Introduction
This Chambers is required to comply with the law governing the management and storage of personal data, which is outlined in the General Data Protection Regulation 2016 (GDPR) and the Data Protection Act.
For this reason, the protection of personal data and respect for individual privacy is fundamental to the day-to-day operations of Chambers.
Compliance with the GDPR is overseen by the UK data protection regulator, the Information Commissioner’s Office (ICO). This Chambers is accountable to the ICO for its data protection compliance.
Purpose
This policy aims to protect and promote the data protection rights of individuals and of Chambers, by informing members and everyone working for and with Chambers, of their data protection obligations and of Chambers procedures that must be followed in order to ensure compliance with the GDPR.
Scope
This policy applies to all members of chambers, pupils, staff, consultants and any third party to whom this policy has been communicated.
This policy covers all personal data and special categories of personal data processed on computers or stored in manual (paper-based) files.
Responsibility
Clive Barrett, the Senior Finance and Operations Manager, is responsible for monitoring Chambers’ compliance with this policy.
Everyone in Chambers (and any third party to whom this policy applies to) is responsible for ensuring that they comply with this policy. Failure to do so may result in disciplinary action/termination of third-party contracts.
DATA PROTECTION MANAGER (DPM)
Chambers has appointed the Chambers Senior Finance and Operations Manager, Clive Barrett, as its Data Protection Manager (DPM). This is not a statutory role. His responsibilities within this role include:
Developing and implementing data protection policies and procedures;
GDPR
The GDPR is designed to protect individuals and personal data which is held and processed about them by Chambers or other individuals.
The GDPR uses some key terms to refer to individuals, those processing personal data about individuals and types of data covered by the Regulation. These key terms are:
Personal data Means any information relating to an identified and identifiable natural person (‘data subject’)
This includes, for example, information from which a person can be directly or indirectly identified by reference to an identifier, i.e. name, ID number, location data, online identifiers, etc.
It also includes information that identifies a person’s physical, physiological, genetic, mental, economic, cultural or social identity.
For Chambers’ purposes, Barristers’ clients and Chambers’ staff are data subjects (other individual third parties concerning whom we hold personal data about are also likely to be data subjects).
Controller means the natural or legal person, public authority, agency or other body who, alone or jointly with others, determines the purposes and means of processing the personal data. This means the controller is the individual, organisation or other body that decides how personal data will be collected and used.
For Chambers’ purposes, this Chambers is a data controller for certain categories of data.
Processing Means any operation which is performed on personal data such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
For Chambers’ purposes, everything that we do with client information (and personal information of third parties) is ‘processing’ as defined by the GDPR. This processing will often be in the capacity of a Data Processor on behalf of a Barrister as a Data Controller.
Special categories of personal data Means personal data revealing:
a) racial or ethnic origin;
b) political opinions;
c) religious or philosophical beliefs;
d) trade union membership;
e) the processing of genetic data or biometric data for the purpose of uniquely identifying a natural person;
f) data concerning health or data concerning a natural person’s sex life or sexual orientation
N.B. data relating to criminal convictions and offences is not included within the special categories. However, there are additional provisions for processing this type of data (see Regulation 10 of GDPR)
Data Protection Principles
The GDPR is based on 8 principles, which are the starting point to ensure compliance with the Regulation. Everybody working in, for and with Chambers must adhere to these principles in performing their day-to-day duties. The principles require Chambers to ensure that all personal data and sensitive personal data are:
Chambers must be able to demonstrate its compliance with (a) – (f) above (‘accountability’).
Processing personal data and sensitive personal data
You must process all personal data in a manner that is compliant with the GDPR, in short, this means you must:
You must ensure that you are aware of the difference between personal data and special categories of personal data and ensure that both types of data are processed in accordance with the GDPR.
The conditions for processing special categories of personal data that are most relevant to our Chambers are:
If you have any concerns about processing personal data, please contact Russell Burton-Lawrence, who will be happy to discuss matters with you.
Rights of the data subject
The GDPR gives rights to individuals in respect of the personal data that any organisations hold about them. Everybody working for Chambers must be familiar with these rights and adhere to Chambers’ procedures to uphold these rights.
These rights include:
If anybody receives a request from a data subject (a client or other third party concerning whom we hold personal data) to exercise any of these rights, the request must immediately be referred to Clive Barrett, Data Protection Manager, or to Isabelle Watson, Head of Chambers, in his absence.
Note: we have one month to respond to a request to access a copy of personal data.
Confidentiality and data sharing
The barristers and Chambers must ensure that they share personal information with other individuals or organisations only where they are permitted to do so in accordance with data protection law.
Wherever possible, you should ensure that you have the client’s (or other data subject’s) consent before sharing their personal data, although it is accepted that this will not be possible in all circumstances, for example, if the disclosure is required by law.
Any further questions around data sharing should be directed to Russell Burton-Lawrence.
Data Protection Impact Assessments (DPIAs)
DPIAs are required to identify data protection risks; assess the impact of these risks; and determine appropriate action to prevent or mitigate the impact of these risks when introducing or making significant changes to systems or projects involving the processing of personal data.
In simpler terms, this means thinking about whether Chambers is likely to breach the GDPR and the consequences if Chambers uses personal data in a particular way. It is also about deciding whether there is anything that Chambers can do to stop, or at least minimise the chances of any of the potential problems identified, from happening.
DPIAs will be undertaken by Clive Barrett, Data Protection Manager, or other designated persons.
Breaches
A data protection breach is defined as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”.
Breaches will be reported to the Information Commissioner’s Office (ICO) by the person who created the breach within 72 hours after having become aware of the breach unless Chambers is able to demonstrate that the personal data breach is unlikely to result in a risk to the rights and freedoms of data subjects.
Everybody working in, for and with Chambers has a duty to report any actual or suspected data protection breach without delay to Isabelle Watson, Head of Chambers and Clive Barrett, Data Protection Manager.
Hard copies of Chambers’ Data Protection Breach Reporting Procedure (DPBRP) is located in the Chambers Library, on First Floor West and in the Clerks Room on Ground Floor East. An electronic version has been emailed to every member of the chambers, pupil, and staff in any event.
The DPBRP explains how to report a breach to the ICO.
The Data Protection Manager will maintain a central register of the details of any data protection breaches.
Complaints
Complaints relating to breaches of the GDPR and/or complaints that an individual’s personal data is not being processed in line with the data protection principles should be referred to Isabelle Watson, Head of Chambers and Clive Barrett, Data Protection Manager, without delay.
Penalties
It is important that everybody working for Chambers understands the implications for Chambers if we fail to meet our data protection obligations. Failure to comply could result in:
Note: Chambers could be fined up to €20,000,000, or up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher.