Refine By
Clear all filter
About 91970 results for "*"
PRACTICE NOTES
Your complaints handling framework (See Practice Note: How to implement and maintain effective complaints handling procedures—law firms) will be designed with the size and nature of your firm in mind. It is important to acknowledge that certain situations may require a more tailored approach, while still being handled within your overarching complaints processes. This How-to-guide sets out examples of situations where additional considerations may be required, beyond those addressed in your standard complaints handling framework. Complaints about the bill Complaints about bills are reasonably common. You must treat a complaint about your bill in the same way as any other complaint. The Legal Ombudsman (LeO) has published guidance on Complaints about legal costs, having identified common themes in complaints. Although the guidance is geared towards complaints associated with cases funded by conditional fee agreements, it provides an insight into LeO’s approach more generally. When investigating complaints about costs, LeO will check whether you made sure, right from the start, that the client fully understood what they would or might have to pay. The
PRACTICE NOTES
This Practice Note is intended for private-sector commercial organisations in the UK. It sets out expectations of the Information Commission’s Office (ICO) in relation to obtaining, recording and managing consent to process personal data. This Practice Note also reflects UK General data Protection Regulation (UK GDPR) requirements on consent to process personal data. What is consent? Consent is any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data. Consent must therefore be: • freely given • specific • informed • unambiguous There are two levels of consent depending on the type of data you are processing: • standard consent, which is required to rely on consent to process non-sensitive personal data • explicit consent, which is required to rely on consent to process special category (sensitive) personal data—there is no definition of explicit consent but see Practice Note: How to identify and manage special category personal data—Explicit consent For
PRACTICE NOTES
Corporate criminal liability is the legal mechanism through which an organisation may be held criminally responsible for criminal conduct, and it can arise in a number of ways. Once corporate criminal liability risks have been identified and assessed, organisations should consider whether their existing governance arrangements, compliance controls and reporting mechanisms are sufficient to manage them effectively. This ‘How to’ guide provides practical guidance for private sector commercial organisations in the UK on how to manage corporate criminal liability risks. It should be read alongside ‘How to’ guide: How to identify and assess corporate criminal liability risks. See also Precedent: Corporate criminal liability—risk management plan which you can use to plan your approach for implementing appropriate measures to manage corporate criminal liability risks, and Corporate criminal liability risk management—checklist for a practical framework for reviewing whether your governance arrangements, compliance controls, reporting mechanisms and risk management measures adequately address risks. Understanding corporate criminal liability Corporate criminal liability may arise in a number of ways, including through senior manager attribution, failure to prevent offences
PRACTICE NOTES
This Practice Note is intended for commercial organisations based in the UK. It summarises key features of the UK General Data Protection Regulation (UK GDPR). It also provides practical guidance on what you need to do to ensure UK GDPR compliance and signposts relevant tools and Precedents in Lexis+AI™. The challenge of ongoing compliance with the UK GDPR should not be underestimated, nor should the consequences of failing to comply—the potential for fines of £17.5m or 4% of annual global turnover. Does the UK GDPR apply to your organisation? The UK GDPR applies to all UK organisations that handle personal data. As it is virtually impossible to operate a business without handling personal data, it's probably safe to assume your organisation is caught by the UK GDPR. The UK GDPR also applies to organisations outside the UK that offer goods or services to individuals in the UK. For more guidance, see Practice Note: Introduction to the EU GDPR and UK GDPR—Territorial scope of the GDPR regimes. What data is covered by the
PRACTICE NOTES
This Practice Note is intended for general commercial organisations based in the UK. It explains the retention requirements that apply to personal data and provides practical guidance on how to comply with these obligations. This Practice Note reflects the UK General Data Protection Regulation (UK GDPR), Assimilated Regulation (EU) 2016/679. The data retention requirements arise out of the storage limitation principle in the UK GDPR. You must not keep personal data for longer than you actually need it. You should delete or anonymise personal data once it is no longer required. Good practice around storage limitation can also reduce the burden of dealing with questions about retention and individual requests for erasure. It will also limit the risk of individuals’ data being used in error or in ways which could adversely affect their rights and freedoms under the UK GDPR. From a practical perspective, it is inefficient to hold more personal data than you need, and you could be incurring unnecessary costs associated with storage and security. Data protection principles It is important to understand
PRACTICE NOTES
Written for in-house lawyers, this risk management guide aims to provide a useful checklist when considering how to address the environmental risks relating to an organisation and to provide the tools to monitor compliance with the laws. Managing environmental risk General counsel and in-house lawyers may consider environmental risk in varying degrees, depending largely on what the organisation does and what drivers might cause organisations to have to consider how they demonstrate compliance with environmental laws. For example, organisations that wish to achieve and maintain certification under the ISO 14001 will have to demonstrate legal compliance (see Practice Note: Environmental management—environmental legal registers) while others are bound by environmental regulation to ensure that the activities they undertake can be sustained. In a time where stakeholders are demanding companies prove their environmental, social and governance (ESG) commitments, managing environmental risks will be high on the agenda for inhouse legal teams. This guide aims to set out: • key environmental issues to consider primarily as part of an office, with reference to some key legislation
PRACTICE NOTES
You have a duty to take precautions to minimise the risk of fire in your workplace and ensure the safety of your employees in the event of fire. There are no hard and fast rules about what fire safety provisions you are required to put in place. Smaller organisations may only need minimal provision while other larger organisations or those with particular fire risks may require more resources. This Practice Note provides practical information on managing and ensuring fire safety in the workplace. It covers fire safety in an office-based, non-residential workplace. Other industry/premises-specific requirements may apply in different environments, especially to residential and domestic buildings, including flats and multi-storey residential buildings. Regulatory requirements in relation to fire safety in residential and domestic premises are outside the scope of this Practice Note as are building regulations requirements in relation to fire safety. For information about regulatory requirements relevant to fire safety in an office-based workplace, see Practice Note: Fire safety in the workplace—regulatory requirements. Fire safety assessment and planning Having
PRACTICE NOTES
You have a duty to provide adequate and appropriate equipment, facilities and personnel to ensure your employees receive immediate attention if they are injured or become ill in the workplace. There are no hard and fast rules about what first aid provisions you are required to put in place. Some smaller organisations may only need the minimum provision of first aid but other larger organisations or those with particular first aid risks may require more resources. This Practice Note provides information on managing and ensuring the effective provision of first aid in the workplace. For information about regulatory requirements relevant to first aid, see Practice Note: First aid in the workplace—regulatory requirements. First aid needs assessment You should already have conducted a first aid needs assessment—see Precedents: First aid needs assessment and First aid provision management lifecycle. The result of this assessment will enable you to ensure you allocate sufficient first aid equipment, facilities and personnel appropriate to the particular circumstances of your workplaces—see further Practice Note: How to conduct
PRACTICE NOTES
The Economic Crime and Corporate Transparency Act 2023 (ECCTA 2023) introduced a corporate offence of failure to prevent fraud, in force from 1 September 2025. This Practice Note is intended for commercial organisations, including law firms. It summarises the main elements of the failure to prevent fraud offence introduced through ECCTA 2023. It covers government expectations of the procedures organisations should have in place to prevent fraud and resulting compliance issues. Failure to have such procedures in place can leave the organisation exposed to criminal offences. Organisations should also consider how to avoid becoming victim to fraud. While the failure to prevent fraud offence is a different aspect of fraud prevention, the risk management steps and preventative measures taken by commercial organisations are likely to be very similar. For this reason, both aspects of fraud risk management are covered in this Practice Note. What is fraud? Fraud is the deliberate use of deception or dishonesty to deprive, disadvantage or cause loss (usually financial) to another person or party. Specific offences are set out in Schedule 13
PRACTICE NOTES
An organisation has a duty to ensure it manages the health and safety risks in its workplace effectively and efficiently. This Practice Note provides information on managing and ensuring health and safety in the workplace. It covers health and safety requirements in an office-based workplace. Other industry/workplace-specific requirements may apply in different working environments. For information about regulatory requirements relevant to workplace safety, see Practice Note: Health and safety in the workplace—regulatory requirements. What are the organisation’s workplaces? A workplace may include an organisation’s own premises including any office space and other areas from which it delivers its services. An organisation may need to consider other areas such as any other locations from which it provides services or goods such as outreach or voluntary centres. Organisations may share work spaces with other businesses. An example would be serviced offices that share common reception, toilet and kitchen areas. In these circumstances, there may already be some communal protection measures in place and/or the organisation may need to comply with particular
PRACTICE NOTES
This Practice Note provides information on investigating, handling and reporting health and safety incidents in an office-based workplace. Other industry/workplace-specific requirements may apply in different working environments. Dealing with incidents Employers and others in control of work premises have a duty to maintain records and to report certain incidents such as serious injuries, death, disease or dangerous occurrences. For information about regulatory requirements concerning health and safety incidents, see Practice Note: Dealing with health and safety incidents—regulatory requirements. Key staff members Ensure that the person (or team of people) with overall responsibility for health and safety is of sufficient seniority to enable them to lead the assessment and management process when an incident occurs and oversee any measures put in place—see Practice Note: Dealing with health and safety incidents—regulatory requirements. Depending on the size and the nature of the business, an organisation may need to appoint other staff members to ensure it meets its health and safety duties. Any person(s) appointed to take on a particular role within the organisation
PRACTICE NOTES
This Practice Note is intended for in-house lawyers and privacy and compliance professionals in private sector commercial organisations in the UK. It provides guidance on how to manage international transfers of personal data and explains the legal and practical challenges organisations face in relation to international data transfers. It reflects ICO guidance on international transfers, including in relation to transfer risk assessments (TRAs), also known as data protection tests. This Practice Note is not intended for public sector organisations. The data protection regime on international transfers Where you transfer personal data internationally (outside the UK), you must satisfy and comply with requirements in Chapter V of the UK GDPR. These requirements are set out in Articles 44–50 of the UK GDPR and are referred to in this Practice Note as the transfer rules. They apply even when the receiver of the information is subject to the UK GDPR. To comply with the transfer rules and wider data protection regime, you should consider: • is there an alternative to transferring personal data outside