IMPORTANT NOTICE: FRAUDULENT EMAILS ALERT

We are aware of fraudulent emails circulating that claim to be from Taylors Legal and request payment of funds.

Please be advised we will never send our bank details via email.

To protect yourself, always speak directly to your fee earner or a member of our support team to verify any payment information.

If you have any doubts or receive a suspicious message, please contact us immediately by phone.

✕
Skip to main content

Main navigation

  • Expertise
    • Property
    • Family
    • Private Client
    • Litigation
    • Independent Legal Advice
    • Frequently Asked Questions
  • About Us
    • Our Story
    • Our Team
    • Our Values
    • Careers
  • Testimonials
  • News
  • Contact Us

Privacy Policy

1. About this Policy

This Privacy Policy explains how Taylors Legal Limited (we, us, our or the firm) collects, uses, stores and otherwise processes personal data about clients, staff, suppliers and other individuals with whom we deal.

We are required to manage personal data in accordance with our legal, regulatory and operational obligations. As a regulated law firm we take these responsibilities very seriously. This Policy reflects the law as it stands in June 2026, following the coming into force of the Data (Use and Access) Act 2025 (DUAA), which received Royal Assent on 19 June 2025 and is being phased in between June 2025 and June 2026. The DUAA amends but does not replace the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR).

We will keep this Policy under regular review and update it as the remaining DUAA provisions come into force and as further guidance is issued by the Information Commissioner’s Office (ICO).

2. Who we are

Taylors Legal Limited is the data controller for the personal data described in this Policy. Our details are:

  • Taylors Legal Limited, 184 Manor Road, Chigwell, Essex IG7 5PZ
  • Authorised and regulated by the Solicitors Regulation Authority – SRA No. 629612
  • Website: www.taylorslegal.com

We are registered with the Information Commissioner’s Office as a data controller. Our Money Laundering Compliance Officer (MLCO) is Elliott Costa, Partner and Solicitor ([email protected]).

3. Our Data Protection Manager

Our Data Protection Manager (DPM) is the contact point within the firm for any concern or question about data protection. They are authorised by us to deal with all data protection matters, including subject access requests, complaints and rectification requests.

Data Protection Manager: Nicola Daniel

  • Telephone: 0208 501 4959
  • Email: [email protected]
  • Post: Data Protection Manager, Taylors Legal Limited, 184 Manor Road, Chigwell, Essex IG7 5PZ

If you do not understand this Policy, or if you would like it provided in a different format (for example in larger print, in another language, or read aloud), please contact our Data Protection Manager and we will do our best to assist.

4. Who this Policy applies to

This Policy applies to personal data we hold about:

  • clients and former clients, and people who enquire about our services;
  • third parties involved in our matters (such as opposing parties, witnesses, professional contacts, lenders, agents and brokers);
  • beneficial owners, directors, shareholders and other persons connected to corporate clients whom we are required to identify under anti-money laundering law;
  • job applicants, our current and former employees, consultants, contractors, work experience personnel and providers of outsourced services;
  • people who make enquiries or requests under data protection law;
  • people who subscribe to our newsletter or other marketing communications; and
  • visitors to our website.

5. The Data Protection Principles

Under the UK GDPR (as amended by the DUAA) and the DPA 2018, we must comply with six core data protection principles. Personal data must be:

  • processed lawfully, fairly and in a transparent manner;
  • collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes;
  • adequate, relevant and limited to what is necessary;
  • accurate and, where necessary, kept up to date;
  • kept for no longer than is necessary; and
  • processed in a manner that ensures appropriate security.

We are accountable for, and must be able to demonstrate compliance with, all of these principles.

6. The information we collect

The information we collect depends on the role you have in relation to the firm and the nature of any work we are doing. Typically we collect and use:

  • your name and (where relevant) the names of family members or other related parties;
  • your relationship to us (for example, client, employee, opposing party, beneficial owner) and, for conflict-checking and professional reasons, your relationship to other clients;
  • your address, email address and contact telephone numbers;
  • your date of birth and gender (the latter so we can address you correctly);
  • identity verification documents (such as passport, driving licence and proof of address) collected to comply with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017) and the Proceeds of Crime Act 2002 (POCA 2002);
  • bank and payment details, source of funds and source of wealth information;
  • case-related information (including information provided through client questionnaires, instructions, correspondence, court documents, contracts and other material relevant to your matter);
  • for staff and job applicants – CVs, employment history, references, next-of-kin, bank details, GP details and other employment-related information;
  • CCTV images at our premises (where applicable) and material received from law enforcement agencies; and
  • technical information about visitors to our website, such as IP address, browser type and pages viewed (see section 13 below).

Because of the wide range of legal work we undertake, we may collect other categories of personal data in connection with a particular matter. We will only collect what is necessary for the work in question.

7. Special category and criminal-offence data

Some of the information we hold may fall within the “special categories” of personal data defined in the UK GDPR, namely information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health, sex life or sexual orientation.

We may also process information about actual or alleged criminal offences and proceedings (criminal-offence data).

We only process this data where one of the additional conditions in Article 9 UK GDPR or Schedule 1 DPA 2018 applies. In our practice the most common conditions are:

  • your explicit consent;
  • processing necessary for the establishment, exercise or defence of legal claims;
  • processing necessary for purposes of substantial public interest, including the prevention and detection of unlawful acts; and
  • processing necessary to comply with our legal and regulatory obligations as a regulated law firm (including anti-money laundering and counter-terrorism financing).

8. Why we process your data and our legal basis

Under the UK GDPR (as amended by the DUAA) we must identify a lawful basis for every processing activity. The bases we rely on are:

  • Contract – to enter into and perform the retainer with our clients, contracts with staff and supplier agreements.
  • Legal obligation – to comply with the SRA Standards and Regulations, MLR 2017, POCA 2002, the Terrorism Act 2000, tax legislation, the Companies Act 2006, employment law and other laws and regulations applicable to us.
  • Legitimate interests – to run our business efficiently and lawfully (for example, IT and network security, conflict checks, business development, client care, marketing to existing contacts, file audits and pursuing or defending claims). Where we rely on legitimate interests we carry out and record a balancing test to ensure that our interests are not overridden by your rights.
  • Recognised legitimate interests – the DUAA introduces this as a new lawful basis at Article 6(1)(ea) UK GDPR. It applies to a limited list of pre-approved public-interest purposes including the prevention, investigation and detection of crime, public security, national security and safeguarding of vulnerable individuals. We may rely on this basis when, for example, we make a Suspicious Activity Report to the National Crime Agency or share information with law enforcement bodies. Where we rely on a recognised legitimate interest we are not required to carry out a balancing test, but we still apply the data protection principles.
  • Consent – we rely on consent for certain limited activities such as direct marketing emails to non-clients and the processing of certain special category data where no other condition applies. Where we rely on consent you can withdraw it at any time by contacting our Data Protection Manager.
  • Vital interests – in rare cases, to protect the life or physical safety of you or another person.

The table below summarises the typical position for the main categories of individuals about whom we hold data. Detailed information about a particular matter will be provided in your client-care or engagement letter.

Type of individual Main lawful basis Sharing Retention
Clients and former clients Contract; legal obligation; legitimate interests; recognised legitimate interests (for AML reporting) HMRC, SRA, NCA, Legal Ombudsman, lenders, counsel, experts, courts, agents, professional indemnity insurers and others as required by the matter or by law In accordance with our Data Retention Policy – generally a minimum of 7 years from date of completion, longer for certain matters (e.g. trusts, probate, conveyancing where lender requirements apply)
Current and former staff, consultants and contractors Contract; legal obligation; legitimate interests HMRC, pension providers, payroll providers, insurers, professional regulators, where required In accordance with our Data Retention Policy
Job applicants Legitimate interests (assessing suitability); consent for retaining CVs for future opportunities Recruitment agencies and referees, where you have consented 6 months after the recruitment exercise unless you ask us to keep your details for longer
Outsourced service providers Contract; legitimate interests Not generally shared further In accordance with our Data Retention Policy
People making data protection enquiries or complaints Legal obligation; legitimate interests Not generally shared Up to 3 years from resolution of the request or complaint
Newsletter subscribers and marketing contacts Consent (non-clients); legitimate interests (existing clients within the “soft opt-in” under PECR) Email service providers acting as our processors Until you unsubscribe
Website visitors Legitimate interests; consent (for non-essential cookies) Hosting and analytics providers acting as our processors As set out in our cookie banner

