Legl
Last Reviewed: 27 Jul 2026
At a Glance
Legl's Services Agreement addresses the key GDPR requirements for its UK-based operations, including breach notification, subprocessor flow-down obligations, and audit rights. The main practical point to note is that international transfer safeguards (e.g. SCCs) are committed to only on a conditional, as-needed basis rather than pre-emptively incorporated.
Company & Product Details
HQ
United Kingdom
Products
KYC/AML & Payments Platform for Law Firms
Product description
No-code platform for client onboarding, AML/KYC identity checks, and payment collection for law firms.
What data is being processed?
Personal Data relating to End Users (clients/potential clients of the Client), including identity documents, biometric information collected for KYC/AML checks, and Account Information (End User financial transaction data)
Document Details
Date of DPA
26 Jun 2023
Additional date information
Document footer states "Last updated 26 June 2023 (v.6)". The data protection terms are clause 12 of the main Legl Services Agreement rather than a standalone dated addendum.
What jurisdictions are covered?
Privacy Laws are defined to include the UK Data Protection Act 2018, UK GDPR, and PECR 2003. Services are limited to UK use by default, and Personal Data residing in the UK must not be transferred outside the UK without appropriate safeguards. Governing law and jurisdiction is England (clauses 5.1.6, 12.6.7, 14.12, 15.1).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
United Kingdom The Services are limited to UK use by default; the Client may not use the Services in another jurisdiction if that would require Legl to physically store data there without Legl's prior written consent, and Personal Data residing in the UK must not be transferred outside the UK unless appropriate safeguards are put in place (clauses 5.1.6, 12.6.7).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Legl must take all measures required under Article 32 of the GDPR, taking into account the state of the art, cost of implementation, and the nature, scope, context and risk of the processing; Legl also holds ISO/IEC 27001 certification (clause 12.6.2).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Legl will promptly notify the Client of a confirmed Security Breach and provide all reasonable help to investigate and remedy it; no specific fixed time limit (e.g. a number of hours) is stated (clause 12.6.9).
What happens to the data on termination?
Legl deletes Personal Data not necessary for the Services without further notice. Upon the Client's request, or once Legl no longer needs the data for the agreed purposes (whichever is earlier), Legl will cease all use and destroy all Personal Data, unless retention is required by applicable law (clause 12.6.10).