Legal
Data Protection and Information Security Policy
Last updated
This policy describes the technical and organisational measures Standing Lawyers applies to personal data and to confidential information, whether it belongs to a client, to a person a client's matter concerns, to an applicant for a position, or to a visitor to this website. Our Privacy Policy explains what this website collects and why; this explains how information is looked after once we hold it, and what happens if something goes wrong.
1. Scope, and who this applies to
1.1 This policy applies to all personal data and confidential information in the firm's possession or control, in whatever form, including electronic records, email, paper documents and material held by any person engaged to assist the firm.
1.2 It binds the proprietor and every person who works for or with the firm, whether as employee, intern, consultant, contractor or agent. Adherence to it is a condition of access to firm systems and of any engagement to assist on a matter.
1.3 Where the firm acts on a client's instructions in relation to personal data the client controls, the firm acts as a Data Processor in respect of that data and processes it only on the client's documented instructions and on the terms of the engagement.
2. The principles we apply
2.1 Five principles govern every decision under this policy:
- Lawfulness and purpose. Personal data is processed for a specified lawful purpose, and not for a further purpose incompatible with it.
- Minimisation. We collect what the purpose requires and no more. The design of this website is the clearest expression of this: it stores no submission at all, because it does not need to.
- Accuracy. We take reasonable steps to keep personal data accurate and up to date, and to correct it when told it is wrong.
- Storage limitation. Personal data is kept for no longer than the purpose or the law requires, on the schedule in clause 6.
- Integrity, confidentiality and accountability. Personal data is protected by the measures in clause 4, and the firm remains responsible for compliance regardless of any arrangement with a processor.
3. What the firm holds
| Category | Where it is held | Notes |
|---|---|---|
| Client and matter records, including documents, advice, correspondence and due diligence records | Firm systems and the firm's mailbox | Subject additionally to the duty of confidentiality and to legal professional privilege |
| Recovery matter files, being the identity, entitlement, estate and financial documents a claim is built on: identity and address documents, permanent account numbers, folio, policy, account and member numbers, share certificates, passbooks and premium receipts, death certificates, wills and grants, succession and legal heirship certificates, and the bank details an institution will pay into | Firm systems and the firm's mailbox | The most sensitive category the firm holds, and the reason clause 4 exists. Much of it is sensitive personal data or information within the SPDI Rules, 2011, and some of it concerns people who have died and who cannot themselves object. It is never collected through this website: clause 3.2.3 of the Privacy Policy asks visitors not to send it, and clause 4 of that policy explains that the website stores nothing in any event |
| Enquiries and applications for positions | The firm's mailbox only | This website stores no copy of either. A CV is an email attachment and is never uploaded to any file store |
| Published website content, being service descriptions, notes, policies, announcements and settings | Firestore database | Not personal data, save for the firm's own contact details |
| Pseudonymous website measurement records and daily counters | Firestore database | Described in clause 3.4 of the Privacy Policy. Nobody can be identified from the counters |
| Anti-abuse records | Firestore database | A keyed one-way digest, a counter and timestamps. No recoverable address |
4. Technical and organisational measures
4.1 Access control
- Access to personal data is limited to those who need it for work in hand, and is removed when a person ceases to need it or ceases to work with the firm.
- Administrative access to this website requires an individual account. Accounts are not shared, and administrative sessions expire and must be re-established.
- Administrative functions are enforced on the server, so a restriction cannot be bypassed by manipulating the browser.
- Database security rules deny client applications any direct read or write access to enquiry, application and analytics data. Even an authenticated administrator cannot read an enquiry collection, because no such collection is written to.
4.2 Encryption and transmission
- All traffic to and from this website is served over TLS, and the website instructs browsers to refuse an unencrypted connection to it.
- Data at rest is encrypted by the hosting platforms.
- Identifiers derived from network addresses are keyed one-way digests, never the address itself, and the key is a server-side secret that the application refuses to start without in production.
4.3 Application hardening
- Responses carry security headers that prevent the site being framed by another site, prevent content type sniffing, restrict referrer disclosure, restrict access to device features, and require encrypted transport.
- All input is validated against a schema on the server, and the server's verdict is final regardless of what the browser accepted.
- Form submissions are rate limited and are screened by a hidden field that ordinary users never complete.