9. How we collect your data

We collect personal data:

  • directly from you, in person, by telephone, by email, through our website or through documents you provide;
  • from third parties involved in a matter (for example, opposing solicitors, lenders, estate agents, brokers, accountants, family members, the Land Registry, Companies House and HMRC);
  • from publicly available sources (such as Companies House, the Land Registry, Court records, the electoral register and online searches);
  • from electronic identity verification and AML screening providers (including PEP and sanctions screening); and
  • from automated logging of website visits and email activity.

If we obtain personal data about you from a source other than you, we will, where required, tell you within a reasonable time what data we hold, where it came from, and how we will use it, unless an exemption applies (for example where doing so would prejudice the prevention or detection of crime).

10. How we share your data

We share personal data only where it is lawful and necessary to do so. The recipients fall into the following categories:

  • Other parties in your matter – opposing parties, their representatives, courts and tribunals, counsel, experts, agents, lenders, estate agents, brokers and other professional advisers.
  • Regulators and oversight bodies – the Solicitors Regulation Authority, the Legal Ombudsman, the Law Society, the Information Commissioner’s Office and HM Land Registry.
  • Law enforcement and tax authorities – the National Crime Agency (for Suspicious Activity Reports), HM Revenue & Customs, the police and other competent authorities, where required by law.
  • Service providers acting as processors – our IT and case management providers, hosting providers, cloud storage providers, electronic ID verification providers, search providers, accountants and auditors, payroll providers, marketing and email providers, and providers of artificial intelligence tools used to assist (but not replace) our professional judgement. We have written contracts in place with all our processors that comply with Article 28 UK GDPR.
  • Insurers and professional advisers – our professional indemnity insurers, brokers and their advisers, in connection with claims, notifications or audits.
  • Successors – in the event of a sale, merger or restructuring of the firm, to potential successors and their advisers under appropriate confidentiality protections.

In most cases we will tell the person whose information we hold that we are sharing it. We will not do so where to do so would prejudice the prevention or detection of crime (for example, we are prohibited by section 333A POCA 2002 from “tipping off” a person who is the subject of a Suspicious Activity Report).

11. International transfers

Our usual practice is to store personal data within the United Kingdom. From time to time, however, we may need to transfer personal data outside the UK – for example where a matter has an international element, where a service provider hosts data in the European Economic Area or another country, or where overseas counsel are instructed.

The DUAA has reworded the test for international transfers. We are required to ensure that the level of protection of the data being transferred is not materially lower than under UK data protection law. Where we transfer personal data outside the UK we will rely on one of the following safeguards:

  • a UK Government “adequacy regulation” in respect of the destination country (including, where applicable, transfers to the European Economic Area, which the European Commission has determined offers adequate protection until 27 June 2031);
  • the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or other appropriate safeguards under Article 46 UK GDPR;
  • an exception under Article 49 UK GDPR (for example, where the transfer is necessary for the performance of a contract with you or for the establishment, exercise or defence of legal claims).

Further detail on any specific transfer is available from our Data Protection Manager.

12. How long we keep your data

We will keep your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying our legal, regulatory and operational requirements.

Our Data Retention Policy sets out the retention periods that apply to our different categories of file and data. As a general guide:

  • conveyancing matters: at least 7 years from completion for sales and at least 15 years from completion for purchases;
  • wills, probate and trust files: indefinitely, in line with professional guidance, except where you tell us to destroy them;
  • commercial and other matters: at least 7 years from completion;
  • AML/CDD records: at least 5 years from the end of the business relationship or completion of the transaction (regulation 40 MLR 2017);
  • employment records: 6 years from the end of employment;
  • unsuccessful job applicants: 6 months from the end of the recruitment exercise.

After the relevant retention period has expired we will securely destroy paper records and delete or otherwise render inaccessible electronic records. Our Data Retention Policy is available on request from our Data Protection Manager.

