TMP Law – Privacy Policy
1. Introduction and Core Principles
We at TMP Law respect your privacy and are committed to protecting your personal data.
This Privacy Policy explains how we collect, handle, store, and share your personal information when you visit our website, engage our legal services, or interact with us. TMP Law is authorised and regulated by the Solicitors Regulation Authority (SRA) under SRA Number: 8015794. As a Sole Practitioner firm, Mr. T. M. Pinidiya acts as the primary Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect About You
Depending on your relationship with us (as a client, a prospective client, or a website visitor), we may collect and process the following data:
-
Identity and Contact Data: Name, title, addresses, telephone numbers, and email addresses.
-
Financial Data: Bank account details, billing addresses, and payment card details.
-
Verification & Anti-Money Laundering (AML) Data: Passports, driving licences, or other government-issued identification required to verify your identity.
-
Case-Specific Data: Information relevant to your legal matter, which may include "Special Category Data" (such as health metrics, racial or ethnic origin, or trade union memberships) or information relating to criminal convictions and offences.
-
Technical Data: Internet Protocol (IP) address, browser details, and information about how you navigate our website.
3. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we rely on the following legal bases:
-
Performance of a Contract: To register you as a new client and provide the legal services you have requested.
-
Compliance with Legal Obligations: To comply with court orders, regulatory reporting, and statutory verification checks (such as AML laws).
-
Legitimate Interests: For the effective management and operation of our business, including website optimisation and practice improvements.
4. Disclosures and Sharing of Your Data
We do not sell your personal data. However, to fulfil our legal duties and provide our services, we may share data with external parties, including:
-
Regulatory and Public Bodies: The Solicitors Regulation Authority (SRA), the Legal Ombudsman, and the National Crime Agency (NCA).
-
Professional Intermediaries: Courts, barristers, expert witnesses, medical practitioners, or opposing legal representatives necessary for your case.
-
Service Providers: IT support teams, secure cloud storage providers, and external auditors who operate under strict data processing agreements.
5. Client Confidentiality and Legal Professional Privilege
As a firm of solicitors, your right to confidentiality is protected by the strict rules of the SRA Code of Conduct. Furthermore, certain information shared with us may be protected by Legal Professional Privilege (LPP).
Please note that LPP and client confidentiality operate alongside data protection laws. Where a conflict arises, your right to absolute legal privilege takes precedence over specific UK GDPR disclosure requests (such as certain Subject Access Requests).
6. Data Retention: How Long We Keep Your Data
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including satisfying any legal, accounting, or regulatory reporting requirements.
-
AML Records: Identification and verification evidence will be securely stored for a minimum of 5 years from the date our business relationship ends, in accordance with statutory compliance.
-
Client Files: Case files and transaction records are typically retained for 6 years (or up to 12 years depending on the specific practice area and applicable limitation periods) from the formal closure of your file.
7. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to your personal data to those employees, agents, and contractors who have a legitimate business need to know. They will only process your personal data on our instructions and are subject to a strict duty of confidentiality.
8. Your Legal Rights
Under data protection legislation, you have specific rights concerning your personal information, including:
-
The Right of Access: You can request a copy of the personal data we hold about you via a Subject Access Request (SAR).
-
The Right to Rectification: You can request that we correct any inaccurate or incomplete data.
-
The Right to Erasure ("Right to be Forgotten"): You can ask us to delete your personal data under certain conditions, subject to our overriding legal retention obligations.
-
The Right to Object: You can object to us processing your personal data where we are relying on a legitimate interest.
9. Contact Details and Data Protection Complaints
If you have any questions about this Privacy Policy or wish to exercise any of your statutory rights, please contact our designated data privacy handler:
-
Contact Name: Mr. T. M. Pinidiya, Principal Solicitor
-
Email Address: thejp@tmplaw.co.uk
We operate a formal data protection complaints handling procedure. We will acknowledge any data protection grievance within 30 days of receipt and work to provide an outcome without undue delay.
If you remain dissatisfied with our response, you have the right to lodge a formal complaint with the UK's independent supervisory authority:
-
Regulator: Information Commissioner’s Office (ICO)
-
Website: www.ico.org.uk
-