UK data protection law has changed under the Data (Use and Access) Act 2025 (DUAA), with all provisions of the Act now in force as of June 2026, including the new mandatory complaints-handling procedure. For many law firms, this raises a difficult question: does your GDPR training still reflect the law as it stands, or the law as it stood when staff were last trained?
GDPR training has become a recurring compliance exercise, but has it kept pace with regulatory change and been practice wide? It will likely be that many firms may need to revisit not only their policies and procedures, but also how they ensure staff understand and apply data protection requirements in their day-to-day roles.
While most firms are familiar with the fundamentals of GDPR, data protection remains an area where small mistakes can have significant consequences, particularly when dealing with client information, special category data, marketing communications and subject access requests.
Moving Beyond Awareness
The regulatory focus is increasingly shifting from simply having policies in place to demonstrating that staff understand their responsibilities and can respond appropriately when issues arise.
Questions firms may wish to consider include:
- Do all members of staff understand what constitutes personal data?
- Are employees aware of the differences between controllers and processors?
- Can fee earners identify special category data and apply the correct safeguards?
- Is there a clear understanding of lawful processing requirements?
- Would staff know how to recognise and escalate a potential data breach?
- Are teams prepared to respond to subject access requests and complaints appropriately?
For many firms, the greatest risk is not a lack of policies but a lack of consistent understanding across the wider business.
Why Data Protection Remains a Challenge
On the surface, GDPR principles appear straightforward. Collect only the information you need, keep it secure and retain it only for as long as necessary.
The risks are not hypothetical. In April 2025, the ICO fined DPP Law £60,000 following a ransomware attack, citing delayed breach notification and outdated, unpatched systems among the firm’s failings. It’s a reminder that data protection compliance isn’t just a policy exercise. It depends on staff and systems responding correctly under pressure.
In reality, law firms process large volumes of personal information across multiple systems, departments, suppliers and third-party platforms. Understanding what data is held, where it is stored, who has access to it and how it flows through the business can be considerably more complex.
Regulatory changes, evolving technology and increasing client expectations only add to that complexity.
As a result, regular training remains one of the most effective ways of reducing risk and ensuring staff remain aware of their obligations.
What Should Firms Be Thinking About Now?
As the DUAA begins to reshape aspects of the UK data protection landscape, firms should consider whether staff have received training that reflects the latest requirements and emerging best practice.
As of June 2026, all data protection provisions of the Data (Use and Access) Act 2025 are now in force; including the new requirement for organisations to operate a formal complaints-handling procedure. Firms should treat this as confirmation that DUAA-related changes are no longer upcoming, but already a live compliance requirement, and check that staff training reflects the law as it now stands.
Themes from special category data through to breach reporting, along with our learning from real compliance failures, are exactly what the Legal Eye training sessions are designed to address, as set out below.
A proactive approach to training can help firms reduce risk, demonstrate compliance and reinforce a culture of accountability throughout the organisation.
A Practical Training Session for Law Firms
To support firms in meeting their data protection obligations, Legal Eye offers a live, interactive GDPR training session delivered exclusively for your firm.
Each session begins with a scoping call to understand your firm’s specific requirements, allowing the content to be tailored to your people, processes and areas of risk.
The one-hour training session covers:
- Where we are now, from GDPR and Brexit through to the Data (Use and Access) Act 2025 and forthcoming changes during 2026
- A refresher on key GDPR definitions
- Personal data and special category data
- Controllers and processors
- Data protection principles
- Accountability and record-keeping obligations
- Lawful processing under Articles 6 and 9
- Privacy notices and marketing consent
- Subject rights, access requests and complaints procedures
- Data breach identification and management
- Practical examples of where things have gone wrong
- Key takeaways and action points
To support ongoing compliance, a recording of the session and presentation slides are provided to all registered staff. This also enables those unable to attend the live session to complete their training at a later date, helping firms maintain records of updated training across the business.
Supporting GDPR Compliance Beyond Training
Training is often only one part of the compliance journey.
Legal Eye has helped hundreds of solicitors, barristers, legal advisers and business managers understand their GDPR obligations and prepare for regulatory change. Our specialist team can support firms through data audits, gap analysis exercises, policy reviews and the implementation of practical compliance improvements.
By taking a holistic approach, firms can gain greater confidence that their policies, procedures and day-to-day practices align with evolving data protection requirements.
A Practical Opportunity to Refresh Staff Knowledge
Data protection obligations continue to evolve, and staff awareness remains one of the most important controls available to any firm.
Regular, relevant and practical training can help ensure that employees understand their responsibilities, reduce the likelihood of costly mistakes and support a stronger culture of compliance across the business.
To find out more about Legal Eye’s live GDPR training programme or discuss your firm’s wider GDPR compliance requirements, get in touch with our team.
Contact our team at [email protected] or call 020 3051 2049.
(0)20 3051 2049