GDPR in the law firm: record, notices, requests and breaches
What the GDPR and Belgian law ask of a law firm, in the order the firm meets them, with the rules specific to the profession: professional secrecy, anti-money laundering, criminal data.
Updated on 7 October 2026
GDPR record of processing for a law firmThe essentials
- Always a record. Every firm keeps a written record of its processing activities (art. 30 GDPR). The exemption for organisations of fewer than 250 persons does not apply: a firm's processing is not occasional and includes sensitive and criminal data.
- Inform at intake. Clients receive a privacy notice when their data are collected, with the engagement letter (art. 13). Opposing parties and other third parties fall under art. 14 and its exemptions linked to professional secrecy.
- Reply within a month. An access request or a request about another right gets an answer within one month of receipt, which may be extended by two months (art. 12(3)).
- 72 hours for a breach. A personal data breach is notified to the Belgian DPA within 72 hours, weekend included, unless it is unlikely to result in a risk (art. 33). Every breach goes in the breach register.
- AI calls for an assessment. Before a generative AI tool is used on files, an impact assessment is in practice needed.
The record of processing activities starts from a firm's usual processing, pre-filled with the legal basis and its source.
The record of processing activities
The record names the controller and its contact details, the purposes, the categories of data subjects and of data, the recipients, the transfers outside the European Economic Area, the retention periods and a description of the security measures (art. 30(1)). It is kept in writing, including in electronic form, and provided to the Belgian DPA on request.
For a firm, the typical activities are client files, opposing parties and third parties in files, intake and conflict checks, anti-money laundering, billing and accounting, staff, the website and IT. Depending on the firm, the newsletter, CCTV, AI tools, second-line legal aid or work as an insolvency trustee or mediator are added.
Two Belgian rules complete the GDPR. For health and criminal data, the firm keeps a list of the categories of persons with access, with their function and the basis of their confidentiality (Law of 30 July 2018, arts. 9 and 10 §2). And lawyers may process criminal data insofar as the defence of their clients requires it (art. 10 §1 2°).
Each retention period has its source. A client file is kept five years after the end of the mandate: the former Civil Code then discharges the lawyer from liability and from keeping the documents (art. 2276bis). Data gathered for anti-money laundering purposes are kept ten years from the end of the business relationship, then erased (Law of 18 September 2017, arts. 60 and 62). Accounts are kept seven years (Code of Economic Law arts. III.86 and III.88), CCTV images at most one month. For recruitment, logs or the contact form, no legal rule was found: the firm sets the period and writes it down.
Informing clients and third parties
The client is informed when the data are collected, so at intake (art. 13): the firm's identity, the data protection contact, purposes and legal bases, recipients, transfers, retention, rights and the right to complain to the Belgian DPA. For a firm that handles matters under the AML law, the notice also contains the general warning due before the business relationship (Law of 18 September 2017, art. 64 §3) and says that rights are restricted for that processing (art. 65). Keep the proof: a clause in the engagement letter refers to the attached notice and its version.
For opposing parties and other persons named in a file, art. 14 applies. The firm does not inform them individually where a law provides for obtaining the data or where the data must remain confidential under professional secrecy (art. 14(5)(c) and (d)); a notice published on its website then makes the information public. The OVB recommends one notice per audience, linked from every page of the website. Since 1 September 2026, professional secrecy has been art. 352 of the new Penal Code (formerly art. 458).
The privacy notices are built from your answers, for clients, third parties and the website, in the language you choose.
Answering data subjects' requests
The period runs from the day the request reaches the firm, even if nobody has read it yet. It is computed under Regulation 1182/71: the day of receipt is not counted, the period ends on the same date of the following month or, failing that, on the last day of the month, and a last day on a Saturday, a Sunday or a Belgian public holiday moves to the next working day. A request received on Saturday 31 January 2026 must therefore be answered by Monday 2 March 2026.
Three rules come up often. A doubt about identity allows the firm to ask for information, never to refuse without asking (art. 12(6)). The first copy is free, even when the request serves a dispute (CJEU, C-307/22). And professional secrecy cannot be held against a client who asks for their own data. Towards an opposing party, the OVB accepts a refusal for data received from the client, without confirming that they exist; no Belgian DPA decision on this case was found, and it remains a decision for the lawyer. For anti-money laundering files, rights are fully restricted by law.
The data subject requests tool gives the deadline, each step of the calculation and the reply letters.
Personal data breaches: 72 hours
The 72 hours run from the moment the firm is reasonably certain that personal data were affected. They include weekends and public holidays, with no shift to the next working day, and count real hours, even across the clock change. The loss of confidentiality of data covered by professional secrecy is a damage the GDPR names expressly: losing an unencrypted laptop holding files in principle leads to a notification and to informing the clients. A strongly encrypted device whose key stayed safe in principle calls only for a register entry.
The APD's form has two parts: part 1 within 72 hours, possible without an enterprise account, and part 2 within 21 calendar days. The data breach tool computes the end of the 72 hours, suggests a risk level and prepares the register entry and the draft notification.
AI tools and the impact assessment
Each AI tool used on files is an activity in the record, with its provider, hosting and retention settings, and the privacy notice mentions it. Generative AI counts as an innovative use; on sensitive data it usually meets two criteria of the WP248 list that the Belgian DPA applies, which calls for an impact assessment. The DPIA for an AI tool prepares that document.
A data protection officer is in principle not mandatory for a sole practitioner or a typical small or medium firm: recital 91 GDPR states that the data of an individual lawyer's clients are not processed on a large scale.
What decision 99/2026 teaches
On 8 May 2026, the Litigation Chamber of the Belgian DPA ruled on a law firm. It found that the firm had never informed its clients and that its engagement letter had no clause on data. It also found that a former client's access request had been rejected on an identity "not proven" without any request for proof, that a fee had been asked for a request that was not abusive, and that professional secrecy had been invoked against the client herself. The firm had to answer the request within one month. The Normalex tools draw the lessons: a notice at intake with its version, an identity request before any refusal, a free first copy and the reminder that secrecy protects the client.
Sources
- Regulation (EU) 2016/679 (GDPR), arts. 5, 9, 10, 12 to 22, 30, 33 to 35. Checked on 7 October 2026.
- Regulation 1182/71 determining the rules applicable to periods, dates and time limits, art. 3. Checked on 7 October 2026.
- Law of 30 July 2018, arts. 9, 10 and 10/2; Law of 18 September 2017, arts. 60 to 65; former Civil Code, art. 2276bis. Checked on 7 October 2026.
- Belgian DPA, decision 99/2026 of 8 May 2026; breach notification manual, v2.0; model record. Checked on 7 October 2026.
- EDPB, Guidelines 01/2022 on the right of access and 9/2022 on breach notification; CJEU, C-307/22 of 26 October 2023. Checked on 7 October 2026.
- OVB, GDPR-wijzer: record, data subjects' rights, information and professional secrecy, data breaches. Checked on 7 October 2026.
- FPS Justice, new Penal Code in force on 1 September 2026. Checked on 7 October 2026.
A drafting aid based on the sources cited. To be reviewed and adapted by the lawyer; it is neither advice nor a guarantee of compliance.
Tools for this procedure
- GDPR record of processing for a law firmThe typical processing of a law firm, pre-filled, plus your AI tools: the Article 30 record, ready to adapt and export.
- Privacy notices for the firmNotices for clients, third parties and the website, built from your answers and Articles 13 and 14 GDPR.
- Data subject requestsAccess, erasure and other GDPR rights: the deadline to answer, identity checks, the limits of professional secrecy and the reply.
- Data breach: the 72-hour clockWhen the 72 hours end, whether to notify the DPA and the people concerned, and the drafts to send.
- DPIA for an AI toolA data protection impact assessment for an AI tool used in the firm: when it is needed, the risks and the measures.