Privacy Policy

Introduction

KMT Law LLP (referred to as KMT, the Firm, we, us or our in this policy) respects your privacy and is committed to protecting your personal data. This policy explains how we look after your personal data when you instruct us, or otherwise interact with us, and tells you about your privacy rights and how the law protects you.

This policy covers how KMT collects and uses personal data belonging to you, or to individuals connected with your organisation, in the context of providing legal services through the ways we interact with you as described below. Where our processing of your personal data in connection with a specific matter is subject to additional or different terms, we will explain this to you separately (for example, in our engagement letter or terms of business).

Our website is not intended for children, and we do not knowingly collect data relating to children.

1.     Who we are

KMT Law LLP is a limited liability partnership registered in England and Wales (registered number OC345380), authorised and regulated by the Solicitors Regulation Authority (SRA number 513195). Our registered office is at 11 Haymarket, St James, London, SW1Y 4BP.

KMT Law LLP is the controller and is responsible for your personal data for the purposes of data protection law.

If you have any questions about this policy, including any request to exercise your legal rights, please contact us using the details in section 10 below.

2.     The personal data we collect about you

Personal data means any information about an individual from which that person can be identified. We may collect, use, store and transfer the following kinds of personal data about you:

  • Identity Data — first name, last name, title, date of birth, and (where relevant to a matter) marital status and other identity details.
  • Contact Data — address, email address and telephone numbers.
  • Financial Data — bank account and payment details, and source of funds/wealth information.
  • Transaction Data — details of payments to and from you and of the services we have provided.
  • Identity Verification Data — copies of identification documents and verification results obtained through Thirdfort or otherwise, for AML and client due diligence purposes.
  • Matter Data — the substantive information you provide, or that we collect or generate, in the course of advising you or handling your matter, which may include Special Category Data or Criminal Convictions and Offences Data where relevant to the matter.

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of our engagement with you, and you do not provide that data when requested, we may not be able to perform the services set out in our engagement letter, including because we are unable to complete AML or client due diligence checks.

3.     How is your personal data collected?

We collect data from and about you in the following ways:

  • directly from you, when you instruct us, correspond with us by email, post, phone or video call, complete a form, request our services, register for an event, subscribe to our publications, or provide feedback;
  • through your organisation, its representatives, or other parties to your matter and their advisers;
  • through our identity verification and AML provider, Thirdfort, when you are asked to complete identity or source of funds checks;
  • through networking, including at in-person or virtual events;
  • through publicly available sources, such as Companies House and the Land Registry, and from data providers used for professional and conflict checking purposes;
  • through our website, including via forms you complete and, using cookies and similar technologies, through automated interactions (see our cookie policy for details); and
  • from regulatory bodies, courts, or other third parties in the course of a matter.

4.     How we use your personal data

Lawful basis for processing

We rely on one or more of the following lawful bases to process your personal data:

  • Performance of a contract — where we need to perform, or take steps to enter into, a contract with you.
  • Legitimate interests — where it is necessary for our legitimate interests as a legal services provider (or those of a third party), and your interests and rights do not override those interests. Our legitimate interests include managing our relationships with clients and their staff, running and promoting our business, and ensuring the security of our systems and premises.
  • Legal obligation — where we need to comply with a legal or regulatory obligation, including under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 and SRA Standards and Regulations.
  • Consent — where we have obtained your active agreement, for example to send you marketing communications.

Where we process Special Category Data or Criminal Convictions and Offences Data, we do so only where necessary in connection with legal claims or advice, where another appropriate condition under data protection law is met, or with your explicit consent.

Purposes for which we use your personal data

The table below sets out the main ways we use your personal data, our lawful basis for doing so, and a summary of the applicable retention period (full detail is set out in our internal Data Retention Policy, available on request).

Purpose / use

Type of data

Lawful basis and retention

To assess whether we can act for you (or your business), including conflict checks, and to carry out AML, sanctions and client due diligence checks (including via Thirdfort)

Identity, Contact, Financial

Legal obligation (Money Laundering Regulations 2017); performance of a contract; legitimate interests (preventing fraud and money laundering). Retained for a minimum of 6 years after the end of the business relationship — see our Data Retention Policy.

To deliver our legal services to you, including managing your matter on LEAP, corresponding with you, and engaging counsel or other service providers on your behalf

Identity, Contact, Financial, Transaction, Special Category (where relevant to the matter)

Performance of a contract; legal obligation; legitimate interests. Retained for the applicable matter retention period set out in our Data Retention Policy (typically 6–15 years, or indefinitely for original wills).

To manage billing, payments and recovery of fees owed to us

Identity, Contact, Financial, Transaction

Performance of a contract; legitimate interests (recovering debts due to us). Retained for 6 years in line with accounting record requirements.

To manage our relationship with you, including updating you about changes to our terms or this policy

Identity, Contact, Profile, Marketing and Communications

Performance of a contract; legal obligation; legitimate interests. Retained for the matter retention period.

To send you newsletters, legal updates and invitations to events, and to manage suppression lists

Identity, Contact, Marketing and Communications

Consent (individuals) or legitimate interests (existing business contacts). Business contact data retained for 3 years from last engagement or until you opt out; suppression records retained indefinitely to give effect to an opt-out.

To administer, secure and improve our website and IT systems (including troubleshooting and support provided by ECC)

Identity, Contact, Technical

Legitimate interests (network security, running our business); legal obligation. Retained per our cookie policy and IT security log retention (typically 12 months).

To manage recruitment and job applications

Identity, Contact, Professional, Special Category (where volunteered)

Consent; legitimate interests; legal obligation (equal opportunities monitoring). Retained for 6 months following the recruitment process for unsuccessful candidates.

5.     Disclosures of your personal data

We do not sell your personal data. We may share your personal data with the following categories of recipient, only to the extent necessary and subject to appropriate contractual protections:

  • LEAP — our case and document management provider, which hosts the definitive electronic record of your matter.
  • ECC — our IT and technical support provider, who may have access to our systems (and therefore to personal data held on them) for support and maintenance purposes.
  • Thirdfort — for identity verification, source of funds/wealth checks and AML/client onboarding.
  • Deepstore Records Management — for secure off-site storage, retrieval and confidential destruction of archived physical files.
  • other professional advisers, barristers, experts, mediators, arbitrators or other law firms instructed in connection with your matter;
  • counterparties to your matter and their advisers, where necessary to progress the matter;
  • courts, law enforcement, regulators (including the SRA and ICO) and government bodies, where required or permitted by law;
  • our insurers and auditors, where necessary; and
  • a prospective buyer or successor firm, if we were to sell, transfer or merge parts of our business, subject to appropriate confidentiality protections.

We require all third parties to respect the security of your personal data, to treat it in accordance with the law, and to process it only for the purposes we specify and in accordance with our instructions.

6.     International transfers

Where we do transfer personal data outside the UK (including to a supplier who processes data on our behalf, or in connection with a cross-border matter) we will ensure that an appropriate safeguard is in place, such as:

  • transferring data only to a country that the UK Government has confirmed provides an adequate level of protection for personal data; or
  • using the International Data Transfer Agreement or the International Data Transfer Addendum to the European Commission’s standard contractual clauses, together with a transfer risk assessment where required.

You can request further details of any such safeguards by contacting us using the details in section 10.

7.     Data security

We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used, accessed, altered or disclosed without authorisation. We limit access to your personal data to those of our people, and those of our third-party providers, who have a business need to know, and who are subject to a duty of confidentiality.

We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

8.     Data retention

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including to satisfy any legal, regulatory, tax, accounting or reporting requirement, or to establish, exercise or defend legal claims.

In broad terms, and subject always to the full detail in our Data Retention Policy (available on request):

  • client matter files are typically retained for 6–15 years from the conclusion of the matter, depending on matter type (for example, 7 years for most commercial and litigation matters, and 15 years for property and probate matters), with original wills retained indefinitely unless returned to the client;
  • identity verification and other AML due diligence records are retained for a minimum of 6 years after the end of our business relationship with you; and
  • accounting and financial records are retained for 6 years.

To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, whether we can achieve those purposes by other means, and our applicable legal and regulatory obligations. In some circumstances we will anonymise your personal data so that it can no longer be associated with you, in which case we may use it indefinitely without further notice to you.

9.     Your legal rights

Under data protection law, you have rights in relation to your personal data, including the right to:

  • request access to your personal data;
  • request correction of your personal data;
  • request erasure of your personal data, in certain circumstances;
  • object to our processing of your personal data, where we rely on legitimate interests;
  • request restriction of processing of your personal data;
  • request transfer of your personal data to you or a third party, in certain circumstances; and
  • withdraw consent, where we rely on consent as the lawful basis for processing.

You will not usually have to pay a fee to exercise any of these rights, although we may charge a reasonable fee, or refuse to comply, if your request is clearly unfounded, repetitive or excessive. We may need to request specific information from you to confirm your identity. We try to respond to all legitimate requests within one month; if your request is particularly complex, we will notify you and keep you updated. Please note that we may not always be able to comply with a request, for example, because we are subject to a legal obligation to retain the data, or because of legal professional privilege, and we will explain why if this is the case.

10.  Contact details

If you have any questions about this policy or about how we use your personal data, or wish to exercise any of your rights, please contact us:

  • Post: KMT Law LLP, 11 Haymarket, St James, London, SW1Y 4BP
  • Telephone: +44 (0)20 7292 2060
  • Email: [email protected]

11.  Complaints

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection (www.ico.org.uk). We would, however, appreciate the chance to address your concerns before you approach the ICO, so please contact us in the first instance using the details above. If your complaint concerns our legal services more generally, you may also have the right to complain to the Legal Ombudsman or the SRA.

12.  Changes to this privacy policy

We keep this privacy policy under regular review. This version was last updated on 31 July 2026. Please check this page from time to time to see any updates.

It is important that the personal data we hold about you is accurate and current. Please let us know if your details change during your relationship with us.

13.  Third-party links

Our website may include links to third-party websites, plug-ins and applications, including those of Thirdfort and other service providers. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website you visit.