13. Our website and cookies

When you visit our website we may collect standard internet log information, including your IP address, browser type and the pages you view. We use this information to monitor and improve the site. This information is processed in a way that does not identify any individual.

The DUAA has amended PECR to remove the requirement for explicit consent for certain low-risk “non-intrusive” cookies, including those used solely for statistical analytics, remembering user preferences (such as language or display settings) and improving the appearance or performance of a website. We still rely on consent for all other non-essential cookies (including advertising and cross-site tracking cookies), and we set strictly necessary cookies without consent as permitted by PECR.

You can manage your cookie preferences at any time through our cookie banner or by changing your browser settings. Information about how to control or delete cookies is available at www.allaboutcookies.org.

14. People who email us

Any email sent to or from the firm, including any attachments, may be monitored and used by us for reasons including IT and network security, appropriate use, prevention of malware, and compliance with our internal policies. We use email security software, encryption, and blocking software as appropriate.

Please be aware that email is not always secure. If you wish to communicate with us about a sensitive matter we are happy to use encrypted email or another secure channel – please let us know.

15. Automated decision-making, profiling and use of AI

Article 22 UK GDPR (as amended by the DUAA) restricts solely automated decisions (decisions taken without meaningful human involvement) that produce legal or similarly significant effects on you. We do not make any such decisions about you.

We do use technology to assist our work, including electronic identity verification, sanctions and PEP screening, document automation and, in some matters, artificial intelligence (AI) tools to help summarise documents, search content or generate first drafts. In each case the output is reviewed by a qualified fee-earner before any decision is taken or advice is given. No solicitor-client decision is delegated to an automated system.

If you have any concerns about our use of automated tools or AI in your matter, please raise this with the fee-earner handling your case or with our Data Protection Manager.

16. Your rights

Under the UK GDPR (as amended by the DUAA) and the DPA 2018, you have the following rights in relation to your personal data:

  • The right to be informed – to know what data we hold, why, and what we do with it. This Policy is part of how we provide that information.
  • The right of access – to obtain a copy of the personal data we hold about you (commonly called a “subject access request” or SAR). The DUAA has clarified that we are only required to carry out a reasonable and proportionate search and that the statutory “stop the clock” applies where we need to verify your identity or request clarification of your request.
  • The right to rectification – to have inaccurate data corrected or incomplete data completed.
  • The right to erasure (the “right to be forgotten”) – to ask us to delete your data. This right is not absolute. We will not be able to delete data which we need to retain to comply with a legal or regulatory obligation (for example AML records under regulation 40 MLR 2017, or limitation-period requirements for conveyancing and other matters).
  • The right to restrict processing – to ask us to pause processing of your data in certain circumstances.
  • The right to data portability – in limited circumstances, to receive certain data you have provided to us in a structured, commonly used and machine-readable format.
  • The right to object – to processing carried out on the basis of legitimate interests, and to processing for direct marketing (which we will stop on request).
  • Rights in relation to automated decision-making and profiling – see section 15 above.
  • The right to withdraw consent – where we rely on your consent, you may withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.
  • The right to complain – to us, in the first instance (see section 18 below), and to the ICO.

17. How to exercise your rights

Please direct any request relating to your rights to our Data Protection Manager (see section 3 above). We prefer requests in writing (email or post) but we are required to accept requests made in any way, including by telephone.

Where we receive a subject access request we will:

  • acknowledge your request promptly;
  • verify your identity (we accept a copy of your passport or driving licence – please do not send originals);
  • clarify the scope of your request if needed (we may stop the statutory clock while we do so);
  • carry out a reasonable and proportionate search of our records; and
  • provide our response within one month of receiving the request (or within one month of receiving the information we need to verify your identity or clarify the request). We may extend this period by up to a further two months where the request is complex or where we have received several requests from you; if we do this we will tell you why.

There is normally no fee, but we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive (for example, repetitive requests). If we refuse to act we will tell you why and explain your right to complain to the ICO.

18. How to complain to us about data protection

From 19 June 2026, the DUAA places a new statutory duty on controllers (including us) to facilitate the making of data protection complaints and to deal with them promptly. We are committed to handling all data protection complaints fairly and transparently.

