is met:the processing is necessary for the purposes of the legitimate interests of the Firm (which are the provision of legal services to clients & the effective management of the Firm);
Where the provision of personal data is a statutory or contractual requirement or a requirement relating to entering into a contract, if you fail to provide that data it might affect our ability to enter into a contract with you or to continue to provide services to you.
The table below provides a summary of how we collect and use personal data:
Information processed for relationship management and file opening procedures such as name, business information and identification documentation.
Additional personal data will be processed when individuals are named in matters on which we are advising
Relationship management and file opening information is collected from the client directly and further information (e.g. to verify identity) may be collected from third parties, such as publicly available sources.
All additional personal data is collected when supplied to us, or created by us in connection with a particular matter on which we are advising. eg through clients or other law Firms
Relationship management and file opening data is used for providing legal services, administration, commercial purposes (eg creditworthiness) and as required by law (eg anti money laundering).
All other personal data will be used for the purposes of providing legal services and to comply with our legal/ professional/statutory/ regulatory obligations/internal compliance/ security
Personal data:
Personal data such as name, address, contact details, education and employment history; information relating to next of kin/ dependants; financial information including bank details and identifiers (e.g. National Insurance numbers); records of your use of the Firm’s IT and information services (e.g. LexisNexis);
Also we may process information revealing sensitive information such as health details, racial origin, religious beliefs and information about offences/ alleged offences.
Personal data will be collected from a number of sources including staff application form/CV; tracking use of the Firm’s IT and information services; notes and records kept throughout employment including absences, annual appraisals and details of any grievances/ disciplinary action;
Personal data will be used for: human resources administration; to assess your suitability for the role; to ensure the Firm’s information and offices are secure; to comply with legal obligations and management purposes.
Photographs, education and career information may be used in marketing and promotional material for the Firm including our website, brochures, bids and tenders.
Personal data:
Personal data such as name, address, contact details, financial information including bank details
Personal data will be collected from a number of sources including invoices and contracts
Personal data will be used for: administration and management purposes.
All other personal data will be used for the purposes of providing legal services to our clients and to comply with our legal/ professional/statutory/ regulatory obligations/internal compliance/ security
Personal data:
Information such as name and business information (email address, job title, Firm/company ).
Data is collected in our system when you register to receive legal updates.
You will also be provided with the option to opt out and/ or be removed from the database with each marketing communication you receive from us.
Personal data will be used to:
– contact you with communications about legal updates, breaking news, newsletters and event invitations which we think are relevant to your interests;
Personal data:
Personal data such as name, address, contact details, financial information including bank details
Personal data will be collected from a number of sources including invoices and contracts and directly from the Partnership Organisation.
Personal data will be used for: administration and management purposes and to comply with our legal/ professional/ regulatory obligations/internal compliance/ security
Personal data:
Personal data must be processed in line with individuals’ rights, including the right to:
Should you wish to make a request in line with your rights as an individual, please forward it to the Managing Partner of Elliott Duffy Garrett. Further information on these rights is available at the Information Commissioners website https://ico.org.uk/.
Staff must notify or inform the Managing Partner or Partner responsible for Data Protection immediately if they receive a request in relation to personal data which the Firm processes.
The Firm operates the following data retention periods:
You should direct all complaints relating to how the Firm has processed your personal data to the Managing Partner.
Staff must inform the Managing Partner or Partner responsible for Data Protection immediately if they receive a complaint relating to how the Firm has processed personal data so the Firm can respond to the complaint.
Information security is a key element of data protection. The Firm takes appropriate measures to secure personal data and protect it from loss or unauthorised disclosure or damage.