Booking options
£48 - £64
+ VAT

£48 - £64
+ VATDelivered Online
1 hour
All levels
This practical course explains how and why law firms should carry out data audits and Data Protection Impact Assessments (DPIAs), focusing on proportionate compliance rather than technical or overly legalistic approaches.
The session demystifies what a data audit is, how it differs from a DPIA, and when each is required under UK GDPR. Participants will be guided through how to identify the personal data their firm holds, understand why it is processed, assess legal bases, spot unnecessary or high-risk processing, and address common weaknesses such as over-retention, insecure storage, and unclear data sharing arrangements.
The course also explores when a DPIA is required, how to approach it in a law firm context, and how DPIAs support better decision-making around new systems, technology, outsourcing, and changes to working practices. Throughout, the emphasis is on creating simple, usable records that help manage risk, demonstrate accountability, and withstand regulatory scrutiny from the ICO or SRA.
Partners, directors, and owners of law firms
Compliance Officers for Legal Practice (COLPs) and Compliance Officers for Finance and Administration (COFAs)
Practice managers and office managers
Senior fee earners involved in introducing new systems, processes, or suppliers
This course is particularly suited to firms without in-house data protection specialists.
A copy of the course notes and slides will be provided to all delegates which may be useful for ongoing reference.
Please note a recording of the course will not be made available.
Matthew Howgate, Consultant, DG Legal
Matt is a non-practising solicitor who has considerable experience in regulatory issues and advising on complex issues of compliance and ethics. He is also an expert in data protection, UK GDPR and on the civil legal aid scheme.
Matthew is a lead trainer on and co-developed the LAPG Certificate in Practice Management (a training programme for legal managers and law firm owners) as well as regularly providing training on legal aid Supervision, costs maximisation, data protection and security and on general SRA compliance.
Yes, prior to the event a link will be sent to the email address used to register for the course so please ensure the delegate details are correct.
You may also wish to save the domain @system.cademy.io as a safe sender to avoid emails containing access details and handouts from being diverted to junk/spam folders.
No, a recording will not be made available.
No, recording the training session is not allowed. If you attempt to record the session or are found to be recording the event, you may be removed from the session and you will not be eligible for a refund.
For our Premier Training courses, please email us at teamadmin@dglegal.co.uk after the event if you require a certificate of attendance.
The slides will be distributed by email after the event.
You may also wish to save the domain @system.cademy.io as a safe sender to avoid emails containing access details and handouts from being diverted to junk/spam folders.
Yes and these will be distributed by email after the event.
You may also wish to save the domain @system.cademy.io as a safe sender to avoid emails containing access details and handouts from being diverted to junk/spam folders.
The majority of delegates should choose the General Delegate rate.
A discount is available for delegates attending from firms with a current retainer contract with DG Legal i.e. firms that are paying a monthly or annual subscription for our Retainer Service (please contact us by emailing admin@dglegal.co.uk for confirmation of eligibility). If you choose the Retainer Delegate option and are not eligible, you are still bound to pay the full rate and will be invoiced accordingly.