Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Lawscot Foundation

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Our logo and branding

    • Equality and diversity

  1. Home
  2. News and events
  3. Law Society news
  4. GDPR – Do you need a data protection officer?

GDPR – Do you need a data protection officer?

24th November 2017 | Professional support | Data protection

Dr Kenneth Meechan, member of the Law Society of Scotland’s Privacy Law Committee, explains the new rules on data protection officers and sets out some important tasks which all law firms should consider.

Data Protection Officers (DPOs) have existed for as long as data protection has been on the statute books.  Originally, almost all IT staff were considering DPOs under the original Data Protection Act 1984 (“Making sure 1984 isn’t like 1984” as I once said), and they have increasingly become information law and information management specialists.

However, the appointment of a data protection officer was a matter of choice for all organisations, and many simply saw no need to do so.

The GDPR changes all that as of 25 May 2018.

What’s changing?

Article 37 of the GDPR creates a new obligation to appoint a data protection officer in one of three cases:

“(a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;

(b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or

(c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data … and personal data relating to criminal convictions and offences” – this is what you may recognise as sensitive personal data under the 1998 Act.

The first is simple enough and public bodies are all busily identifying appropriate staff for the role. 

However, for law firms, the third category in particular merits closer consideration. If your firm does criminal defence work, you will be processing a lot of personal data relating to criminal convictions and offences.  If your firm does personal injury work, then you are likely to be processing a lot of special category data under the heading of medical conditions.

Does this mean you need to appoint a data protection officer?

The short answer is the classic legal response:  it depends. 

There is some helpful (and authoritative) guidance on the role of the DPO which has been issued by the Article 29 Working Party – read the guidance on the European Commission website.

Applying the guidance to the question at hand, we are told that “‘Core activities’ can be considered as the key operations to achieve the controller’s or processor’s objectives. These also include all activities where the processing of data forms as inextricable part of the controller’s or processor’s activity.”

If you are a criminal defence firm, or a personal injury firm, you can’t do your job without processing this sort of data, so you would seem to be ticking the “core activities” box (although arguably this would also depend on the extent to which these areas of practice were indeed the core activities of the firm, as opposed to a minority activity). 

This leads us to the second limb of the test, “processing on a large scale”.  The guidance recommends that the following factors, in particular, be considered when assessing this:

  • the number of data subjects concerned - either as a specific number or as a proportion of the relevant population
  • the volume of data and/or the range of different data items being processed
  • the duration, or permanence, of the data processing activity
  • the geographical extent of the processing activity

The guidance does helpfully tell us that processing of personal data relating to criminal convictions and offences by an individual lawyer does not constitute large-scale processing, but the question is open for everyone else.

What should you do next?

Law firms might find it helpful to consult the guidance, and the terms of Articles 37 to 39 of the GDPR, and carry out a formal assessment against the criteria listed above, at the end of which you should know if you need a DPO or not. 

The Information Commissioner may disagree with your assessment down the line and order you to get one where you had decided not to bother, but the fact of having documented this assessment will go a long way to heading off regulatory action.  Such action is far more likely for those who simply haven’t bothered to do anything about this than those who have made a conscientious decision that they believed it was not required.

And if you do need a DPO, this doesn’t necessarily mean recruiting someone: the important thing is to have the relevant knowledge and expertise in data protection available when needed.  Firms with expertise in this field may see a potential growth area in terms of providing a DPO service to companies (and firms) who need a DPO but not necessarily a full time one.  Having the Law Society of Scotland’s specialist accreditation in Data Protection and FOI would seem to be an ideal qualification for this.

Dr Meechan is also chair of the accreditation panel for Data Protection and FOI -  find out more about applying for accredited specialist status.

GDPR blog

Tim Musson, Convener of the Law Society of Scotland’s Privacy Law Committee, explains why the General Data Protection Regulation (GDPR) is all-important for law firms.

GDPR Personal data breaches

Anna Drozd, policy adviser on professional issues at our Brussels Office, explains what personal data breaches are and how to report them under the GDPR.

GDPR legal basis and why it matters

Carolyn Thurston Smith, policy executive at the Law Society of Scotland, explains the legal bases in article 6 of the General Data Protection Regulation (GDPR).

GDPR changes to consent

Domhnall Dods, regulatory solicitor and GDPR expert at Towerhouse and member of the Law Society’s Privacy Law Committee, explains the changes to rules around consent in the General Data Protection Regulation (GDPR).

GDPR

Our guide to data protection from the perspective of a legal practice

Read more about GDPR
Add To Favorites

Additional

Categories

  • New lawyers
  • Law Society news
  • Regulation
  • Research and policy
  • Legal aid
  • Professional support
  • Wellbeing
  • Business support
  • Equality and diversity
  • International
  • In-house lawyers
  • Schools
  • For the public
  • Videos
  • Fraud alerts
  • Career growth
  • Member benefits
  • Law and technology
  • Professional skills courses
  • Aberdeen
  • Edinburgh
  • Glasgow
  • Perth
  • Inverness
  • Commercial skills for young professionals
  • Roadshow
  • CPD event
  • Working in-house
  • Public Policy Committee
  • Roadshows
  • careers
  • property (non-commercial)
  • licensing
  • Journal online news
  • Sustainability
  • Policy committees

News Archive

  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015
  • 2014
  • 2013

Related articles

  • Law Society members reach new career heights
  • New partnership bolsters Law Society sustainability commitment
  • Spring celebrations for newly accredited Law Society members
  • Celebrations at first banking and finance paralegal accreditation
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited