Kingsley Napley

Privacy Notice

We keep our privacy notice under regular review. This privacy notice was last updated in August 2026.

This notice tells you what to expect when Kingsley Napley uses your personal data as a ‘controller’ of personal data for the purposes of the Data Protection Act 2018 and the UK General Data Protection Regulation. When we use personal data, we are required to do so in accordance with applicable data protection legislation.

When we say ‘we’, ‘our’ or ‘Kingsley Napley’, we are referring to Kingsley Napley LLP, Kingsley Napley Trust Corporation Limited or affiliated entities.

If you need further information or have any questions or complaints about our privacy notice or privacy practices please contact our Data Protection Officer using the details below:

This notice describes:

  1. The personal data that we collect
  2. How we obtain personal data
  3. Our lawful bases
  4. How we use personal data
  5. Use of artificial intelligence (AI)
  6. How long we keep personal data
  7. Who we share personal data with
  8. Which countries we transfer personal data to
  9. How we protect personal data
  10. The legal rights of individuals whose personal data we process

1. The personal data that we collect

Because of the wide-ranging nature of our work, and the different reasons why we need to use personal data, what we collect is very varied and includes:

  • Identity and Contact Data: Name, date of birth, email address, postal address, telephone number, passport details, and any other information provided or collected as part of our client onboarding process.
  • Matter Data: Any personal data provided to us by or on behalf of our clients or otherwise provided to us or generated by us in the course of providing services to our clients that is necessary for the administration of your matter, including but not limited to information about your employment and family members. In order to provide our services, we may collect special category data. Special category data includes personal data which reveals racial or ethnic origin, religious or philosophical beliefs, trade union membership, data concerning health and data concerning a person’s sex life or sexual orientation.
  • Criminal Convictions Data: Information relating to criminal convictions and offences to the extent relevant to your matter.
  • Financial and Transaction Data: Bank account details, payment card details and details of payments from and to individuals.
  • Feedback Data: Any personal data such as your name, email address and details of your matter that you choose to provide in your feedback to us.
  • Technical and Usage Data: Information about how individuals use our website.
  • Marketing Data: Name, email address, and interests to the extent they relate to preferences in receiving marketing from us.
  • Events Data: Dietary information and accessibility requirements.
  • Call Recordings Data: Personal data of clients and other callers, including such persons’ names, contact details and the content of the call, contained within recordings of telephone calls made to or by us, and associated transcripts.

2. How we obtain personal data

We obtain personal data in different ways, including through:

  • Direct contact – individuals may give us their personal data by corresponding with us by post, email or telephone or otherwise. This includes incoming calls, which are triaged by our call management provider. Callers are notified at the start of the call that recording is taking place so that they can choose not to provide information.
  • Clients – our clients may give us personal data of individuals (for example a client’s employees) to enable us to provide our services.
  • Third parties or publicly available sources – we may receive personal data of individuals from third parties (for example disclosure by the police or CPS in connection with a prosecution or information provided by a witness) in connection with the provision of services by us to our clients. We may also receive information from business contact databases or enrichment services which use publicly available information to improve the accuracy and detail of data. We may also receive information from sources such as Companies House, HM Land Registry, credit reference agencies and suppliers of information that enables us to comply with our anti money laundering, sanctions and other due diligence obligations.
  • Our website – we use cookies to help us to provide users with a good experience when browsing the website and allow us to improve the site. Details of the cookies we use, the information we gather and how cookies can be blocked can be found in our Cookie Policy on our websiteand in our Legal Notices.

3. Our lawful bases

We will only use personal data (including special category data and data relating to criminal convictions and offences) when the law allows us to. Most commonly, we will use personal data in the following circumstances:

  • Where it is necessary for our Legitimate Interests (or those of a third party such as one of our clients) and the interests and fundamental rights of the individual whose personal data we are using do not override those interests.
  • Where we need to do so to perform a Contract we are about to enter into or have entered into.
  • Where it is necessary to comply with a Legal Obligation.
  • When we use special category data and data relating to criminal convictions and offences it will normally be when this is necessary for the establishment, exercise or defence of legal claims.
  • Generally, we do not rely on Consent as a legal basis for processing personal data other than in relation to placing cookies and sending direct marketing communications where you have opted-in to receive marketing from us. Consent can be withdrawn at any time, by contacting us using the contact address above.

4. How we use personal data

  • To provide our services to our clients we may, to the extent relevant to your matter, process your Identity and Contact Data, Criminal Convictions Data, Matter Data, and Financial and Transaction Data. We process this personal data to perform our Contract with you.
  • To continually improve the quality and efficiency of the services we provide we may process your Matter Data, Feedback Data and Technical and Usage Data. We process this personal data in our Legitimate Interests to improve our services. Where we collect your Technical and Usage Data using cookies, we rely on your Consent to process your personal data.
  • To promote our services and to manage our relationships with clients, prospective clients and business contacts we may process your Feedback Data and Marketing Data in our Legitimate Interests to promote our services and engage with you.
  • For internal training and development purposes we may process your Matter Data to share knowledge internally within our firm in our Legitimate Interests to improve our services.
  • To meet our Legal Obligations, including our audit and insurance obligations we may process your Financial and Transaction Data for financial accounting purposes, and any of your personal data as necessary to meet our regulatory reporting obligations.
  • To deliver our events we may process your Identity and Contact Data, and your Events Data in our Legitimate Interests to seek to tailor our events to meet your interests and requirements.
  • To record calls for the accurate recording of queries, instructions and advice we may process your Call Recordings Data in our Legitimate Interests to support you with your query and / or to perform our Contract with you.

