Data collection is a “core part” of a solicitor’s daily professional duties, according to Cian Clinch, partner and head of the data-protection and privacy team at Hayes Solicitors LLP.
“Under the GDPR and the Data Protection Act 2018”, he said, “your firm acts as a data controller for the data it holds, which means you are accountable for how that information is handled, retained, and securely destroyed”.
Clinch was outlining GDPR obligations from the perspective of running a legal practice at the DSBA webinar, Focus on Clients: Care, Complaints, GDPR and AML Considerations (2 September).
The GDPR defines personal data very broadly, and Clinch flagged “items you might not necessarily think of, such as a client's IP address, their vehicle registration number, or handwritten notes that you might have on the file about their character”.
Special-category data, which include information revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, health data, and data relating to criminal convictions and offences are subject to additional protections.
When processing such data, a firm must identify both a lawful basis under article 6 and a separate condition under article 9 of the GDPR, most commonly article 9 (2) (F), which permits processing where necessary for the establishment, exercise, or defence of legal claims.
The regulation provides six possible lawful bases for processing personal data:
Clinch said that, although there was a common assumption that consent was the safest or preferred basis for processing personal data, this was not necessarily the case and, where another lawful basis was available, this might be more appropriate.
Firms must be able to demonstrate compliance, and Clinch recommended that privacy policies and terms of engagement be reviewed regularly, and that they should accurately describe what data is collected, why it is collected, who it is shared with, the lawful basis relied upon, and how long it will be retained.
Regarding data-sharing with counsel, Clinch referred to the Law Society and Bar Council of Ireland data-sharing protocol. He said that solicitors and barristers were independent data controllers, rather than operating in a controller-processor relationship.
The protocol provides for a mutual assumption of compliance, but does not remove the requirement for data minimisation.
Regarding data-sharing with service providers, Clinch said that the role of the provider, either as data processor (such as payroll) or independent data controller (for example, an external auditor or bank) must be determined and appropriate agreements put in place.
“If the service provider is acting under your instructions, they tend to be the data processor,” he said.
“Under article 28 of the GDPR, a data-protection agreement is a strict legal requirement whenever an outside provider acts as a data processor”, Clinch explained. “Article 28 provisions can be included in the commercial agreement, or it can be a standalone DPA [data-processing agreement]”.
However, if a service provider determines their own purposes and means for handling the data, a DPA is “inappropriate”.
Clinch said that similar considerations arose when instructing expert witnesses. Firms should consider the security of the method used to transfer information and should establish what happens to client data when the expert’s work ends.
For experts outside the EEA, he said that firms should first consider whether an adequacy decision applies. Where there is no adequacy decision, appropriate safeguards – including Standard Contractual Clauses – may be required. He also referred to Transfer Impact Assessments following Schrems II.
Clinch identified subject access requests (SARs) as another area requiring particular attention.
A request does not have to come from a client and may be made by employees, witnesses, beneficiaries, or other individuals involved in a matter. A firm will generally have one month to respond.
He stressed, however, that an SAR was a request for personal data and “not a request for the entire file”. Legal files contain information relating to multiple individuals, and firms must consider third-party information and applicable exemptions.
He added that privileged correspondence, legal advice, internal legal analysis, and documents created for litigation might be exempt from disclosure.
Clinch also addressed rectification and erasure requests. Factual inaccuracies should be corrected, but a client cannot use the right to rectification to require a solicitor to change an accurate professional opinion or historical record.
In such circumstances, a supplementary statement recording the client’s disagreement may be appropriate.
The right to erasure is also not absolute. Firms may have legal, regulatory, and professional obligations requiring them to retain information.
Clinch said that retention periods should be documented and justified, with different categories of legal work potentially requiring different periods.
Speaking about data breaches, Clinch said the majority did not necessarily involve sophisticated cyberattacks. He referred to the Data Protection Commission’s 2025 annual report and the number of breach notifications involving correspondence being sent to the wrong recipient.
His advice following a breach was to contain it, record what happened, and assess the risk.
“Not every data breach must be reported, but every data breach must be assessed,” he stated.
Where the relevant threshold is met, the Data Protection Commission must generally be notified within 72 hours.
Clinch concluded by addressing AI. He said that GDPR applied where AI tools processed personal data, adding that there was “no separate legal holiday for AI”. He warned against entering confidential or personal client information into public or standard AI tools.
He added that firms using AI should consider the security arrangements of the provider, international transfers, the use of inputs and outputs, and the accuracy of AI-generated material.