Data Protection and Privacy | By Lawyers
Skip to main content

Data Protection and Privacy

This publication guides practitioners through the complexities of data protection and privacy laws, covering individual rights, business compliance, data processing, security incidents, and breaches.

1 Matter Plan

Overview

The commentary covers topics like freedom of information requests, data retention, employee data, penalties, sanctions, and enforcement.

The Reference materials folder includes guidance on electronic signing and witnessing, and the comprehensive Getting the matter underway folder includes compliance and client care documents. Using the extensive Retainer Instructions when gathering information ensures nothing is missed.

Precedents in this publication include:

  • a data protection due diligence checklist;
  • data subject request forms;
  • correspondence dealing with data subject requests;
  • data protection, privacy, and record retention policies;
  • impact assessments;
  • data processing agreements;
  • a Data Breach Reporting Evaluation;
  • a Letter of Claim to Data Controller or Processor;
  • a Settlement Agreement.
Icon

1 Matter Plan Included

  • Item icon ALERTS - Nil
  • Item icon Full Commentary - Data Protection and Privacy
  • Folder icon Reference materials
    • Item icon Electronic Signing and Witnessing
    • Item icon Looking to the Future
    • Item icon Further information
  • Item icon Overview and limitation periods
    Since the General Data Protection Regulation (GDPR) came into force in 2018, data protection and privacy laws have rapidly evolved and continue to do so. These areas of law impact everyday life, with government and lawmakers finding it increasingly challenging to legislate quickly enough to protect ...

    This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

  • Item icon Summary of the process
    The usual steps in acting on data protection are:

    This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

  • Folder icon A. Getting the matter underway
    • Item icon File cover sheet - Data protection and privacy
    • Item icon To do list - Data protection and privacy
    • Item icon First steps
    • Item icon Retainer instructions - Data protection and privacy
    • Folder icon Compliance documents
      • Item icon Client Due Diligence and Anti-money Laundering Guidance
      • Item icon Client Details, Identity Verification and Source of Funds
      • Item icon Conflict of interest check
      • Item icon Client and matter risk assessment
      • Folder icon If required - Reporting an issue
        • Item icon Anti-money laundering internal disclosure
    • Item icon Initial letter to client enclosing Client Care and Terms of Business
    • Folder icon Enclosures for initial letter to client
      • Item icon Client care information
      • Item icon Terms of business
      • Item icon Scope of work - Data protection - Acting for a data processor - Data breach
      • Item icon Scope of work - Data protection - Acting for a commercial client - Data processing
      • Item icon Scope of work - Data protection - Acting for a data subject exercising rights
    • Item icon Funding
      Standard retainer Under a standard retainer the hourly costs of handling the case are paid by the client to the solicitor, together with all disbursements and expenses incurred.

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Folder icon If required - Conditional fees and damages-based agreements
      • Item icon Conditional fee agreement
        A conditional fee agreement is a no-win no fee arrangement based on the premise that a client is not responsible for the solicitor’s costs if the case is unsuccessful. The agreement will state that the client is liable to pay a solicitor’s costs only if the claim is successful. If it is, the ...

        This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

      • Item icon Letter to client giving informed consent to conditional fee agreement
      • Item icon Letter to client explaining barrister's fees
      • Item icon Conditional fee agreement
      • Item icon Enclosure - Conditional fee agreements explained
      • Item icon After the event insurance
        If the claim is unsuccessful the client is still likely to have to pay the other side’s costs. This cannot be alleviated by a conditional fee agreement. For this reason, clients are well advised to consider after the event insurance to accompany a conditional fee agreement. Simply put, the ...

        This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

      • Item icon Damages-based agreements
        A damages-based agreement is a contract between a solicitor and client that, if the client’s claim is successful, the solicitor will be entitled to a share of the recoveries. Damages-based agreements are different to conditional fee agreements in that they can be used only with claimant clients.

        This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

      • Item icon Letter to client enclosing damages-based agreement for signing
      • Item icon Damages-based agreement
      • Item icon Enclosure - Damages-based agreements
      • Item icon Notice of funding of case or claim
      • Item icon Litigation funding by a third party
        This is a relatively new mechanism by which a party who is not related to the case funds it in return for a fee. Essentially funding is predicated on the concept that claims are potential investment assets. While this raises ethical issues it gives an individual somewhere to go to fund certain ...

        This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Time and costs estimates
    • Folder icon If required - Letter to client varying the Client Care and Terms of Business
      • Item icon Letter to client varying the Client Care and Terms of Business
    • Folder icon General deeds, agreements, statements, declarations, consents, and execution clauses
      • Item icon Deeds and agreements
      • Folder icon Deeds
        • Item icon Deed for general use
        • Item icon Deed of assignment of agreement
        • Item icon Deed of assignment of agreement with consent
        • Item icon Deed of assignment of an insurance policy
        • Item icon Deed of assignment of equitable interest in residential land
        • Item icon Deed of gift
        • Item icon Deed of guarantee
        • Item icon Deed of release
        • Item icon Deed of release and grant
        • Item icon General deed of indemnity
        • Folder icon Library of standard clauses for deeds
          • Item icon Amendment
          • Item icon Confidentiality
          • Item icon Confidentiality - Extensive
          • Item icon Costs
          • Item icon Counterparts
          • Item icon Dispute resolution
          • Item icon Events beyond control
          • Item icon Governing law and jurisdiction
          • Item icon Interpretation
          • Item icon No assignment
          • Item icon Notices
          • Item icon Severance
          • Item icon Third parties
          • Item icon Waiver
          • Item icon Whole agreement
      • Folder icon Agreements
        • Item icon Agreement for general use
        • Item icon Boundary agreement
        • Item icon Confidentiality agreement
        • Item icon Construction agreement
        • Item icon Heads of agreement
        • Folder icon Library of standard clauses for agreements
          • Item icon Amendment
          • Item icon Confidentiality
          • Item icon Confidentiality - Extensive
          • Item icon Costs
          • Item icon Counterparts
          • Item icon Dispute resolution
          • Item icon Events beyond control
          • Item icon Governing law and jurisdiction
          • Item icon Interpretation
          • Item icon No assignment
          • Item icon Notices
          • Item icon Severance
          • Item icon Third parties
          • Item icon Waiver
          • Item icon Whole agreement
      • Folder icon Statements and declarations
        • Item icon Statement of truth
        • Item icon Statement of truth - High Court
        • Item icon Statutory declaration
        • Item icon Statutory declaration of solvency
        • Item icon Affidavit - General
        • Item icon Exhibit sheet for affidavits - General
        • Item icon Witness statement - Family matters
        • Item icon Exhibit sheet to witness statement - Family matters
        • Item icon Witness statement - Civil matters
        • Item icon Exhibit sheet to witness statement - Civil matters
      • Folder icon Execution clauses
        • Item icon Execution clauses - Agreements and contracts
        • Item icon Execution clauses - Deeds
        • Item icon Execution clauses - Overseas companies
      • Folder icon Consents
        • Folder icon If required - Personal data consent - General
          • Item icon Letter to client enclosing consent - General
          • Item icon Letter to third party enclosing consent - General
          • Item icon General letter enclosing client consent
          • Item icon General letter enclosing third party consent
          • Item icon Consent to provide information - General
          • Item icon Consent to provide information - General - Third party
        • Folder icon If required - Personal data consent - Health professional
          • Item icon Letter to client enclosing consent - Health professional
          • Item icon Letter to third party enclosing consent - Health professional
          • Item icon Letter to doctor enclosing client consent
          • Item icon Letter to doctor enclosing third party consent
          • Item icon Consent to provide information - Health professional
          • Item icon Consent to provide information - Health professional - Third party
        • Folder icon Change of name
          • Item icon Change of name deed for an adult - Concise
          • Item icon Change of name deed for a minor - Concise
          • Folder icon If required - Enrolment by an adult
            • Item icon Change of name deed for an adult - For enrolment
            • Item icon Statutory declaration - Enrolment of adult change of name deed
            • Item icon Notice for the London Gazette on the change of name of an adult
            • Item icon Consent to enrolment of change of name of an adult
          • Folder icon If required - Enrolment by a minor
            • Item icon Change of name deed for a minor - For enrolment
            • Item icon Statutory declaration - Enrolment of minor change of name deed
            • Item icon Affidavit of best interest for the change of name of a minor
            • Item icon Consent to enrolment of change of name of a minor
  • Folder icon B. The fundamentals
    • Item icon The fundamentals
      Data protection law is based on seven fundamental principles:

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Glossary of terms
      The Information Commissioner’s Office provides a glossary of useful terms:

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Human rights
      Article 8 of the Human Rights Act 1998 grants the right to a private life, supported by the Data Protection Act 2018, the General Data Protection Regulation, and European legislation. The handling of personal data must protect the rights and freedoms of individuals as set out in both data ...

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Oversight and governance of a privacy programme
      The General Data Protection Regulation requires a data protection officer to be appointed in an organisation:

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Collecting personal data
      Personal data is any information relating to a person who can be identified, directly or indirectly, by one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity. Technology which processes personal data must be subject to security and ...

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Checklist - Data protection due diligence
  • Folder icon C. An individual's rights
    • Item icon An individual’s rights
      Under the General Data Protection Regulation, individuals are granted several rights regarding their personal data.

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon The right to make requests
      The right to access A subject access request is the most exercised right, allowing an individual to obtain a copy of all data held about them under Article 15. It may be necessary to clarify further details to fully understand the scope of the request and ensure all relevant data is included.

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Folder icon Acting for a data subject
      • Item icon Data subject rectification request form
      • Item icon Data subject rights request form
      • Item icon Letter to client enclosing consent to obtain their personal data
    • Folder icon Acting for a data controller
      • Item icon Letter to data subject confirming their request was made
      • Item icon Letter to data subject enclosing response received
      • Item icon Letter to data subject requesting further information
      • Item icon Letter to data subject enclosing the personal data requested
    • Item icon Freedom of information requests
      The Freedom of Information Act 2000 allows any individual to request information in writing from public authorities. Schedule 1 notes some exceptions that may limit the type of information that can be released following a request or, in some cases, allow the recipient not to respond at all.

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Environmental information requests
      The Environmental Information Regulations 2004 allow individuals to request environmental information from public authorities. The scope of environmental information is defined in r 2(1). The Information Commissioner’s Office has a Code of Practice on the discharge of the obligations of public ...

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Letter making an information request
  • Folder icon D. Compliance for business
    • Item icon Compliance for business
      Registration If an organisation is a data controller, it must register with the Information Commissioner’s Office and pay the appropriate registration fee for certification: see Data protection fee.

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Data protection policy
    • Item icon Data protection policy for a business
    • Item icon Privacy policy
    • Item icon Data protection internal compliance audit checklist
    • Item icon Concise data protection impact assessment
    • Item icon Extensive data protection impact assessment form
    • Item icon Data protection privacy notice
    • Item icon Data retention
      Organisations should maintain a retention policy setting out the periods when data is retained based on a department’s needs or industry standards. The general principle is that once data is no longer required, it will be deleted in line with the storage limitation principle in Article 5(1)(e) ...

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Records retention policy
    • Item icon Data processing and data sharing agreements
      Contractual considerations Data protection provisions may appear embedded in commercial contracts or separate agreements.

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Data processing agreement
    • Item icon Data processing agreement - Letter form
    • Item icon Employee data
      Employee data must be handled with the same degree of care as client or customer data. Appropriate processes need to be in place to ensure that data is collected, stored, processed, and deleted in line with data protection principles.

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

  • Folder icon E. Security incidents and data breaches
    • Item icon Security incidents and data breaches
      Not all security incidents are data breaches, but the two often entwine. While a system's technical security may be compromised, there may be no unauthorised access to personal data. As such, processes must be in place to ensure that the facts of an incident can be determined quickly, implementing ...

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Data breach reporting evaluation
    • Item icon Letter to affected client reporting a data breach
    • Item icon Data breach in office reporting
    • Item icon Data breach report including remediation actions
    • Item icon Penalties, sanctions, and enforcement
      Penalties and sanctions are assessed against:

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Pre-action protocols
      Pre-action protocols are set out in Practice Direction – Pre-Action Conduct and Protocols of the Civil Procedure Rules. The pre-action protocols include the steps the court expects parties to take before commencing proceedings. The objectives of the pre-action conduct and protocols are to ensure ...

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Letter of claim to data controller or processor
    • Item icon Certificate of service
  • Folder icon F. Settling the matter
    • Item icon Settling the matter
      Court proceedings should be the last resort. If the parties have taken the protocol steps described above and still cannot agree, paragraph 8 of the Practice Direction – Pre-Action Conduct and Protocols requires them to take appropriate steps to resolve the dispute without starting court ...

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Alternative dispute resolution
      The Glossary to the Civil Procedure Rules defines alternative dispute resolution (ADR) as a collective description of methods of resolving disputes rather than through the normal trial process. There is no prescribed form of ADR, as much depends on the case, the parties, the merits of their ...

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Letter to the other side’s solicitor suggesting alternative dispute resolution
    • Item icon Mediation settlement agreement
    • Item icon Offers to settle
      There are opportunities to settle disputes, even when the parties’ relationship has soured. Settling the dispute can reduce costs and stress for all parties.

      This excerpt is a preview of the full publication. You can Subscribe Now and gain immediate access to the complete publication.

    • Item icon Letter to defendant’s solicitor making Calderbank offer
    • Folder icon If required - Part 36 offers
      • Item icon Enclosure - Part 36 offers
      • Item icon Letter to client suggesting making a Part 36 offer
      • Item icon Offer to settle (Section I Part 36)
      • Item icon Letter to other side's solicitor making Part 36 offer
      • Item icon Letter to client enclosing copy Part 36 offer made
      • Item icon Letter to client enclosing copy Part 36 offer received
    • Item icon Settlement agreement
    • Item icon Letter to client with draft settlement agreement
    • Item icon Letter to other side's solicitor with settlement agreement
    • Item icon Letter to court confirming settlement
    • Item icon General form of judgment or order
    • Folder icon Library of example consent orders
      • Item icon Clause - Consent order for judgment notation of agreement
      • Item icon Clause - Consent order payment inclusive of costs
      • Item icon Clause - Consent order judgment in favour of one party
      • Item icon Clause - Consent order for proceedings to be dismissed with no order as to costs
      • Item icon Clause - Consent order for acceptance of lesser sum
    • Item icon Letter to other side's solicitor sending draft consent order
    • Item icon Letter to court filing draft consent order on settlement
  • Folder icon G. Finalising the matter
    • Item icon Letter to client finalising the matter
    • Item icon Example invoice
    • Item icon Invoice recital - Acting for a data processor - Data breach
    • Item icon Invoice recital - Acting for a commercial client - Data processing
    • Item icon Invoice recital - Acting for a data subject exercising rights
    • Item icon Enclosure - Explaining the bill
    • Item icon Closing the file
    • Item icon File closing checklist
    • Item icon File review form - General
  • Item icon Comments and suggestions for By Lawyers

Our Authors

More than 50 legal professionals have contributed to By Lawyers' publications, all helping to ensure content is updated regularly to reflect changes in legislation, practice and procedure.

Meet Our Authors
Authors