When we say 'Brodies', 'we' or 'us' in this statement, it means Brodies LLP. Brodies LLP is the 'controller' of your personal information.
We collect, use and store different types of personal information about you, which we have grouped together as follows:
| Types of personal information | Description |
| Identity Data | ID information including your name, marital status, title, date of birth, gender and National Insurance Number |
| Contact Data | Where you live and how to contact you |
| Financial Data | Your financial position, status and history, including bank details and credit rating |
| Transactional Data | Details about payments to and from you and other details about services you purchase from us |
| Contractual Data | Information obtained by providing legal services to you |
| Communications Data | What we learn about you from letters, emails, call recordings and conversations between us |
| Social Relationships Data | Details about your family, friends and other relationships |
| Publicly Available Data | Details about you that are publicly available, such as on Companies House or elsewhere on the internet |
| Marketing Data | Details about your preferences in receiving marketing communications from us and our third parties |
| Consents Data | Any permissions, consents or preferences that you give us |
| Usage Data | Information about how you use our website, products and services |
| Special Category Data | Some types of personal information are defined as special. We will only collect and use these types of information where we need to and if the law allows us to:
|
How we use your information
If you work for an organisation which is a client of the firm or if you are a director, officer, partner, shareholder or other owner of such an organisation, we may use your personal information in the course of providing legal services to that client. The table below outlines how we use your personal information and our reasons. Where these reasons include legitimate interests, we explain what these legitimate interests are.
| What we use your information for | Our reasons | Our legitimate interests |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Where we collect your personal information from
We may collect personal information about you from the following sources:
- Directly from the organisation and the organisation’s website
- Directly from you during the course of providing legal services to the organisation
- Public registrars and public information repositories, such as Companies House and Registers of Scotland
- The internet and social networking sites such as LinkedIn
- Title and search agents for real estate work
- Intermediaries such as other professional firms who know you
- Other solicitors, intermediaries, expert witnesses, courts, adjudicators, arbiters and other that we engage (or have engaged us) in connection with the products and services that we provide to the organisation
- Market researchers
Where we decline to accept your instructions
In the event that we decline your request for Brodies to act for you, either directly as a personal client of the firm or on your behalf in relation to a corporate entity, we may retain information relating to the prospective instruction and our reasons for declining to act.
Who we share your information with
We may share your personal information with the following third parties:
- Your organisation and your colleagues within it
- Our anti-money laundering service providers, Amiqus, Credit Safe and TransUnion
- Our service providers, including providers of e-discovery and document analysis tools, data rooms and extranets used by us in the course of providing our products and services
- Other agents and service providers who we utilise in the provision of our products and services, including solicitors, counsel, intermediaries, expert witnesses, courts, law accountants, sheriff officers (or similar), third party payees, search agents and insurance brokers
- The police and other law enforcement agencies, HMRC and other government bodies where it is necessary to do so for the purpose of providing you with our services, or where we have a legal or regulatory obligation to do so
- Public registrars and public information repositries, such as Companies House and Registers of Scotland
- Relevant regulators, including the Information Commissioner's Office in the event of a personal data breach, the Scottish Legal Complaints Commission and the Law Society of Scotland and the Solicitors Regulation Authority
- Credit reference agencies and fraud prevention agencies
- Counterparties to any transaction, dispute or legal proceedings, or other matter on which we are advising your organisation
- Other professional advisors and agents engaged by your organisation
- (a) Subsidiaries or affiliates of Brodies LLP and (b) Brodies & Co (Trustees) Limited and any of its subsidiaries or affiliates
- Potential or actual purchasers of any part of our business or assets, or other third parties in the context of a possible transfer or restructuring of our business
If you have any questions on how we share your personal information with third parties then please email privacy@brodies.com.
If you choose not to give your personal information
Where we need to collect personal information from you to meet our legal obligations – for example to carry out anti-money laundering checks – or under the terms of a contract we have with your organisation and you fail to provide that data when requested, it may delay or prevent us from being able to perform the contract we have entered into with the organisation and/or comply with our own legal obligations. In some cases, we may be unable to act for the organisation or may have to withdraw from acting.
Automated decisions
We do not envisage taking any decisions about you based solely on automated processing (i.e. without human involvement), which have a legal or similarly significant effect on you.
How long we keep your personal information
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
In relation to matters in which we act for clients, we follow the guidelines issued by our regulators concerning the retention of client files which means that we will retain those files (and your personal information within them) for a basic minimum period of 10 years. In some areas of practice, such as real estate or wills, trusts and executries, the nature of the matters on which we are instructed, may require us to hold our client files (and your personal information) for longer periods because the time periods during which legal claims can arise are much longer than 10 years.
International transfers
We will only send your personal information outside the United Kingdom:
- where you ask us to
- where we are being instructed by someone outside the United Kingdom (for example, the organisation for whom you work or another law firm)
- where we need to do so to provide the legal services that you (or the organisation for whom you work) have instructed us to provide – for example, in instructing/dealing with foreign solicitors or other advisors on your organisation’s behalf
- where we need to do so in order to comply with a legal duty incumbent on us or you
- where the transfer is necessary for important reasons of public interest
- where the transfer is necessary for the establishment, exercise or defence of legal claims
- where we are using a supplier or service provider (including an expert or other professional) outside the United Kingdom.
Some of the IT systems or services that we use are hosted or provided from outside the United Kingdom or may be supported by teams located outside the United Kingdom. Where this is the case, we will usually use IT systems or services where personal information is hosted in or accessed only from countries or territories that are recognised under data protection law as providing an adequate level of protection for personal information (an approved destination) but we may process personal information in other countries or territories as well.
We may also engage experts or other professionals or service providers who host or access personal information outside the United Kingdom or an approved destination. In all cases where we process personal information outside the United Kingdom or an approved destination then we will use appropriate safeguards in accordance with the requirements of data protection law, such as a contract with the recipient that requires them to protect that information to the same standards as if the information were being processed within the United Kingdom.
The safeguards we use will depend on the location of the recipient, the function they are performing and the personal information being transferred.
Complaints
We seek to resolve directly all complaints about how we handle personal information. If you have a complaint about how your personal information has been handled, please follow our complaints process outlined here.
In your complaint, please include your name and contact details, whether you are a client or not, the nature of the complaint and any relevant documents and background information to help us make appropriate enquiries. Please also tell us the outcome you are seeking. Please note that in appropriate cases, we may need to ask you to verify your identity as part of this process, especially if you are not an existing client.
If you submitted a complaint, we will acknowledge receipt of your complaint within 2 working days and provide you with a unique customer number to quote in future correspondence.
We aim to provide you with a substantive response to your complaint within 28 days of receiving all of the information we need to understand and investigate with your complaint. If we are unable to respond within 28 days we will advise you of this as soon as possible and explain why it has not been possible to respond within that timescale.
If you remain dissatisfied, you also have the right to lodge a complaint with the UK's Information Commissioner's Office:
- Online: https://ico.org.uk/make-a-complaint/
- By phone: 0303 123 1113
- By post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF