41 jobs in Harperjames
Remote/Hybrid B2B Growth Manager
Posted 2 days ago
Job Viewed
Job Description
Harper James is seeking a Business Development Manager in Sheffield or fully remote, focusing on new client growth and B2B sales. The role involves managing leads, building relationships, and collaborating with solicitors for consultative sales.
With a base salary of £40,000–£45,000 plus uncapped OTE, the position offers flexibility, strong support from the sales leadership team, and clear progression opportunities. Join an innovative legal firm and help ambitious UK businesses thrive.
#J-18808-LjbffrIs this job a match or a miss?
Business Development Manager Hybrid or Remote
Posted 2 days ago
Job Viewed
Job Description
Business Development Manager
Location: Sheffield/Hybrid (3 days in Sheffield office) or Fully Remote (with 1-2 days a month in Birmingham or Sheffield)
Salary: £40,000–£45,000 base salary plus OTE
Harper James has an exciting opportunity for a Business Development Manager to join our busy, successful and growing sales team. We are looking for ambitious, commercially minded sales professionals with experience in consultative B2B sales who want to build their career within an innovative and fast‑growing professional services business.
You will work as part of a collaborative, supportive and high‑performing team, helping ambitious UK businesses access high‑quality legal support while contributing to Harper James’ continued growth.
About Harper JamesHarper James is a national commercial law firm designed to support entrepreneurial businesses from start‑up through to exit. Our mission is to make high‑quality legal support more accessible, commercial and aligned with how modern businesses operate.
Founded in 2014, Harper James has grown rapidly and continues to expand at 40%+ year‑on‑year. This financial year more than 150 people will support over 4,000 businesses, with turnover expected to exceed £14m, and we anticipate doubling in size over the next two years.
Our innovative approach to delivering legal services challenges the traditional law firm model, providing flexible and tailored legal support to ambitious businesses across the UK.
The OpportunityAs a Business Development Manager, you will play a key role in driving new client growth for the firm. You will work with SMEs and growing businesses to understand both their immediate legal challenges and their longer‑term commercial goals.
This is a consultative sales role, where success comes from understanding a client’s business and demonstrating how Harper James’ legal services can support their growth while managing risk. You will engage with business leaders across sectors and collaborate closely with our solicitors to ensure prospective clients receive clear, practical advice on how we can help.
You will receive a consistent flow of inbound leads generated by our marketing team, while also developing opportunities through outbound activity, referrals and strategic partnerships.
A key part of the role is developing strong relationships across influential professional networks, you will help generate warm introductions to high‑value growth businesses while strengthening Harper James’ reputation as a trusted legal partner.
High performers are rewarded through our commission structure and clear progression opportunities within the business development team.
What You’ll Do- Act as the first point of contact for many new business enquiries
- Qualify inbound leads generated by the marketing team
- Proactively generate new opportunities through outbound activity and networking
- Take a consultative approach to understand clients’ legal and commercial needs
- Demonstrate how Harper James’ legal services support business growth and manage legal risk
- Manage the full sales pipeline from initial enquiry through to client onboarding
- Secure warm introductions to growth‑stage UK businesses through professional networks and partners
- Build strong, structured relationships with strategic referral partners and ensure those partnerships are actively developed and governed
- Work closely with solicitors and practice teams across the firm during the sales process
- Maintain accurate records and pipeline management within our CRM system
- Provide regular reporting on activity, opportunities and pipeline performance
- Consistently strive to meet and exceed individual targets and KPIs
- 5+ years’ experience in consultative or phone‑based B2B sales with a strong track record of meeting or exceeding targets
- Experience building relationships with senior decision‑makers, from founders to C‑suite leaders
- Strong communication and relationship‑building skills
- A consultative mindset focused on understanding and solving client problems
- Experience managing opportunities through a CRM‑based sales pipeline
- Highly organised with strong attention to detail
- Self‑motivated, resilient and comfortable working in a target‑driven environment
- Ability to work effectively both independently and collaboratively
- Interest in building strategic partnerships and referral networks
- A desire to learn and develop within a fast‑growing, innovative business
Legal sector experience is not required. You will receive training to build your understanding of the legal landscape and the challenges faced by growing UK businesses.
Technology and Ways of WorkingWe are a modern, technology‑enabled business and expect our team to be comfortable working with digital tools that improve efficiency and collaboration.
You’ll thrive in this role if you:- Enjoy learning and adapting to new systems and technology
- Are interested in using AI tools to improve productivity and sales effectiveness
- Have a solid working knowledge of Microsoft 5\) (Word, Excel, PowerPoint and Outlook)
- Are confident using CRM systems and SharePoint to manage information and collaborate with colleagues
This role operates on a hybrid or fully remote basis. As the role involves frequent communication with prospective clients and colleagues, you must be able to conduct calls and meetings in a professional, distraction‑free environment with a reliable internet connection suitable for regular video calls.
If working fully remotely, you will be required to attend our Birmingham or Sheffield office 1–2 times per month for meetings.
