PRIVACY & COOKIE POLICY

 

 

Privacy and Cookies Notice

Last updated: 4 September 2026

 

  1. About this notice

Catherine Higgins Law Limited is committed to protecting your personal information and respecting your privacy.

This Privacy and Cookies Notice explains how we collect, use, store and share personal information when you:

  • instruct us or enquire about our legal services;
  • are involved in a matter in which we are acting;
  • communicate with us;
  • visit or use our website;
  • apply for a role or provide services to us; or
  • otherwise interact with the firm.

It also explains your rights under data protection law and how you can raise a concern or complaint about the way we handle your personal information.

This notice is intended to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), as amended by the Data (Use and Access) Act 2025 (DUAA), and, where relevant to our website and electronic communications, the Privacy and Electronic Communications Regulations 2003 (PECR).

 

  1. Who is responsible for your personal information?

Catherine Higgins Law Limited is the data controller responsible for determining how and why your personal information is used.

Our contact details are:

Catherine Higgins Law Limited

45 Allerton Road

Woolton

Liverpool

Merseyside

L25 7RE

Telephone: 0151 428 2472

Email: enquiries@chigginslaw.co.uk

Catherine Higgins Law Limited is a company registered in England and Wales under company number 08484440 and is authorised and regulated by the Solicitors Regulation Authority under SRA number 598763.

If you have any questions about this notice, wish to exercise your data protection rights or wish to make a data protection complaint, please contact us using the details above and mark your correspondence for the attention of the person responsible for data protection.

 

  1. What personal information do we collect?

The personal information we collect will depend upon your relationship with us and the legal service or other interaction concerned.

It may include:

  • your name, address, telephone number, email address and other contact information;
  • date of birth and other identifying information;
  • copies of identification documents;
  • information obtained during identity, anti-money laundering and sanctions checks;
  • information about your occupation, employment, business or financial circumstances;
  • bank and payment information;
  • source-of-funds and source-of-wealth information;
  • information about property, assets, liabilities, trusts, estates or companies;
  • family and relationship information;
  • information contained in wills, probate records and estate administration documents;
  • correspondence, attendance notes and records of advice;
  • information about disputes, litigation, claims, opponents, witnesses, experts and court proceedings;
  • information provided by courts, tribunals, government bodies, regulators and other professional advisers;
  • information relating to complaints;
  • information relating to your use of our website; and
  • other information that is relevant to the legal services we provide or our legal and regulatory obligations.

Where information is obtained from somebody other than the individual concerned, data protection law may also require us to tell the individual about the categories and source of the information, subject to applicable exemptions.

 

  1. Prospective clients and conflict checking

When you contact us about a potential instruction, we may collect information about you and other people or organisations connected with the proposed matter.

We use this information to:

  • identify you;
  • understand the nature of the proposed instruction;
  • determine whether we are able to act;
  • carry out conflict-of-interest checks;
  • identify any confidentiality or professional conduct issues;
  • assess whether the matter falls within an area in which we provide services;
  • provide initial information or an estimate of costs; and
  • comply with legal and professional obligations.

We may retain a limited record of an enquiry even where you do not ultimately instruct us, including information necessary to evidence our conflict checks and protect the firm, our clients and prospective clients.

Our lawful bases may include compliance with legal or regulatory obligations and our legitimate interests in operating a regulated legal practice, protecting confidential information and identifying and managing conflicts of interest.

 

  1. Providing legal services

Where you instruct us, we process personal information as necessary to provide legal services and administer our relationship with you.

This may include using information to:

  • open and administer your matter;
  • communicate with you and others involved in your matter;
  • provide legal advice;
  • prepare documents;
  • negotiate and correspond on your behalf;
  • undertake searches and enquiries;
  • communicate with courts, tribunals, government bodies and other organisations;
  • instruct barristers, experts or other professional advisers;
  • manage deadlines and limitation periods;
  • comply with court orders and procedural requirements;
  • issue or defend legal proceedings;
  • administer estates, trusts, property transactions or other legal arrangements;
  • issue bills and collect sums due to us;
  • manage client account transactions where applicable;
  • maintain our professional records; and
  • manage complaints, claims, audits and regulatory enquiries.

Depending upon the circumstances, our lawful bases may include:

  • taking steps at your request before entering into a contract;
  • performance of our contract with you;
  • compliance with a legal obligation;
  • our legitimate interests in providing, administering and protecting our legal services and business; and
  • where applicable, the establishment, exercise or defence of legal claims.

 

  1. Identity verification and anti-money laundering checks

Solicitors are subject to legal and regulatory requirements concerning identity verification, anti-money laundering, counter-terrorist financing and prevention of financial crime.

