Client Data Protection Information Notice
1. introduction
Bloom Budd LLPThis document sets out the obligations of AFP Bloom LLP (our Firm) regarding data protection and your rights as our client (data subjects) in respect of your personal data under the UK General Data Protection Regulation (GDPR) which sits alongside The Data Protection Act 2018 (DPA 2018).
We take your privacy very seriously. Please read this privacy notice carefully as it contains important information on who we are and how and why we collect, store, use and share your personal data. It also explains your rights in relation to your personal data and how to contact us or supervisory authorities in the event you have a complaint.
The UK GDPR defines “personal data” as any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
This document sets our Firm’s obligations regarding the collection, processing, transfer, storage, and disposal of your personal data. Our Firm has implemented procedures and policies for our employees, agents, contractors, or other parties working on behalf of our Firm to follow at all times.
Our Firm is committed not only to the letter of the law, but also to the spirit of the law and places high importance on the correct, lawful, and fair handling of all personal data, respecting the legal rights, privacy, and trust of all individuals with whom it deals.
2. Lawful, Fair, and Transparent Data Processing
The UK GDPR seeks to ensure that personal data is processed lawfully, fairly, and transparently, without adversely affecting your rights as the data subject.
As you are a client of our Firm and have contracted with us to provide you with the necessary legal assistance, under the UK GDPR we are allowed to process your personal data as a necessity for the performance of the contract.
We collect and use your personal data to provide legal services. If you do not provide personal data we ask for, it may delay or prevent us from providing those services.
3. The Data Protection Principles
The UK GDPR sets out the following principles with which any party handling personal data must comply. All personal data must be:
• Processed lawfully, fairly, and in a transparent manner in relation to the data subject.
• Collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes.
• Adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
• Accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased, or rectified without delay.
• Kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed. Personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to the implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of the data subject.
• Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.
4. keeping you informed
Our Firm shall provide the information set out below to every client:
Where your personal data is collected directly from you, you will be informed of its purpose at the time of collection; and
Where your personal data is obtained from a third party, you will be informed of its purpose:
• If the personal data is used to communicate with you, when the first communication is made; or
• If the personal data is to be transferred to another party, before that transfer is made; or
• As soon as reasonably possible and in any event, not more than one month after the personal data is obtained
5. how your personal data is collected
We collect most of this information from you, direct. However, we may also collect information:
• From publicly accessible sources, eg Companies House orHM Land Registry
• Directly from a third party, eg:
• Sanctions screening providers
• Creditreference agencies
• Client due diligence providers
• From a third party with your consent, e.g.:
• Your bank or building society, another financial institution or advisor
• Consultants and other professionals we may engage in relation to your matter
• Your employer and/or trade union, professional body or pension administrators
• Your doctors, medical and occupational health professionals
• Via our website - we use cookies on our website(for more information on cookies, please see our Cookie Policy on our website
• Via our information technology (IT) systems
6. How and Why We Use Personal Data
Under data protection law, we can only use your personal data if we have a proper reason, e.g.:
• Where you have given consent
• To comply with our legal and regulatory obligations
• For the performance of a contract with you or to take steps at your request before entering into a contract; or
• For our legitimate interests or those of a third party
A legitimate interest is when we have a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. We will carry out an assessment when relying on legitimate interests, to balance our interests against your own.
The table below explains what we use your personal data for and why.
