Data Protection

It is increasingly important for businesses to embed privacy, by design and by default, into every aspect of your activities.

Our approach is to build a deep understanding of the specifics of your business so we can identify your data protection issues throughout the duration of your customer and employee relationships as well as the lifecycle of your company.

Our comprehensive services include:

  • Process: legal advice around process improvements for established businesses
  • Documentation review: to ensure existing privacy statements and contracts are compliant with current and future legislation
  • Breaches: breach notification to the ICO, navigating fallout with stakeholders, dealing with threatened claims and litigation against providers in your supply chain
  • International: assisting international clients to understand their obligations when they are processing the data of EU citizens
  • Start ups: advisory work to ensure that the complex legislative regime around data protection is adhered to from the ground up

Pitmans Law GDPR Insights
Pitmans is currently providing a series of Pitmans Points Specials into GDPR compliance. Sign up. You can also find out more about our GDPR event here.

Pitmans Law GDPR Countdown
Are you regulation ready? Check our GDPR Countdown to see how long you’ve got before you could face a 20 million EURO fine.


We act for a diverse range of domestic and international clients, from start-ups to multinationals, and everything from tech companies leveraging big data in their service offerings through to charities navigating a response to a subject access request for the first time.

Case studies

Advising a provider of technology-backed healthcare services in connection with the processing of sensitive personal data and drafting documentation to support their processes

Reviewing the document suite of a national provider of insurance-related services through a web portal in connection with GDPR compliance

Advisory and data breach notification work following a hack of a US-based business with a significant percentage of its customers located in the UK and EU

Investigation and pre-litigation correspondence in connection with the data theft of commercially sensitive business and personal information by a “bad leaver”


“They are willing to go the extra mile for the relationship. You get a city performance from a regional office.”

“They are diligent and very thorough. They go beyond the call of duty.”

Chambers & Partners

“The firm’s performance is excellent, I can’t fault it.”

Chambers & Partners