Skip to main content

GDPR Compliance & Data Protection

Quick Answer

BundleCreator is built to help legal professionals and their clients meet UK GDPR obligations. Documents are stored on UK-hosted infrastructure (europe-west2, London), encrypted with AES-256 at rest and TLS 1.3 in transit, subject to 7-year audit logging, and protected by row-level security in PostgreSQL. Users retain full rights under UK GDPR — including access, rectification, erasure, and portability — through in-app tools, with a documented Data Processing Agreement.

GDPR Compliance for Legal Professionals

BundleCreator.co is designed from the ground up to meet GDPR requirements, providing legal professionals with tools to help protect personal data. Our comprehensive approach aims to support both your practice and your clients' data protection needs.

1. Core GDPR Principles Implementation

BundleCreator.co is built with GDPR's seven key principles in mind, designed to support lawful, transparent, and secure data processing.

1.1 Lawfulness, Fairness & Transparency

  • Clear Legal Basis: Processing under legitimate interests for legal proceedings (Article 6(1)(f)) and legal obligations (Article 6(1)(c))
  • Transparent Processing: Clear privacy notices at every data collection point
  • Fair Processing: No hidden data uses, all processing explicit and expected
  • Client Notifications: Automated notifications for all data processing activities

1.2 Purpose Limitation

  • Specific Purposes: Data collected solely for legal bundle creation and court submission
  • No Secondary Use: Personal data never used for marketing or unrelated purposes
  • Purpose Documentation: Each data field mapped to specific legal requirement
  • Purpose Enforcement: Technical controls prevent purpose creep

1.3 Data Minimisation

  • Minimal Collection: Only data required for court bundles collected
  • Automatic Redaction: Tools to remove unnecessary personal data
  • Smart Forms: Dynamic forms only show relevant fields
  • Data Review: Regular audits to ensure minimal data retention

1.4 Accuracy

  • Version Control: Complete audit trail of all document changes
  • Update Rights: Easy mechanisms for data subjects to update information
  • Accuracy Checks: Automated validation of key data fields
  • Source Documentation: Clear attribution of data sources

1.5 Storage Limitation

  • Retention Policies: Automated deletion after case conclusion plus statutory period
  • Litigation Hold: Smart preservation for ongoing matters
  • Client Control: Users can set custom retention periods
  • Deletion Confirmation: Cryptographic proof of deletion

1.6 Integrity & Confidentiality

  • End-to-End Encryption: AES-256 encryption at rest and in transit
  • Access Controls: Role-based access with principle of least privilege
  • Audit Logging: Comprehensive logs of all data access
  • Breach Prevention: Multiple layers of security controls

1.7 Accountability

  • Documentation: Complete records of all processing activities
  • DPIAs: Data Protection Impact Assessments for all features
  • Training: Regular GDPR training for all staff
  • Compliance Monitoring: Continuous compliance verification

2. Data Subject Rights Implementation

2.1 Right of Access (Article 15)

  • Self-Service Portal: Data subjects can view all their data instantly
  • Export Functions: Download personal data in common formats (PDF, CSV, JSON)
  • Processing Information: Clear explanations of how data is used
  • Third-Party Sharing: Complete list of any data recipients

2.2 Right to Rectification (Article 16)

  • Inline Editing: Direct correction of personal data
  • Correction Requests: Simple form for rectification requests
  • Propagation: Changes automatically updated across all documents
  • Audit Trail: Complete history of all corrections

2.3 Right to Erasure (Article 17)

  • Deletion Tools: One-click deletion where legally permissible
  • Legal Hold Check: Automatic verification of deletion eligibility
  • Cascade Deletion: Removal from all backups and archives
  • Deletion Certificate: Cryptographic proof of erasure

2.4 Right to Data Portability (Article 20)

  • Standard Formats: Export in JSON, XML, or CSV
  • Direct Transfer: API for direct transfer to other controllers
  • Comprehensive Export: All personal data and metadata included
  • Machine Readable: Structured data for easy import elsewhere

