Guide · Updated 2026-08-08

GDPR Compliance Guide for Law Firms

Law firms process some of the most sensitive personal data there is: health records in personal injury files, financial data in corporate work, criminal-history data in defence matters. This guide explains what the GDPR requires of a law firm as a controller, how to evaluate the legal tech you use, and how Nomoaxis is built so that practice management does not become your weakest compliance link.

1. Your firm is the controller, your software is a processor

Under Article 4 GDPR, the firm decides why and how client personal data is processed, so the firm is the controller. A practice management platform that stores matter files on your instruction is a processor. That split matters: obligations such as lawfulness, transparency, retention and responding to data-subject requests stay with the firm, while the processor must act only on documented instructions and offer sufficient guarantees under Article 28.

Practically, this means every vendor that touches client data needs a written data processing agreement. Nomoaxis publishes its Data Processing Agreement with a full sub-processor list, so you can attach it to your records rather than negotiate one from scratch.

2. The obligations that actually bite in legal practice

RequirementWhat it means for a firmWhere it usually fails
Art. 6 & 9 — lawful basisMost client data rests on contract or legitimate interests; special-category data (health, criminal matters) needs an Article 9(2)(f) legal-claims basis.No written note of the basis for special-category files.
Art. 13/14 — transparencyClients and opposing parties must be told how their data is used.Engagement letters that omit retention periods and sub-processors.
Art. 15–22 — data-subject rightsAccess, rectification and erasure requests must be answered within one month.Data scattered across email, desktops and shared drives, so nobody can find it all.
Art. 30 — record of processingA written register of processing activities, purposes, categories and recipients.Never created, or last updated before the current toolset.
Art. 32 — security of processingEncryption, access control, resilience, and regular testing.Shared logins and client files in personal cloud accounts.
Art. 33/34 — breach notificationNotify the supervisory authority within 72 hours of becoming aware.No detection or logging, so the clock starts late.
Art. 28 & 44 — processors and transfersDPAs with every vendor; a transfer mechanism for anything leaving the EEA.US-hosted tools adopted by one team without review.

3. Professional secrecy sits on top of the GDPR

Legal professional privilege and national bar rules are separate from, and often stricter than, the GDPR. In Greece, the Code of Lawyers imposes confidentiality independently of data protection law; across the EU, Article 90 GDPR lets member states restrict supervisory-authority powers where privilege applies. The upshot: a tool can be GDPR-compliant on paper and still be unacceptable if it exposes file contents to vendor staff.

This is why Nomoaxis is designed so that no Nomoaxis employee has access to your matter files. Files are encrypted at rest and in transit, and access is scoped to your firm's own authenticated users.

4. Data residency and international transfers

Chapter V GDPR restricts transfers outside the EEA. Since Schrems II, using a US-hosted service means running a transfer impact assessment and relying on Standard Contractual Clauses plus supplementary measures — a real burden for a small firm. Keeping data in the EU removes the question entirely.

  • Where is the data stored? Nomoaxis hosts firm data in the EU.
  • Who are the sub-processors, and where do they sit? Ours are listed in the DPA and the Privacy Policy.
  • Is support access remote from a third country? Ask every vendor; support tooling is a transfer too.
  • Are backups in the same region? Backups follow the same residency rules as live data.

5. Retention: the obligation firms most often get wrong

Article 5(1)(e) requires storage limitation, but professional and tax rules require firms to keep files for years after a matter closes. The answer is not to keep everything forever — it is a written retention schedule per document category, with a defensible trigger date (usually matter closure) and a deletion step that actually runs.

A practice management system helps here only if closure is a real state in the system rather than a folder convention. In Nomoaxis, matters carry phases and status, so retention can be measured from a recorded closure date instead of a guess.

6. Access control, audit and the 72-hour clock

  • Named accounts, never shared logins. Article 32 accountability depends on knowing who did what.
  • Least privilege by role. Not every seat needs billing or client-wide visibility.
  • Audit trail. Without logs you cannot establish scope during a breach, and the 72-hour notification window does not pause while you investigate.
  • Conflict checks and ethical walls. Restricting internal access to a matter is both a professional-conduct and a data-minimisation control.
  • Offboarding. Revoking a departing lawyer's access is a security measure under Article 32, not an IT chore.

7. AI features and the GDPR

AI assistance in legal work raises two distinct questions: whether client data is used to train third-party models, and whether the output is reviewed by a lawyer. Article 22 concerns fully automated decisions with legal effect; drafting assistance reviewed by a professional does not fall there, but the processing still needs a basis, a DPA with the model provider, and transparency toward the client.

  • Confirm in writing that prompts and documents are not used to train the provider's models.
  • Check where inference happens and whether it constitutes a third-country transfer.
  • Keep a human-in-the-loop record: AI output in legal work is a draft, not a decision.
  • List the model provider as a sub-processor in your Article 30 register.

Nomoaxis names its AI sub-processors in the DPA, and AI features operate on your matter data only when you invoke them.

8. A practical checklist

  • Maintain an Article 30 record listing each processing activity, purpose, data category, recipient and retention period.
  • Hold a signed DPA with every processor — practice management, email, storage, accounting, e-signature, AI.
  • Write a retention schedule per document type and run deletion on a real trigger.
  • Use named accounts with role-based access and review permissions quarterly.
  • Keep an incident procedure that names who assesses a breach and who notifies within 72 hours.
  • Update engagement letters and privacy notices to reflect the tools actually in use.
  • Run a DPIA for large-scale special-category processing, such as mass-claim or medical litigation.
  • Prefer EU hosting to avoid transfer impact assessments altogether.

9. What to ask a legal tech vendor

  • Where is data stored and backed up, and can it leave the EU for support?
  • Can you provide a DPA and a current sub-processor list without negotiation?
  • Is data encrypted in transit and at rest, and can vendor staff read matter files?
  • How is access controlled, and is there an audit trail?
  • What happens to our data on termination — export format and deletion timeline?
  • Are client documents ever used to train AI models?

Nomoaxis answers each of these publicly: see Security for the technical measures, the Privacy Policy for what we process, and the DPA for contractual terms and sub-processors.

10. Disclaimer

This guide is general information about data protection practice in law firms. It is not legal advice and does not create a lawyer–client relationship. Verify obligations against the GDPR, your national implementing law and your bar's rules of professional conduct.