Skip to content

UK GDPR

Data protection support for lead intake.

Casey qualifies an enquiry, then takes the fuller account after the firm accepts. This notice explains how the platform fits into a firm's own UK GDPR governance.

Roles

Controller, processor, and a recorded notice.

Controller responsibility stays with the firm

The firm determines the legal basis, privacy wording, matter retention, disclosure decisions, and responses to data subject rights.

Processor support from Casey

Casey provides the hosted workflow, access controls, operational safeguards, and product records needed to process data on the firm's instructions.

Evidence of notice

The account flow presents a privacy notice before it continues, and acknowledgement can be stored against the account.

Compliance model

Built to support, not replace, firm governance

Casey helps firms control access to data, keep records of activity, limit use to legitimate legal purposes, and reduce the chance of unauthorised disclosure.

UK GDPR principles

  • Lawfulness, fairness, and transparency
  • Purpose limitation and data minimisation
  • Accuracy and storage limitation
  • Integrity, confidentiality, and accountability

How Casey helps

  • Firm-scoped access for legal teams
  • Time-bound, account-specific links
  • Audit-friendly account, upload, submission, and follow-up records
  • Configurable account flows for different lead types

Rights

Requests sit with the firm that controls the matter.

Data subject rights

Depending on the legal basis and the firm's obligations, data subjects may have rights to access, rectify, erase, restrict, object to processing, or request portability.

Firm responsibilities

Casey is a tool used by legal professionals to support data protection processes. It is not a substitute for the firm's own privacy notices, record of processing activities, retention rules, data-processing terms, or legal advice.

Firms should confirm their own lawful basis, client-care wording, account privacy notice, processor terms, transfer position, retention policy, and incident response process before using the service for live matters.

Ready to map Casey to your intake process?

This notice explains how Casey fits a firm's UK GDPR governance. It should be read with the privacy policy and DPA.

Read the data processing addendum