Delegating work outside the firm raises an obvious question first: what happens to client confidentiality once a file leaves the building, even electronically.
What should be in place before any file moves?
A signed non-disclosure agreement, matter-limited access rather than open access to a firm’s systems, and a clear, written data-handling standard, addressed fully in our article on what a confidentiality agreement should cover.
Why does matter-limited access matter specifically?
Access to the one matter being worked on, not the firm’s wider client base, keeps any potential exposure contained to the file actually in scope, a control also referenced under Article 28 of the UK GDPR and set out in our article on DPA basics.
What should a firm ask before instructing anyone?
What the deletion timeline looks like once a task is complete, and to see that commitment in writing before any client information is shared, following the guidance in our article on what to ask before instructing a provider.
What does UK GDPR actually require of the firm here?
The instructing firm remains the data controller throughout, and Article 28 of the UK GDPR sets out what a processor agreement must contain: purpose limitation, confidentiality commitments, security measures, and support for the controller’s own obligations. That’s the backbone of the data processing agreement underpinning any outsourced arrangement.
None of this is optional extra paperwork. It’s the mechanism that keeps a firm compliant when part of its work happens outside its own walls.
How does an offshore delivery team fit into international transfer rules?
Personal data leaving the UK needs a recognised transfer mechanism, and the ICO’s guidance on international transfers sets out the UK International Data Transfer Agreement (IDTA) and the UK Addendum as the standard routes. A properly drafted engagement builds a transfer risk assessment into the contract rather than leaving it as an assumption.
This is exactly the kind of detail that separates a compliant delegation arrangement from one that just hopes nobody asks.
What does the SRA expect on confidentiality specifically?
The SRA Code of Conduct requires solicitors to keep client affairs confidential, and that obligation doesn’t loosen because part of the work is delegated externally. The firm stays responsible for confidentiality being maintained throughout the chain, which is why matter-limited access and a signed NDA matter as much as they do.
A firm checking a provider’s confidentiality safeguards is, in effect, checking its own continued compliance with that Code obligation.
What happens if something does go wrong?
A properly drafted engagement includes a breach-reporting clause requiring notification to the firm within hours, not days, so the firm can meet its own reporting obligations if the incident is serious enough to require it. That speed matters more than almost any other single term in the arrangement.
Firms running AML checks or disclosure reviews through an outsourced team should confirm this reporting timeline explicitly before any file moves, not assume it’s standard.
What should a firm check before instructing anyone?
The deletion timeline once a task completes, whether access is genuinely matter-limited rather than firm-wide, and whether the transfer mechanism and breach-reporting terms are written into the contract rather than described verbally. Our Pricing page and contact page are the place to start that conversation, and asking these questions upfront costs nothing.
Does confidentiality risk increase with the volume of work delegated?
Not proportionally, provided access stays matter-limited throughout. A team handling a single litigation matter carries the same access-control discipline as one handling a full back-office arrangement, since the safeguard is structural rather than tied to volume. What matters is that access never widens beyond the specific files in scope, however much work is running through the arrangement.
Firms scaling from a single paralegal to a full team should confirm the same matter-limited principle is applied consistently as volume grows, not assume it holds automatically.
How does device and password hygiene fit into this?
Every team member working client files is bound by the same device-security and password standards a firm would expect of its own staff: no unauthorised storage of client data, secured devices, and prompt reporting of anything unusual. That standard is written into the team agreement each individual signs, not left as an informal expectation.
It’s a detail worth asking about directly, since it’s exactly the kind of control that’s easy to assume and awkward to discover missing after the fact.
Should a firm require a mutual NDA before sharing anything at all?
Yes, particularly before the first file moves. A short mutual non-disclosure agreement, signed ahead of any substantive work, gives a firm a clean legal position before it has shared anything sensitive. It costs little to arrange and removes any ambiguity about confidentiality expectations from day one.
Our provider selection guide covers this as one of the first steps worth taking, well before any matter-specific access is granted.
Does this differ for particularly sensitive matters, like private client or family work?
The safeguards are the same, but firms handling private client or similarly sensitive matters often choose to apply them more visibly, confirming deletion timelines and access logs explicitly rather than relying on the general terms of the engagement. That extra layer of confirmation costs nothing and reassures both the firm and, indirectly, the client.
What happens to client data once a task is finished?
It’s deleted according to the timeline set out in the engagement’s data processing agreement, not retained indefinitely on the offshore side. That deletion commitment is one of the clearer things to verify in writing before instructing anyone, since it’s easy to check and hard to dispute once it’s in the contract.
Firms should ask specifically how deletion is confirmed, not just promised, whether that’s a written confirmation per task or a periodic audit of what’s been retained.
Does the firm lose oversight once work is delegated?
No. Supervision and access oversight sit with the instructing firm throughout, consistent with the position the SRA takes on delegated work generally: the firm retains the ability to direct, review, and end the arrangement at any point. Delegating tasks isn’t the same as delegating control.
That distinction is worth keeping in mind whenever confidentiality concerns are raised about outsourcing: the structural safeguards exist precisely because the firm never actually lets go of oversight.
How does this compare to the confidentiality risk of an in-house junior hire?
An in-house junior also has access to client files, and the same fundamental risks, mishandling, loss, unauthorised disclosure, apply regardless of where the person sits. What differs with an outsourced arrangement is that the safeguards are written into a formal contract rather than resting on an employment relationship and internal policy alone.
Firms sometimes assume in-house work is automatically more secure. That’s not necessarily true; it’s just less examined, which is worth bearing in mind when comparing the two options fairly, alongside the cost picture in our cost comparison article.
What’s the single most important question to ask before any file is shared?
Where exactly does the deletion timeline and access log live in writing, and can it be produced on request. If a provider can answer that clearly and points to a specific clause rather than a general assurance, the rest of the confidentiality picture is usually sound too.
Where should a firm start if it’s considering this for the first time?
With a single, low-stakes task, reviewed carefully, before any wider volume of client data is shared. That trial period is the practical way to confirm confidentiality safeguards work as described, rather than taking them on trust from the outset. Talk it through on our contact page before committing to anything broader.
Does encryption factor into how files are shared and stored?
It should. Files in transit and at rest ought to be handled through the firm’s own encrypted case management system rather than emailed as loose attachments or copied to personal storage. That’s a basic but often overlooked check, and it’s worth confirming explicitly as part of any onboarding conversation, alongside the deletion and access-log commitments covered above.
None of these checks are unusual or onerous to ask for. A properly run engagement will have clear answers ready before the question is even raised.
Confidentiality here isn’t a leap of faith. It’s a set of specific, checkable commitments, and a firm is entitled to see every one of them in writing before a single file changes hands.
Want to see our confidentiality terms before sharing anything?
We’ll assign a dedicated paralegal to your matter for 7 days, no charge, so you can see the standard of work before deciding anything.
Confidential · No obligation · Typically a 20-minute call
Frequently Asked Questions
What access does an outsourced paralegal have to a firm’s wider client base?
None. Access is matter-limited to the specific file being worked on, not the firm’s broader systems or client records.
Is a signed NDA required before any file is shared?
Yes, an NDA and clear data-handling terms are agreed before any client information moves, as a standard first step.
What happens to client data once a task is completed?
It is deleted within an agreed timeline, set out in writing as part of the data processing terms before any engagement begins.


