emailfacebookinstagrammenutwitterweiboyoutube


Managing data risks in practice

Miller Insurance Services outlines a best practices for data retention and destruction, as increasing cyber attacks and evolving regulations put law firm data under the spotlight

Miller Insurance Services||

Documents and personal data are solicitors’ stock-in-trade. The proliferation of cloud-based case management tools, and lately AI-enhanced tools covering all aspects of legal practice makes managing this data effectively more complex, but even more important. How you manage your clients’ data is of increasing interest to clients and your regulators. In an environment where cyberattacks have increased exponentially over the last three to four years, you face material risks in the event that you are not storing data appropriately securely or have held on to it beyond a timescale that is reasonable.

It is therefore important that you understand your obligations regarding client and other third party data, and apply relevant and proportionate policies in practice. This is easier said that done. You have to balance your obligations to your client, the Information Commissioner’s Office (ICO), and the Solicitor’s Regulation Authority (SRA), with your need to meet your other professional and regulatory obligations and to protect yourself and your firm in the event of a claim. There are also practical issues about tracking how and where your data is stored, which includes email folders, paper telephone notes, memory storage on devices such as copiers and printers, and legacy systems – to name but a few.

Data retention & destruction basics

To better understand where you stand in terms of data retention and destruction, it can be helpful to undertake a quick self-audit exercise. As a minimum, you should be able to answer ‘yes’ to the following four questions:

Do you:

  1. Have a policy in place which sets out clear base-line rules for document retention and destruction
  2. Have an up-to-date (annually reviewed) information audit evidencing that you know what data you store and where
  3. Properly understand your UKGDPR obligations. Indicators include:
  • Having a dedicated data protection officer
  • Using a specialist data protection consultant to advise on policies processes and documentation, and/or
  • Applying the latest ICO and Law Society guidance on Data Protection to your policies, procedures and associated documentation (client engagement letters, terms of business, etc).

4. Apply the same principles across all forms of data storage (e.g. paper files, electronic files)?

Regulatory context

UKGDPR (‘GDPR’) requires that you only process information that is adequate, relevant and not excessive. Moreover, the data processed should not be retained for longer than is necessary. Your policy on file retention, storage, and destruction should acknowledge and support enhanced data subject rights. These include the right to be forgotten, the right of access, and rights such as data portability. Clients must be made aware of these rights and how long you will store their data for.

Following the Data (Use and Access) Act 2025 (DUAA), which began coming into force in June 2025, the Information Commissioner requires firms to justify retention periods, securely delete/anonymise data when no longer needed, and update policies to align with AI. Your retention and destruction policy must not be considered in isolation. Your file management, data security policy, and third-party supplier selection criteria are all inherently connected.

Understanding your data

If firms take out cyber insurance, they are likely to be asked questions about the volume of client data they hold. Increasingly, it is being recognised that firms are significantly underestimating the data they hold, reflecting a lack of awareness of what data they are storing and where. A data mapping exercise would help you meet your regulatory reporting obligations, identify security vulnerabilities, and manage your data across your organisation. Your data mapping should capture information about what data you collect, and where it is stored. As well as what category of data it is, and why it is being collected and stored (including the legal basis for processing that data). If you are unsure where to start, it may be simplest to undertake this at a departmental/business function level initially.

Your data retention and destruction policy can then be meaningfully applied to ensure that you are only retaining the data that you need to, in accordance with your policy.

Practical problems in data management

Many firms are experiencing problems with historic data, particularly when held in legacy systems that were introduced before data management was as highly regulated – or as high on the management agenda.

Where your legacy data is unstructured, poorly labelled, or without relevant meta-data that allows you to easily assess what files need to be retained and which destroyed, options could include:

  • archiving the files into a different system for a period of time, off-network, and fully encrypted for a period until a long-stop date is reached – at which point destroying all applicable records;
  • using data-mining software solutions, where practical, to identify files and documents which may require extended retention periods;
  • reviewing other data records, (e.g. time-recording narratives) insofar as available, which may provide insights into the nature of particular files.

For more information, download our full guidance note or contact our risk manager, Calum MacLean: calum.maclean@miller-insurance.com

The information provided is for general practical and informational purposes only and is not legal advice and should not be relied upon as such. It is provided in good faith and based on our assessment as insurance brokers. We make no representation or warranty of any kind, express or implied, as to the content, accuracy, adequacy validity, reliability or completeness of any information, and to the fullest extent permissible by applicable law, disclaim all such representations or warranties and all liability in respect of actions taken or not taken based on any or all of the information provided. The content is not intended and should not be used as a substitute for taking legal advice. You should take independent legal advice if you have any particular legal queries on the information provided. 

LPM Conference 2026

LPM Conference 2026

The LPM annual conference is the market-leading event for management leaders in SME law firms

Levelling the scales

How far has the SME legal sector come on the journey to gender equality?