5. Use of artificial intelligence (AI)

  • In our work, we may, where appropriate, use artificial intelligence (AI) tools to enhance the quality and efficiency of the advice and services we provide. AI tools may be used when, for example, drafting documents, conducting legal research and analysing data. Additionally, we may utilise AI tools for internal-facing functions, such as administrative organisation and optimising our processes. They may either be AI tools obtained by collaboration with third-party providers or bespoke tools we have built and developed. Where we develop our own AI tools, we may anonymise your personal data so that it can no longer be used to identify you, and then use that anonymised data to train and improve these tools.
  • We use AI based tools in accordance with our regulatory and legal obligations and where personal or confidential data is processed, where we have assessed that information will remain confidential and secure. We do not carry out any automated decision making using AI. We are committed to principles of fair and responsible use of AI within our business.

6. How long we keep personal data

  • We will keep personal data in accordance with our data retention practices, which apply appropriate retention periods for each category of personal data. In setting retention periods we take account of the purposes for which the personal data was collected, legal and regulatory obligations on us to retain information, limitation periods for legal action and our business purposes. Call recordings are retained for a period of 6 months and stored in encrypted form; transcripts of calls are anonymised and deleted within 6 months of the date of the call. If you want to learn more about our specific retention periods for your personal data established in our retention policy you may contact our DPO at the address given above.

7. Who we share personal data with

We may share personal data with third parties including:

  • When undertaking necessary enquiries to comply with our anti money laundering, sanctions and other due diligence obligations in connection with employment and provision of client services – for example when verifying identity documents.
  • In the course of providing services to our clients – for example when instructing a medical expert to produce a report or counsel to provide advice.
  • When we outsource certain support services – for example reception, administrative or photocopying services.
  • With suppliers of IT storage, infrastructure and related tools and services for core business purposes.
  • Our professional advisers – for example our auditors, bankers and insurers.
  • To regulatory authorities, courts, tribunals and law enforcement agencies – for example our regulator, the Solicitors Regulatory Authority.
  • Third parties to whom we transfer personal data are required to respect the security of the data and treat it in accordance with the law. We do not sell personal data to third parties.

8. Which countries we transfer personal data to

In the course of providing services to our clients we may need to transfer personal data outside the UK. Whenever we transfer personal data outside the UK, we ensure it is compliant with the law by ensuring:

  • one of the exceptions in the UK GDPR applies allowing us to make a transfer without any further safeguards; or
  • we are transferring the personal data to a country covered by an adequacy decision from the UK Secretary of State; or
  • we put in place one of the ‘appropriate safeguards’ referred to in the UK GDPR such as the UK International Data Transfer Agreement.

9. How we protect personal data

  • We have put in place appropriate security measures to prevent personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We have put in place appropriate measures to inform our staff about how we collect, handle and keep data secure.
  • We have put in place measures to deal with any suspected personal data breach and will notify relevant individuals and the Information Commissioner of a breach when we are legally required to do so.

10. The legal rights of individuals whose personal data we process

Individuals have the rights set out below. If you wish to exercise any of these rights please contact our Data Protection Officer using the contact details given above. We may need you to provide further information so that we can verify your identity before we can handle your request – we will inform you at the time if we require further information.

  • Request access to their personal data. This enables individuals to request a copy of the personal data we hold about them and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about them. This enables individuals to request to have any incomplete or inaccurate data we hold corrected, though we will need to verify the accuracy of the new data provided to us.
  • Request erasure of their personal data. This enables individuals to ask us to delete their personal data where there is no longer a lawful basis for us continuing to process it. Individuals also have the right to ask us to delete their personal data where they have successfully exercised their right to object to processing (see below), where we may have processed their data unlawfully or where we are required to delete their personal data to comply with local law. Note, however, that we may not always be able to comply with a request for erasure for specific legal reasons which will be notified to the individual, if applicable, at the time of their request.
  • Object to processing of personal data where we are relying on a legitimate interest (or that of a third party) and there is something about the individual’s particular situation which makes them want to object to processing on this ground as they feel it impacts on their fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process the data which overrides those rights and freedoms. Individuals also have the right to object where we are processing their personal data for direct marketing purposes.
  • Request restriction of processing of their personal data. This enables individuals to ask us to suspend the processing of their personal data in the following scenarios: (a) if the individual wants us to establish the data’s accuracy; (b) where our use of the data is unlawful but an individual does not want us to erase it; (c) where the individual needs us to hold the data even if we no longer require it as the individual needs it to establish, exercise or defend legal claims; or (d) the individual has objected to our use of their data but we need to verify whether we have overriding legitimate grounds to use it.
  • Withdraw consent at any time where we are relying on consent to process the personal data. However, this will not affect the lawfulness of any processing carried out before consent is withdrawn.
  • Make a complaint to us about how we handle their personal data. If you would like to make a complaint, please contact us using the contact details given above. We have procedures in place for reviewing and handling complaints. We will acknowledge your complaint within 30 days and will respond to it without undue delay to inform you of the outcome of your complaint. We may need you to provide further information so that we can verify your identity before we can handle your complaint – we will inform you at the time if we require further information.
  • Make a complaint to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (ico.org.uk). We would, however, appreciate the chance to deal with any complaints before the ICO is approached so please contact our Data Protection Officer, using the contact details given above, in the first instance.

Contact_us

Let us take it from here

Whatever your legal needs, we’re here to help.

Contact us