Saltar al contenido

Legal

Handling third-party data in a firm

They are neither yours nor your client's: they belong to your client's staff and customers.

Updated on 13/08/2026

A firm handles a layer of data almost nobody else does: that of **its client's** employees and customers. People who did not engage you, do not know you, and never chose for their payslip or ID to pass through your hands.

The three layers, and who answers for each

LayerWhose it isYour role
Your firm's dataYoursController
Your client's contact dataThe client company'sUsually controller
Payslips, IDs and their staff's dataThose individuals'Usually on your client's instructions
The exact allocation of roles depends on the service and the contract; confirm with your adviser or data protection officer.

Important

The third layer carries the most volume and receives the least attention. If your firm suffers a security incident, the people affected are not your clients: they are your clients' employees, and they bear the harm.

What genuinely reduces the risk

When a client leaves

Return their complete file and apply your retention policy to the rest. Keeping the data of a former client's employees, with no obligation justifying it, is accumulating risk with no upside.

Watch out

This is not legal advice and your specific duties depend on the service, the client contract and your professional rules. What is certain is that you will have to answer the question to someone: better to have thought it through first.

Worth knowing

If a client asks for access to their own material, giving it scoped is safer than emailing everything: it leaves no loose copies and records what they looked at.

Do I need a specific contract with my client?

For processing on their instructions one is usually required; check.

Can I keep the file after the client leaves?

Whatever your professional rules require you to keep, and no more.

What if my client's employee asks me for their data?

Such a request normally goes to their employer, not to you; check before answering directly.

A real case

The situation

A firm keeps ID copies of employees of clients who left years ago.

What you do

  1. Checks what it is obliged to retain
  2. Deletes the rest

What you get

Stops holding hundreds of identity documents belonging to people who are not even its clients.

The situation

A client's documentation arrives containing third-party data.

What you do

  1. Checks what it contains before filing it

What you get

You know what you are holding.

The situation

The whole firm can open any matter.

What you do

  1. Limits access according to the engagement

What you get

Access stops being general by default.

The situation

Everything is kept indefinitely just in case.

What you do

  1. Applies a retention policy

What you get

What is kept has a reason and a period.

The situation

A whole file is shared when one document would do.

What you do

  1. Shares only what is relevant

What you get

What was asked for is delivered, and nothing more.

The situation

A client asks what is held about them.

What you do

  1. Checks the index of their file

What you get

The answer is specific.

This article answers

  • personal data of my client's employees
  • law firm third-party data protection
  • data processor accountancy
  • how long to keep data of a client who left