Where applicable, we may collect and use information to:

  • verify your identity;
  • verify the identity of beneficial owners or other relevant persons;
  • understand ownership and control structures;
  • assess money laundering and terrorist-financing risk;
  • conduct customer due diligence;
  • undertake enhanced due diligence where required;
  • identify politically exposed persons;
  • carry out ongoing monitoring; and
  • comply with record-keeping and reporting obligations.

We may obtain information from you directly and from third-party identity verification, electronic verification, credit-reference, fraud-prevention or other screening services.

Where anti-money laundering legislation applies, processing will normally be necessary for compliance with our legal obligations.

We may also process information where necessary for our legitimate interests in protecting the firm and our clients against fraud and financial crime.

 

  1. Sanctions and fraud-prevention checks

We may check personal information against financial sanctions, fraud-prevention and other relevant databases.

This may include checking:

  • clients;
  • beneficial owners;
  • directors or controllers;
  • counterparties;
  • persons providing or receiving funds; and
  • other persons connected with a matter.

We do this where necessary to comply with sanctions legislation, professional obligations and other legal requirements and to protect the firm and our clients from fraud, financial crime and reputational risk.

Information may be shared with or obtained from screening providers, financial institutions, regulators, law-enforcement bodies and other appropriate organisations where lawful and necessary.

 

  1. Source of funds and source of wealth

Depending upon the type of matter and the level of risk involved, we may need information and evidence concerning:

  • where money being used in a transaction came from;
  • how funds were accumulated;
  • your financial circumstances;
  • the origin of particular assets;
  • gifts, loans or third-party contributions;
  • the identity of persons providing funds; and
  • your wider source of wealth.

We collect this information where necessary to comply with anti-money laundering, sanctions, fraud-prevention and professional obligations or where reasonably required to understand and manage financial crime risk.

You may be required to provide this information before we can accept instructions, continue acting or receive or transfer funds.

 

  1. Special category personal information

In providing legal services, we may need to process more sensitive types of information known as special category personal data.

This can include information concerning:

  • health or medical circumstances;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic or biometric information used for identification purposes; or
  • sex life or sexual orientation.

We will only process such information where an appropriate condition under data protection law applies.

Depending upon the circumstances, this may include processing that is necessary for:

  • the establishment, exercise or defence of legal claims;
  • reasons of substantial public interest permitted by the Data Protection Act 2018;
  • employment, social security or social protection obligations;
  • safeguarding or other permitted statutory purposes; or
  • your explicit consent where consent is genuinely appropriate.

We do not rely on consent where another legal basis is more appropriate.

The UK GDPR gives special category information additional protection and organisations must identify both an Article 6 lawful basis and an applicable special-category condition.

 

  1. Criminal offence information

Some legal matters may involve information concerning criminal allegations, investigations, convictions, offences or related proceedings.

We may process criminal offence information where it is relevant and lawful to do so, including for:

  • advising or representing clients;
  • conducting litigation;
  • establishing, exercising or defending legal rights or claims;
  • complying with legal or regulatory obligations;
  • preventing or detecting fraud or unlawful activity; or
  • another purpose permitted by the Data Protection Act 2018.

Where required, we will ensure that an appropriate condition under Schedule 1 of the Data Protection Act 2018 applies and that any additional documentation required by law is maintained.

Criminal offence information has additional statutory protection and requires both an Article 6 basis and appropriate authority under domestic law.

 

  1. Litigation, opponents, witnesses and court information

We do not only process information about our own clients.

When acting in legal matters, we may receive or process information concerning:

  • opponents and other parties;
  • witnesses;
  • family members;
  • beneficiaries;
  • executors and trustees;
  • experts;
  • barristers;
  • other solicitors;
  • medical professionals;
  • insurers;
  • courts and tribunal personnel;
  • government bodies; and
  • other people connected with a matter.

Information may be obtained from our client, the individual concerned, another party, another professional adviser, a court or tribunal, a public authority, publicly available sources or another lawful source.

We use this information where necessary to provide legal services, comply with professional duties, conduct or defend proceedings, establish or exercise legal rights and meet legal and regulatory obligations.

 

  1. Client account and payment information

Where relevant to the services we provide, we process payment and financial information including:

  • bank account details;
  • payment records;
  • information concerning money received or paid;
  • client account records;
  • transaction references; and
  • information needed to identify the source or destination of funds.

We use this information to:

  • receive and make payments;
  • operate our client account;
  • account to clients;
  • comply with the SRA Accounts Rules;
  • prevent fraud and financial crime;
  • comply with anti-money laundering and sanctions requirements; and
  • maintain appropriate financial and audit records.

