Privacy Policy
This notice explains how Clifford Law ("we", "us", "our") collects and uses personal data. We are committed to protecting the privacy of our clients, prospective clients, visitors and correspondents in accordance with the UK GDPR and the Data Protection Act 2018.
Last updated: 21 July 2026
1. Data controller
Clifford Law of 10 Upper Bank Street, London, E14 5JJ, United Kingdom is the data controller responsible for your personal data. You can contact our data protection lead at law@cliffchancelaw.com.
2. Information we collect
We may collect and process the following categories of personal data:
- Identification and contact data (name, address, email, telephone, date of birth, nationality).
- Verification data required for anti-money-laundering and know-your-client checks, including passport, proof of address and source of funds documentation.
- Instruction data relating to the matter on which you have engaged us, including correspondence, documents and files provided by you or third parties.
- Financial data such as billing information, payment records and client account details.
- Technical data collected when you visit our website (IP address, browser type, pages viewed).
3. Lawful bases for processing
We rely on one or more of the following lawful bases:
- Contract — to perform the retainer we have entered into with you.
- Legal obligation — to comply with statutory and regulatory duties, including the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 and the SRA Standards and Regulations.
- Legitimate interests — to run our practice, manage conflicts, pursue debts and improve our services.
- Consent — where required, for marketing communications or the processing of special-category data.
4. How we share your data
We treat client information as strictly confidential. We may share personal data with: counsel and expert witnesses instructed on your matter; opposing parties and courts to the extent required to progress the matter; regulators (including the SRA, ICO and HMRC); our auditors, insurers and professional advisers; and IT and document-management providers acting as processors on our behalf. We do not sell personal data.
5. International transfers
Where matters have a cross-border element we may transfer personal data outside the United Kingdom. Any such transfer is protected by an adequacy decision, the UK International Data Transfer Agreement, or another approved safeguard.
6. Retention
We retain client files for a minimum of seven years from the conclusion of a matter, in line with SRA guidance and our professional indemnity insurance requirements. Anti-money-laundering records are retained for at least five years after the end of the business relationship. Files may be retained for longer where required by law or where the matter concerns minors, trusts or property.
7. Your rights
You have the right to access your personal data, rectify inaccuracies, request erasure (subject to our legal and regulatory retention obligations), restrict or object to processing, and to data portability. To exercise any of these rights please contact us at the address above. You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).
8. Cookies
Our website uses strictly necessary cookies to operate and, where you consent, analytics cookies to help us understand how visitors use the site. You can control cookies through your browser settings.
9. Changes
We may update this notice from time to time. Material changes will be notified to clients with an open matter.