Whilst my primary focus as a consultant is Legal Technology for law firms, this often means that I spend time working with firms on data security, management and compliance, so having a good understanding of GDPR has been a key part of that role. When the opportunity came up to take an exam to allow me to become an approved implementor for the UK’s first ICO approved GDPR certification for providers of Legal Services – The Legal Services Operational Privacy Certification Scheme (LOCS) – I jumped at the chance.
Primarily, this is because it has long been a source of frustration that there is no clear guidance as to how firms should meet their data protection obligations – and the approach differs significantly between firms. LOCS provides a definitive outline of what procedural and technical measures should be in place. This is an extremely important step in ensuring that firms have certainty as to what is required of them and can demonstrate this to the clients and parties that they work with, through formal certification.
As this certification is also open to suppliers to providers of legal services, we also have the opportunity to protect as much of the supply chain as we can, lessening some of the due diligence burden on law firms when taking on a new supplier.
The LOCS scheme is designed to assist legal service providers demonstrate compliance with UK data protection law when processing client’s personal data. It will provide enhanced trust and confidence that personal data and data subject rights are protected. One of the key benefits provided by the certification, as set out in the standard, is that “The ICO would likely consider certification as a mitigating factor if you followed the scheme requirements and took all reasonable steps to prevent non-compliance”.
As a LOCS implementer, I will be able to offer guidance and support to legal services providers who want to apply for LOCS accreditation, providing an assessment, gap analysis and assisting with rectifying any issues.
Cathy Kirby
07388 027471
Latest Articles
Baskerville Drummond Updates – April 2024
Welcome to the latest edition of our newsletter, where we share some of our recent articles, training tips and case studies. In this issue, you will find: The pros & cons of standard and bespoke training The pain of going through Cyber Essentials Plus...
A discussion of all things AI – with Document Direct – Webinar | Thu 18 April
Save the date - Webinar A discussion of all things AI - with Document Direct - Thu 18 April @ 10.00During this webinar we will be discussing the impact of AI on the legal sector with our friends at Document Direct. We will start by defining what “AI” is and the...
Standardise or Bespoke
Have you ever attended a training session and thought “Why am I being taught something I don’t use?” or “I/my team does not work like this”. This is something that sits in the back of my mind when I am preparing for any training session. I want to make sure that...