Country-specific guidance Current
GDPR data controller obligations for client personal data
GDPR is directly applicable in every member state; the substance doesn't vary by country.
When your firm collects and holds a client's personal data, GDPR treats it as the data controller with a specific set of obligations. This guide sets out the core ones. It is general information, not legal or privacy advice.
Action plan
1 Establish a lawful basis before you process a client's personal data Processing is only lawful where at least one specific ground applies, not by default.
GDPR Article 6 requires that processing is lawful only if, and to the extent that, at least one specific ground applies, such as the data subject's consent, necessity for performing a contract with the data subject, or necessity for compliance with a legal obligation the controller is subject to, among the other grounds the article sets out. Identify which ground applies to each category of client data you process, rather than assuming client engagement alone covers everything.
- Identify a specific Article 6 lawful basis for each category of client personal data processed
- Common grounds include contract necessity and compliance with a legal obligation, such as AML due diligence
- Don't rely on a single blanket basis for every kind of processing your firm carries out
Done when: A specific lawful basis is identified and documented for each category of client personal data processed
EUR-Lex: General Data Protection Regulation (EU) 2016/679, Article 62 Keep processing within the purpose you actually collected the data for Purpose limitation and data minimisation work together: define the purpose, then only collect what it needs.
GDPR Article 5 requires personal data to be collected for specified, explicit, and legitimate purposes and not further processed in a way that's incompatible with those purposes, and to be adequate, relevant, and limited to what's necessary for those purposes. Where your firm wants to use client data collected for one engagement for an unrelated purpose, check compatibility before doing so rather than assuming any internal use is automatically fine.
- Define the specific purpose for which client personal data is collected
- Collect only what's adequate, relevant, and necessary for that purpose
- Check compatibility before reusing data collected for one purpose in a different context
Done when: Client personal data processing stays within its stated, documented purpose
3 Respond to a client's access request within the EU-wide one-month clock This specific timeframe is set directly by GDPR itself, uniformly, because GDPR is a Regulation.
GDPR Article 15 gives a data subject the right to obtain confirmation of whether their personal data is being processed, and access to it. Article 12 requires the controller to act on that request without undue delay and, in any event, within one month of receipt, extendable by up to two further months for genuinely complex or numerous requests, with the data subject told of any extension and the reason for it.
- Recognise a client's clear request to see their held personal data as an access request
- Respond within one month of receipt as the default, EU-wide timeframe
- Only extend by up to two further months for genuine complexity or volume, and tell the client why
Done when: Client access requests are recognised, logged, and responded to within the applicable one-month clock or a properly communicated extension
EUR-Lex: General Data Protection Regulation (EU) 2016/679, Article 15