Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Lawscot Foundation

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Our logo and branding

    • Equality and diversity

  1. Home
  2. For members
  3. Journal Archive
  4. Issues
  5. March 2017
  6. GDPR: Practical steps for Scottish law firms to prepare

GDPR: Practical steps for Scottish law firms to prepare

In association with Amiqus: law firms, and their business clients, should be preparing to comply with the General Data Protection Regulation from May next year
20th March 2017

From 25 May 2018, while Brexit negotiations are still ongoing, the EU General Data Protection Regulation (GDPR) will apply to every organisation that processes EU residents’ personally identifiable information, with fines of up to 4% of annual worldwide turnover for non-compliance. Since Scottish law firms deal with plenty of personally identifiable information, they’ll need to ensure they’re following the GDPR by this date.

This requirement isn’t likely to go away after the UK leaves the EU either. To trade with EU member states after Brexit, GDPR standards are likely to be a prerequisite. Therefore, it is unlikely that the UK will transpose this regulation any less rigorously.

How can your firm ensure compliance without losing time to administrative – and non-billable – work? Here are a few tips:

1. Know the rules

Make sure you’re familiar with the rules outlined in the GDPR. This overview of the regulation from the Information Commissioner's Office is a good place to start.

The Information Commissioner’s Office also has a what’s new page that constantly gets updated with the latest guidance on the regulations from the article 29 working party. Keep an eye on this page. There’s currently guidance on data portability, data protection officers, and lead supervisory authorities, but the working party is also expected to publish guidance on a number of other areas, including consent, transparency, and profiling.

2. Start early

May 2018 might still seem distant, but it’ll be here before you know it. If you don’t have measures in place to ensure transparency in how you use your clients’ personal data, you need to start planning now.

For example, can your clients access their personal data and confirm that it is being processed as agreed and with consent? Have you undertaken a data privacy impact assessment? Have you considered appointing a data protection officer? If not, start looking at systems and processes that will allow your firm to comply.

Which brings us to our final tip ...

3. Use tools

Ensuring compliance with the GDPR might seem daunting, but your firm doesn’t need to go it alone. There are plenty of tools available that can help your firm stay compliant without adding extra effort on your end.

Amiqus ID (recently added to the Law Society of Scotland’s members' benefits scheme), is a fast, secure, and reliable tool that helps you to complete anti-money laundering, identity and ongoing compliance checks. Better yet, the company has recently launched an integration with Clio, the world’s leading cloud-based legal practice management provider. Clio’s integration with Amiqus ID provides you with a compliance dashboard that already addresses the key areas that firms need to consider in preparation for the implementation of GDPR, with more features to be added for guidance as implementation progresses.

Amiqus ID compliance features include:

  • explicit consent captured from both existing clients and prospective clients;
  • data portability ensured through the possibility to export all of your clients from Clio to Amiqus ID, or from Amiqus ID to Clio;
  • subject access requests repeatable for clients who wish to review their data;
  • the right to erasure (right to be forgotten) can be implemented on client request.

With guidance and support from the market regulators, ongoing collaboration between products and a focus on the Scottish legal market, it seems certain that Scottish firms are well placed to remain both compliant and competitive in the evolving regulatory environment.

 

Share this article
Add To Favorites
https://lawware.co.uk/

In this issue

  • Ineligibility – an open and shut case?
  • Rent deposits – filling in the gaps
  • EU at the crossroads
  • Brexit: the human rights dimension
  • Reading for pleasure
  • Opinion: Andrew Lothian
  • Book reviews
  • Profile
  • President's column
  • Digital consultation closes
  • People on the move
  • Clear sky over summary courts
  • Defence submissions
  • Bookmark the benchmark
  • GDPR: Practical steps for Scottish law firms to prepare
  • Heads for business
  • Spousal visas and the income rule
  • Compete or get beat
  • Platform party
  • The consequences of excluding consequential loss
  • Understanding the other side's position
  • Family complexities
  • Unitary patent: sunrise or sunset for UK holders?
  • Third option
  • Land reform, step by step
  • Member against member?
  • Scottish Solicitors' Discipline Tribunal
  • Power of attorney update
  • The 2012 Act: a bold step forward?
  • Back to university
  • Accreditation: calling regulatory lawyers
  • Law reform roundup
  • Street Law shows the way
  • Year of big news
  • De-risking email
  • Paralegal pointers
  • Ask Ash
  • Top of the list
  • Just your luck?
  • Executries and pension overpayments

Recent Issues

Dec 2023
Nov 2023
Oct 2023
Sept 2023
Search the archive

Additional

Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited