Privacy Policy | Glynns Solicitors

Last updated: August 2026

Glynns Solicitors Limited has prepared this notice to explain clearly who we are, what personal data we collect, why and how we use it, who we may share it with, how long we keep it and the rights available to you.

Glynns Solicitors is the trading name of Glynns Solicitors Limited. We are registered in England and Wales under company number 07916362. We are authorised and regulated by the Solicitors Regulation Authority under SRA number 566967.

For the purposes of data protection law, Glynns Solicitors Limited is the controller of the personal data described in this notice.

Data protection law

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025 (DUAA), together with other applicable privacy and electronic communications legislation.

The DUAA received Royal Assent on 19 June 2025 and amended aspects of the UK's data protection framework. It supplements and amends the UK GDPR and the Data Protection Act 2018; it does not replace them.

Data protection principles

When processing personal data, we follow the seven principles in Article 5 of the UK GDPR:

  • Lawfulness, fairness and transparency: personal data must be processed lawfully, fairly and transparently.
  • Purpose limitation: personal data must be collected for specified, explicit and legitimate purposes and not used incompatibly with those purposes.
  • Data minimisation: personal data must be adequate, relevant and limited to what is necessary.
  • Accuracy: personal data must be accurate and, where necessary, kept up to date.
  • Storage limitation: personal data must not be kept in an identifiable form for longer than necessary.
  • Integrity and confidentiality: personal data must be protected by appropriate technical and organisational security measures.
  • Accountability: we are responsible for, and must be able to demonstrate, compliance with these principles.

Personal data we may collect

Depending on the nature of your enquiry or legal matter, we may collect and hold:

  • Your name, postal address, email address, telephone numbers and date of birth.
  • Identification and verification information, including your National Insurance number where relevant.
  • Employment records, employer details, earnings and other financial information.
  • Information from HM Revenue & Customs, the Department for Work and Pensions and other public bodies.
  • Medical records and information from doctors, hospitals and other healthcare providers.
  • Bank details, insurance information and details relating to funding a legal claim.
  • Correspondence, call records, enquiry details, witness evidence and information relating to your legal matter.
  • Technical information arising from your use of our website, subject to your cookie choices.

Special-category and criminal-offence data

Some information we process is special-category personal data. This may include information about your physical or mental health, race or ethnicity, religious or philosophical beliefs, sexual orientation, sex life, genetic or biometric information and trade-union membership.

We will only process special-category personal data where both a lawful basis under Article 6 and an additional condition under Article 9 of the UK GDPR apply. In most client matters, health and other special-category information is processed where it is necessary for the establishment, exercise or defence of legal claims. Where we process criminal-offence data, we do so only where permitted by law and with appropriate safeguards.

How we obtain personal data

We may obtain information directly from you, including through telephone calls, emails, forms and our website. We may also obtain information from sources connected with your enquiry or legal matter, including:

  • Your representatives, family members, witnesses or other people authorised by you.
  • Doctors, hospitals and other healthcare providers.
  • Employers, insurers, public authorities and government departments.
  • Experts, barristers, other professional advisers, defendants and their representatives.
  • Courts, tribunals, regulators and publicly available sources.

Why we use your personal data

We use personal data only where the law allows us to do so. The purposes for which we may process it include:

  • Responding to your enquiry and deciding whether we can act for you.
  • Providing legal advice and services and pursuing, defending or resolving legal claims.
  • Verifying identity, preventing fraud, carrying out conflict checks and meeting anti-money-laundering requirements.
  • Managing funding, insurance, payments and our contractual relationship with you.
  • Complying with legal, professional and regulatory obligations.
  • Maintaining records, protecting our legal rights, improving our services and managing our business securely and effectively.
  • Sending marketing communications where permitted by law.

Our lawful bases

Depending on the particular processing activity, we may rely on one or more of the following lawful bases:

  • Contract: processing is necessary to take steps at your request before entering into a contract or to perform our contract for legal services with you.
  • Legal obligation: processing is necessary to meet a legal or regulatory obligation.
  • Legitimate interests: processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your interests, rights and freedoms. These interests may include providing and improving legal services, administering our business, maintaining security, preventing fraud and establishing, exercising or defending legal rights.
  • Consent: where we rely on consent for a particular activity, you may withdraw it at any time. Withdrawal will not affect processing already carried out lawfully before consent was withdrawn.
  • Vital interests or public task: these bases may apply in limited circumstances where the relevant legal requirements are met.

Sharing personal data

While carrying out legal work, we may need to share relevant personal data with third parties such as:

  • Medical-record collation providers, medical experts and other expert witnesses.
  • Barristers, costs specialists and other professional advisers.
  • Insurers, litigation funders and after-the-event insurance providers.
  • Potential or actual defendants and their solicitors, insurers or representatives.
  • Courts, tribunals, the Solicitors Regulation Authority, the Legal Ombudsman, law-enforcement bodies and other authorities where required.
  • IT, hosting, communications, document-storage and other service providers acting on our instructions.

We require service providers acting as processors to protect personal data, maintain confidentiality and process it only for specified purposes and in accordance with our instructions and the law.

We may also disclose personal data in connection with a reorganisation, sale, transfer or merger of all or part of our business, subject to appropriate confidentiality and data-protection safeguards.

International transfers

Some service providers may process personal data outside the United Kingdom. Where personal data is transferred internationally, we will ensure that the transfer is lawful and that an appropriate level of protection is provided. This may include relying on UK adequacy regulations or using approved safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any required risk assessment and supplementary measures.

You may contact our Data Protection Officer for further information about the safeguards used for an international transfer affecting your personal data.

Using personal data for a new purpose

We will normally use personal data only for the purpose for which it was collected. If we wish to use it for another purpose, we will consider whether the new purpose is compatible with the original purpose in accordance with data protection law. If the new purpose is not compatible, we will identify a separate lawful basis and provide any further information required by law.

We may process personal data without your knowledge or consent where this is required or permitted by law. Consent is not the only lawful basis for processing personal data.

Storage and security

We use secure servers, cloud-computing services and physical storage to hold personal data. A client file may include electronic records, paper documents and medical records supplied in other media.

We use appropriate technical and organisational measures designed to prevent personal data from being accidentally lost, altered, destroyed, disclosed or accessed without authority. Access is limited to employees, consultants and service providers who have a genuine need to know and who are subject to confidentiality obligations.

How long we keep personal data

We keep personal data only for as long as is reasonably necessary for the purposes for which it was collected, including meeting legal, regulatory, accounting, insurance and reporting requirements and dealing with possible legal claims.

Closed client files are normally retained for at least six years. Files relating to a child may need to be retained for longer, including until the child reaches the age of 21 or for another period appropriate to the circumstances. Medical records are normally destroyed as soon as practicable after the relevant file-retention requirements permit this. Different retention periods may apply where required by law, regulation, insurance arrangements or the nature of the matter.

In some circumstances we may anonymise information so that it can no longer identify you. We may use genuinely anonymised information for research, analysis or statistical purposes without further notice.

Marketing communications

We may send marketing communications where you have consented or where another lawful basis and the electronic-marketing rules permit us to do so. You can ask us to stop sending marketing communications at any time by using the unsubscribe link in an email or contacting us.

Withdrawing from marketing does not prevent us from retaining other information where we have another lawful reason to keep it, such as information held on a client file or a record of your request not to receive marketing.

Cookies and website information

Our website uses cookies and similar technologies. Some are necessary for the website to function; others are used only in accordance with applicable consent requirements. Further details about the cookies we use, their purposes and how to manage your choices are available on our Cookies page.

Automated decision-making

We do not currently make decisions about clients or prospective clients based solely on automated processing where the decision would produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by law.

Your data-protection rights

Depending on the circumstances and the lawful basis being used, you may have the right to:

  • Be informed about how your personal data is used.
  • Request access to personal data held about you.
  • Ask us to correct inaccurate or incomplete personal data.
  • Ask us to erase personal data in certain circumstances.
  • Ask us to restrict processing in certain circumstances.
  • Object to processing based on legitimate interests and object at any time to direct marketing.
  • Request data portability where the legal conditions apply.
  • Withdraw consent at any time where processing is based on consent.
  • Receive safeguards in relation to qualifying automated decision-making.
  • Complain to us and to the Information Commissioner's Office.

Your right to object: You have the right to object to our use of your personal data where we rely on legitimate interests. We may continue processing only where we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or where processing is needed for legal claims. You may object to direct marketing at any time.

Access requests and identity checks

You will not normally have to pay a fee to exercise your rights. We may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, as permitted by law.

We may ask for information needed to confirm your identity and clarify the scope of a request. We will respond within the applicable legal time limit, normally one month, although the period may be extended where the law permits. When responding to an access request, we will carry out searches that are reasonable and proportionate in accordance with the UK GDPR as amended by the DUAA.

Some rights are subject to exemptions and limitations, including legal professional privilege and the establishment, exercise or defence of legal claims. If we cannot comply fully with a request, we will explain the reason where the law permits us to do so.

If you do not provide personal data

Where we need personal data to comply with the law or provide legal services, failure to supply the requested information may mean that we cannot act for you or continue to act. If this occurs, we will explain the consequences at the appropriate time.

Personal-data breaches

We maintain procedures for identifying, assessing and responding to suspected personal-data breaches. Where legally required, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach. We will also notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

How to make a data-protection complaint

You can raise a concern or complaint about our use of your personal data by contacting our Data Protection Officer using the details below. In accordance with the complaints requirements introduced by the DUAA, we will:

  • Provide a way for you to make a data-protection complaint.
  • Acknowledge receipt of your complaint within 30 days.
  • Take appropriate steps to investigate and respond without undue delay.
  • Keep you informed about the progress of the complaint where appropriate.
  • Tell you the outcome without undue delay once our investigation is complete.

Our Data Protection Officer

Julie Glynn is our Data Protection Officer. You may contact her about this notice, the way we use personal data, your rights or a data-protection complaint:

Julie Glynn
Glynns Solicitors
The Old Piggery
Walley Court Road
Chew Stoke
Bristol
BS40 8XN

Email: julie.glynn@glynns.co.uk
Telephone: 01275 334030

Complaining to the Information Commissioner's Office

You also have the right to complain to the Information Commissioner's Office (ICO), the UK's independent regulator for data protection. We would appreciate the opportunity to address your concerns first, but you may contact the ICO at any time.

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint/

Changes to this notice

We may update this notice from time to time to reflect changes in the law, regulatory guidance or the way we process personal data. The date at the top of the notice shows when it was last updated.

Make An Enquiry





We will only use the information you provide to handle your enquiry, and we will never share it with any third parties.


Why Choose Glynns?

  • Specialist medical negligence solicitors
  • Free initial claim assessment
  • No Win No Fee funding may be available

Reviews

Our Expertise

clinical negligence panel

Helping Clients Across England & Wales

Helping Clients Across England & Wales

Free Medical Negligence Guide

'7 Questions You Must Ask Before Choosing A Medical Negligence Solicitor'

Update cookies preferences