If you are unhappy with how we have handled your personal data you can complain to us in any of the following ways:

  • by email to our Data Protection Manager at [email protected];
  • by post to: Data Protection Manager, Taylors Legal Limited, 184 Manor Road, Chigwell, Essex IG7 5PZ;
  • by telephone on 0208 501 4959; or
  • through any other reasonable means by which you choose to contact us, including via our website contact form.

When we receive a complaint we will:

  • acknowledge it within 30 days of receipt;
  • investigate the complaint, taking into account all the information available to us;
  • provide a substantive response without undue delay, and in any event within a reasonable period, explaining our findings and any action we propose to take; and
  • tell you about your right to complain to the ICO if you remain dissatisfied.

Making a complaint is free of charge. You do not need a solicitor or anyone else to help you make a complaint, although you may use a representative if you wish.

19. Complaining to the Information Commissioner’s Office

You have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent data protection regulator. We would, however, ask that you give us the opportunity to deal with your concerns first by following section 18 above.

The ICO can be contacted at:

  • Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
  • Telephone: 0303 123 1113
  • Website: https://ico.org.uk/

20. Changes to this Policy

We keep this Policy under regular review. The DUAA continues to be phased in and the ICO is expected to publish further guidance during the course of 2026. We will update this Policy as and when changes are made, and the latest version will be available on our website and on request from our Data Protection Manager.

This Policy was last updated in June 2026.

21. How to contact us

Data Protection Manager: Nicola Daniel

Telephone: 0208 501 4959

Email: [email protected]

Taylors Legal Limited
184 Manor Road
Chigwell
Essex IG7 5PZ

SRA No. 629612

www.taylorslegal.com

V6 – June 2026

I just wanted to personally thank you for all the hard work you’ve put in with the selling and buying. We couldn’t ask more from a solicitor. I have no doubt in my mind if we are to move again we will be using yourselves and will be recommending the company to anyone looking to move home.
Robin
Just wanted to say a huge thank you to you and the team at Taylors Legal, you were extremely efficient and helpful each time we had a question/concern so we really appreciate it.
Flutra
Thank you for Nicola and her team’s support throughout the purchasing processes. I am happy that it went smooth and my queries wereanswered in a timely manner. Really appreciated how the team worked together to minimize the impacts of COVID.
Jenny
Thank you for your assistance and ongoing support during this process. We must say that we are very pleased about the service quality, which you have been providing to us from the beginning.
Daria & Chris
We cannot thank you enough for the services that you have rendered on our behalf. From the work you did in reviewing the documents, to finding the time to explain it and following up until the purchase completion. Your prompt responses and attention to detail really meant a lot to us.
Kamal Alkhateeb
Thank you very much for all your hard work and support, we were very pleased with your professionalism at all times and would recommend you unreservedly. This is the third time I am using Taylors Legal for conveyancing.
Amit Joshi
Taylors Legal’s professional approach gave us confidence to proceed with our case from India. We were kept in loop throughout all the stages of the process in accomplishing the work successfully. We highly recommend them.
Mr Yokeshwaran and Mrs Ranganathan

You're in expert hands

020 8501 4959 [email protected]
  • Expertise
    • Property
    • Family
    • Private Client
    • Litigation
    • Independent Legal Advice
    • Frequently Asked Questions
  • About Us
    • Our Story
    • Our Team
    • Our Values
    • Careers
  • Testimonials
  • News
  • Contact Us

Taylors Legal is the trading name of Taylors Legal Limited registered in England and Wales (Company Registration No. 09974709) and is authorised and regulated by the Solicitors Regulation Authority - SRA No. 629612.

Registered Office Address: 184 Manor Road, Chigwell, Essex, England, IG7 5PZ. Company VAT No. 235194313.

A list of directors is available for inspection at our registered office.

This firm is committed to promoting equality and diversity in all of its dealings with clients, third parties and employees. We have a written Equality and Diversity Policy, a copy of which is available upon request.

  • ©Taylors Legal 2021-2026
  • Privacy Policy
  • Terms and Conditions
  • Complaints Policy
  • Data protection complaints policy
Website by NurtureIT