LoginSubscribe Now
Follow Us
Sign up to our free newsletter
Solicitors Journal LogoInforming the legal profession since 1856

Find the knowledge you need from the SJ library of over 20,000 legal articles

Search now
Solicitors Journal Logo
  • Legal News
  • Opinion
  • Features
  • Practice Notes
  • Business
  • International
  • Court Reports
  • AI Search
  • Digital Edition
  • Subscription Options
  • Advertise with Us
    • About Us
    • Contact Us
    • FAQ
    • Guide to Authors
Solicitors Journal

Informing the legal profession since 1856.

Follow us

Topics

  • Legal News
  • Opinion
  • Features
  • Practice Notes
  • Business
  • International
  • Court Reports

About

  • About Us
  • Contact Us
  • Advertise with Us
  • FAQ
  • Guide to Authors

Subscribe

  • Subscription Options
  • Digital Edition
  • Free Newsletter

Editorial

editorial@solicitorsjournal.com+44 (0)1223 750 755

Subscriptions

subscriptions@solicitorsjournal.com+44 (0)1223 750 755

Advertising

Advertise with usadvertising@solicitorsjournal.com+44 (0)1223 750 755

© 2026 Solicitors Journal in partnership with the International In-house Counsel Journal

ISSN 0038-1047  ·  Images: Freepix, Unsplash and by permission of the authors

Terms and ConditionsCookie PolicyPrivacy PolicyPLS Clear logoCopyright & permissions
Jean-Yves GilgJean-Yves Gilg

Editor, Solicitors Journal

A refresher in data security

15 Mar 2016|News|Add your comment
Share:
A refresher in data security

By Jean-Yves Gilg

How can your organisation ensure compliance ahead of the introduction of new data protection legislation, asks John Michael

The new General Data Protection Regulation (GDPR) aims to create strong data protection laws in Europe and is set to replace the outdated patchwork of national rules that have only allowed for small fines in cases of data breach violations. While there are opinions that there is a lot of red tape around the regulations, it has generally been welcomed as what should be an advanced and all-encompassing data protection framework.

Loss of client data is a major risk to any law firm, and the stakes are only getting higher. Firms already have obligations under the Solicitors Regulation Authority's (SRA) Code of Conduct to keep client information confidential and to maintain effective systems and controls to mitigate risks to confidentiality. In addition to this there are separate obligations under the Data Protection Act (DPA) in relation to the personal data they hold.

In 2018, when the GDPR looks set to replace the DPA, the consequences of failing to protect the personal data of clients will become much greater. For example, the maximum fine for DPA breaches is currently £500,000, but this will increase to € 20m or 4 per cent of global turnover. It will also become mandatory for organisations to report most personal data losses, both to the Information Commissioner's Office and to the affected individuals.

How can your organisation ensure compliance ahead of the new legislation's execution in 2018?

  • Update policies: this should demonstrate the new obligations and ensure that any reporting systems are outlined;

  • Appoint a data protection officer: this is mandatory for all organisations with more than 250 employees;

  • Report effectively: a system should be put in place that ensures any breaches of unencrypted data are reported within 72 hours;

  • Encrypt everything: defend against a breach by making data unreadable or in an inaccessible state using unbreakable encryption;

  • Keep records: data controllers should keep internal records as to how data is processed as evidence and to monitor compliance;

  • Obtain written consent: the parent/guardian of any child under the age of 16 should be notified and consent given before processing personal data; and

  • Respond quickly: ensure that any requests from individuals in relation to the handling of their personal data are dealt with efficiently and pro-actively.

Feedback from our legal
clients suggests that most
data losses arise from human error rather than deliberate contravention or a lack of internal compliance effort. While these will never be completely eliminated, the shift in emphasis to pro-active self-review and analysis is likely to result in fewer data losses over time. The increase in financial risk from
the new penalties will also see greater investment in encryption technology and tools to reduce the risks arising from the human element. SJ

John Michael is CEO of iStorage

Comments

Latest Articles

The new General Data Protection Regulation (GDPR) aims to create strong data protection laws in Europe and is set to replace the outdated patchwork of national rules that have only allowed for small fines in cases of data breach violations. While there are opinions that there is a lot of red tape around the regulations, it has generally been welcomed as what should be an advanced and all-encompassing data protection framework.

Loss of client data is a major risk to any law firm, and the stakes are only getting higher. Firms already have obligations under the Solicitors Regulation Authority's (SRA) Code of Conduct to keep client information confidential and to maintain effective systems and controls to mitigate risks to confidentiality. In addition to this there are separate obligations under the Data Protection Act (DPA) in relation to the personal data they hold.

In 2018, when the GDPR looks set to replace the DPA, the consequences of failing to protect the personal data of clients will become much greater. For example, the maximum fine for DPA breaches is currently £500,000, but this will increase to € 20m or 4 per cent of global turnover. It will also become mandatory for organisations to report most personal data losses, both to the Information Commissioner's Office and to the affected individuals.

How can your organisation ensure compliance ahead of the new legislation's execution in 2018?

