Moore SGD Law LLP (“Moore SGD Law” “we,” “us,” “our”), is strongly committed to protecting and respecting the personal data that we hold about you.

Moore SGD Law is part of the Moore Kingston Smith group (MKS). In most circumstances, Moore SGD Law acts as an independent data controller in relation to personal data processed in the course of providing legal services. In limited cases, we may act jointly with other MKS entities where services are delivered collaboratively. This privacy notice sets out how personal data is handled within that structure. Further information about MKS, please see Legal Terms.

This Privacy Notice (“Notice”) explains what personal data we collect about you, why and how we collect and use it, and rights you have in relation to that information under UK Data Protection Legislation including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 (“the Act”), where relevant, Privacy and Electronic Communications Regulation (“PECR”) and the Data Use and Access Act 2025 (DUAA).

When we refer to personal data, we mean any information relating to an identified or identifiable natural person (‘data subject’), whether identifiable directly or indirectly. This includes, for example, names, contact details, financial information, identification numbers, location data, online identifiers, or other information relating to an individual’s physical, physiological, genetic, mental, economic, cultural, or social identity.

Depending on the situation, we may arrange for some of the services to be provided to you by a company or firm which is associated with us. This Notice applies to data you provide us directly, as well as personal data provided to us by others on your behalf or obtained from lawful third-party sources. We use personal data for the purposes described in this Notice or otherwise explained at the point of collection.

We also collect information automatically when you visit our website, including IP addresses, usage and log data, and information collected through cookies or similar technologies. Please read our Cookie Notice for more information.

This website is not primarily intended for children. However, while providing legal services, we may process personal data relating to children where necessary and in accordance with applicable data protection laws.

We may update this Privacy Notice from time to time to reflect changes in how we process personal data or changes in applicable laws.

Data controller and contact information

The data controller is Moore SGD Law LLP.

If you have any questions about this notice or how and why we process personal data, please contact us at:

Head of Data Protection
Moore SGD Law LLP
6th Floor
9 Appold Street
London EC2A 2AP
Email: dataprivacy@mks.co.uk

Our EU Representative, in compliance with Article 27 of the GDPR, can be contacted at:

Email: dataprotection@mooreireland.ie

Phone: +353 (0)21 4275 176

The Moore SGD Law LLP’s website is www.mooresgdlaw.com and is owned and operated by Moore SGD Law LLP.

Personal data we collect

We may collect, store and use the following categories of personal data about you.

Categories of information we collect, process, hold and share

Identity and contact information, such as your name, date of birth, gender, marital status, identification numbers, contact information, and signature.

Identification and verification data, such as information to verify identity and comply with legal, regulatory and due-diligence requirements, including ID documents, national insurance numbers or similar identifiers, immigration, visa or residency information, anti-money laundering checks, or sanction screenings.

Client and business information, such as information provided in the course of our legal services or in connection with a contract or engagement between you and Moore SGD Law.

In addition to personal data provided by you or received from third parties, we may also create personal data about you during our relationship with you. This may include the records of your communications and interactions with us, such as correspondence, meeting notes or attendance events.

Information processed in connection with legal services, including personal data processed in connection with the legal advice and services we provide to our clients, whether in relation to advisory work, dispute resolution, investigations, arbitration or other legal or professional matters.

Employment, professional and education data, information relating to professional life or background, such as employer or organisation details, employment status, or occupation, education, and qualifications.

Technical information, this includes information generated through your use of our websites and other systems, such as details about how you access and interact with them, system and device information, usage data, location data and other technical data. This may also include limited information generated through the use of digital or AI-enabled tools, where relevant to the services or systems being used. Please refer to our Cookie Notice for more information about cookies.

Marketing data, we may use basic contact and professional information such as your name, contact details, job title, organisation, and areas of interest to help ensure communications we sent are relevant. We may also use limited analytics, such as email engagement information, to help us monitor and improve our communication.

Special categories of personal data, including, where necessary, information relating to health or medical matters, racial or ethnic origin, sexual life, sexual orientation, and data relating to criminal offences or allegations. We may need to collect and use this type of information while providing legal services, where it is relevant to particular matter and permitted by law.

Purposes and legal basis for processing

Clients and legal services

We provide services to individuals as well as businesses, non-profits, and other organisations. The exact data held will depend on the services to be provided.

Why do we process personal data?

Providing legal services to clients: to deliver the legal services set out in our engagement letter or other agreed terms, and in accordance with any further instructions or documentation provided during the course of a matter.