Benefits- £40,000–£45,000 base salary depending on experience
- OTE is uncapped and paid from day one, in year 1 we expect you to achieve £47‑£54k
- Company healthcare scheme (including discounted gym membership)
- Company pension
- Electric car scheme
- 33 days’ holiday plus holiday purchase scheme
- Mentoring, training and support from an experienced sales leadership team
- Annual opportunities for external training and development
- Clear progression opportunities within a rapidly growing business
- Monthly team events and socials
- Access to modern sales tools and technology
If you’re looking to develop your career within a high‑growth, innovative business and enjoy working in a fast‑paced environment where performance is recognised and rewarded, we would love to hear from you.
NO AGENCIES PLEASE
#J-18808-LjbffrIs this job a match or a miss?
Senior Commercial Technology Solicitor — Remote
Posted 2 days ago
Job Viewed
Job Description
Harper James, a leading commercial law firm in the United Kingdom, is looking for a Senior Commercial Technology Solicitor with over 10 years of experience to join their expanding commercial team. This role offers a fully remote working arrangement with opportunities to work with businesses across various sectors.
The successful candidate will possess strong expertise in technology contracts, excellent client management skills, and a collaborative approach in a supportive environment.
#J-18808-LjbffrIs this job a match or a miss?
What should a software development agreement include-
Posted 2 days ago
Job Viewed
Job Description
Software Development Agreements: Legal considerations when commissioning custom software
Article
7 mins read
Updated on 17 December 2024
A well-drafted software development agreement is critical when you’re commissioning bespoke software, whether you’re rolling out a complex CRM system across a growing business or building a platform as the core of a new product offering.
The right software can bring efficiency, innovation, and a competitive edge, but it also carries legal and operational risks. You may face challenges such as unclear timelines, changing requirements, or disputes regarding deliverables and ownership.
Unlike standard IT contracts, a custom build needs a legal agreement that reflects the unique features of your project, from your chosen development methodology to how and when the software will be tested and delivered. And it’s just as important to understand the developer’s position: reviewing the project from the supplier’s angle can help you anticipate risks and align expectations early on. For that, it’s worth considering our insights on software development contracts from the developer’s perspective .
Getting this right from the outset helps avoid costly delays and mismatched assumptions. If you’re unsure how to structure your contract or need support negotiating with your supplier, our commercial law solicitors can help you create a robust agreement that supports your goals and protects your investment.
What makes software development contracts unique?Custom software development contracts are critical when you instruct a supplier to develop bespoke software tailored to your specific needs.
Unlike other less tailored IT contracts (such as licences for off-the-shelf software), you’ll need robust software development contracts to address detailed development terms and lay out key niche provisions, such as the deliverables and how the development process will work in practice. These contracts can often involve significant negotiation with developers, especially where the technology is business-critical.
Choosing the right development approach for your projectSoftware projects are each unique, so contracts don’t follow a one-size-fits-all approach.
The development methodology (whether Waterfall, Agile, or a mix) will shape the agreement and determine what it needs to include.
- Waterfall typically follows a structured, step-by-step process. Each phase usually needs to conclude before the next one begins.
- Agile takes a more flexible approach, where the overall scope and goals are set at the start. Still, the details evolve as the project progresses, meaning there’s more room to adjust priorities during development. Agile can come with more uncertainty and risks, making strong contractual protection all the more important.
Your agreement should clearly outline the development methodology to prevent misunderstandings about what, when, and how your software will be developed.
Some key differences include:
- Waterfall : Requires the supplier to deliver specific features by fixed dates, with binding acceptance criteria.
- Agile : Involves ongoing testing during sprints and relies on collaboration, requiring tailored drafting for the development process.
- Waterfall often employs formal change control processes, whereas Agile allows changes to be made naturally within your product backlog.
- Agile projects may include roles such as a ‘Product Owner’ or ‘Agile Coach’ and methodologies like SCRUM or Kanban.
A mismatch between the methodology and the contract can lead to misunderstandings and disputes. For example, an Agile project with a rigid Waterfall contract can result in significant issues. Ensuring your contract accurately reflects the chosen methodology from the outset is crucial.
Essential terms to include in your software development agreementYour contract should clearly outline how the project will operate and define specific terms for deliverables, timelines, acceptance, and responsibilities.
Your software development agreement should reflect whether your project will follow a Waterfall, Agile or hybrid model, as each comes with its contractual risks and drafting priorities. Terms will differ based on the methodology, but here are some key considerations:
- Defining clear requirements : Your project’s scope must be clearly defined. A Waterfall contract will typically lay out a fixed set of requirements with agreed features and timelines upfront, leaving little room for change. Agile projects, on the other hand, are more fluid, starting with an initial roadmap or ‘user stories’ and evolving as development progresses. Hybrid approaches may combine elements of both. For Agile, early road mapping can help focus and prioritise features while allowing flexibility as the project unfolds.
- Payment terms : Understanding what you need to pay and when is critical, especially for high-value projects. Your contract should specify whether payments are based on fixed costs or time-and-materials, and if they are tied to the completion of milestones or sprints. Be cautious of scope creep, as projects can easily exceed their original scope, potentially resulting in unexpected costs.
- Setting acceptance criteria : It’s essential to test the software as it’s developed. Your contract should define what will be tested, when, and by whom. Waterfall projects often have predefined criteria agreed upfront, while Agile projects rely on ongoing testing and feedback throughout development. The contract should also outline what happens if the developer fails to meet the criteria, including rights to retesting, refunds, or additional work. Waterfall usually offers clearer remedies, whereas Agile can make it harder to define defects or delays due to its flexible nature.
- Agreeing on dispute resolution : Disputes can arise in any software project. A clear resolution process can help resolve issues quickly. This is particularly important for Agile projects, where less-detailed requirements can lead to ambiguities, and fast-paced development cycles make swift dispute resolution critical.
- Termination rights : Your contract should clearly outline your termination rights, providing a clear exit route for specific events. It must also outline what happens to the software, including the transfer of source code and deliverables, in the event of early termination. Negotiating termination without cause can be challenging in Waterfall projects.
- IP rights : Intellectual property ownership is often a key point of negotiation in custom software development. While you may assume paying for the development gives you automatic ownership, suppliers often prefer to grant you a licence, particularly when their software includes reusable components. If owning the IP is critical to your business operations or competitive advantage, ensure the contract reflects this and covers issues like open-source licences, the developer’s ‘background IP,’ and third-party code.
- Source code access : Source code is vital, especially for bespoke projects. If you’re concerned about the supplier’s ability to provide ongoing support, negotiate a software escrow agreement. This ensures you can access the source code under specific circumstances, such as supplier insolvency.
- Data protection compliance : If your software processes personal data, .ensure the contract includes clauses that comply with data protection laws like UK GDPR . The exact terms will depend on whether you or the supplier acts as a data controller, processor, or both. Failing to address this could leave your business vulnerable to significant penalties.
Every software project comes with risks. Addressing them in your contract can help protect your business.
Key risk management measures include:
- IP indemnities to compensate your business if the software infringes third-party rights.
- Supplier warranties , such as guaranteeing the software is free from defects.
- Remedies for delays or defects, particularly for Agile projects, where delays can be harder to quantify.
- Cost control measures to manage unexpected charges.
- Reviewing limitation of liability clauses to ensure critical breaches, such as IP or data protection failures, are uncapped.
Carefully crafted clauses reduce risks and help your project succeed.
Typically, a good developer will have its own standard development contracts or terms, which you’re likely to find land in your inbox for signature before you start a project. In many cases, you’ll start off with their terms rather than negotiate your own development contract from scratch.
When reviewing a supplier’s legal terms (particularly those of reputable suppliers with strong bargaining power), you may find that a practical approach is best for balancing the protection of your business from risk and facilitating a successful deal.
Some key strategies you can consider are the following:
- Focus on key clauses : Pay close attention to high-risk areas, such as deliverables, timelines, payments, intellectual property rights, and supplier liability. These provisions are crucial to protecting your business, so avoid getting sidetracked by lower-risk issues.
- Review terms carefully : Take the time to review the supplier’s terms thoroughly, even if you’re in a rush or eager to proceed. Larger or high-value contracts often involve negotiation, so don’t hesitate to push for changes that better suit your needs.
- Plan ahead : Consider potential negotiation roadblocks and explore middle-ground solutions. For instance, if the supplier won’t transfer IP ownership, could an exclusive licence with additional protections work instead? Having fallback options can give you the flexibility to secure an agreement that works for both parties.
Software development agreements are often lengthy and complex, and even small oversights can have serious consequences. If you’re not confident reviewing or negotiating the contract, it’s worth seeking legal advice. Given the significant time and costs involved in these projects, working with an experienced commercial solicitor can ensure your contract is legally robust and tailored to your needs. Our commercial technology solicitors are always here to help.
Get expert legal support for your software projectWhether you’re navigating a fixed-scope Waterfall build or managing evolving Agile requirements, a strong legal framework is essential to make your project a success. From intellectual property rights and dispute resolution to supplier liability and data protection, minor contractual oversights can lead to significant commercial risks.
Our commercial law solicitors can help you draft, review or negotiate your software development agreement– ensuring it's tailored to your needs, aligned with your commercial objectives, and structured to keep your project running smoothly.
About our expert
Rebecca is a senior solicitor with nearly two decades of experience advising on commercial, technology and data matters. Her diverse clientele ranges from start-ups to established businesses to national and global brands, as well as the UK Government, spanning various sectors such as technology, digital, professional services, retail, automotive and manufacturing. With her extensive expertise, she adeptly guides organisations through complex legal challenges, tailoring her approach to meet their unique needs.
#J-18808-LjbffrIs this job a match or a miss?
Head of Digital Growth & Performance (Remote UK)
Posted 7 days ago
Job Viewed
Job Description
Harper James is a modern, ambitious law firm seeking a Head of Digital Marketing and Performance to lead and scale its digital acquisition engine. You will own strategy across paid, organic and AI-led discovery across the full funnel from website sessions to revenue contribution.
The role requires senior leadership, analytical rigour, and the ability to partner with the CCO, Brand, CRM/Data and Finance to deliver measurable growth, improved CAC efficiency and EBITDA impact.
#J-18808-LjbffrIs this job a match or a miss?
A ticket to success: Guiding TicketSellers through their acquisition by Citizen Ticket
Posted 18 days ago
Job Viewed
Job Description
A ticket to success: Guiding TicketSellers through their acquisition by Citizen Ticket
Reflecting a well-planned and executed strategy, leading ticketing and event management platforms, TicketSellers and its subsidiary Eventree were acquired by Citizen Ticket in a multiple seven-figure deal.
