Privacy Policy – Legal Advisor

Legal Advisor — Malone & White Solicitors Ltd

Privacy Policy

This policy explains how Malone & White Solicitors Ltd, trading as Legal Advisor, collects, uses, stores and protects your personal data. We are committed to handling your information responsibly, transparently and in full compliance with UK data protection law.

Version 2.0 Last updated: July 2026 ICO registration: ZA543515 Governed by UK GDPR and the Data Protection Act 2018
⚠ Legal review required before publishing This document contains amber flagged sections marked [CONFIRM WITH MAVISH SHAH]. These are areas where the firm's specific practices, third-party arrangements, retention periods or technical setup must be verified before the policy is published. Publishing inaccurate information in a privacy policy is itself a UK GDPR breach. Mavish Shah (Legal Director, COLP and COFA) should review and approve the final version.

1. Who we are

Data controller: Malone & White Solicitors Ltd, trading as Legal Advisor.

Registered address: Nr 2 Fletcher Street, Unity House, Bolton, England, BL3 6NE.

Company number: 11863106 (registered in England and Wales).

SRA registration: 659436 — authorised and regulated by the Solicitors Regulation Authority.

ICO registration: ZA543515.

Responsible person for data protection: Mavish Shah, Legal Director and Compliance Officer for Finance and Administration (COFA).

Contact for data matters: info@legaladvisor.co.uk / 01204 939470.

This policy applies to all personal data processed by Malone & White Solicitors Ltd through the website legaladvisor.co.uk, through our telephone and email communications, and in the course of providing legal services to clients.

As an SRA-regulated firm, our data processing obligations extend beyond UK GDPR and the Data Protection Act 2018. We are also subject to the SRA Standards and Regulations, which require us to keep client information confidential except where disclosure is required or permitted by law or with client consent.

2. Personal data we collect

We collect and process the following categories of personal data:

Identity and contact data

  • Full name, preferred name
  • Postal address
  • Email address
  • Telephone number(s)
  • Date of birth (where required for identity verification or eligibility assessment)

Financial data

  • Bank account details (where required to pay compensation to you)
  • Financial product details (for undisclosed commission / car finance claims)
  • Income and expenditure information (where relevant to your matter)

Matter and case data

  • Details of your legal matter, claim or dispute
  • Correspondence relating to your matter, including with third parties
  • Documents you provide in support of your case
  • Evidence gathered on your behalf (survey reports, medical records, expert opinions)

Technical and website data

  • IP address and device information
  • Browser type and version
  • Pages visited and time spent on our website
  • Referring website or advertisement
  • Cookie data (see Section 10)

Communications data

  • Records of telephone calls (which may be recorded)
  • Email and letter correspondence
  • Form submissions

3. Special category and criminal offence data

Some of the services we provide require us to process data that attracts heightened protection under UK GDPR. We process these categories only where strictly necessary for the services you have instructed us to provide, and with your explicit consent where required.

Health data (Article 9 UK GDPR)

We process health and medical data in the following service contexts:

  • Industrial deafness claims: audiogram results, GP records, ENT specialist reports and hearing assessment outcomes.
  • Housing disrepair claims: medical evidence relating to health conditions caused or exacerbated by the disrepair (respiratory conditions, mould-related illness, etc.).
  • Criminal injury claims: medical evidence of physical and psychological injuries sustained as a result of a crime, including psychiatric assessments.

Our lawful basis for processing this data is explicit consent (Article 9(2)(a)) combined with processing necessary for the establishment, exercise or defence of legal claims (Article 9(2)(f)).

Criminal convictions and offences data (Article 10 UK GDPR)

We process criminal offence data in the following service contexts:

  • Criminal defence: details of allegations, charges, previous convictions and court proceedings.
  • Criminal injury claims: information about the crime and any convictions (of either the victim or the offender) relevant to a CICA application.

Processing of this data is carried out under Schedule 1 of the Data Protection Act 2018, specifically in connection with legal proceedings and the provision of legal services.

[CONFIRM WITH MAVISH SHAH] Please confirm whether the firm has a formal Data Protection Impact Assessment (DPIA) in place for processing special category health data and criminal offence data. Under UK GDPR Article 35, a DPIA is required where processing is likely to result in high risk — processing special category data at scale meets this threshold. If no DPIA exists, one should be completed before this policy is published.

4. How we collect your personal data

We collect personal data in the following ways:

Directly from you

  • When you submit an enquiry form on our website
  • When you call us or email us
  • When you instruct us to act on your behalf
  • When you provide documents and evidence in connection with your matter
  • When you communicate with us during the course of your case

From third parties

  • Medical professionals and expert witnesses instructed in connection with your matter
  • Opposing parties and their legal representatives
  • Courts, tribunals and regulatory bodies
  • The Criminal Injuries Compensation Authority (CICA) — for criminal injury claims
  • The Financial Conduct Authority (FCA) and financial institutions — for car finance commission claims
  • Tenancy deposit protection schemes (DPS, TDS, mydeposits) — for tenancy deposit claims
  • Employers' liability insurers and tracing agents — for industrial deafness claims
  • Referring organisations, lead generation partners or introducers
[CONFIRM WITH MAVISH SHAH] Please confirm the complete list of lead generation partners and introducers who refer data to the firm. Each must be listed in the relevant third-party data sharing agreements, and their own privacy policies must be compatible with yours. Where the firm pays for referrals, this arrangement may also need to be disclosed under SRA transparency guidance.

Automatically

  • Through cookies and tracking technologies on our website (see Section 10)
  • Through call recording systems (where calls are recorded)
  • Through our case management and CRM systems

5. Lawful basis for processing

Under UK GDPR, we must have a valid lawful basis for each category of processing. We rely on the following bases:

Processing purpose Lawful basis UK GDPR Article
Providing legal services you have instructed us to carry out Performance of a contract Article 6(1)(b)
Complying with our legal and regulatory obligations (SRA, ICO, court orders, anti-money laundering) Legal obligation Article 6(1)(c)
Responding to your initial enquiry before a contract is in place Pre-contractual steps at your request Article 6(1)(b)
Running our business, maintaining records, managing complaints, preventing fraud Legitimate interests Article 6(1)(f)
Sending you marketing communications by email or SMS Consent Article 6(1)(a)
Processing health data for claim purposes Explicit consent + legal claims Article 9(2)(a) & (f)
Processing criminal offence data for defence or claim purposes Legal proceedings / legal services (DPA 2018 Schedule 1) Article 10
Recording telephone calls Legitimate interests (quality, training and regulatory purposes) Article 6(1)(f)

Where we rely on legitimate interests, we have carried out a legitimate interests assessment (LIA) to confirm that our interests are not overridden by your rights and interests. You have the right to object to processing based on legitimate interests — see Section 12.

[CONFIRM WITH MAVISH SHAH] Please confirm that legitimate interests assessments (LIAs) have been documented for each purpose listed above where Article 6(1)(f) is relied on, particularly call recording and marketing analytics. These should be retained as internal records even if not published.

6. How we use your personal data

We use your personal data for the following purposes:

Providing legal services

  • Assessing your eligibility for a claim or legal service
  • Conducting your matter from instruction through to resolution
  • Communicating with you, the other side, courts, experts and third parties
  • Preparing, filing and serving legal documents
  • Instructing and working with barristers, experts and other professionals
  • Negotiating settlements and enforcing judgments on your behalf

Regulatory and compliance obligations

  • Verifying your identity and conducting anti-money laundering checks
  • Maintaining records required by the SRA
  • Responding to complaints through our internal complaints procedure
  • Cooperating with the SRA, Legal Ombudsman, courts or other regulatory bodies
  • Complying with court orders or legal obligations requiring disclosure

Business operations

  • Managing our client relationship and file management systems
  • Invoicing and financial administration
  • Quality assurance, training and call monitoring
  • Preventing and detecting fraud or abuse
  • Improving our services and website

Marketing (with your consent)

  • Sending you information about our services where you have opted in
  • Remarketing to website visitors through digital advertising platforms
[CONFIRM WITH MAVISH SHAH] Please confirm whether the firm currently uses remarketing pixels (e.g. Google Ads conversion tracking, Meta Pixel) on the website. If so, this must be disclosed in this section and in the cookies section, and a valid consent mechanism must be in place (a cookie consent banner) before such tracking is activated. Running remarketing without a compliant consent banner is a PECR breach.

7. Who we share your personal data with

We will not sell your personal data to any third party. We share your data only where necessary to provide our services or to meet our legal obligations, and only with parties who are contractually required to protect your information.

Parties we share data with in the course of providing legal services

Recipient categoryPurposeApplies to
Barristers and counsel Advice and court representation All contentious matters
Independent medical experts and audiologists Medical evidence for your claim Industrial deafness, criminal injury, housing disrepair
Independent surveyors Property survey evidence Housing disrepair
Opposing solicitors and parties Necessary disclosure in legal proceedings All contentious matters
Courts and tribunals Filing and serving documents; court orders All matters proceeding to court
Criminal Injuries Compensation Authority (CICA) Processing your compensation application Criminal injury claims
Financial institutions and lenders Lodging and pursuing commission redress complaints Undisclosed commission claims
Financial Ombudsman Service (FOS) Escalating unresolved financial complaints Undisclosed commission claims
Tenancy deposit protection schemes (DPS, TDS, mydeposits) Verifying deposit protection status Tenancy deposit claims
Employers' liability insurers and tracing agents Identifying and pursuing insurers for historic claims Industrial deafness
High Court Enforcement Officers (HCEOs) and bailiff companies Enforcing court judgments Enforcement matters
Police and Crown Prosecution Service Disclosure obligations in criminal matters Criminal defence

Service providers and processors

We share data with trusted service providers who process data on our behalf under written data processing agreements. These include:

  • IT and case management system providers
  • Cloud storage and email providers
  • Call recording and telephony providers
  • Website hosting and analytics providers
  • CRM and lead management platforms
[CONFIRM WITH MAVISH SHAH] Please provide the specific names of your case management system, CRM, call recording provider, website host and any marketing platforms in use. Data Processing Agreements (DPAs) must be in place with each. This list should be maintained as your Record of Processing Activities (ROPA) under Article 30 UK GDPR, which is mandatory for firms of this size and type.

Regulatory authorities

As an SRA-regulated firm, we may be required to disclose information to the following bodies in the discharge of our regulatory obligations:

  • The Solicitors Regulation Authority (SRA)
  • The Legal Ombudsman (LeO)
  • The Information Commissioner's Office (ICO)
  • HM Revenue & Customs (HMRC)
  • National Crime Agency (NCA) — in connection with anti-money laundering obligations

Business transfers

If Malone & White Solicitors Ltd is acquired by, merged with or enters into a partnership with another firm or entity, your personal data may be transferred to the acquiring firm as part of that transaction. We will notify you of any such transfer and ensure that your data continues to be protected to the same standard.

8. International data transfers

We aim to process and store all personal data within the United Kingdom or the European Economic Area (EEA). Where data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR Article 46.

[CONFIRM WITH MAVISH SHAH] Please confirm whether any of your service providers (particularly cloud storage, CRM, email or analytics platforms) process data outside the UK or EEA. Common examples include US-based providers such as Google (Google Analytics, Google Workspace), Microsoft (Office 365, Azure), Salesforce, HubSpot or Meta. If so, the transfer mechanism in place (e.g. UK Adequacy Regulations, International Data Transfer Agreement (IDTA), or binding corporate rules) must be identified and documented here. The ICO has specific guidance on international transfers post-Brexit.

Where we do transfer data internationally, we use one or more of the following safeguards:

  • The country has been deemed adequate by the UK Government under Article 45 UK GDPR
  • Standard contractual clauses (SCCs) or the UK International Data Transfer Agreement (IDTA)
  • The recipient is subject to binding corporate rules approved by the ICO

9. How long we keep your personal data

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law or regulation. The SRA requires solicitors to retain matter files for a minimum of six years from the date of closure of the matter, though longer periods may apply in certain circumstances.

Data typeRetention periodReason
Client matter files and case records 6 years from matter closure SRA requirements; limitation periods for professional negligence
Financial records and invoices 6 years Companies Act 2006; HMRC requirements
Anti-money laundering records 5 years from end of business relationship Money Laundering Regulations 2017
Complaints records 6 years from resolution SRA requirements; Legal Ombudsman time limits
Call recordings 12 months Quality and regulatory purposes
Website enquiries that did not become clients 12 months Legitimate interests in responding to enquiries
Marketing consent records Until consent is withdrawn, plus 3 years Demonstrating compliance with consent obligations
Website analytics data 26 months ICO guidance on analytics retention
[CONFIRM WITH MAVISH SHAH] Please review these retention periods against your actual practice. In particular: (1) some personal injury and clinical negligence matters may require longer retention due to extended limitation periods — confirm whether any of your services attract a longer period; (2) confirm the actual retention period set in your call recording system; (3) if you have a formal retention and disposal policy document, this privacy policy should cross-reference it.

When personal data is no longer required, we securely delete or anonymise it. Physical documents are shredded. Electronic data is permanently deleted in a manner that prevents recovery.

10. Cookies and tracking technologies

Our website uses cookies and similar tracking technologies. Cookies are small text files stored on your device when you visit our website. We use them to make our website work properly, to understand how it is used, and — where you have consented — to deliver relevant advertising.

Strictly necessary cookies

These cookies are essential for the website to function and cannot be switched off. They include cookies that enable form submissions, session management, and security features. No consent is required for strictly necessary cookies.

Analytics cookies

We use analytics tools to understand how visitors use our website — which pages are visited, how long visitors spend on the site, and where they come from. This helps us improve our content and user experience.

[CONFIRM WITH MAVISH SHAH / AZZAM] Please confirm which analytics platform is in use (e.g. Google Analytics 4, Matomo, Hotjar). If Google Analytics is in use, the specific cookie names and their duration must be listed here (e.g. _ga, _gid, _ga_XXXXXXXXXX). Under UK PECR, analytics cookies require prior consent via a cookie consent banner — confirm whether a compliant banner is in place. If not, this is a regulatory priority to address.

Marketing and advertising cookies

Where you have given your consent, we may use cookies to deliver targeted advertising through platforms such as Google Ads and social media networks. These cookies track your browsing activity across websites to show you relevant advertisements.

[CONFIRM WITH MAVISH SHAH / AZZAM] Confirm whether Google Ads conversion tracking, Meta Pixel, or any other advertising pixel is installed on the site. If so, these must only fire after the user has actively consented via a cookie banner. Running these without consent is a PECR breach and could attract ICO enforcement, particularly for a site processing significant volumes of enquiries.

Managing cookies

You can control and manage cookies in several ways:

  • Using our cookie preference centre on the website [insert cookie banner/settings link once implemented]
  • Through your browser settings — most browsers allow you to refuse or delete cookies
  • Through opt-out tools provided by analytics and advertising platforms, including the Google Analytics opt-out browser add-on

Please note that disabling certain cookies may affect the functionality of our website.

11. Marketing and communications

We will only send you marketing communications where you have explicitly opted in to receive them, or where we have an existing client relationship and are contacting you about similar services (the "soft opt-in" under UK PECR).

You can withdraw your consent to marketing at any time by:

  • Clicking the unsubscribe link in any marketing email
  • Emailing us at info@legaladvisor.co.uk
  • Calling us on 01204 939470

Withdrawing consent to marketing does not affect our ability to contact you about your active legal matter.

We do not sell, rent or trade your personal data to third parties for their own marketing purposes.

Contact by telephone

If you contact us by telephone, or if we contact you at your request, the call may be recorded for quality monitoring, training and regulatory purposes. You will be informed if a call is being recorded.

[CONFIRM WITH MAVISH SHAH] Confirm whether the firm conducts any outbound telephone marketing to people who have not previously contacted the firm. If so, the firm must check against the Telephone Preference Service (TPS) register before calling, and this must be stated here. Calling TPS-registered numbers without consent is a PECR breach subject to ICO fines.

12. Your rights under UK GDPR

You have the following rights in relation to your personal data. To exercise any of these rights, please contact us using the details in Section 16. We will respond within one calendar month of receiving your request.

1
Right of access (Subject Access Request) You have the right to request a copy of the personal data we hold about you. We will provide this free of charge within one month, unless the request is manifestly unfounded or excessive.
2
Right to rectification You have the right to have inaccurate personal data corrected, and incomplete data completed. Please contact us if you believe any information we hold is incorrect.
3
Right to erasure ("right to be forgotten") You may request that we delete your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent. Note that this right does not apply where we are required to retain data by law or regulation (e.g. SRA file retention obligations).
4
Right to restrict processing You have the right to ask us to pause processing of your data — for example, while you contest its accuracy or object to our use of it.
5
Right to data portability Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format.
6
Right to object You have the right to object to processing based on legitimate interests or for direct marketing. If you object to direct marketing, we must stop immediately. For other legitimate interests processing, we will stop unless we can demonstrate compelling legitimate grounds that override your interests.
7
Rights related to automated decision-making You have the right not to be subject to decisions made solely by automated processing that produce significant legal or similarly significant effects, without human involvement.
8
Right to withdraw consent Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Please note that some of these rights may be limited in the context of legal proceedings — for example, we cannot delete data that we are required to disclose to a court, or that is necessary to defend a legal claim against the firm.

13. How to make a data protection complaint

If you are unhappy with how we have handled your personal data, we would ask you to contact us in the first instance so that we can try to resolve the matter (see Section 16).

If you remain dissatisfied, you have the right to lodge a complaint with the UK's data protection supervisory authority:

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

As an SRA-regulated firm, data protection complaints may also be relevant to our regulatory obligations. Where a complaint relates to how we have handled your information as a client, you also have the right to complain to the Legal Ombudsman (legalombudsman.org.uk) and, in serious cases of professional misconduct, to the Solicitors Regulation Authority (sra.org.uk).

14. Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction or disclosure.

[CONFIRM WITH MAVISH SHAH / AZZAM] Please confirm the specific security measures in place so these can be listed accurately. Common measures to confirm: (1) SSL/TLS encryption on the website; (2) encryption of data at rest in your case management system; (3) two-factor authentication for staff access to client systems; (4) access controls limiting who can see client data; (5) staff data protection training; (6) secure document destruction policy; (7) whether the firm has Cyber Essentials certification. Only list measures that are actually in place — overstating security measures in a privacy policy creates a misleading impression.

Our general security measures include:

  • Secure, encrypted transmission of data via our website (HTTPS)
  • Access controls limiting staff access to personal data to those who need it to carry out their role
  • Staff training on data protection and information security
  • Secure disposal of physical documents containing personal information
  • Regular review of our data protection practices

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, as required by UK GDPR Article 33. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.

15. Changes to this policy

We review this Privacy Policy regularly and may update it from time to time to reflect changes in our practices, services, or legal obligations. The date of the most recent revision is shown at the top of this page.

Where we make material changes to this policy, we will notify you by email (where we hold your email address and the change affects you) or by placing a prominent notice on our website.

We recommend checking this page periodically to stay informed of how we protect your information.

16. Contact us about data protection

For any questions, requests or concerns relating to this Privacy Policy or your personal data, please contact us:

Malone & White Solicitors Ltd (trading as Legal Advisor)

For the attention of: Mavish Shah, Legal Director

Address: Nr 2 Fletcher Street, Unity House, Bolton, England, BL3 6NE

Telephone: 01204 939470

Email: info@legaladvisor.co.uk

Please mark correspondence or email subject lines with "Data Protection" to ensure your request reaches the right person promptly. We will acknowledge your request within 5 working days and respond in full within one calendar month, as required by UK GDPR.

This Privacy Policy is governed by and construed in accordance with the laws of England and Wales.

Scroll to Top