Client and matter coordination: to communicate with clients and others involved in a matter, understanding and assessing instructions, and ensuring that legal services are provided appropriately and effectively.

Administration and business management: we process personal data to manage and administer our practices, including maintaining internal records, billing and accounting, supporting internal operational processes, or hosting client events.

Legal and regulatory compliance: we process personal data to meet legal, professional, and regulatory requirements, including conflict checks, anti-money laundering and sanctions compliance, and responding lawful requests from courts, regulators and authorities.

The legal basis we rely on

Our processing activities of personal data in this context is carried out on one or more of the following legal bases:

  • where it is necessary for the performance including taking steps prior to entering a contract, providing legal advice and representation, managing client matters, communicating with clients and other parties, and fulfilling our obligations under agreed engagement terms;
  • where it is necessary to comply with a legal or regulatory obligation, including undertaking conflict checks, performing anti-money laundering and sanctions screening, adhering to our professional responsibilities, maintaining appropriate records, and responding to lawful requests from courts, regulators, and public authorities;
  • where it is necessary for our legitimate interests in operating and managing our business, including administering and improving our legal services, ensuring information security and business continuity, hosting client events;
  • where required, we rely on consent, in particular in limited circumstances such as certain marketing communications or where no other lawful basis is available. Individuals may withdraw their consent at any time.

Where we process special category personal data or data relating to criminal offences, we do so only where this is necessary and lawful under data protection law. In particular, we may process such data where:

  • it is necessary for compliance with our legal, regulatory, or professional obligations, including obligations relating to anti-money laundering, sanctions, and client due diligence;
  • it is necessary for the establishment, exercise, or defence of legal claims;
  • the data has been manifestly made public by the individual;
  • it is necessary for reasons of substantial public interest in accordance with applicable law; or
  • in limited circumstances, where we have obtained the individual’s explicit consent to process such data for a specific purpose.
Our people

We collect personal data for our people as part of the administration, management, and promotion of our business activities.

Our People Handbook, Partnership Deed and consultancy agreements explain further how personal data is held for our staff, partners and consultants.

Applicants

Where an individual is applying to work for us, personal data is collected through the application process. We use the information to review applications, assess suitability for the roles, and manage recruitment process.

We may also use this data for general administration or to monitor our recruitment activities.

If you join us as an employee, director, partner, or independent contractor, we will provide you with further details on how your personal data is used in the MKS People Fair Processing Notice.

Suppliers

We collect and process personal data about our suppliers, sub-contractors, and the individuals associated with them. The data is held to manage our relationship, to contract and receive services from them, and in some cases to provide professional services to our clients.

Why do we process data?

  • Receiving goods and services – we process personal data in relation to our suppliers and their staff as necessary to receive the services.
  • Providing services to our clients – where a supplier is helping us to deliver professional services to our clients, we process personal data about the individuals involved in providing the services in order to administer and manage our relationship with the supplier and the relevant individuals and to provide such services to our clients.
  • Administering, managing and developing our businesses and services – we process personal data in order to run our business, including:
    • managing our relationship with suppliers;
    • developing our businesses and services, such as identifying client needs and improvements in service delivery;
      maintaining and using IT systems;
    • hosting or facilitating the hosting of events; and
    • administering and managing our website and systems and applications.
  • Security, quality, and risk management activities – we have security measures in place to protect our and our clients’ personal data, which involve detecting, investigating, and resolving security threats. Personal data may be processed as part of the security monitoring that we undertake; for example, automated scans to identify harmful emails. We have policies and procedures in place to monitor the quality of our services and manage risks in relation to our suppliers. We collect and hold personal data as part of our supplier contracting procedures. We monitor the services provided for quality purposes, which may involve the processing of personal data.
  • Complying with any requirement of law, regulation, or a professional body of which we are a member – we are subject to legal, regulatory and professional obligations. We need to keep certain records to show we comply with those obligations, and those records may contain personal data.

The legal basis we rely on

We process personal data relating to suppliers, sub‑contractors, and service providers where this is:

  • necessary for the performance of a contract, or to take steps before entering into a contract;
  • necessary to comply with legal, regulatory, or professional obligations; or
  • necessary for our legitimate interests, including operating and managing our business, engaging, and overseeing suppliers, ensuring the security and quality of our services and systems, and supporting the delivery of legal services, provided those interests are not overridden by individuals’ rights.
People who visit our offices

Personal data is collected when individuals visit our offices via CCTV and / or a visitors’ sign-in book. We have security in place at our offices, for the physical security of client information and for the benefit of our staff.