TicketSellers, known for servicing major festivals such as Glastonbury, Shambala, and Nozstock, decided to explore the prospect of a sale within 3-5 years. To achieve this goal, its directors brought on Phil Hayes as Chief Executive Officer, who initiated the sales process by engaging with various investment firms and brokers – it was during this process that Citizen Ticket, also a premium ticketing and booking platform, recognised an opportunity to expand its offering and approached them about buying the company. Both teams instantly clicked, and TicketSellers and Eventree were subsequently acquired by Citizen Ticket in April 2024.
Like most business looking to sell, TicketSellers needed trusted legal advisors with seller experience by their side. They turned to Matt Shakesheff, Partner in our Corporate Team along with Senior Corporate Solicitor, Jenni Ferguson, who guided them through every step of the acquisition process, including:
- Preparation and Due Diligence: We conducted thorough due diligence, prepared all necessary legal documentation, and ensured TicketSellers were sale-ready.
- Share Purchase Agreement: We crafted a water-tight share purchase agreement, ensuring all terms were clearly defined and in the best interest of TicketSellers.
- Consideration Shares: Since part of the price was paid via consideration shares in Citizen Ticket, we advised on terms relating to these shares, protecting TicketSellers as minority shareholders.
In addition to acquisition support, Ian Fraser, Partner in our Employee Share Schemes Team, assisted TicketSellers with growth share plans to incentivise and reward their staff.
Commenting on what it was like working with our team, Phil Hayes, CEO, adds:
I really appreciated that they were both quick on their feet when it came to presenting documents to the other side. Jenni was great at explaining the implications and highlighting risk factors of various technical aspects in a clear and concise manor. It was clear that Matt, Jenni and Ian were there to protect our best interests from day one.
Now, post-acquisition, Phil and the TicketSellers team are focused on integrating services with Citizen Ticket and exploring international expansion for Eventree. The directors of TicketSellers will transition to new roles within Citizen Ticket, leveraging their expertise to drive the combined company's growth and innovation. The collaboration will foster innovation and improve the overall customer experience.
Phil emphasises the importance of finding a law firm that understands your business and long-term goals. This relationship is crucial for saving time and money and ensuring your best interests are protected throughout the acquisition process. He advises:
When you’re looking for a law firm that’s going to be representing you, make sure you gel with them. It’s really important that they have a thorough understanding of what your business does, and what you’re trying to achieve – in the long-term, it’ll save you time and money. Also, it’s essential that before you kickstart a process of this kind, you know what you want to get out of the deal, whether that’s understanding that you want to take a step back from your business or being prepared to work with the new owners of your business. It’s about identifying whether the risk outweighs the reward. Harper James helped us with all of this and more.
#J-18808-LjbffrIs this job a match or a miss?
Strategic Guide to a Major Ticketing Company Acquisition
Posted 18 days ago
Job Viewed
Job Description
A ticket to success: Guiding TicketSellers through their acquisition by Citizen Ticket
Reflecting a well-planned and executed strategy, leading ticketing and event management platforms, TicketSellers and its subsidiary Eventree were acquired by Citizen Ticket in a multiple seven-figure deal.
TicketSellers, known for servicing major festivals such as Glastonbury, Shambala, and Nozstock, decided to explore the prospect of a sale within 3-5 years. To achieve this goal, its directors brought on Phil Hayes as Chief Executive Officer, who initiated the sales process by engaging with various investment firms and brokers – it was during this process that Citizen Ticket, also a premium ticketing and booking platform, recognised an opportunity to expand its offering and approached them about buying the company. Both teams instantly clicked, and TicketSellers and Eventree were subsequently acquired by Citizen Ticket in April 2024.
Like most business looking to sell, TicketSellers needed trusted legal advisors with seller experience by their side. They turned to Matt Shakesheff, Partner in our Corporate Team along with Senior Corporate Solicitor, Jenni Ferguson, who guided them through every step of the acquisition process, including:
- Preparation and Due Diligence: We conducted thorough due diligence, prepared all necessary legal documentation, and ensured TicketSellers were sale-ready.
- Share Purchase Agreement: We crafted a water-tight share purchase agreement, ensuring all terms were clearly defined and in the best interest of TicketSellers.
- Consideration Shares: Since part of the price was paid via consideration shares in Citizen Ticket, we advised on terms relating to these shares, protecting TicketSellers as minority shareholders.
In addition to acquisition support, Ian Fraser, Partner in our Employee Share Schemes Team, assisted TicketSellers with growth share plans to incentivise and reward their staff.
Commenting on what it was like working with our team, Phil Hayes, CEO, adds:
I really appreciated that they were both quick on their feet when it came to presenting documents to the other side. Jenni was great at explaining the implications and highlighting risk factors of various technical aspects in a clear and concise manor. It was clear that Matt, Jenni and Ian were there to protect our best interests from day one.
Now, post-acquisition, Phil and the TicketSellers team are focused on integrating services with Citizen Ticket and exploring international expansion for Eventree. The directors of TicketSellers will transition to new roles within Citizen Ticket, leveraging their expertise to drive the combined company's growth and innovation. The collaboration will foster innovation and improve the overall customer experience.