  • Update policies: this should demonstrate the new obligations and ensure that any reporting systems are outlined;

  • Appoint a data protection officer: this is mandatory for all organisations with more than 250 employees;

  • Report effectively: a system should be put in place that ensures any breaches of unencrypted data are reported within 72 hours;

  • Encrypt everything: defend against a breach by making data unreadable or in an inaccessible state using unbreakable encryption;

  • Keep records: data controllers should keep internal records as to how data is processed as evidence and to monitor compliance;

  • Obtain written consent: the parent/guardian of any child under the age of 16 should be notified and consent given before processing personal data; and

  • Respond quickly: ensure that any requests from individuals in relation to the handling of their personal data are dealt with efficiently and pro-actively.

Feedback from our legal
clients suggests that most
data losses arise from human error rather than deliberate contravention or a lack of internal compliance effort. While these will never be completely eliminated, the shift in emphasis to pro-active self-review and analysis is likely to result in fewer data losses over time. The increase in financial risk from
the new penalties will also see greater investment in encryption technology and tools to reduce the risks arising from the human element. SJ

John Michael is CEO of iStorage

Legal News desk contact: editorial@solicitorsjournal.com|PLS LogoCopyright & permissions
Can the SFO restore its credibility?
Solicitors Journal

Can the SFO restore its credibility?

Recent successes cannot obscure the operational failures continuing to undermine the Serious Fraud Office’s credibility in complex cases
Business31 Jul 2026
UN urges UK to end IPP sentences
Solicitors Journal

UN urges UK to end IPP sentences

The United Nations has deemed the UK government's IPP sentences arbitrary and called for immediate investigations into longstanding injustices
News31 Jul 2026
New evidence supports targeted diversion efforts
Solicitors Journal

New evidence supports targeted diversion efforts

The Youth Justice Board has published a report reinforcing the value of targeted prevention and diversion initiatives for reducing youth crime and promoting safer communities
News31 Jul 2026
Upper Tribunal confirms corporate settlors can face secondary liability under Lexgreen Services v HMRC
Solicitors Journal

Upper Tribunal confirms corporate settlors can face secondary liability under Lexgreen Services v HMRC

Tribunal rules companies fall within section 201(1)(d) IHTA's "life of the settlor" wording.
Court Report31 Jul 2026
Court strikes out telecoms reseller's declaration-only claim in Yello v Onecom
Solicitors Journal

Court strikes out telecoms reseller's declaration-only claim in Yello v Onecom

Circuit Commercial Court finds two-stage litigation strategy over pricing dispute an abuse of process.
Court Report31 Jul 2026
High Court rejects CMA's fixed ratio rule for mattress discount pricing in Emma Matratzen case
Solicitors Journal

High Court rejects CMA's fixed ratio rule for mattress discount pricing in Emma Matratzen case

Court declines to impose 1:2 sales ratio on online retailer's reference pricing despite admitted rule breaches.
Court Report31 Jul 2026
High Court dismisses challenge to Northamptonshire warehouse scheme near protected bird site
Solicitors Journal

High Court dismisses challenge to Northamptonshire warehouse scheme near protected bird site

Judicial review over habitat mitigation for warehousing near Upper Nene SPA fails on all grounds.
Court Report31 Jul 2026
High Court strips fraud insinuations from Home Office defences in Hossain v Home Office
Solicitors Journal

High Court strips fraud insinuations from Home Office defences in Hossain v Home Office

Judge rules on which pleaded passages breach earlier findings on TOEIC test fraud litigation.
Court Report31 Jul 2026
High Court dismisses historic care home abuse claim in KHX v Isle of Wight Council
Solicitors Journal

High Court dismisses historic care home abuse claim in KHX v Isle of Wight Council

Court gives first ruling on new child sexual abuse limitation regime but rejects claimant's factual case.
Court Report31 Jul 2026
TCC refuses summary judgement in building safety remediation dispute Durkan v Wallace
Solicitors Journal

TCC refuses summary judgement in building safety remediation dispute Durkan v Wallace

Court finds repudiatory breach claim over cladding remediation too fact-sensitive for summary disposal.
Court Report31 Jul 2026
High Court refuses permission for derivative claim in Gamett v Hughes dispute
Solicitors Journal

High Court refuses permission for derivative claim in Gamett v Hughes dispute

Court finds no director would pursue claim over ownership of German subsidiary built on decades-old oral deal.
Court Report31 Jul 2026
High Court dismisses £334,000 unjust enrichment claim in AG Retail v Andron
Solicitors Journal

High Court dismisses £334,000 unjust enrichment claim in AG Retail v Andron

Summary judgement granted after court finds shopping centre buyer's enrichment was not at contractor's expense.
Court Report31 Jul 2026
Court of Appeal overturns relocation refusal and travel ban in Re S-O
Solicitors Journal

Court of Appeal overturns relocation refusal and travel ban in Re S-O

Appeal judges find welfare analysis insufficient and discharge order barring son's travel to see mother abroad.
Court Report31 Jul 2026
SJ Interview: Hannah Field
Solicitors Journal

SJ Interview: Hannah Field

Hannah Field, head of Shoosmiths’ London office and its Dispute Resolution & Litigation team in London, speaks to Solicitors Journal about the firm’s growth strategy,...
Interview28 Jul 2026
Matters of judgement
Solicitors Journal

Matters of judgement

Foreword1 Jul 2026