‘CCTV in Operation’ signs are placed in the reception of our offices confirming that CCTV is deployed. The images are held securely with limited access, and only available on a strict ‘need-to-know basis.’

Why do we process data?

CCTV and building access controls may require visitors to our offices to sign in at reception and keep a record of visitors. This is retained in case of theft or other incident, and to protect the staff and information in the office.

Personal data that may be stored on CCTV will be footage of those visiting our offices for the purposes of physical security of our premises.

CCTV recordings are overwritten after 31 days unless an issue requiring investigation is brought to our attention.

We have a legitimate interest in using CCTV and access controls to protect our premises, people, and information and to investigate security incidents where necessary.

People who use our website and other means

When people visit our website, mobile apps, and other means, personal data is collected both through automated tracking and interactions with various forms on the website or apps (collectively referred to as the websites).

When individuals visit our websites, certain personal data may be automatically collected.

We work closely with third parties who may collect data on our behalf, including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies.

Often, individuals who visit our website additionally fall into another category as listed by this notice. For instance, users of our websites may be current clients, business contacts or become clients in the future. Where this is the case, data held and processed for individuals who use our website may also become data that is held and processed for another purpose.

Why do we process data?

There are various reasons why we will process the personal data that an individual may provide to us when visiting our websites. For examples, these include:

  • Administration – to administer our website and to improve internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes. For example, we use this data to ensure that the website is presented well for individuals and is optimised appropriately.
  • Functionality – in order to allow individuals to use some functionality of our website, certain personal data must be entered in order for features to work as intended.
  • Security – in order to keep our website safe and secure, we may sometimes collect personal data, for instance login information and other data that can be used to vouch an individual’s identity.
  • Promotion and development of our offerings – some personal data may be used in order to measure or understand the effectiveness of advertising we serve to individuals, and to ensure that only relevant advertising appears.

The legal basis we rely on

We process personal data collected through our website and digital platforms where this is:

  • necessary for our legitimate interests, including operating, improving, and securing our website and systems, understanding how they are used, and ensuring relevant and effective communications, provided those interests are not overridden by individuals’ rights; and
  • necessary to comply with legal or regulatory obligations, where applicable.

Where cookies or similar technologies are used, these are handled in accordance with our Cookie Notice and applicable consent requirements.

Business improvement

At Moore SGD Law, we work to continually improve our services and how we support our clients, making appropriate use of data and technology and, AI enabled tools. Where appropriate and permitted, information obtained in the course of providing our professional services may be used to:

  • Improving our services – we may use information obtained through our legal services to enhance our methodologies, develop insights, and improve the quality and effectiveness of what we deliver.
  • Developing tools and capabilities – we may use information to support the development and testing of our tools, technologies, AI-enabled capabilities and internal processes.
  • Using technology responsibly – we make appropriate use of data and technology to support how we deliver our services and improve client experience.
  • Managing third-party providers – where third-party technologies, including AI-enabled tools are used, we undertake appropriate due diligence and risk assessments to ensure personal data is processed securely and in accordance with applicable data protection requirements.

The legal basis we rely on

We rely on our legitimate interests to provide and improve our legal services and to operate our business effectively, including through the responsible use of data analytics and technology tools. These tools may be used to support activities such as legal research, document analysis, drafting assistance and administrative processes, with the aim of improving efficiency, accuracy, and service delivery, provided this does not override the rights and interests of individuals.

Direct marketing

We may use your personal data to send you information about our services, publications, events and other updates that may be relevant to you and in line with your communication preferences.

We may also use limited engagement information, such as whether you open or interact with our communications, to help us understand the relevance and effectiveness of our marketing activities.

The legal basis we rely on

We rely on our legitimate interests to promote our services, maintain relationship with clients and business contacts, and provide relevant business updates. Where required, we will obtain your consent before sending marketing communications.

You can opt out of receiving marketing communications at any time, free of charge, by using unsubscribe option included in our communications or by contacting us.

Moore Global Network Limited

We are part of a worldwide accountancy and consultancy network called Moore Global Network Limited (‘Moore Global’). Moore Global is a company incorporated in accordance with the laws of England and does not provide professional services to clients. Services provided are solely by member firms of Moore Global in their respective geographic areas. Moore Global and its member firms are legally distinct and separate entities. They are not and nothing shall be construed to place these entities in the relationship of parents, subsidiaries, partners, joint ventures or agents. No member firm of Moore Global is an agent or partner of Moore Global and has no authority (actual, apparent, implied or otherwise) to obligate or bind Moore Global or any other Moore Global member firm in any manner whatsoever.

