The profession of legal advisor and attorney in relation to GDPR provisions

29 August 2019

Legal advisors and attorneys, along with notaries, are the most recognized professions of public trust. Clients entrust their representatives with many confidential pieces of information, and often even their most closely guarded secrets.

This particularly concerns lawyers acting as defenders, although not exclusively – divorce, family, and even economic proceedings also require full trust from clients in the individuals handling their cases.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
A lawyer can thus be aptly described as a trustee. It is worth noting that under the Code of Criminal Procedure, legal advisors and advocates (just like clergy) cannot be questioned as witnesses regarding facts covered by professional secrecy.

Among the many pieces of information that attorneys and defenders possess, there is also a vast amount of personal data. Their processing obliges adherence to a series of strict rules and regulations. What specific requirements are imposed on legal advisors and advocates under the GDPR and national regulations? To facilitate lawyers in conducting their activities in compliance with applicable regulations, the National Chamber of Legal Advisors, together with the Supreme Bar Council, with the participation of one of the law firms, has issued – in connection with the recent amendment of, among others, the Act on Legal Advisors and the Act on Advocacy – an updated GDPR guide for legal advisors and advocates. The most interesting topics discussed in it are presented below.

Not only GDPR

The General Data Protection Regulation allows member states to supplement EU regulations with national provisions. The Polish legislator has taken advantage of this authority by enacting not only the Act of May 10, 2018, on the Protection of Personal Data (which relates to the matter of personal data protection in a general way) but also the so-called implementation act, which came into force on May 4, 2019. This act amends 162 sectoral laws, including the Act of July 6, 1982, on Legal Advisors and the Act of May 26, 1982 – the Advocacy Law.

At first glance, it may seem that lawyers in the course of their profession will also be subject to the Act of December 14, 2018 on the protection of personal data processed in connection with the prevention and combating of crime. However, it should be emphasized that the provisions of the implementing act of the "police" directive apply, among others, to the processing of personal data within criminal proceedings exclusively by law enforcement authorities and judicial authorities, and not by professional representatives or defenders participating in such proceedings on behalf of one of the parties. Therefore, these provisions currently remain outside the scope of our interest.

Who is the data controller?

According to the division indicated by the authors of the guide regarding the processing activities conducted by legal advisors and attorneys, two categories can be distinguished:

  • data processed in connection with the provision of legal assistance,
  • data processed in connection with the operation of a law firm or company.

Considering the distinction made, the issue of the status of the data controller (ADO) in the respective areas needs to be addressed. While the fact that a legal advisor or attorney is a data controller for data processed for the purpose of running a business in the form of a law firm or company is beyond doubt, the area of processing personal data related to the provision of legal assistance raises significantly more emotions. Moving on to the analysis of the mentioned issue, it should first be pointed out that both legal advisors and attorneys can practice in forms strictly defined by the relevant industry laws. In the case of legal advisors, the bases for providing legal services are: a civil law contract, an employment relationship, or running a legal advisor's office or company. Attorneys, on the other hand, additionally have the option of operating in the form of an attorney team.

Resolving the previous doubts of representatives of doctrine and practice unequivocally, the guide posits the thesis that a legal advisor or an attorney practicing in statutorily defined forms is not a data processor in the context of processing data related to the provision of legal assistance. As an argument for this position, it is emphasized that the essence of a data processor is to be subordinate to the decisions of the data controller regarding the processing of personal data.

On the other hand, providing legal services in a manner compliant with the law and ethical principles, while simultaneously maintaining professional secrecy, requires independent decision-making by the professional representative. Furthermore, it must be concluded that following the client's instructions (acting as a data controller) by the lawyer would create a risk not only of complications in performing professional duties but also (and perhaps primarily) of violating ethical principles.

The statement by the authors of the guide deserves approval as it stands in opposition to the assertion that a legal advisor or attorney is a data processor in relation to personal data processed in the context of executing one-off assignments, which consist solely of conducting an audit or drafting a contract. However, contrary to the above, the position presented in the guide states that in the situation where lawyers provide services based on a civil law contract, the client (or another entity for which the legal advisor provides the service based on the civil law contract) holds the status of data controller and authorizes the legal advisor to process personal data.

GDPR Compliance Diagnosis - do it yourself!

Given the possibility of lawyers practicing based on an employment contract, it should be emphasized that in such a situation, the data controller is not the legal advisor but their employer, on whose authorization the lawyer acts. In this case, the legal advisor will process personal data on behalf of the controller and at their instruction. However, a debatable view, causing discord among practitioners as well as in doctrine, is the thesis presented in the guide, according to which in the case of practicing in a law firm or a partnership or civil law company, the data controller should be considered that entity, rather than the individual attorneys or legal advisors practicing within those structures.

When is the information obligation not mandatory?

The GDPR imposes an obligation on the data controller to inform individuals whose data is being processed about the details of such processing. However, considering the potential conflict and the legal advisors' and attorneys' obligation to maintain professional secrecy, professional representatives and defenders are exempted from the obligation to provide information in circumstances specified by Article 14(5)(d) of the GDPR. This pertains to situations where data has been obtained by a lawyer from a third party, such as witness data or data from the opposing party in proceedings, obtained from publicly available sources or from the client, and the confidentiality of such data must be maintained due to professional secrecy.

A similar situation arises concerning requests directed to the data controller by individuals whose data is being processed. Given the primacy of professional secrecy, the rights of individuals provided for in the GDPR are limited regarding the request for data deletion, access to information about the processing of personal data, or the provision of copies of personal data.

Professional Secrecy Above All

In addition to the aforementioned differences, which reflect the significance of professional secrecy, one cannot overlook its impact on the relationship between legal advisors and attorneys with the supervisory authority – the President of the Polish Data Protection Authority. As a result of the latest amendments to the Act on Legal Advisors and the Advocacy Act, the primacy of professional secrecy over the prerogatives of the President of the Polish DPA has been established. The obligation to maintain professional secrecy cannot be limited in any way – even in the event of the President of the Polish DPA approaching a professional representative to obtain information covered by professional secrecy, which remains inviolable in such a situation. This principle applies to every legal advisor and attorney, regardless of the form in which they practice their profession.

It should be noted that according to corporate regulations, professional secrecy encompasses all documents created by the professional representative and correspondence with the client and individuals involved in the conduct of the case – in connection with its execution, as well as information disclosed to the lawyer prior to the lawyer undertaking professional activities, if it can be presumed that the relevant assignment will be undertaken.

How Long to Retain Data?

In the amended Act on Legal Advisors and in the Advocacy Law, there are analogous provisions establishing the retention period for personal data processed in connection with the performance of the profession. This period is set at 10 years from the end of the year in which the proceedings, during which the personal data was collected, were concluded.

RODO Support
GDPR.
Support is useful
Determine the scope of support to ensure the organization’s full compliance with GDPR at optimal costs.
ORDER A QUOTE
The authors of the guide indicate that the data referred to in the aforementioned provisions should be understood as all personal data covered by procedural documents (in both paper and electronic form), as well as any other personal data collected during the provision of legal assistance in other forms – recorded in information systems and in traditional form. This also applies to drafts of documents and notes prepared by lawyers and legal advisors.

In light of the above, it should be emphasized that the designated ten-year retention period applies to data processed in connection with the ongoing proceedings. The provisions, however, do not address data processed during legal assistance provided outside of proceedings, e.g., in connection with legal advice or legal opinions. The authors of the guide point to two possible courses of action regarding data collected without connection to the proceedings:

  • adopting uniform retention periods for all personal data processed in the course of performing the profession,
  • differentiating retention periods depending on the category of the case – whether they pertain to proceedings or other matters, to which general, universally applicable deadlines for the deletion of personal data would apply.

Is it worth reaching for the GDPR guide for legal advisors and lawyers?

Finally, it is worth noting the templates of documents related to personal data protection attached to the guide, such as the authorization for processing personal data or the document appointing the Data Protection Officer. These may be useful for professional representatives.

On one hand, it is undeniable that the GDPR guide for legal advisors and attorneys dispels numerous doubts that have arisen not only among professional representatives but also in the work of specialists dealing with personal data protection. On the other hand, some of the theses put forward by the authors may be considered controversial. Which of the proposed solutions will be adopted in practice and which will be subject to verification will likely become clear in the near future.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.