For law firms

Data protection & confidentiality

An overview of how GKB Legal handles confidentiality, security, and data protection when taking on outsourced work from law firms, so you can assess whether it fits your own compliance requirements before instructing.

GKB Legal · Last reviewed 2026

Confidentiality

Any material shared as part of an instruction — client documents, correspondence, case notes, or background context — is treated as strictly confidential. It is used only for the purpose of the specific task instructed, is not discussed or shared outside that instruction, and is not retained or reused for any other matter. A confidentiality undertaking, and a conflict check against existing and previous work, is completed before any instruction begins.

Secure devices

Work is carried out on a personal, password-protected device that is not shared with other users. The device is kept updated with current operating system and security patches, and runs up-to-date antivirus and firewall protection. Work is not carried out on public or shared computers, and files are not opened or transferred over unsecured public Wi-Fi.

Password protection

Access to devices, email, and any file-sharing or case-management tools used in connection with an instruction is protected by strong, unique passwords, with two-factor authentication enabled wherever the platform supports it. Passwords are not reused across services and are not shared with any third party.

Document security

Documents received or produced during an instruction are stored in an encrypted or access-controlled location, separate from personal files. Where a firm's own secure portal, practice management system, or file-sharing tool is available, that is used in preference to email attachments. Printed copies are avoided where possible; where necessary, they are stored securely and destroyed by cross-cut shredding once no longer needed.

Data retention & deletion

Documents and working files relating to an instruction are retained only for as long as needed to complete the task and any agreed handover, and are permanently deleted once the instructing firm confirms the work is complete — or sooner, at the firm's request. Firms are welcome to specify their own retention or immediate-deletion requirements as part of an instruction, and those instructions take precedence over the default approach described here.

Breach procedures

In the event of a suspected data breach — such as a lost device, unauthorised access, or an email sent in error — the instructing firm is notified without undue delay, along with what is known about the nature of the breach, the data or documents affected, and the steps being taken to contain it. This is treated as an immediate priority, not something batched into a later update.

Operating location GKB Legal operates remotely from India. This is disclosed upfront precisely because it is relevant to a firm's own data protection assessment — particularly around international data transfers, addressed below — and firms are encouraged to factor this into their own compliance review before instructing.

Data-processing arrangements

For firms that require it, a written data-processing agreement or confidentiality agreement can be put in place before any instruction begins, setting out the basis on which documents and information will be handled, the security measures applied, retention and deletion commitments, and notification obligations in the event of a breach. Firms with their own standard-form agreements or outsourcing policies are welcome to send these to be reviewed and signed, rather than relying on a generic version.

International data transfers

Because GKB Legal operates from India, any client or case data shared as part of an instruction involves a transfer of data outside the United Kingdom. Firms should treat this as an international transfer for the purposes of their own UK GDPR obligations, and may wish to put in place appropriate safeguards — such as the UK's International Data Transfer Agreement (IDTA) or Addendum to the EU Standard Contractual Clauses — before sharing personal data. GKB Legal is willing to enter into these, or an equivalent transfer mechanism a firm prefers, as part of the data-processing arrangements above. Firms that are not able to authorise an international transfer for a particular matter should flag this before instructing, so the scope of work can be adjusted accordingly — for example, working from anonymised or redacted materials only.

This page describes GKB Legal's working practices and is provided for firms carrying out their own due diligence. It is not a substitute for a formal data-processing agreement, and does not constitute legal advice on a firm's own UK GDPR or data protection obligations. Firms should carry out their own assessment, and are encouraged to put a signed agreement in place before sharing personal or client data.

Considering outsourcing a task?

Happy to discuss confidentiality and data-handling requirements before any instruction begins.

Get in touch