How we collect your personal data

We collect your personal data in various ways directly and indirectly, including:

  • when you connect us, or contacted by us via in writing, via email, telephone, or other electronic means;
  • when you or your organisation engages us, or make an enquiry about or legal services;
  • when you or your organisation complete enquiry or contact forms, or otherwise interact with us through our websites or digital platforms;
  • when personal data is provided to us by third parties acting on your behalf or otherwise involved in a legal matter (such as professional advisers, counterparties, courts, regulators, or referrers); and
  • when you register for or attend events, seminars, webinars, or similar activities organised or hosted by us.

Sharing personal data

We may share your personal data within Moore Global and with our associated businesses where this is necessary and proportionate for the purposes of providing services, managing client relationships, or operating our business.

This may include sharing personal data:

  • across different service lines (tax, audit, advisory or HR Consultancy) where services are provided as part of a joint or coordinated engagement.
  • to support internal administrative functions, including Finance, IT and Compliance; and
  • where required to meet legal, regulatory, or professional obligations.

Where personal data is shared within MKS, this is done on a controlled and need-to-know basis and subject to appropriate confidentiality, contractual and security safeguards.

Moore SGD Law will process personal data in accordance with applicable data protection legislation and its own privacy obligations. Where Moore SGD Law acts jointly in relation to an engagement, they will determine their own respective responsibilities in accordance with applicable legal requirements.

We may disclose your personal data to third parties, where appropriate:

  • Law enforcement agencies, courts, regulators or public authorities, where required by law or regulation, or in connection with investigations, proceedings, or regulatory oversight.
  • Auditors and other professional advisers.
  • Service providers and IT suppliers, who support the operation of our business and systems, such as providers of technology, cloud-based software and platforms, identity and access management, storage, and back-up services.
  • Suppliers and contractors, where this is necessary to receive goods or services or to support the delivery of our services; and support us in providing our services, obtaining feedback from our clients and prospective clients and to help provide
  • Third party advisers and professional service providers, including auditors and other advisers who assist us in carrying out our professional and business functions.
  • Any relevant third‑party acquirer or successor, in connection with the sale, transfer or other reorganisation of all or part of our business or assets (including mergers or acquisitions), where this is necessary and subject to appropriate confidentiality and data protection safeguards.

Requests for disclosure

From time to time, we may receive requests from third parties with lawful authority to obtain personal data, including for the purposes of verifying compliance with legal or regulatory obligations, investigating suspected offences, or establishing, exercising, or defending legal rights. We will only disclose personal data where permitted and in accordance with applicable law.

Where we engage third parties, we carry out appropriate due diligence and implement contractual and security measures to ensure personal data is protected and processed in line with applicable data protection, confidentiality, and security requirements.

Data rights

Much of the personal data we process is subject to legal professional privilege and strict duties of confidentiality. These obligations may limit the extent to which we can disclose information, including in response to data subject rights requests.

Under applicable Data Protection Legislation, you have a number of rights in relation to the personal data we hold about you. We may require you to verify your identity before responding to any request, and in some circumstances, we may be entitled to refuse a request where a legal exemption applies. If so, we will explain our reasons.

Your rights include:

  • Right of access – to obtain a copy of the personal data we hold about you, including details of how we process your personal data and who we share it with.
  • Right to rectification – to have inaccurate or incomplete personal data amended or corrected.
  • Right to erasure – to request deletion of your personal data where the data is no longer necessary in relation to the purposes for which they were processed, or you withdraw your consent and we have no further lawful basis for processing of your personal data (if we relied on consent), or your personal data must be deleted to comply with a legal obligation which we are subject to.
  • Right to restrict processing – to request that we limit how we use your data in certain circumstances (e.g. your personal data is no longer required for the original purpose but is required to establish, exercise or defend legal claims).
  • Right to be informed – about how we collect and use your personal data, as set out in this Privacy Notice.
  • Right to data portability – where technically feasible, you have a right to receive personal data you have provided to us and to have this sent to another organisation in a structured, commonly used format. This right only applies where our legal basis for processing your personal data is either consent or performance of a contract.
  • Right to object – you have right to object to our processing of your personal data in certain circumstances, including for direct marketing and profiling.
  • Rights relating to automated decision-making –automated decision making refers to decisions made without human involvement, including profiling, which may have legal or similarly significant effects on an individual, we do not make decision about individuals in this way. Where we use AI-enabled or automated tools to support our services, business processes, or internal administration, we assess the data protection risks and apply appropriate safeguards, including human oversight where required. If such automated decision-making applies, you may request human review, express your point of view, and challenge the outcome by contacting us using the details above.