Phil emphasises the importance of finding a law firm that understands your business and long-term goals. This relationship is crucial for saving time and money and ensuring your best interests are protected throughout the acquisition process. He advises:
When you’re looking for a law firm that’s going to be representing you, make sure you gel with them. It’s really important that they have a thorough understanding of what your business does, and what you’re trying to achieve – in the long-term, it’ll save you time and money. Also, it’s essential that before you kickstart a process of this kind, you know what you want to get out of the deal, whether that’s understanding that you want to take a step back from your business or being prepared to work with the new owners of your business. It’s about identifying whether the risk outweighs the reward. Harper James helped us with all of this and more.
#J-18808-LjbffrIs this job a match or a miss?
Data processor obligations under UK GDPR
Posted 18 days ago
Job Viewed
Job Description
Data processor obligations under UK GDPR
Article
8 mins read
Updated on 30 April 2025
If you process personal data on behalf of clients, your business has legal responsibilities under UK GDPR as a data processor .
Whether you're managing payroll data, providing cloud hosting services, or delivering analytics based on customer lists, your obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 are specific, direct, and legally binding. Many service providers underestimate these responsibilities – often at their peril.
Our experienced data protection solicitors help businesses navigate the often complex landscape of processor obligations, from reviewing contracts and mapping data flows to advising on international transfers, training and regulator engagement. If you're processing data for others, understanding your role and responsibilities isn't just a regulatory necessity – it's a critical step in protecting your business from enforcement, reputational damage, and commercial loss.
Understanding your role – controller, processor, or both?Your role under data protection law depends on how you handle personal data in practice:
- You are a data controller if you decide how and why personal data is used.
- You act as a processor if you only handle data based on a controller’s instructions. Being a processor means you have no autonomy about how personal data is used – this is all up to the controller, who calls the shots.
If your service delivery gives you access to the personal data of a controller, then you’re likely a processor:
- You have access to your client’s systems, which contain personal data.
- You handle payroll data provided by your client, using it solely for payroll purposes.
- You store customer data as part of a service, e.g. in hosting or support, but don’t use that data for your purposes.
- You carry out customer-dictated tasks, such as email marketing or analytics, by using the data and instructions provided by your client.
You can be a controller and a processor for different activities, too. You might be a processor when you deliver email campaigns for a client using a client’s contact list, but at the same time, a controller when you send marketing messages to your clients for your own business. Your role depends on the context and level of control you have over personal data.
In some situations, you and another party may jointly determine the purposes and means of processing. In this case, you are joint controllers, and additional considerations will apply.
It is essential that you accurately determine each party’s role in a data processing scenario, as this will directly dictate the legal obligations that arise under data protection law. If you’re unsure of your role, it’s essential to take legal advice to make sure you don’t fall foul of your obligations.
Your responsibilities as a data processorAs a data processor, you have specific responsibilities under the UK GDPR:
- Follow written instructions: You must only process personal data in accordance with your controller client’s written instructions. If you use it differently or for your purposes, you might be deemed a controller, which brings about additional legal obligations.
If your client gives you an instruction you believe is unlawful, then you should raise this with them immediately. - Protect personal data with security measures: You are responsible for protecting personal data by implementing appropriate technical and organisational measures to safeguard the data you hold against cyber attacks or data breaches. The specific measures you choose must be justified based on your risks and circumstances. Common examples include:
- Passwords and access controls
- Encryption
- Multi-factor authentication (MFA)
- Staff training and awareness
- Regular risk assessments and reviews
Failure to implement sufficient security can have serious consequences. For example, the Information Commissioner's Office (ICO) fined a data processor over £3 million for failing to use multi-factor authentication. This highlights that even processors must prioritise robust data security. - Train your staff: Ensure that your staff understand and are trained on how to handle personal data safely, and receive training on key issues, including what constitutes personal data, how to protect it, and how to report concerns. Staff working with large volumes or sensitive data may need more detailed training, depending on their role. Only authorised personnel should process personal data, and they should be bound by confidentiality obligations too.
- Keep records of processing activities: You should keep a clear, written record of your processing activities,e.g. what data you handle, who it’s for, where it’s stored, whether it’s transferred internationally, and how you protect it. Even if you qualify for an exemption from mandatory record-keeping, maintaining this practice is still advisable. It shows that you take data protection seriously and highlights your accountability. It could also arise in client due diligence from your controllers, for example, when your clients inquire about whether you maintain accurate and up-to-date records of processing.
- Help your controllers meet their legal duties: You need to support controllers in complying with specific legal responsibilities, such as when a controller requires input on a data protection impact assessment. You must be prepared and able to assist when asked.
- Report data breaches to the controller: If something goes wrong and there’s any personal data breach (e.g. data is lost, shared by mistake, or accessed without permission), you must inform your controller client without undue delay. They have just 72 hours from becoming aware to report reportable breaches to the ICO, so time matters. Some contracts set even stricter timelines, e.g. immediately – so check carefully what you’ve agreed to and when you’re negotiating timelines for reporting breaches, make sure you can stick to them in practice.
- Use only approved sub-processors: If you want to bring in another business to help you deliver services and process personal data (e.g. a subcontractor who handles some aspects of the project), you must get written authorisation from your controller client first. This can either be prior specific authorisation or general authorisation. Several critical rules apply when appointing sub-processors , and youare fully responsible to the controller for their actions. Therefore, run due diligence to ensure they are UK GDPR compliant,enter robust subcontracting agreementswith them, and verify that they comply with their obligations.
