Firm Policy

Data Protection & Data Security Policy

How M by Mariah Legal protects personal data and maintains data security standards.

Data Protection and Data Security Policy

Statement and purpose of policy

M by Mariah Legal is committed to ensuring that all personal data handled by us will be processed according to legally compliant standards of data protection and data security.

For the purposes of data protection law, the firm is a data controller of personal data in connection with its work. This means that we determine the purposes for which and the manner in which personal data is processed.

The purpose of this policy is to set out the rules on data protection and the legal conditions that must be satisfied when we collect, receive, handle, process, transfer and store personal data.

Data protection principles

  • Personal data must be processed lawfully, fairly and transparently.
  • Personal data must be collected only for specified, explicit and legitimate purposes.
  • Personal data must be adequate, relevant and limited to what is necessary.
  • Personal data must be accurate and kept up to date.
  • Personal data must be kept only for the period necessary for processing.
  • Personal data must be secure and protected by appropriate measures.

Who is responsible for data protection and data security?

Maintaining appropriate standards of data protection and data security is a collective task shared across the firm. All individuals who handle personal data have responsibility for ensuring it is handled consistently with data protection principles.

Questions about this policy, or requests for further information, should be directed to the Data Protection Officer.

Data security

We use appropriate technical and organisational measures to keep personal data secure and to protect against unauthorised or unlawful processing, accidental loss, destruction or damage.

  • Only authorised people should access personal data.
  • Where possible, personal data should be pseudonymised or encrypted.
  • Information should be accurate and suitable for the purpose for which it is processed.
  • Confidential information should be kept securely, including through appropriate password protection and secure storage.
  • Personal data should not be removed from the firm’s premises or systems without appropriate safeguards.

Individual rights

Individuals have rights in relation to their personal data, including rights of access, correction, erasure, restriction and objection where applicable. Requests should be made to the firm so they can be reviewed and responded to in accordance with the law.

Data breaches

If a personal data breach is identified, the firm will assess the breach and take appropriate action, including reporting to the Information Commissioner where required by law.

This policy page is based on the firm’s existing published policy wording and should be reviewed by the firm before final launch.