We may share relevant information with banks, payment providers, accountants, auditors, regulators and other organisations where necessary and lawful.

 

  1. Our lawful bases for using personal information

The lawful basis we rely upon depends upon why we are using the information.

We may rely upon:

Contract – where processing is necessary to take steps at your request before entering into a contract or to provide services under our agreement with you.

Legal obligation – where we are required to process information to comply with legislation or other legally enforceable obligations.

Legitimate interests – where processing is necessary for our legitimate interests or those of another person, provided those interests are not overridden by your rights and interests. Examples include operating and protecting our business, preventing fraud, maintaining appropriate records, managing conflicts and establishing or defending legal rights.

Consent – where we have specifically asked for and obtained your consent and it is appropriate to rely upon consent. Where processing is based on consent, you may withdraw it at any time.

Legal claims and other statutory conditions – where additional conditions are required for special category or criminal offence data.

The particular lawful basis applying to a matter may vary according to the circumstances.

 

  1. Legal and professional obligations

As a regulated law firm, we are subject to obligations imposed by law and by our professional regulators.

These may require or permit us to process and, where appropriate, disclose information for purposes including:

  • compliance with the SRA Standards and Regulations;
  • anti-money laundering and counter-terrorist financing;
  • sanctions compliance;
  • prevention and detection of crime and fraud;
  • safeguarding client money;
  • conflict checking;
  • professional indemnity insurance;
  • responding to complaints and claims;
  • regulatory investigations or inspections;
  • court proceedings and legal obligations; and
  • maintaining appropriate business and client records.

Legal and professional obligations may sometimes restrict what we are able to tell you about particular processing or disclosures.

 

  1. Who do we share personal information with?

We only disclose personal information where there is an appropriate reason to do so.

Depending upon the matter, recipients may include:

  • barristers and other legal professionals;
  • expert witnesses;
  • medical professionals;
  • courts and tribunals;
  • government departments and public bodies;
  • HM Land Registry;
  • HM Revenue & Customs;
  • HM Courts & Tribunals Service;
  • the Probate Registry;
  • financial institutions and banks;
  • estate agents, managing agents and other property professionals;
  • search providers;
  • identity-verification and electronic screening providers;
  • accountants and auditors;
  • insurers and insurance brokers;
  • our professional indemnity insurers;
  • the Solicitors Regulation Authority;
  • the Legal Ombudsman;
  • the Information Commissioner’s Office;
  • law-enforcement agencies;
  • fraud-prevention and sanctions-screening providers;
  • IT, hosting, case-management, document-management and cybersecurity suppliers;
  • cloud and communications providers;
  • confidential waste and records-storage providers;
  • payment providers; and
  • other persons or organisations where disclosure is necessary for the matter or is required or permitted by law.

Some organisations process personal information on our behalf as processors. We require processors to handle information securely and in accordance with applicable data protection requirements.

Others may act as independent controllers and will be responsible for their own use of personal information.

 

  1. International transfers

Some organisations providing technology, hosting, communications or other services to us may process information outside the United Kingdom.

Where a transfer of personal information outside the UK constitutes a restricted transfer, we will ensure that an appropriate lawful transfer mechanism is in place.

Depending upon the circumstances, this may include:

  • UK adequacy regulations;
  • the UK Extension to the EU-US Data Privacy Framework, where applicable;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved standard contractual clauses; or
  • another lawful safeguard or permitted exception.

Where appropriate, we also carry out the required risk assessment and due diligence concerning international transfers.

The ICO confirms that restricted transfers must be covered by UK adequacy regulations, appropriate safeguards or an applicable exception.

 

  1. How long do we keep personal information?

We do not keep personal information for longer than is reasonably necessary.

The period for which information is retained will depend upon factors including:

  • the type of legal work undertaken;
  • the purpose for which the information was collected;
  • applicable limitation periods;
  • professional and regulatory obligations;
  • anti-money laundering record-keeping requirements;
  • tax and accounting requirements;
  • professional indemnity requirements;
  • whether legal proceedings or a complaint are contemplated or ongoing; and
  • whether original documents are held for safekeeping.

Different categories of files and records may therefore have different retention periods.

Some records, such as wills, deeds, probate or trust records and other documents held for safekeeping, may need to be retained for substantially longer periods.

When information is no longer required, we will delete, destroy or anonymise it securely in accordance with our retention procedures.

The ICO requires privacy notices to state either the applicable retention periods or the criteria used to determine them.

 

  1. Marketing

We may use contact information to provide existing or prospective clients with information about our services, legal updates or other information which we believe may be relevant to them, where permitted by law.

