This notice is addressed to individuals who are either clients of Powell Gilbert LLP or Powell Gilbert (Europe) LLP (we, our or us) in their own right, or representatives of a client (including prospective clients), visitors to our website or social media accounts, and other individuals that may deal with us, including suppliers and individuals related to a matter we are working on. We collectively refer to these categories of individuals as “you”.
If you are applying for a job, or you are a staff member of the firm, a different policy will apply, which will be provided to you.
It describes how we process that data when you deal with us, receive our services, visit our website www.powellgilbert.com (our site), interact with us via our social media accounts, complete a survey, or make a complaint.
We are
together known as Powell Gilbert.
If you have any questions about this policy, or how we process your personal data, email us at dataprotection@powellgilbert.com.
If you have a question about Powell Gilbert LLP‘s German branch office at Königsallee 2b, 40212 Düsseldorf, Germany our Local Data Protection Officer can be reached at dataprotection@powellgilbert.com or by post at the above address.
If you have a complaint, we ask you to get in touch with us as soon as you can. You can, of course, make a complaint at any time to the competent supervisory authority.
In the UK, this is the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues. You’ll find more information at https://ico.org.uk/concerns.
In Ireland, this is the Data Protection Commission (DPC). You’ll find more information at https://www.dataprotection.ie/en/contact.
In Germany, this is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW). You’ll find more information at https://www.ldi.nrw.de/kontakt.
In this notice, we refer to our clients’ transactions, disputes and other situations requiring legal advice as “matters”. “SRA” refers to the Solicitors Regulation Authority.
For the purposes of the EU General Data Protection Regulation (EU GDPR) and the UK General Data Protection Regulation (UK GDPR) we process your personal data as a controller.
We, Powell Gilbert LLP and Powell Gilbert (Europe) LLP, process your personal data in systems we share. We have concluded the necessary data protection agreement between ourselves, which ensures that your data will be processed in accordance with the law.
It is important that the personal data we hold is accurate and current. Please inform us if your personal data changes during your relationship with us.
This notice was last updated on 18 March 2026. You can obtain previous versions by contacting us.
Any changes that we make to this policy in the future will be posted on this page and, where appropriate, notified to you by email.
Our site, and information that we may post on our site or via our social media accounts, may include links to third-party websites, plug-ins and applications for your convenience and information. If you use these links, you will leave our site or our accounts. When you access a site or social media account that is owned by a third party, we do not control the content and are not responsible, or liable, for how they process your personal data. For example, they may send their own cookies to users, collect data or solicit personal data from you.
Any personal data received from you in order to comply with the applicable legislation will only be processed for the purpose of preventing money laundering or terrorist financing unless such processing is permitted by law or you consent to the alternative use of the data, as specified below.
Your name, address and other contact details
We get these from you, or your organisation. We use these for:
Information about your affairs
By this we mean information about the matter we are advising on which relates to you, including our communications with you or about you. We get this from you, other people connected with your affairs (e.g. other parties to your transactions and disputes), official sources (e.g. details of your company directorships and shareholdings from Companies House) and occasionally other public sources. We use it for:
Information we collect through your use of our website
This is personal data about the information you search for or view, your device you are using, its software, and the telephone and other unique numbers associated with it, the network you are using, and the unique address associated with your connection to the internet. We use this for presenting our website content to you in the best way and for testing and improving it, all this being necessary for ensuring its proper operation and for developing it, which we have a legitimate interest in doing.
Sensitive personal data / special categories of personal data
While it is extremely unlikely, depending on the nature of the services that we provide to you, we may collect special categories of personal data about you. This includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic data. We may also need to collect information about actual or alleged criminal convictions and offences. We will tell you how we collect this type of data, and for what purposes, at the time.
Automated decision making
We provide a very personal service and we do not make any decisions which could have a legal effect, or other significant effect on you, based solely on automated processing of your personal data.