What we use your personal data for
Our reasons
Providing services to you
To perform our contract with you or to take steps at your request before entering into a contract
Preventing and detecting fraud against you or us
For our legitimate interest, ie to minimise fraud that could be damaging for you and/or us
Conducting checks to identify our clients and verify their identityScreening for financial and other sanctions or embargoesOther activities necessary to comply with professional, legal and regulatory obligations that apply to our business, eg under health and safety law or rules issued by our professional regulator
To comply with our legal and regulatory obligations
To enforce legal rights or defend or undertake legal proceedings
Depending on the circumstances:
• to comply with our legal and regulatory obligations
• in other cases, for our legitimate interests, ie to protect our business, interests and rights
Gathering and providing information required by or relating to audits, enquiries or investigations by regulatory bodies
To comply with our legal and regulatory obligations
Ensuring policies are adhered to, eg policies covering security and internet use
For our legitimate interests, ie to make sure we are following our own internal procedures so we can deliver the best service to you
Operational reasons, such as improving efficiency, training and quality control
For our legitimate interests, ie to be as efficient as we can so we can deliver the best service to you at the best price
Ensuring the confidentiality of commercially sensitive information
Depending on the circumstances:
• for our legitimate interests, ie to protect trade secrets and other commercially valuable information
• to comply with our legal and regulatory obligations
Statistical analysis to help us manage our business
For our legitimate interests, ie to be as efficient as we can so we can deliver the best service to you at the best price
Preventing unauthorised access and modifications to systems
Depending on the circumstances:
• for our legitimate interests, ie to prevent and detect criminal activity that could be damaging for you and/or us
• to comply with our legal and regulatory obligations
Protecting the security of systems and data used to provide services
To comply with our legal and regulatory obligations. We may also use your personal data to ensure the security of systems and data to a standard that goes beyond our legal obligations, and in those cases our reasons are for our legitimate interests, ie to protect systems and data and to prevent and detect criminal activity that could be damaging for you and/or us
Depending on the circumstances:
• to perform our contract with you or to take steps at your request before entering into a contract
• to comply with our legal and regulatory obligations
• for our legitimate interests, eg making sure we can keep in touch with our clients about existing and new services
To comply with our legal and regulatory obligations
Ensuring safe working practices, staff administration and assessments
Depending on the circumstances:
• to comply with our legal and regulatory obligations
• for our legitimate interests, eg to make sure we are following our own internal procedures and working efficiently so we can deliver the best service to you
Marketing our services to:
• existing and former clients
• third parties who have previously expressed an interest in our services
• third parties with whom we have had no previous dealings
For our legitimate interests, ie to promote our business to existing and former clients
Credit reference checks via external credit reference agencies where applicable
For our legitimate interests, ie to ensure our clients are likely to be able to pay for our services
External audits and quality checks
Depending on the circumstances:
• for our legitimate interests, ie to maintain our accreditations so we can demonstrate we operate at the highest standards
• to comply with our legal and regulatory obligations
To share your personal data with members of our group and third parties that will or may take control or ownership of some or all of our business (and professional advisors acting on our or their behalf) in connection with a significant corporate transaction or restructuring, including a merger, acquisition, asset sale or in the event of our insolvency. In such cases information will be anonymised where possible and only shared where necessary
Depending on the circumstances:
• to comply with our legal and regulatory obligations
• in other cases, for our legitimate interests, ie to protect, realise or grow the value in our business and assets
7. How and Why We Use Your Personal Data — Special
Certain personal data we collect is treated as a special category to which additional protections apply under data protection law:
• Personal data revealing racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs or trade union membership
• Genetic data
• Biometric data (when used to uniquely identify an individual)
• Data concerning health, sex life or sexual orientation
Where we process special category personal data, we will also ensure we are permitted to do so under data protection laws, e.g. :
• We have your explicit consent
• The processing is necessary to protect your (or someone else’s) vital interests where you are physically or legally incapable of giving consent; or
• The processing is necessary to establish, exercise or defend legal claims
8. Sharing of personal data
During our retainer with you we may share your information with the following entities:
• Courts and Tribunals
• Experts required to advise or provide reports
• Barristers & Barristers Chambers
• Accountants
• Our Professional Advisors
• Opposing Lawyers and representatives
• Solicitors Regulation Authority
• Legal Ombudsman
• Banks and Lenders
• Mediation and Arbitration service providers
• Government Bodies
• Auditors
• IT support, Infrastructure and System providers
• Employees of the Firm
• Contractors to the Firm working on your matter
• Postal Service Providers, including Couriers
• Insurers and Brokers
• HM Land Registry
• Other third parties we use to help us run our business, e.g.marketing agencies or website hosts
• Third parties approved by you, eg social media sites you choose to link your account to or third party payment providers
• Credit reference agencies and card payment providers
• Our external auditors, e.g. in relation to the audit of our accounts or files, or systems and processes
• Other parties that have or may acquire control or ownership of our business (and our or their professional advisers) in connection with a significant corporate transaction or restructuring, including a merger, acquisition or asset sale or in the event of our insolvency, usually, information will be anonymised but this may not always be possible. The recipient of any of your personal data will be bound by confidentiality obligations
Where we outsource to third party providers, we only allow those organisations to handle your personal data if we are satisfied they take appropriate measures to protect your personal data. We also impose contractual obligations on them to ensure they can only use your personal data to provide services to us and to you.