2.5 Right to Object & Restrict (Articles 18 & 21)

  • Processing Controls: Granular control over data processing
  • Restriction Flags: Mark data for restricted processing
  • Automated Compliance: System enforces processing restrictions
  • Objection Handling: Clear process for handling objections

3. Technical & Organisational Measures

3.1 Privacy by Design

  • Default Privacy: Most restrictive settings by default
  • Pseudonymisation: Automatic pseudonymisation where appropriate
  • Data Isolation: Complete separation between clients' data
  • Privacy Controls: User-friendly privacy settings dashboard

3.2 Security Measures

  • Encryption: AES-256 encryption for all personal data
  • Access Control: Multi-factor authentication required
  • Network Security: Firewall, IDS/IPS, and DDoS protection
  • Vulnerability Management: Regular penetration testing

3.3 Breach Response

  • Detection: Real-time breach detection systems
  • 72-Hour Notification: Automated ICO notification system
  • Impact Assessment: Immediate risk assessment tools
  • Communication: Template notifications for affected parties

4. Legal Sector Specific Compliance

4.1 Legal Professional Privilege

  • Privilege Markers: Clear identification of privileged documents
  • Access Restrictions: Technical enforcement of privilege rules
  • Audit Exemption: Privileged data excluded from routine audits
  • Waiver Prevention: Safeguards against inadvertent disclosure

4.2 Court Requirements

  • Practice Direction 27A: Tools designed to assist with court bundle requirements
  • Redaction Tools: Court-compliant redaction with audit trail
  • Metadata Preservation: Maintains required metadata for evidence
  • Chain of Custody: Complete documentation for court admissibility

4.3 Special Category Data

  • Enhanced Protection: Additional encryption for sensitive data
  • Access Logging: Detailed logs for special category access
  • Consent Management: Explicit consent tracking where required
  • Impact Assessments: Automatic DPIAs for sensitive processing

5. International Data Transfers

All data remains within the UK/EEA. No transfers to third countries without adequate protection.

5.1 Data Localisation

  • UK Data Centres: Primary processing in UK facilities
  • EU Backup: Disaster recovery within EEA
  • No US Transfer: No reliance on Privacy Shield or similar
  • Sovereignty Guarantee: Data never leaves UK/EU jurisdiction

5.2 Third-Party Processors

  • Vetted Processors: All processors GDPR compliant
  • Data Processing Agreements: Comprehensive DPAs in place
  • Regular Audits: Annual audits of all processors
  • Processor List: Available on request

6. Compliance Documentation & Auditing

6.1 Records of Processing (Article 30)

  • Processing Register: Comprehensive record of all activities
  • Purpose Documentation: Clear purposes for each processing
  • Category Mapping: All data categories documented
  • Retention Schedule: Clear retention periods for all data

6.2 Regular Audits

  • Internal Audits: Quarterly compliance reviews
  • External Audits: Annual third-party assessment
  • Audit Reports: Available to clients on request
  • Remediation Tracking: All findings tracked to closure

6.3 Training & Awareness

  • Staff Training: Annual GDPR training for all employees
  • Legal Updates: Regular updates on regulatory changes
  • Client Resources: GDPR guides for legal professionals
  • Compliance Culture: Privacy embedded in company values

7. Your Rights as Data Controller

Full Control: You remain the data controller for client data

Processing Agreement: Clear processor agreement defining responsibilities

Instruction Rights: We only process data on your instructions

Audit Rights: Full audit rights over our processing

Portability: Export all data at any time

Data Protection Contact

Data Protection Officer:

dpo@bundlecreator.co

Prompt response to all requests

ICO Registration:

ZB969283

Fully registered with the ICO

Supervisory Authority: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been infringed. Visit ico.org.uk for more information.

GDPR Resources for Legal Professionals

Available Documents:

  • • Full Privacy Policy
  • • Data Processing Agreement Template
  • • GDPR Compliance Checklist
  • • Data Breach Response Plan

Compliance Tools:

  • • Data Subject Request Forms
  • • Privacy Impact Assessment Template
  • • Consent Management Tools
  • • Retention Policy Builder

Last Updated: 24/07/2026

Version: 1.0

Next Review: 22/10/2026