- Manage international transfers lawfully: If you transfer or access personal data from outside the UK (e.g. when you send a client’s data to a third‑party supplier overseas), you must follow the UK GDPR rules on international transfers. Depending on the destination of the data, you may require additional safeguards, such as theInternational Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as well asa Transfer Risk Assessment . It’s vital to know where data will be shared and to ensure it is protected when it leaves the UK.
- Your core work involves large‑scale, regular, and systematic monitoring of individuals or the processing of sensitive data related to crimes and criminal convictions .
- You’re a public authority (except courts acting in a judicial role), or
- Your DPO will need to report to senior management, act independently, and have expert knowledge of data protection law. You’ll need to provide them with the necessary resources for their role. Even if you don’t legally need one, you can choose to appoint a DPO voluntarily as best practice.
While these reflect core obligations of processors, you will also need to take other steps, such as cooperating with data protection regulators like the ICO when necessary.
Compliance with GDPR is critical for both legal and commercial reasons.
- Legal risks: As a processor, failing to meet your responsibilities under UK GDPR can lead to serious consequences, including significant fines, legal claims, reputational damage, and even criminal penalties in extreme cases. You may also face contractual liabilities – for example, where you have agreed to indemnify a data controller for your breaches.
- Commercial value: Clients, business partners, investors, and other stakeholders expect processors to demonstrate strong data protection practices. Meeting your obligations indicates that you are a credible and trustworthy supplier, which helps you build and maintain valuable business relationships. Robust compliance can give you a commercial edge, particularly where data protection is a deciding factor for clients handling high‑risk information. As a supplier, being prepared for due diligence questions on your data practices can set you apart from competitors and can help you secure contracts.
One of the biggest pitfalls for processors is assuming that only the controller is responsible for GDPR compliance. While controllers do bear many obligations, processors also have direct duties under the law.
- Confusing roles : Not recognising when you are acting as both a controller and a processor, leading to missed or muddled obligations.
- Sub‑processor mismanagement : Failing to appoint or manage sub-processors properly in line with legal requirement s.
- Neglecting staff training : Leading to avoidable data breaches.
- Misunderstanding controller duties : For example, believing processors must provide privacy notices to data subjects (this is the controller’s responsibility).
Avoiding these pitfalls and taking a proactive, knowledgeable approach to compliance will help protect your business, legally and commercially.
How legal advice can helpThere is a lot of misinformation out there, and the UK GDPR is a topic that can cause uncertainty and risk non‑compliance. That’s why investing in expert legal advice, which is tailored to your business, is critical.
It’s essential to map out your data flows and thoroughly understand your data processing activities, enabling you to determine your specific legal obligations and identify the applicable rules for your business.
Legal advice will help you understand the applicable rules, the steps you need to take (e.g., which processes or policies to implement), and how to mitigate risk as a processor. This is particularly important where you’re a service provider delivering services to multiple clients, meaning there is even greater scope for increased liability.
If you're unsure about your responsibilities under data protection law, our expert data protection solicitors can help you. They can develop tailored policies, systems, and training to ensure compliance and to safeguard both your business and the personal data you handle.
About our expert
Lillian is an experienced data protection , privacy and AI lawyer, qualified since 2008 (England and Wales). She advises clients on a broad range of matters, from complex data protection issues to strategic compliance with a global perspective, as well as day‑to‑day operations.
#J-18808-LjbffrIs this job a match or a miss?
Data Processor: GDPR Compliance & Security
Posted 18 days ago
Job Viewed
Job Description
Data processor obligations under UK GDPR
Article
8 mins read
Updated on 30 April 2025
If you process personal data on behalf of clients, your business has legal responsibilities under UK GDPR as a data processor .
Whether you're managing payroll data, providing cloud hosting services, or delivering analytics based on customer lists, your obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 are specific, direct, and legally binding. Many service providers underestimate these responsibilities – often at their peril.
Our experienced data protection solicitors help businesses navigate the often complex landscape of processor obligations, from reviewing contracts and mapping data flows to advising on international transfers, training and regulator engagement. If you're processing data for others, understanding your role and responsibilities isn't just a regulatory necessity – it's a critical step in protecting your business from enforcement, reputational damage, and commercial loss.
Understanding your role – controller, processor, or both?Your role under data protection law depends on how you handle personal data in practice:
- You are a data controller if you decide how and why personal data is used.
- You act as a processor if you only handle data based on a controller’s instructions. Being a processor means you have no autonomy about how personal data is used – this is all up to the controller, who calls the shots.
If your service delivery gives you access to the personal data of a controller, then you’re likely a processor:
- You have access to your client’s systems, which contain personal data.
- You handle payroll data provided by your client, using it solely for payroll purposes.
- You store customer data as part of a service, e.g. in hosting or support, but don’t use that data for your purposes.
- You carry out customer-dictated tasks, such as email marketing or analytics, by using the data and instructions provided by your client.
You can be a controller and a processor for different activities, too. You might be a processor when you deliver email campaigns for a client using a client’s contact list, but at the same time, a controller when you send marketing messages to your clients for your own business. Your role depends on the context and level of control you have over personal data.
