---
id: KB-LE-003
url: https://app.codecontract.io/help/legal/handling-third-party-data-in-a-firm
idioma: en
categoria: sector-legal
subcategoria: privacidad
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-GL-013, KB-TZ-006]
citadoPor: [KB-LE-008, KB-LE-009, KB-LE-021, KB-LE-025, KB-LE-032]
---

# Handling third-party data in a firm

_They are neither yours nor your client's: they belong to your client's staff and customers._

**Responde a:** personal data of my client's employees · law firm third-party data protection · data processor accountancy · how long to keep data of a client who left

A firm handles a layer of data almost nobody else does: that of **its client's** employees and customers. People who did not engage you, do not know you, and never chose for their payslip or ID to pass through your hands.

## The three layers, and who answers for each

| Layer | Whose it is | Your role |
| --- | --- | --- |
| Your firm's data | Yours | Controller |
| Your client's contact data | The client company's | Usually controller |
| Payslips, IDs and their staff's data | Those individuals' | Usually on your client's instructions |

_The exact allocation of roles depends on the service and the contract; confirm with your adviser or data protection officer._

> [!IMPORTANT]
> The third layer carries the most volume and receives the least attention. If your firm suffers a security incident, the people affected are not your clients: they are your clients' employees, and they bear the harm.

## What genuinely reduces the risk

**En corto**

- Ask for the minimum: many engagements need no ID copy, only the number.
- One team per client, so nobody sees what is not theirs.
- Delete when the period ends, rather than accumulating just in case.

## When a client leaves

Return their complete file and apply your retention policy to the rest. Keeping the data of a former client's employees, with no obligation justifying it, is accumulating risk with no upside.

> [!WARNING]
> This is not legal advice and your specific duties depend on the service, the client contract and your professional rules. What is certain is that you will have to answer the question to someone: better to have thought it through first.

> [!NOTE]
> If a client asks for access to their own material, giving it scoped is safer than emailing everything: it leaves no loose copies and records what they looked at.

**Do I need a specific contract with my client?**

For processing on their instructions one is usually required; check.

**Can I keep the file after the client leaves?**

Whatever your professional rules require you to keep, and no more.

**What if my client's employee asks me for their data?**

Such a request normally goes to their employer, not to you; check before answering directly.

## Ejemplos

**A firm keeps ID copies of employees of clients who left years ago.**

- Checks what it is obliged to retain
- Deletes the rest

→ Stops holding hundreds of identity documents belonging to people who are not even its clients.

**A client's documentation arrives containing third-party data.**

- Checks what it contains before filing it

→ You know what you are holding.

**The whole firm can open any matter.**

- Limits access according to the engagement

→ Access stops being general by default.

**Everything is kept indefinitely just in case.**

- Applies a retention policy

→ What is kept has a reason and a period.

**A whole file is shared when one document would do.**

- Shares only what is relevant

→ What was asked for is delivered, and nothing more.

**A client asks what is held about them.**

- Checks the index of their file

→ The answer is specific.
