|
Writing this article in the first few weeks of the GDPR era, it is clear that the 25 May start date was just a milestone and that data protection will be a topic we must continue to focus on in the weeks and months ahead. I am already hearing anecdotes about subject access requests being made on 25 May in reliance on the improved rights which have been granted to data subjects. It is clear that this is a significant change in the way things are and for us, as lawyers, the consequences include even more scrutiny of our systems, processes and responses. |
![]() |
I would hope and anticipate that the Information Commissioner’s Office’s attention will be concentrated on the big guns – the online companies and the large-scale data processors – but we are nevertheless in the spotlight. We know that the ICO was expressing opinions about our handling of personal data long before GDPR was on the agenda. It is unlikely we will be forgotten in this new age of data protection.
Think back to 2014 if you will. The ICO published a notice directed at the legal profession. In it, the incumbent Commissioner reported that he was disturbed by the number of breach reports the ICO had received about the handling of data by barristers and solicitors. He had received reports of 15 data breaches in 3 months and had concerns about the serious personal data we processed and our over reliance on paper files. The warning was concluded in this way: “It is important that we sound the alarm at an early stage to make sure this problem is addressed before a barrister or solicitor is left counting the financial and reputational damage of a serious breach”. At first glance, this may appear to be a helpful ‘heads up”, but the body which can instigate the financial and reputational damage is the body which was issuing the warning! You’ll understand my unease.
Having said that, I am nevertheless confident that working in the legal services profession, we have a head start when considering the ways to respond to GDPR. After all, if there is one thing we know about, it’s confidentiality. Our clients expect us to keep the matters secret and most solicitors and most law firms have designed processes to manage the risk of inadvertent disclosure. This is a solid foundation stone on which to develop the GDPR response. My overriding message to the firms I have been working with over the last few months is not to panic about all of this. Another confidence-booster ought to be the familiarity of oversight and the understanding of the need to be able to have good conversations with stakeholders who have a right to be interested in what we do and how we do it. This is what we already experience with our relationship with the SRA.
So, whilst there is no need to panic, there is the need to make sure that answers to the GDPR questions are in your compliance response. Most of you will have revised and/or drafted new processes by now and, hopefully, rolled these out with suitable training within your firms. What’s next, in this honeymoon period with the new legislation?
My compliance response in the next few months would be as follows:
Tracey Calvert, 14 June 2018
Oakalls Consultancy Limited
tcalvert@oakallsconsultancy.co.uk
Tracey Calvert is a lawyer who has worked as a senior ethics adviser with the Law Society and the SRA, and was part of the SRA policy team which drafted the SRA Handbook which was launched in 2011. She now provides compliance and ethics services to lawyers and others through her company, Oakalls Consultancy Limited, and also writes extensively on these topics. For further information about the services which Tracey can provide, please see her website, www.oakallsconsultancy.co.uk, or contact her by email or phone, tracey@oakalls.com, 07833 253057