Legal Bases
We refer to the ‘(UK/EU) GDPR’ in this notice when cited articles have the same content in both the UK GDPR and the EU GDPR. Unless a different legal basis is specified for a particular processing purpose in this section 5, the legal bases are:
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose under Article 6(4) UK/EU GDPR. If you would like to understand more about any of our purposes, please contact us. We will notify you to explain if we need to use your personal data for an unrelated purpose.
We hope that you enjoy and value our marketing material. We may send you this information by various means, including email, text message, post, telephone, or social media. We respect your right to choose what marketing messages you receive.
The legal bases for processing your personal data for marketing purposes are:
You can withdraw your consent or opt out of any marketing material that we send you at any time by clicking the unsubscribe link in our emails, unsubscribing from our social media accounts, or by contacting us.
We may ask you to confirm or update your marketing preferences over time, such as when you instruct us to provide further services in the future, or if there are changes in the law or the regulation or structure of our business.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. The maximum retention period for your matter files is twelve years after the conclusion of the engagement or your last contact with us, in line with the longest statutory and professional retention requirements applicable under German, UK and Irish law.
Where we no longer have a need or duty to keep your information, we will delete or anonymise it.
It is entirely up to you what personal data you provide, although if you withhold any relevant information our advice may be inadequate or inappropriate, or we may even have to decline to advise or continue providing our advice. However, if there is any indication of money laundering or terrorism financing by anyone, we may have to ask you for certain information and we will not be able to do any more work until you provide it. Your failure to provide it may trigger a report to the authorities. We will tell you when this is the case if we can, although the law may prevent us from doing so.
We do not generally transfer your personal data outside the UK or the European Economic Area (EEA), although we may do so for administrative reasons or on your request. Wherever we do so, we will take legally required steps to ensure that appropriate safeguards are in place to protect your personal data, and you may contact us for an explanation of the basis on which we have done so and, where relevant, to request a copy of the legal safeguards which we have put in place.
We have no control over the routes emails take, and even emails exchanged between two people in the UK could appear on equipment in countries outside the EEA, where they may not be protected by strong privacy or data protection laws. You will probably not consider this an issue, but if you have any concerns please raise them with us and we will make alternative arrangements.
Our duty to keep information about you and your affairs confidential is set by law (including the SRA’s code of conduct for solicitors). In summary, we have to keep it confidential unless: (i) we need to disclose it in the course of providing our service to you; (ii) you have given us permission to disclose it to a particular person; or (iii) the law or a rule or order of the court requires us to disclose it.
We may need to disclosure your personal data to businesses that we use to support our services, this being necessary for them to provide that service (which we have a legitimate interest in them doing). For example, we may engage sub-contractors in providing our advice, such as consultants, or engage other professionals on your behalf. We also use support service providers such as IT support, cloud storage, off-site disaster recovery, storage, archiving, shredding, payment services, call answering and conference calling, marketing and advertising services, analytics, and search and social media information and optimisation services. Those businesses have all signed confidentiality agreements which only permit them to use personal data as necessary to provide their services to us, and that their staff had made appropriate confidentiality commitments.
We may also be required to disclose your personal data to our professional indemnity insurer in relation to any actual or potential claims.
If our business, or part of it, should ever be put up for sale, or we re-structure our business, we may allow potential buyers or transferees, to have access to your personal data and matter files after they have signed confidentiality agreements which restrict their use of it to that transaction.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. This includes:
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
If you would like to know more about our data security measures please contact us.
A warning about website security
Information carried over the Internet is not secure; information can be intercepted, lost, redirected, changed and read by other people. If you need to send us personal data securely then please contact your main point of contact.
You have the right to ask us:
You also have the right:
No fee is usually required – You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee or refuse your request, if your request is clearly unfounded, repetitive or excessive.
What we may need from you – We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond – We try to respond to all legitimate requests. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
We will be pleased to discuss any of this with you.
© Powell Gilbert 18 March 2026