Guide

UK solicitors and cloud tools and AI: the SRA and Law Society guidance, in plain English

UK solicitors and cloud tools and AI: what SRA standards and Law Society guidance mean for confidentiality, competence, supervision and data protection.

By , practising lawyer15 min read

TL;DR

  • Solicitors in England and Wales are regulated by the SRA under its Principles and Codes of Conduct. The SRA does not approve tools; it sets outcomes.
  • The duties that bite on cloud and AI are confidentiality, competence, supervision, client care, client money and data protection under UK GDPR, plus anti-money-laundering and cyber-fraud vigilance.
  • The Law Society and the SRA publish practical material on technology, cyber risk and generative AI. Read the current versions.
  • Scotland and Northern Ireland have their own regulators. This is practical information, not legal advice.
Free downloadLawyerOS — Matters, Clients, Billing & AIGet it

Solicitors in England and Wales are regulated by the Solicitors Regulation Authority (SRA) under its Standards and Regulations, which set Principles and Codes of Conduct for solicitors and firms. The SRA does not approve software; it expects you to meet outcomes such as keeping client affairs confidential, acting competently, protecting client money and supervising anyone who handles client work. The Law Society of England and Wales publishes practical guidance on technology, cyber risk and generative AI. Scotland and Northern Ireland have their own regulators. This is practical information, not legal advice; read the current text.

The SRA framework in brief

The SRA Standards and Regulations include Principles (for example, acting with integrity, in the best interests of each client, and in a way that upholds public trust), a Code of Conduct for Solicitors, RELs and RFLs, a Code of Conduct for Firms, and rules including the Accounts Rules on client money, the Transparency Rules and requirements on insurance. The Codes include duties to keep the affairs of current and former clients confidential, to provide a proper standard of service, to maintain competence, and to supervise others. None names a product. They expect a reasoned approach and the ability to show it.

The duties that apply to cloud and AI

DutyWhat it means for a cloud or AI tool
ConfidentialityProtect client information from unauthorised access, including via vendors and AI services
Competence and serviceUnderstand the tool well enough to use it properly; do not rely on unverified output
Supervision and accountabilityYou remain responsible for work done with help from staff, vendors or AI
Client care and informationBe open with clients about how their matter is handled where it matters to them
Client money (Accounts Rules)Keep client-money records in suitable software and reconcile as required; never in a general workspace
Data protection (UK GDPR and the Data Protection Act 2018)Lawful basis, security, retention, transfer safeguards and a data processing agreement
Anti-money launderingClient due diligence records, kept securely and accessible
Honesty and integrityDo not mislead courts or clients, including through unverified AI output

Data protection: UK GDPR in practice

  • Controller and processor. You are typically the controller of client personal data; a cloud vendor is a processor and must be bound by a written agreement.
  • Security. Appropriate technical and organisational measures, scaled to the risk: access control, MFA, encryption, backups.
  • International transfers. If a vendor processes data outside the UK, check the transfer mechanism that applies.
  • Breach reporting. Certain personal data breaches must be reported to the Information Commissioner's Office, generally within 72 hours of becoming aware, and sometimes to individuals.
  • Records and rights. Keep records of processing; handle subject-access requests.

The regulator is the Information Commissioner's Office, which publishes guidance on AI and data protection.

Generative AI: what to take from the guidance

The Law Society has published guidance on generative AI for solicitors, and the SRA has commented on AI in its risk material. The themes are consistent with the professional duties:

  • Understand the tool's limits, including that it can produce plausible but wrong output.
  • Protect confidentiality and privilege; know what happens to data you enter.
  • Check output before use; remain accountable for the work.
  • Comply with data protection law, including transparency and lawful basis.
  • Have a policy, training and supervision for staff.
  • Consider client communication, fees and the client's own requirements.

Check the current titles, dates and content on the Law Society and SRA sites, as they are updated.

Cyber-fraud: the risk the SRA keeps highlighting

Conveyancing and client-money fraud is a persistent theme. Criminals impersonate clients, other firms or the firm itself, and send changed bank details. Controls that matter more than any software brand:

  • Verify bank details and any changes by telephone to a number you already hold.
  • Warn clients early and in writing that you will never change bank details by email.
  • Use secure channels for sensitive exchanges; be suspicious of urgency.
  • Train staff, and test them.
  • Report suspected fraud promptly to the right bodies and your insurer.

A practical approach

  1. Read the SRA's current Standards and Regulations and its technology and risk material.
  2. Read the Law Society's guidance on generative AI and on technology and cyber security.
  3. Check the Information Commissioner's Office guidance on AI and data protection.
  4. Review your insurer's requirements, which can be stricter than the SRA's.
  5. Write a decision record for each significant tool (see what regulators actually require).
  6. Review it annually.

Sources: SRA Standards and Regulations, The Law Society. See Notion for UK solicitors, what compliance labels mean and can lawyers use Notion for client data?

Frequently asked questions

Do UK solicitors need SRA approval to use cloud software?

No. The SRA does not approve or ban specific tools. Its Standards and Regulations set principles and outcomes, including keeping client affairs confidential, and expect you to choose and supervise tools so you can meet them.

Is there UK guidance on solicitors using AI?

Yes. The Law Society of England and Wales has published guidance on generative AI, and the SRA has commented on AI in its risk and regulatory material. Read the current versions, as they are updated.

Does UK GDPR apply to a law firm using Notion?

Yes, a firm handling personal data is typically a controller with duties of its own, including lawful basis, security, retention and international transfer safeguards, regardless of its vendors' compliance. A data processing agreement with the vendor is required.

What are the SRA Accounts Rules?

The rules governing how solicitors handle client money and keep accounts, including client accounts and reconciliations. Client-money records belong in software suited to them, not in a general workspace tool.

What is the 'Friday afternoon fraud' risk?

A form of conveyancing fraud in which criminals impersonate a party and send changed payment instructions near the end of the week to divert completion funds. Verify payment details by phone to a known number and never act on emailed changes.

What does my professional indemnity insurer expect?

Insurers commonly ask about cyber controls, multi-factor authentication, backups and how you manage fraud and deadlines. Check your policy and proposal questions; SRA minimum terms set a baseline and insurers may ask for more.

Do Scottish and Northern Irish solicitors follow the same rules?

No. They are regulated by their own bodies (the Law Society of Scotland and the Law Society of Northern Ireland), with their own rules, though the themes of confidentiality, competence and client money are similar.