9. Marketing
We will use your personal data to send you updates (by email, text message, telephone or post)about our services, including exclusive offers, promotions or new services.
We have a legitimate interest in using your personal data for marketing purposes. This means we do not usually need your consent to send you marketing information. If we change our marketing approach in the future so that consent is needed, we will ask for this separately and clearly. You have the right to opt out of receiving marketing communications at any time by notifying us in writing by email.
We may ask you to confirm or update your marketing preferences if you ask us to provide further services in the future, or if there are changes in the law, regulation, or the structure of our business.
We will always treat your personal data with the utmost respect and never sell OR share it with other organisations for marketing purposes.
10. Personal Data Collected, Held, and Processed
The following personal data is collected, held, and processed by our Firm
data ref
type of data
purpose of data
To send communication via email
Your mobile telephone number
To communicate with you by phone and/or by text
To identify you and comply with Anti-money laundering regulations – where applicable
Your driving licence details
To identify you and comply with Anti-money laundering regulations – where applicable
To identify you and comply with Anti-money laundering regulations – where applicable
Matter history and associated information
Information relating to the matter in which you are seeking our advice or representation
Your finance/credit information
Information to enable us to undertake a credit or other financial checks on you
Your financial information
Your financial details so far as relevant to your instructions, eg the source of your funds if you are instructing on a purchase transaction
Your access to our communication systems
Information about your use of our IT, communication and other systems, and other monitoring information
11. Personal Data Collected for Compliance with the Firm’s Regulatory Responsibilities
Pursuant to Regulation 41of The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 and The Money Laundering and Terrorist Financing(Amendment) Regulations 2019, the Firm will not use any personal data provided for the purpose of complying with the regulation for any purpose other than for the prevention of money laundering or terrorist financing.
12. Where Your Personal Data Is Held
Personal data may be held a tour offices and those of our third party agencies, service providers, representatives and agents as described above (see ‘Sharing of Personal Data’).
13. How Long Your Personal Data Will Be Kept For
We will not keep your personal data for longer than we need it for the purpose for which it is used or as agreed with you.
As a general rule, if we are no longer providing services to you, we will delete or anonymise your account data after seven years. However, different retention periods apply for different types of personal data and for different services as set out in out Client Care letter and Terms and Conditions.
Following the end of the of the relevant retention period, we will delete or anonymise your personal data.
14. Transferring Your Personal Data Out of the UK The EEA and other countries outside the UK and the UK have differing data protection laws, some of which may provide lower levels of protection of privacy.
It is sometimes necessary for us to transfer your personal data to countries outside the UK. In those cases we will comply with applicable UK laws designed to ensure the privacy of your personal data.
Under data protection laws, we can only transfer your personal data to a country outside the UK where:
i. In the case of transfers subject to UK data protection law, the UK government has decided the particular country ensures an adequate level of protection of personal data(known as an ‘
adequacy regulation’) further to Article 45 of the UKGDPR. A list of countries the UK currently has adequacy regulations in relation to is available
here.
ii. In the case of transfers subject to EEA data protection laws, the European Commission has decided that the particular country ensures an adequate level of protection of personal data (known as an ‘
adequacy decision’) further to Article 45 of the EU GDPR.A list of countries the European Commission has currently made adequacy decisions in relation to is available
here.
iii. There are appropriate safeguards in place, together with enforceable rights and effective legal remedies for you; or
iv. A specific exception applies under relevant data protection law.
Where we transfer your personal data outside the UK, we do so on the basis of an adequacy decision. In the event we cannot or choose not to continue to rely on either of those mechanisms at any time, we will not transfer your personal data outside the UK unless we can do so on the basis of an alternative mechanism or exception provided by UK data protection law and reflected in an update to this notice.
Any changes to the destinations to which we send personal data or inthe transfer mechanisms we rely on to transfer personal data internationallywill be notified to you in accordance with the section on ‘
Changes to this Privacy Notice’ below.
15. Transferring Your Personal Data Outof the UK - Further Information
If you would like further information about data transferred outside the UK, please contact us.
16. Your Rights (As a Data Subject)
The UK GDPR sets out the following rights applicable to data subjects (please refer to the parts of this notice indicated for further details):
• The right to be informed
• The right of access
• The right to rectification
• The right to erasure (also known as the ‘right to be forgotten’)
• The right to restrict processing
• The right to data portability
• The right to object
• Not to be subject to automated individual decision making
• The right to withdraw consent
17. Data Subject Access Requests You may make
Subject Access Requests (“SARs”) at any time to find out more about the personal data that our Firm holds about you, what it is doing with that personal data, and why.