We will comply with UK GDPR and PECR when sending electronic marketing.

Where consent is required, we will obtain it before sending the relevant communication.

Where the law permits us to rely on another basis, such as the applicable existing-customer provisions, we will only do so where the legal requirements are satisfied.

You can ask us to stop sending marketing communications at any time by:

Objecting to direct marketing will not affect communications which we need to send in connection with an existing legal matter or another non-marketing purpose.

 

 

  1. Our website, cookies and storage/access technologies

Our website may use cookies and other technologies that store information on, or access information from, your device.

These are sometimes collectively referred to as storage and access technologies and can include:

  • cookies;
  • tracking pixels;
  • scripts and tags;
  • local or web storage;
  • navigational tracking; and
  • similar technologies.

PECR applies to these technologies, not only conventional browser cookies.

We use, or may use, these technologies for purposes including:

  • operating and securing the website;
  • remembering choices or preferences;
  • detecting fraud, abuse or technical faults;
  • understanding how the website is used;
  • improving website functionality and performance; and
  • where specifically permitted and enabled, other analytics or marketing purposes.

 

  1. Strictly necessary technologies

Some technologies are necessary for our website to function properly or to provide a service you have requested.

For example, they may be required for:

  • website security;
  • fraud prevention;
  • maintaining a user’s choices;
  • load balancing;
  • preventing technical faults; or
  • operating a requested website feature.

Where a technology satisfies an applicable PECR exception, consent may not be required.

We will nevertheless provide appropriate information about its purpose.

The current ICO guidance recognises exceptions including technologies required for transmission of communications and those strictly necessary to provide a user-requested service.

 

  1. Analytics and statistical technologies

We may use analytics technologies to understand how visitors use our website and to improve its performance.

Following changes made by the Data (Use and Access) Act 2025, certain technologies used solely to collect statistical information about use of a service with a view to improving that service may qualify for a specific PECR exception.

Where we rely upon that exception:

  • the information must be used solely for the permitted statistical purpose;
  • it must not be used to track, profile or make decisions about individual visitors;
  • appropriate information must be provided to visitors; and
  • visitors must be given a simple and free means of objecting.

Where those requirements are not met, we will obtain consent before using the technology.

 

  1. Preference and appearance technologies

We may use technologies which remember or apply preferences concerning the appearance or functionality of the website.

Certain technologies used solely for this purpose may qualify for the PECR appearance exception.

Where we rely upon this exception, we will:

  • explain the purpose clearly;
  • use the technology only for the relevant appearance or functionality purpose; and
  • provide a simple and free means of objecting.

The exception does not permit us to profile visitors or tailor content or advertising according to their inferred interests.

 

  1. Technologies requiring consent

Unless an applicable legal exception applies, we will obtain your consent before using storage or access technologies which are not necessary for the website or otherwise exempt.

This may include, depending upon what is actually deployed on our website:

  • non-exempt analytics;
  • advertising technologies;
  • cross-site tracking;
  • behavioural profiling;
  • certain embedded media;
  • social media tracking;
  • marketing pixels; and
  • other third-party tracking technologies.

Non-exempt technologies will not be activated before you have made the relevant choice.

Consent must be freely given, specific, informed and represented by an affirmative action. Simply continuing to browse the website does not amount to valid consent. The ICO also states that non-exempt technologies must not be pre-enabled.

 

  1. Managing your cookie and privacy choices

When you first visit our website, you will be given information and appropriate controls concerning the storage and access technologies we use.

Depending upon the technology concerned, you may be able to:

  • accept relevant technologies;
  • reject relevant technologies;
  • choose particular categories;
  • object to technologies used under a statutory exception where an objection mechanism is required; and
  • change your choices later.

You can change your choices at any time using the Cookie Settings link available on our website.

Withdrawing consent will not affect the lawfulness of processing which took place before consent was withdrawn.

Where we rely upon the statistical purposes or appearance exceptions rather than consent, we will provide a simple and free means of objecting as required by PECR.

 

  1. Cookies and technologies used on this website

The cookies and other storage or access technologies used by our website may change from time to time as our website and the services used to operate it are updated.

You can find current information about the technologies in use, including their purposes, relevant third-party providers and how long they operate, through our Cookie Settings tool.

Where consent is required, you can use the Cookie Settings tool to choose whether to allow the relevant technologies. You can also change or withdraw your choices at any time.

Where we use a technology under an applicable legal exception rather than consent, we will provide appropriate information and any objection mechanism required by law.

This keeps the notice accurate even if IT later changes a technical cookie, rather than requiring the privacy policy itself to be rewritten every time a cookie name or expiry period changes.