Limitations to your rights

In certain circumstances, your rights may be restricted or limited where permitted by applicable data protection law. This may include situations where:

  • personal data is subject to legal professional privilege or confidentiality obligations.
  • complying with a request would prejudice the establishment, exercise or defence of legal claims;
  • we are required to retain or process personal data in order to comply with a legal or regulatory obligation; or
  • the data also relates to other individuals, and it would not be reasonable to disclose it without their consent.

Where we rely on an exemption, we will explain our reasons where we are legally able to do so.

Complaints

If you have a concern about how we handle your personal data or wish to exercise your rights, you can contact our Head of Data Protection using the details above or by emailing DataPrivacy@mks.co.uk.

We will investigate and respond to your concern in a fair and timely manner in accordance with our internal complaints procedure. Further details about how we handle complaints, including how to raise a complaint and applicable response timeframes, are set out in our Complaints Procedure, available here:

https://mooreks.co.uk/wp-content/uploads/2023/07/MKS-Complaints-Procedure.pdf 

We encourage you to raise concerns with us in the first instance and allow us the opportunity to resolve them. If you remain dissatisfied after our internal process has been completed, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) (www.ico.org.uk).

Right to withdraw consent

In circumstances where you may have provided your consent or explicit consent to the collection, processing and transfer of your personal data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact our Data Protection Team. Once we have received notification that you have withdrawn your consent, we will no longer process your data for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.

To exercise any of the above rights, please write to:

Head of Data Protection
Moore SGD LLP
6th floor
9 Appold Street
London EC2A 2AP
Email: dataprivacy@mks.co.uk

Third-party websites

Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy notices and that we do not accept any responsibility or liability for these notices. Please check these notices before you submit any personal data to these websites.

Locations of processing

As part of our business and the provision of legal services, we may transfer personal data to recipients located outside the United Kingdom.

This may include transfers to:

  • other MKS and Moore Global Network firms where we work collaboratively on client matters;
  • external legal advisers, including law firms, barristers, or consultants located in other jurisdictions;
  • courts, tribunals, regulators or public authorities outside the UK; and
  • service providers who support our operations (such as IT, document management, or legal technology providers).

Where personal data is transferred outside the UK, we ensure that it is protected in a manner consistent with UK data protection law. This includes implementing appropriate safeguards, such as:

  • relying on adequacy regulations where the recipient country is recognised as providing an adequate level of protection;
  • entering into UK International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU Standard Contractual Clauses; or
  • relying on other lawful transfer mechanisms permitted under applicable data protection law, where relevant (for example, where the transfer is necessary for the establishment, exercise, or defence of legal claims).

We also consider the nature of the transfer and implement appropriate technical and organisational measures to safeguard personal data.

Further information about international transfers, including the safeguards we rely on, can be obtained by contacting our Data Protection Team.

Security of your data

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures include a combination of physical, technical and administrative controls, such as:

  • access controls and authentication measures to ensure that only authorised personnel can access personal data on a need-to-know basis;
  • encryption and secure storage systems to protect data in transit and at rest, where appropriate;
  • monitoring, logging and testing of systems to identify and respond to potential security threats;
  • policies and procedures governing the handling, retention and disposal of personal data; and
  • regular training and awareness programmes for our personnel on data protection, confidentiality and information security obligations.

We also carry out due diligence on third-party service providers and require them to implement appropriate security measures where they process personal data on our behalf.

Our security framework is regularly reviewed and updated to ensure it remains effective and proportionate to the risks involved, taking into account the nature of the personal data we process, including sensitive and legally privileged information.

Our information security framework is aligned with recognised industry standards, including ISO 27001, under which we maintain certification for our information security management systems. Our controls are subject to regular internal review and independent audit.

How long we store your personal data for

Personal data relating to legal matters is typically retained for a period after a matter has closed, in accordance with our retention policies, professional obligations and risk management requirements. This will usually reflect applicable legal limitation periods and may, in some cases, be longer where necessary to establish, exercise or defend legal claims.

Personal data collected for other purposes (such as business contacts, suppliers, recruitment or website use) is retained only for as long as there is a legitimate business need or legal or regulatory requirement to do so.

When personal data is no longer required, it is securely deleted or anonymised in accordance with our data protection and information security policies.

Changes to this privacy notice

This privacy notice was last updated in July 2026.

Get in touch