- Dependencies are kept current, and the application is rebuilt and redeployed when a security update requires it.
4.4 Email
- The firm's sending domain publishes SPF, DKIM and DMARC records, and the DMARC policy is set to reject, so that mail forged in the firm's name is refused rather than delivered.
- Delivery failures are surfaced rather than suppressed, because the architecture in clause 4 of the Privacy Policy means an undelivered enquiry is a lost enquiry rather than a delayed one.
4.5 Organisational measures
- Everyone given access is required to be bound in writing to confidentiality that survives the end of their engagement, before access is given.
- Any provider processing personal data for the firm is engaged on terms restricting them to the firm's instructions.
- Devices used for firm work are required to carry full disk encryption, a screen lock and current security updates, and a device that does not is not to be used for firm work.
- Firm information is not to be placed on personal file sharing or messaging accounts, and confidential material is not to be discussed on a channel that has not been agreed with the client.
- This policy and the measures under it are reviewed at least annually, and after any incident.
4.6 Artificial intelligence tools
4.6.1 The firm uses artificial intelligence tools in its legal operations work. Their use is governed by the following rules, which exist to ensure that a tool never becomes a route by which confidential information leaves the firm's control or an unreviewed output reaches a client.
- No client confidential information, and no personal data belonging to a client or to a person a matter concerns, is entered into any tool that is not engaged on terms which prohibit the provider from using it to train models and which restrict the provider to processing on the firm's instructions.
- Every output is reviewed by a lawyer before it is relied upon or reaches a client. Responsibility for advice rests with the advocate and is never delegated to a tool.
- Tools are not used to make any decision about a person.
- Where a client instructs that no such tool is to be used on their matter, that instruction is followed.
5. Personal data breaches
5.1 A personal data breach is any unauthorised access to, disclosure of, alteration of, loss of access to, or destruction of personal data that compromises its confidentiality, integrity or availability.
5.2 Anyone who becomes aware of an actual or suspected breach must report it to the Grievance Officer immediately, and in any event on the day they become aware. There is no penalty for reporting something that turns out not to be a breach, and reporting late is treated more seriously than reporting a false alarm.
5.3 On becoming aware, the firm will:
- contain the breach and preserve the evidence needed to understand it;
- assess what data, and whose, is affected, and the likely consequences for them;
- notify the affected persons without delay, describing the nature and extent of the breach, its likely consequences, the measures taken, and what those affected can do to protect themselves;
- notify the competent authority within the period the law requires, which under the Digital Personal Data Protection Rules, 2025 is an immediate intimation to the Data Protection Board on becoming aware followed by a detailed report within seventy-two hours, once those provisions commence;
- notify the client where the breach concerns a client matter, and consider whether any professional obligation to a court or regulator is engaged; and
- record the facts, the effects and the remedial action, and review what allowed the breach to happen.
5.4 A record of every breach is kept whether or not notification was required, so that patterns are visible.
6. Retention and disposal
6.1 Personal data is retained on the schedule in clause 8 of the Privacy Policy, and client matter records are retained for the period professional record-keeping, applicable limitation periods and tax law require. A file is not kept indefinitely merely because nobody has considered whether to close it.
6.2 On the conclusion of a matter, we tell the client what we hold, and return or securely destroy documents as the client directs, subject to any record we are required to retain.
6.3 Disposal is secure. Electronic records are deleted from the systems that hold them, and paper is shredded rather than discarded.
7. Requests, and responsibility for this policy
7.1 Requests about personal data are handled under clause 10 of the Privacy Policy. Complaints are handled under our Grievance Redressal Policy.
7.2 The proprietor of the firm is responsible for this policy, for the measures under it, and for the firm's compliance with data protection law, and holds that responsibility regardless of any agreement with any provider or any failure by any other person.
Effect, review and contact
A This policy takes effect on 7 August 2026 and replaces any earlier version of it published on this website. The version published here is the operative version at any given time.
B We review this policy at least once a year, and additionally whenever the law, our systems or our practice changes in a way that affects it. Where a change is material we will say so on this page and, where the change concerns personal data and we hold a means of reaching you, we will tell you directly.
C Questions about this policy, and any request or complaint arising from it, should be sent to work@standinglawyers.com, marked for the attention of the Grievance Officer where it is a complaint. We can also be reached on +91 63766 28978.
