Our information security approach is based on the principles of access control, confidentiality, encryption, record-keeping, backup, employee awareness, and incident response.
In legal services, information security is a fundamental requirement in terms of both personal data protection and the obligation of professional secrecy.
Scope and purpose
This policy covers the fundamental principles for protecting client files, personal data, trade secrets, contracts, correspondence, and all sensitive information held in digital systems.
Access control
Access to information is restricted to those who need it for their duties. Permissions are defined on a role basis and are removed when the need ceases.
Technical and administrative measures
- Strong authentication and access logs,
- Secure cloud and backup infrastructure,
- Encryption and device security,
- Employee awareness and confidentiality undertakings,
- Incident response and notification processes.
Professional secrecy protection
Information security measures are applied in a manner that supports the confidentiality obligation of the legal profession.
Security incident management
In the event of potential security incidents, detection, containment, logging, notification, and remediation steps are applied. Where necessary, the client and the competent authorities are informed within the statutory periods.
Supplier and business partner security
Technical service providers and business partners are selected with due regard to confidentiality, data security, and authorisation limits; the necessary contractual safeguards are established.
Change History
- Version 1.0Mar 2026Initial publication.