 

  1. Third-party website services

Our website may contain services or content provided by third parties, such as:

  • maps;
  • embedded videos;
  • analytics tools;
  • security services;
  • social media functionality; or
  • other externally hosted content.

These services may use their own storage or access technologies.

Where consent is required, we will take reasonable steps to prevent the relevant third-party technology from operating until the appropriate consent has been obtained.

Where third parties receive personal information through storage or access technologies, we will provide appropriate information about those third parties and their purposes.

The ICO states that where consent is relied upon, visitors must be given control over non-exempt technologies and be informed of relevant third parties.

 

  1. Information submitted through our website

If you contact us through an online enquiry, callback or other website form, we will use the information you provide to:

  • respond to your enquiry;
  • assess whether we may be able to assist you;
  • carry out preliminary conflict or risk checks where appropriate; and
  • take steps at your request before entering into a solicitor-client relationship.

Please do not provide unnecessary sensitive or confidential information through a general website enquiry form.

Submitting an enquiry does not, by itself, create a solicitor-client relationship.

Further information may be requested through an appropriate secure method if required.

 

  1. Security

We use appropriate technical and organisational measures designed to protect personal information against:

  • unauthorised access;
  • accidental loss;
  • misuse;
  • alteration;
  • disclosure; and
  • destruction.

Access to personal information is limited to people who have an appropriate reason to access it.

Our staff and relevant service providers are subject to confidentiality and data-security requirements.

No method of electronic transmission or storage can be guaranteed to be completely secure, but we maintain and review safeguards having regard to the nature and sensitivity of the information we process.

 

  1. Your data protection rights

Depending upon the circumstances and the lawful basis for processing, you may have the right to:

  • be informed about how we use your personal information;
  • obtain access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase personal information;
  • ask us to restrict the way information is used;
  • object to certain processing;
  • receive certain information in a portable format;
  • withdraw consent where processing is based upon consent; and
  • exercise rights relating to certain forms of automated decision-making.

These rights are not absolute and exemptions may apply, particularly where information is subject to legal professional privilege, is required for legal proceedings or must be retained to comply with legal or regulatory obligations.

We may need to verify your identity before responding to a rights request.

The ICO requires the applicable individual rights to be clearly explained and specifically requires the right to object to be brought prominently to people’s attention. (ICO)

Your right to object

You have the right to object to the processing of your personal information where we rely upon legitimate interests, subject to the circumstances and applicable legal exemptions.

You have an absolute right to object to the use of your personal information for direct marketing purposes.

 

  1. Your right to make a data protection complaint to us

You have a statutory right to complain to us if you consider that we have infringed your data protection rights or have otherwise failed to comply with data protection law in relation to your personal information.

You do not need to quote legislation or use legal terminology when making a complaint.

A complaint might concern, for example:

  • the way we collected or used your information;
  • an alleged unauthorised disclosure;
  • the security of your information;
  • the accuracy of information we hold;
  • how long information has been retained;
  • our handling of a subject access or other rights request; or
  • another concern about our compliance with data protection law.

Our detailed complaints procedure explains how to raise a data protection complaint and how we will deal with it.

We aim to acknowledge all complaints within two working days. In any event, data protection law requires a data protection complaint to be acknowledged within 30 days, and requires appropriate investigation, progress information and an outcome without undue delay.

The ICO’s current guidance confirms that organisations must have a process for handling data-protection complaints and that individuals do not have to use legal terminology to exercise the right.

This wording is also consistent with the more detailed data-complaint wording already incorporated into your revised complaints procedure.

 

  1. Your right to complain to the Information Commissioner’s Office

You also have a separate right to complain to the Information Commissioner’s Office (ICO) if you believe that the way in which your personal information has been processed infringes data protection law.

We would encourage you to raise the matter with us first so that we have an opportunity to investigate and, where appropriate, put matters right. However, your right to complain to the ICO is not dependent upon completing any optional internal review process operated by us.

The ICO can be contacted at:

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Telephone: 0303 123 1113

Website: https://ico.org.uk/make-a-complaint/

The ICO currently states that it normally expects individuals to give the organisation an opportunity to consider the issue before asking the ICO to investigate it.

 

  1. Changes to this notice

We keep this Privacy and Cookies Notice under review.

We may update it where:

  • our processing activities change;
  • we introduce new technology or service providers;
  • our website changes;
  • our retention practices change; or
  • legal, regulatory or ICO requirements change.

Where a change materially affects the way in which we use personal information, we will take appropriate steps to bring the change to the attention of affected individuals.

The current version will always be published on our website.