Data protection & confidentiality
An overview of how GKB Legal handles confidentiality, security, and data protection when taking on outsourced work from law firms, so you can assess whether it fits your own compliance requirements before instructing.
GKB Legal · Last reviewed 2026
On this page
Confidentiality
Any material shared as part of an instruction — client documents, correspondence, case notes, or background context — is treated as strictly confidential. It is used only for the purpose of the specific task instructed, is not discussed or shared outside that instruction, and is not retained or reused for any other matter. A confidentiality undertaking, and a conflict check against existing and previous work, is completed before any instruction begins.
Secure devices
Work is carried out on a personal, password-protected device that is not shared with other users. The device is kept updated with current operating system and security patches, and runs up-to-date antivirus and firewall protection. Work is not carried out on public or shared computers, and files are not opened or transferred over unsecured public Wi-Fi.
Password protection
Access to devices, email, and any file-sharing or case-management tools used in connection with an instruction is protected by strong, unique passwords, with two-factor authentication enabled wherever the platform supports it. Passwords are not reused across services and are not shared with any third party.
Document security
Documents received or produced during an instruction are stored in an encrypted or access-controlled location, separate from personal files. Where a firm's own secure portal, practice management system, or file-sharing tool is available, that is used in preference to email attachments. Printed copies are avoided where possible; where necessary, they are stored securely and destroyed by cross-cut shredding once no longer needed.
Data retention & deletion
Documents and working files relating to an instruction are retained only for as long as needed to complete the task and any agreed handover, and are permanently deleted once the instructing firm confirms the work is complete — or sooner, at the firm's request. Firms are welcome to specify their own retention or immediate-deletion requirements as part of an instruction, and those instructions take precedence over the default approach described here.
Breach procedures
In the event of a suspected data breach — such as a lost device, unauthorised access, or an email sent in error — the instructing firm is notified without undue delay, along with what is known about the nature of the breach, the data or documents affected, and the steps being taken to contain it. This is treated as an immediate priority, not something batched into a later update.
Data-processing arrangements
For firms that require it, a written data-processing agreement or confidentiality agreement can be put in place before any instruction begins, setting out the basis on which documents and information will be handled, the security measures applied, retention and deletion commitments, and notification obligations in the event of a breach. Firms with their own standard-form agreements or outsourcing policies are welcome to send these to be reviewed and signed, rather than relying on a generic version.
International data transfers
Because GKB Legal operates from India, any client or case data shared as part of an instruction involves a transfer of data outside the United Kingdom. Firms should treat this as an international transfer for the purposes of their own UK GDPR obligations, and may wish to put in place appropriate safeguards — such as the UK's International Data Transfer Agreement (IDTA) or Addendum to the EU Standard Contractual Clauses — before sharing personal data. GKB Legal is willing to enter into these, or an equivalent transfer mechanism a firm prefers, as part of the data-processing arrangements above. Firms that are not able to authorise an international transfer for a particular matter should flag this before instructing, so the scope of work can be adjusted accordingly — for example, working from anonymised or redacted materials only.
Considering outsourcing a task?
Happy to discuss confidentiality and data-handling requirements before any instruction begins.
Get in touch