Privacy Notice Effective 25th May 2018
Welch & Co Cyfreithwyr Solicitors
Mercantile Building
5 Castle Street
Cardigan
Ceredigion
SA43 3AB
Tel/Ffon: 01239 614070
Fax/Ffacs: 01239 613579
DX 92654 CARDIGAN
UK Data Privacy/Data Protection Law will change significantly on 25th May 2018.
The General Data Protection Regulation (or GDPR for short) is a positive step towards you having more control over how your data is used and how you are contacted by us.
If you are an individual, the rights you have under the GDPR include the following:
The changes will also help to better protect your personal Data. We have therefore updated our privacy notice to reflect these changes.
We use your personal data to help us provide an excellent client service, which includes tailoring the information we share with you to help ensure that it’s relevant, useful and timely.
We will respect your privacy and work hard to ensure we meet strict regulatory requirements.
We will not sell your personal data to third parties.
We will provide you with easy ways to manage and review your marketing choices if you receive direct marketing communications from us.
We are a firm that is regulated by the Solicitors regulation Authority (SRA). As you might expect, we are already subject to strict rules of confidentiality. It is therefore already part of the fabric and culture of our firm to keep your information private and secure.
We would ask you to help us keep your data secure by carefully following any guidance and instructions we give e.g. communicating bank account details and transferring funds to us.
We are sometimes obliged to share your Personal Data with external authorities without notifying you e.g. as required by the Anti-Money Laundering & Counter Terrorist Financing Act 2017. In all other cases, we will be transparent, and we will explain to you why we are requesting your data and how we are using it.
Lawful Bases for Processing you Data
The new law states that we are allowed to use personal information only if we have a proper and lawful reason to do so. This includes sharing it with others outside the firm e.g. an auditor of a relevant quality standard.
The GDPR says we must have one or more of these reasons:
A legitimate interest is when we have a business or commercial reason to use your information.
Here is a list of all the ways that we may use your personal data, and which of the reasons we rely on to do so.
Use of your Personal Data |
Our reason/justification for processing |
Legitimate Business Interest |
Opening, progressing, closing, archiving and storing a matter/case file |
|
Fulfilling your instructions (the retainer). Complying with regulations and the law. |
Direct Marketing to you |
|
Keeping our records up-to-date, working out which of our products and services may interest you and telling them about them. Providing information on changes in the law and inviting you to contact us for advice. |
|
|
Keeping accounts systems up-to-date. Complying with SRA Accounts Rules and other regulations. Effective and efficient management of a sustainable business. |
To detect, investigate, report, and seek to prevent financial crime.
|
|
Developing and improving how we deal with financial crime including suspected money laundering as well as complying with our legal obligations in this respect. Complying with regulations that apply to us. Being efficient about how we fulfil our legal and contractual duties. |
To run our business in an efficient and proper way. This includes managing our financial stability, business capability, planning, communications, corporate governance, and audit. |
|
Complying with the SRA Accounts Rules and Code of Conduct and other regulations that apply to us. Being effective and efficient about how we run our business. To allow external consultants, advisers and auditors to inspect files. |
To exercise our rights and comply with obligations set out in agreements or contracts. |
|
Complying with contractual requirements e.g. for the provision to clients of Public Funding by Public Bodies. |
Types of Personal Data we process
Type of Personal Information |
Description |
Financial |
Your Bank account details and your financial status and information. |
Contact Information |
Where you live and how to contact you. |
Socio-Demographic |
This includes details about your work or profession, nationality etc. |
Transactional |
Details about payments to and from your bank accounts. |
Contractual |
Details about the products or services we provide to you. |
Behavioural |
Details about how you use our services. |
Communications |
What we learn about you from letters, emails, and conversations between us. |
Social Relationships |
Your family, friends and other relationships. |
Open Data and Public Records |
Details about you that are in public records such as the Land Registry, and information about you that is openly available on the internet. |
Documentary Data |
Details about you that are stored in documents in different formats, or copies of them. This could include things like your passport, drivers licence, or birth certificate. |
Special types of data |
The Law and other regulations treat some types of personal information as a special category. We will only collect and use these types of data if the law allows or requires us to do so:
|
Consents |
Any permissions, consents or preferences that you give us. This includes things like how you want us to contact you. |
National Identifier |
A number or code given to you by a government to identify who you are, such as National Insurance Number. |
Legal Aid Application and Bill |
Information required to submit an application for public funding and to claim our fees under any legal aid certificate issued to you. |
Sources of Data
We collect personal data from various sources:
Data |
Source |
Purpose |
Data you give us when you instruct us to advise you or act for you |
You |
To enable us to decide whether to accept your instructions and to progress you matter. |
Data you give us by letter/phone/email and other documents |
You |
To enable us to decide whether to accept your instructions and to progress your matter. |
Data you give us when you visit our website, via a messaging service or social media |
You |
To enable us to deal with your query or request and to contact you if appropriate. |
Data you give us during interviews |
You |
To enable us to advise you and represent you and to communicate with other solicitors and third parties on your behalf. |
Data you give us in client surveys |
You |
To enable us to improve our services and respond to any expressions of dissatisfaction. |
Data provided to us by referrers and introducers |
Referrers |
To enable us to contact you and to enable us to decide whether to accept your instructions and to progress your matter. |
Fraud Prevention agencies |
Agency |
To enable us to comply with the law and regulations and carry out client due diligence checks. |
Estate Agents |
Agents |
To enable us to act on your behalf in relation to a land transaction. |
Other Solicitors |
Solicitor Firms |
As part of an exchange of information to enable us to progress the matter and advise you. |
Public Bodies |
Public Body such as HMRC, HM Treasury, Local Authority, Land Registry, Land Charges Registry, Probate Registry, Legal Aid Agency, Police, CPS, Courts Service and other government departments |
To enable us to advise you and progress your matter. To prevent fraud and money laundering. |
Your GP or other medical professionals |
Doctor |
To obtain appropriate medical reports. |
The Legal Aid Agency |
LAA |
Under our contractual obligations we will receive ‘Shared Data’ from the LAA if your matter is legally aided. |
Who we share your Data with
Subject to the SRA Code of Conduct and the requirements with regard to client confidentiality, we may share your personal information with:
Automated Decision-Making
We do not use automated decision-making systems. All decisions relating to you and your matter are made by a person.
Personal Data we use
We typically will use the following types of personal data:
Sending Data outside the European Economic Area (EEA)
Unless you instruct us in a matter or case that involves an international element, we don’t normally send your personal data outside the EEA. If we do, then we will seek your consent to do so, explain the risks to you and talk to you about potential safeguards depending on the country involved.
Your refusal to provide Personal Data requested
If you refuse to provide the information requested, then it may cause delay and we may be unable to continue to act for you or complete your matter.
Marketing Information
We may from time to time send you letters or emails about changes in the law and suggestions about actions that you might consider taking in the light of that information e.g. reviewing your will. We will send you this marketing information either because you have consented to receive it or because we have a ‘legitimate interest’.
You have the right to object and to ask us to stop sending you marketing information by contacting us at any time. You can of course change your mind and ask us to send the information again.
How long we keep your personal information
We are legally obliged to keep certain information for at least 5 years and typically store your file for 6 years before destroying it.
In some cases, e.g. Legal Aid Matters we are obliged to keep your files for a longer period of time, this period will be set out in our closing letter to you.
We will store Wills and other documents indefinitely.
We will keep your name and personal contact details on our database until you tell us that you would like them removed e.g. where you have changed solicitor.
How to get a copy of your Personal Information
If you wish to access your personal data then write to:
Ms Katy Hanson
Mercantile Building
5 Castle Street
Cardigan
Ceredigion
SA43 3AB
Telling us if your Personal Information is incorrect (The right to rectification)
If you think any information we have about you id incomplete or wrong, then you have the rright to ask us to correct it. Please contact us as above.
Other Rights
As mentioned above you also have other rights, namely:
You have the right to ask us to delete (erase) or stop us using your date if there is no longer any need for us to keep it (e.g. under a legal obligation).
In terms of data portability then subject to any lien we may enjoy for non-payment of fees, we will comply promptly (where permitted) to your request to transfer your physical paper file to another solicitor upon receipt of your signed consent. If your file is in electronic format we will take reasonable steps to export the file to a ‘portable format’ where possible so that your new solicitor can upload it to their system. As many different IT systems are used by the legal profession we cannot guarantee that we can provide data in compatible format.
Consent
GDPR in some cases requires us to obtain your explicit consent i.e.
Where acting for you involves us processing such data we will seek your explicit consent e.g. when we plan to obtain your medical records.
You have the right to withdraw your consent by contacting us as stated above.
However, if you do so then we may not be able to progress you case or indeed continue to act for you.
How to Complain
If you are unhappy about how we are using your Personal Data then you can complain to us using the contact information above.
You also have the right to complain to the Information Commissioner’s Office (ICO). Further details on how to raise a concern with the ICO can be found on the ICO’s website: https://ico.org.uk/concerns
Cookies
We do not use cookies on our website www.welchlaw.co.uk
Updating this Notice
We will, from time to time, update this Privacy Notice after 25th May 2018 to reflect emerging ICO and Working Party 29 guidance, requirements of the new Data Protection Act and any other relevant changes in the law or regulations. We will also seek to learn from any published cases of Data Protection breaches.