In some situations, you and another party may jointly determine the purposes and means of processing. In this case, you are joint controllers, and additional considerations will apply.
It is essential that you accurately determine each party’s role in a data processing scenario, as this will directly dictate the legal obligations that arise under data protection law. If you’re unsure of your role, it’s essential to take legal advice to make sure you don’t fall foul of your obligations.
Your responsibilities as a data processorAs a data processor, you have specific responsibilities under the UK GDPR:
- Follow written instructions: You must only process personal data in accordance with your controller client’s written instructions. If you use it differently or for your purposes, you might be deemed a controller, which brings about additional legal obligations.
If your client gives you an instruction you believe is unlawful, then you should raise this with them immediately. - Protect personal data with security measures: You are responsible for protecting personal data by implementing appropriate technical and organisational measures to safeguard the data you hold against cyber attacks or data breaches. The specific measures you choose must be justified based on your risks and circumstances. Common examples include:
- Passwords and access controls
- Encryption
- Multi-factor authentication (MFA)
- Staff training and awareness
- Regular risk assessments and reviews
Failure to implement sufficient security can have serious consequences. For example, the Information Commissioner's Office (ICO) fined a data processor over £3 million for failing to use multi-factor authentication. This highlights that even processors must prioritise robust data security. - Train your staff: Ensure that your staff understand and are trained on how to handle personal data safely, and receive training on key issues, including what constitutes personal data, how to protect it, and how to report concerns. Staff working with large volumes or sensitive data may need more detailed training, depending on their role. Only authorised personnel should process personal data, and they should be bound by confidentiality obligations too.
- Keep records of processing activities: You should keep a clear, written record of your processing activities,e.g. what data you handle, who it’s for, where it’s stored, whether it’s transferred internationally, and how you protect it. Even if you qualify for an exemption from mandatory record-keeping, maintaining this practice is still advisable. It shows that you take data protection seriously and highlights your accountability. It could also arise in client due diligence from your controllers, for example, when your clients inquire about whether you maintain accurate and up-to-date records of processing.
- Help your controllers meet their legal duties: You need to support controllers in complying with specific legal responsibilities, such as when a controller requires input on a data protection impact assessment. You must be prepared and able to assist when asked.
- Report data breaches to the controller: If something goes wrong and there’s any personal data breach (e.g. data is lost, shared by mistake, or accessed without permission), you must inform your controller client without undue delay. They have just 72 hours from becoming aware to report reportable breaches to the ICO, so time matters. Some contracts set even stricter timelines, e.g. immediately – so check carefully what you’ve agreed to and when you’re negotiating timelines for reporting breaches, make sure you can stick to them in practice.
- Use only approved sub-processors: If you want to bring in another business to help you deliver services and process personal data (e.g. a subcontractor who handles some aspects of the project), you must get written authorisation from your controller client first. This can either be prior specific authorisation or general authorisation. Several critical rules apply when appointing sub-processors , and youare fully responsible to the controller for their actions. Therefore, run due diligence to ensure they are UK GDPR compliant,enter robust subcontracting agreementswith them, and verify that they comply with their obligations.
- Manage international transfers lawfully: If you transfer or access personal data from outside the UK (e.g. when you send a client’s data to a third‑party supplier overseas), you must follow the UK GDPR rules on international transfers. Depending on the destination of the data, you may require additional safeguards, such as theInternational Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as well asa Transfer Risk Assessment . It’s vital to know where data will be shared and to ensure it is protected when it leaves the UK.
- Your core work involves large‑scale, regular, and systematic monitoring of individuals or the processing of sensitive data related to crimes and criminal convictions .
- You’re a public authority (except courts acting in a judicial role), or
- Your DPO will need to report to senior management, act independently, and have expert knowledge of data protection law. You’ll need to provide them with the necessary resources for their role. Even if you don’t legally need one, you can choose to appoint a DPO voluntarily as best practice.
While these reflect core obligations of processors, you will also need to take other steps, such as cooperating with data protection regulators like the ICO when necessary.
Compliance with GDPR is critical for both legal and commercial reasons.
- Legal risks: As a processor, failing to meet your responsibilities under UK GDPR can lead to serious consequences, including significant fines, legal claims, reputational damage, and even criminal penalties in extreme cases. You may also face contractual liabilities – for example, where you have agreed to indemnify a data controller for your breaches.
- Commercial value: Clients, business partners, investors, and other stakeholders expect processors to demonstrate strong data protection practices. Meeting your obligations indicates that you are a credible and trustworthy supplier, which helps you build and maintain valuable business relationships. Robust compliance can give you a commercial edge, particularly where data protection is a deciding factor for clients handling high‑risk information. As a supplier, being prepared for due diligence questions on your data practices can set you apart from competitors and can help you secure contracts.
One of the biggest pitfalls for processors is assuming that only the controller is responsible for GDPR compliance. While controllers do bear many obligations, processors also have direct duties under the law.
- Confusing roles : Not recognising when you are acting as both a controller and a processor, leading to missed or muddled obligations.
- Sub‑processor mismanagement : Failing to appoint or manage sub-processors properly in line with legal requirement s.
- Neglecting staff training : Leading to avoidable data breaches.
