Legl

Last Reviewed: 27 Jul 2026

GDPR Addressed

At a Glance

Legl's Services Agreement addresses the key GDPR requirements for its UK-based operations, including breach notification, subprocessor flow-down obligations, and audit rights. The main practical point to note is that international transfer safeguards (e.g. SCCs) are committed to only on a conditional, as-needed basis rather than pre-emptively incorporated.

Company & Product Details

HQ

United Kingdom

Products

KYC/AML & Payments Platform for Law Firms

Product description

No-code platform for client onboarding, AML/KYC identity checks, and payment collection for law firms.

What data is being processed?

Personal Data relating to End Users (clients/potential clients of the Client), including identity documents, biometric information collected for KYC/AML checks, and Account Information (End User financial transaction data)

Document Details

Date of DPA

26 Jun 2023

Additional date information

Document footer states "Last updated 26 June 2023 (v.6)". The data protection terms are clause 12 of the main Legl Services Agreement rather than a standalone dated addendum.

What jurisdictions are covered?

Privacy Laws are defined to include the UK Data Protection Act 2018, UK GDPR, and PECR 2003. Services are limited to UK use by default, and Personal Data residing in the UK must not be transferred outside the UK without appropriate safeguards. Governing law and jurisdiction is England (clauses 5.1.6, 12.6.7, 14.12, 15.1).

Is the DPA incorporated into service or customer agreements?

Yes
The data protection terms are set out as clause 12 of the main Legl Services Agreement itself, rather than a standalone addendum, and therefore automatically form part of the Agreement (clause 12).

Location & Transfers

Where is data held or processed?

United Kingdom The Services are limited to UK use by default; the Client may not use the Services in another jurisdiction if that would require Legl to physically store data there without Legl's prior written consent, and Personal Data residing in the UK must not be transferred outside the UK unless appropriate safeguards are put in place (clauses 5.1.6, 12.6.7).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Unclear
Clause 12.6.7 commits Legl to putting in place appropriate transfer safeguards, "including, where appropriate, executing the Standard Contractual Clauses approved by the relevant United Kingdom authority," before transferring UK Personal Data abroad. This is a conditional, as-needed commitment rather than SCCs being pre-emptively incorporated or attached to the Agreement, so it is unclear whether SCCs are currently in place for any given transfer (clause 12.6.7).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Legl must take all measures required under Article 32 of the GDPR, taking into account the state of the art, cost of implementation, and the nature, scope, context and risk of the processing; Legl also holds ISO/IEC 27001 certification (clause 12.6.2).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Clause 12.5 confines Legl's processing of Personal Data to what is necessary to comply with its obligations under the Agreement, and clause 12.6.10 requires Legl to delete any Personal Data not necessary for providing the Services, without further notice. No controller rights or independent-use provisions over Personal Data processed on the Client's behalf were identified. Separately, the Fraud Database Service Provider (a specialist third party used for AML/KYC checks) may retain identity documents suspected of fraud for future fraud-prevention purposes, which is a standard AML control rather than a use by Legl itself for its own commercial purposes (clauses 6.2, 12.5, 12.6.10).

Subprocessing

General authorization

General
Before making Personal Data available to any new third-party subprocessor, Legl must give the Client an opportunity to object, impose contractual obligations on the subprocessor substantially similar to its own obligations, and add the subprocessor to its published Sub-Processor Policy list. If the Client objects, Legl has no liability for any resulting delay to the Services (clause 12.6.6).

Do all the DPA terms flow down to sub-processors?

Yes
Legl must impose contractual obligations on new subprocessors that are substantially similar to its own obligations under this DPA, and remains liable to the Client for any breach caused by an act, error or omission of such third party (clause 12.6.6).

Is data only processed on the instruction of the controller?

Yes
Legl processes Personal Data in accordance with the Agreement and any other documented instructions from the Client, save where required otherwise by law (in which case it will inform the Client) or where an instruction appears to infringe Privacy Laws (clause 12.6.1).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Legl implements technical and organisational measures to assist the Client in responding to Data Subject Rights requests (access, rectification, erasure, restriction, portability, objection), and may direct data subjects to contact the Client directly using the Client's provided contact information (clause 12.6.4).

Does the contract include staff confidentiality clauses?

Yes
Legl takes reasonable steps to ensure the reliability of personnel with access to Personal Data, limiting access to those who require it and who are bound by confidentiality obligations or an equivalent statutory duty (clause 12.6.3).

Are there audit rights for the data?

Structured
Upon 60 days' written notice, no more than once per contract year, during normal business hours, Legl will provide the Client reasonable access to its books and records to demonstrate compliance with Privacy Laws. Additional audit requests are at Legl's discretion and the Client's cost, unless the audit reveals a breach by Legl (clause 12.6.8).

Is there assistance with DPIA requests?

Yes
Legl will assist the Client in ensuring compliance with obligations under GDPR Articles 32–36, taking into account the nature of processing and information available to Legl (clause 12.6.5).

How much notice is provided for data breaches?

Legl will promptly notify the Client of a confirmed Security Breach and provide all reasonable help to investigate and remedy it; no specific fixed time limit (e.g. a number of hours) is stated (clause 12.6.9).

What happens to the data on termination?

Legl deletes Personal Data not necessary for the Services without further notice. Upon the Client's request, or once Legl no longer needs the data for the agreed purposes (whichever is earlier), Legl will cease all use and destroy all Personal Data, unless retention is required by applicable law (clause 12.6.10).