TL;DR: Data protection and confidentiality are two separate duties that often get treated as one. Knowing where they overlap and where they diverge is what keeps your firm out of trouble with clients and regulators.

What Do Data Protection And Confidentiality Mean For A Law Firm?

Data protection and confidentiality sound like the same thing, but they cover different ground. Confidentiality is a professional duty you owe every client, built into the way solicitors have always worked. Data protection is a legal obligation under UK GDPR, covering how you collect and use personal information.

Client confidentiality existed long before data protection law did. It covers anything a client tells you in confidence, even if that information doesn’t count as personal data under GDPR. Data protection covers personal data belonging to anyone connected to your firm, including staff and job applicants.

Treating the two as interchangeable is where firms run into trouble. You can meet every GDPR requirement and still breach client confidentiality. The reverse happens just as often. For a managing partner, that gap is exactly where client complaints and regulatory scrutiny tend to start.

What Does The SRA Code Of Conduct Say About Client Confidentiality?

The SRA Code of Conduct for Solicitors requires you to keep the affairs of current and former clients confidential, unless disclosure is required by law or the client agrees to it. This duty sits with you personally, not only with your firm.

That distinction matters when you’re weighing up a disclosure request. A court order might satisfy your data protection obligations while still testing what your client expects you to keep private.

Does GDPR Compliance Replace Your Duty Of Confidentiality?

No. GDPR compliance gives you a lawful basis for processing personal data. It doesn’t release you from your separate duty to keep client information confidential. Firms that rely on a GDPR checklist alone are missing half the picture.

Where Do Confidentiality And Data Protection Obligations Conflict?

Most of the time, the two duties line up fine. The friction shows up in specific situations. Work out your position in advance, because there’s rarely time to think it through once a request lands on your desk. Most partners assume meeting one obligation covers the other. It usually doesn’t.

Third Party Disclosure Requests

When another party asks for information about a client matter, GDPR might allow disclosure under a legitimate interest. Client confidentiality can still require you to say no, or to hand over only what’s strictly necessary. A lawful basis under GDPR is not the same as permission from your client.

Litigation Holds And Data Retention

Data protection principles push you to hold personal data for no longer than necessary. Litigation holds and professional indemnity requirements often require you to keep records for years. Build a retention policy that accounts for both, and revisit it whenever a new matter type comes in.

How Can Your Firm Protect Confidential Client Data?

Start with who can see what. Most firms give more people access to more files than the job requires, and narrowing that down closes a real gap in your confidentiality position.

Access Control And Encryption

Set permissions by matter, not by department, so a conveyancing file isn’t visible to someone working in litigation with no reason to see it. Encrypt anything that leaves the building, including laptops and email attachments. Labyrinth Technology’s cyber security services are built around this kind of access control.

Staff Training And Everyday Behaviour

Most confidentiality breaches don’t come from anything dramatic. Someone replies to the wrong email thread, or leaves a document open on a shared screen, and client information ends up somewhere it shouldn’t. Training that uses real examples from your own firm sticks far better than a policy nobody reads twice. We build this into our managed security services, alongside the email security controls that catch a lot of these mistakes before they ever reach a client.

The ICO’s 72 hour clock for breach notification starts the moment you become aware of a problem, not once you’ve decided what to do about it. Firms with separated confidentiality and data protection policies meet that deadline. Firms without one spend the first day arguing about which policy applies.

Newsletter

Stay informed with practical IT insights

Get useful updates, security advice, and technology guidance from the Labyrinth Technology team.