Legal and information governance
Data Handling
1. Intake is deliberately limited
The public intake route is for a minimal first screen only: contact details, matter type, jurisdiction, timing and party names needed for an initial conflict check. Prospective clients should not send privileged documents, detailed evidence, credentials, financial models or special-category personal data at this stage.
2. Conflict and independence check
Before substantive information is accepted, HALD identifies the instructing party, relevant counterparties and other relationships necessary to assess conflicts, independence and engagement fit. A limited record may be retained to preserve the integrity of future checks.
3. Agreed secure transfer
Once scope and parties have been screened, HALD agrees the transfer method appropriate to the information. Engagement documents should not be exchanged through the public website. Access should be restricted to named authorised users and protected with multi-factor authentication where supported.
4. Storage and access
- Access is assigned on a need-to-know basis and reviewed when the team or scope changes.
- Local downloads and removable-media use are restricted and protected in line with the matter's risk classification.
- Material sent in error is isolated, reported and deleted or returned where appropriate.
5. Specialists and processors
Vetted specialists may receive access only where the client, scope and confidentiality arrangements permit it. Their access is limited to what they need, and they must follow written confidentiality and data-protection obligations. Technology providers acting as processors are subject to appropriate contractual and security review.
6. Working papers and review
HALD maintains a traceable evidence base linking material inputs, assumptions, calculations and conclusions. Review copies, comments and model versions should be controlled so that the final basis of the work is identifiable. The engagement terms determine the status and permitted use of working papers and deliverables.
7. Retention and disposal
Files are retained according to the engagement purpose, professional and legal requirements, conflict-record needs and the ability to establish, exercise or defend legal claims. At the end of the applicable period, records are securely deleted or anonymised and access is removed.
8. Incidents and rights requests
Suspected loss, unauthorised access or misdirection of information must be escalated promptly. HALD assesses containment, client communication, processor duties and any regulatory notification requirement. Privacy-rights requests are handled through the contact stated in the Privacy Statement.
9. Client-specific requirements
Law firms, investors, boards and regulated institutions may require additional controls, approved platforms, confidentiality terms or deletion certificates. These should be agreed in writing before information is transferred.