- Misunderstanding controller duties : For example, believing processors must provide privacy notices to data subjects (this is the controller’s responsibility).
Avoiding these pitfalls and taking a proactive, knowledgeable approach to compliance will help protect your business, legally and commercially.
How legal advice can helpThere is a lot of misinformation out there, and the UK GDPR is a topic that can cause uncertainty and risk non‑compliance. That’s why investing in expert legal advice, which is tailored to your business, is critical.
It’s essential to map out your data flows and thoroughly understand your data processing activities, enabling you to determine your specific legal obligations and identify the applicable rules for your business.
Legal advice will help you understand the applicable rules, the steps you need to take (e.g., which processes or policies to implement), and how to mitigate risk as a processor. This is particularly important where you’re a service provider delivering services to multiple clients, meaning there is even greater scope for increased liability.
If you're unsure about your responsibilities under data protection law, our expert data protection solicitors can help you. They can develop tailored policies, systems, and training to ensure compliance and to safeguard both your business and the personal data you handle.
About our expert
Lillian is an experienced data protection , privacy and AI lawyer, qualified since 2008 (England and Wales). She advises clients on a broad range of matters, from complex data protection issues to strategic compliance with a global perspective, as well as day‑to‑day operations.
#J-18808-LjbffrIs this job a match or a miss?
Companies House steps up ECCTA enforcement
Posted 18 days ago
Job Viewed
Job Description
Companies House steps up ECCTA enforcement
The link has been copied to your clipboard Okay
Legal updates
3 mins read
Updated on11 July 2025
Companies House steps up ECCTA enforcementCompanies House is already using new powers introduced by the Economic Crime and Corporate Transparency Act 2023 (ECCTA) to crack down on fraud and improve the integrity of the corporate register. A new government report, published on 30 June 2025 , confirms these powers are having a real-world impact, with tens of thousands of companies affected in just the first year.
The changes mark a significant shift in how Companies House monitors and enforces compliance. Businesses now face stricter requirements around transparency, accuracy and identity verification, and those that fall short risk penalties, strike-off or further scrutiny.
While full ECCTA implementation is expected to continue into 2026 and beyond, enforcement is already well underway. Here’s what you need to know, and how to ensure your company stays compliant.
What’s happening now? Companies House enforcement in actionSince the initial rollout, Companies House has significantly increased its powers and is now using them to drive compliance across the UK corporate landscape. Key actions include:
- Crackdown on inappropriate registered office addresses
Companies can no longer use PO boxes as a registered office. Companies House has changed the addresses of more than 82,000 companies to a default address where the original was found to be inappropriate or used without consent. Companies that fail to update their details risk being struck off the register. - Major data cleansing underway
Companies House has removed false or misleading information affecting more than 100,000 companies, including errors in registered office addresses, officer and PSC (Person with Significant Control) details, incorporation documents and other key company filings. - Suspicious and fraudulent filings rejected
Over 10,000 suspicious company applications have been blocked before approval, including those using false addresses or fabricated identities. - Tackling identity misuse
In partnership with data providers, Companies House has identified companies listing deceased individuals, prompting corrections and in some cases further investigation into potential fraud. - New financial penalties for non-compliance
A financial penalty system has been piloted to target serious repeat offenders and late filers. This is expected to expand significantly going forward.
Companies House has already begun rolling out several ECCTA reforms, with more changes on the way. Here is what businesses need to know:
- Voluntary identity verification is now available
Directors and PSCs can already verify their identity using GOV.UK One Login or through an Authorised Corporate Service Provider (ACSP). This allows companies to get ahead before identity checks become mandatory. - ACSP registration is open
Solicitors, accountants and other trusted professionals can now register as ACSPs to carry out verification and submit filings on behalf of clients. - Mandatory identity verification is coming
Identity verification will soon be required for all new directors and PSCs at the time of appointment or incorporation. There will be a transition period to bring existing records in line. - Filing restrictions will increase
Soon, only verified individuals or ACSPs will be allowed to file documents at Companies House. Unverified individuals may face blocked filings or additional scrutiny. - Full compliance required by late 2026
All directors, PSCs and presenters will be expected to have completed verification by the end of 2026. Failure to comply may lead to rejected filings, penalties or disqualification.
These reforms are designed to reduce fraud, prevent misuse of the corporate register and make UK businesses more transparent. But they also create new obligations for business owners and company officers to manage carefully.
What this means for your businessIf you run a startup, scaleup or SME, it is important to:
- Verify the identity of all directors and PSCs using approved routes
- Ensure your company records are accurate and up to date
- Act now to prevent future delays or rejections when filing documents
- Prepare for stricter access controls and enforcement action if obligations are missed
The changes are significant, and many are already being enforced. Acting early will give your business time to adapt and avoid disruption.
How we can helpAt Harper James, we understand that navigating regulatory change can be complex, especially as your business grows. We can support you with all aspects of the ECCTA compliance and identity verification, helping you review and update officer and PSC details, advise on GOV.UK One Login verification and ACSP registration, manage statutory registers and company filings, and respond to Companies House notices.
To access legal support from just£159 per hour arrange your no-obligation consultation today. We aim to respond to all messages received within 24 hours.
#J-18808-LjbffrIs this job a match or a miss?