If you wish to make a SAR you may do so in writing. SARs should be addressed to the Firm's
Data Compliance Manager, who is
William Healing. You should send your request by: email to william.healing@afpbloom.com or post to 106-108 Wigmore Street, London, W1U 3LR. Responses to SARs shall normally be made within one month of receipt, however, we may extend by up to two months if the SAR is complex and/or numerous requests are made. If such additional time is required, you shall be informed.
All SARs received shall be handled by the Firm’s
Data Compliance Manager. Our Firm does not charge a fee for the handling of normal SARs. However, we reserve the right to charge reasonable fees for additional copies of information that has already been supplied to you, and for requests that are manifestly unfounded or excessive, particularly where such requests are repetitive.
18. Rectification of Personal Data
You have the right to require us to rectify any of your personal data that is inaccurate or incomplete.
Our Firm shall rectify the personal data in question, and inform you of that rectification, within one month of you informing our Firm of the issue. The period can be extended by up to two months in the case of complex requests. If such additional time is required, you shall be informed.
In the event that any affected personal data has been disclosed to third parties, those parties shall be informed of any rectification that must be made to that personal data.
19. Erasure of Personal Data
You have the right to request that our Firm erases the personal data it holds about you in the following circumstances:
• It is no longer necessary for our Firm to hold your personal data with respect to the purpose(s) for which it was originally collected or processed
• You wish to withdraw your consent to our Firm holding and processing your personal data
• You object to our Firm holding and processing your personal data (and there is no overriding legitimate interest to allow our Firm to continue doing so)
• The personal data has been processed unlawfully
• The personal data needs to be erased in order for our Firm to comply with a particular legal obligation.
Unless our Firm has reasonable grounds to refuse to erase personal data, all requests for erasure shall be complied with, and you will be informed of the erasure, within one month of receipt of your request. The period can be extended by up to two months in the case of complex requests. If such additional time is required, you shall be informed.
In the event that any personal data that is to be erased in response to your request has been disclosed to third parties, those parties shall be informed of the erasure (unless it is impossible or would require disproportionate effort to do so).
20. Restriction of Personal Data Processing
You may request that our Firm ceases processing the personal data it holds about you. If you make such a request, our Firm shall retain only the amount of personal data concerning you (if any) that is necessary to ensure that the personal data in question is not processed further.
In the event that any affected personal data has been disclosed to third parties, those parties shall be informed of the applicable restrictions on processing it (unless it is impossible or would require disproportionate effort to do so).
21. Objections to Personal DataProcessing
You have the right to object to our Firm processing your personal data based on legitimate interests and direct marketing (including profiling).
Where you object to our Firm processing your personal data based on its legitimate interests, our Firm shall cease such processing immediately, unless it can be demonstrated that the Firm’s legitimate grounds for such processing override your interests, rights, and freedoms, or that the processing is necessary for the conduct of legal claims.
Where you object to our Firm processing your personal data for direct marketing purposes, our Firm shall cease such processing immediately.
22. Withdrawing consentIf you have provided us with a consent to use your personal data you have a right to withdraw that consent easily at any time.
You may withdraw consents by contacting our
Data Compliance Manager via
email to william.healing@afpbloom.com or post to 106-108 Wigmore Street, London, W1U 3LR. Withdrawing a consent will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn.
24. keeping your personal data secure
We have appropriate security measures to prevent personal data from being accidentally lost, or used or accessed unlawfully. We limit access to your personal data to those who have a genuine business need to access it. Those processing your personal data will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
25. How to complainPlease contact us if you have any queries or concerns about our use of your personal data (see below ‘
How to Contact Us’). We hope we will be able to resolve any issues you may have.
You also have the right to lodge a complaint with the The Information Commissioner in the UK;
The UK’s Information Commissioner may be contacted using the details at
https://ico.org.uk/make-a-complaint or by telephone: 0303 123 1113
26. changes to this notice
We may change this notice from time to time, if we do we will inform you.
27. how to contact us
You can contact us and/or our Data Compliance Manager by post, email or telephone if you have any questions about this notice or the information we hold about you, to exercise a right under data protection law or to make a complaint. Details of how to contact us can be found on our website - https://www.afpbloom.com/
GO BACK