For UK solicitors and small law firms

GDPR your COLP would actually trust.

Your firm holds client confidentiality at its core and personal data on top of it. Both have rules. Both intersect. Rowpa is the working tool that produces the ROPA, vendor DPAs, privacy policy, DSR procedure, and DUAA-ready complaints procedure, all aligned with SRA and Law Society guidance.

The shape of the problem

You're a controller for some processing (matter management, billing, client onboarding) and a processor for others (acting on client instructions during a matter). Some data is special-category. Some is privileged. The cross-border data flows of a typical commercial matter are non-trivial. Your professional indemnity insurer would like to know you have a written policy and a complaints procedure. The SRA would like to know the same. The ICO would prefer to never know your firm exists.

The Law Society's GDPR guidance is detailed but not a tool. The ICO's guidance is thorough but generic. Your firm's last GDPR review was probably in 2018, and the DUAA complaints requirement has been in force since 19 June 2026.

What Rowpa builds for you

01
When a corporate client's procurement runs due diligence on the firm
Panel appointments and client onboarding increasingly come with a data protection questionnaire. Rowpa assembles a supplier pack from the firm's record, privileged and special-category handling described without disclosing any matter, or drafts the data protection rows of the client's spreadsheet with the evidence beside each answer.
02
Article 30 ROPA tailored to a legal practice
AI classifies the matter management, billing, client onboarding, marketing, employee, and supplier data flows. Special-category handling is flagged separately. Every entry has a legal basis, retention period, and security measures.
03
Vendor DPA register for your stack
Clio, Leap, Actionstep, iManage, NetDocuments, Tessaract, Insight Legal, Quill and MyCase are represented in the vendor library with source URLs, sub-processor lists and transfer fields to review.
04
Privacy notice that reads like a solicitor wrote it
Not a template. Generated from your ROPA, plain English, ICO-aligned, the kind of notice that wouldn't embarrass you in a regulatory submission.
05
DUAA complaints procedure, required since 19 June 2026
Public intake form, 30-day SLA tracking, audit trail. Separate from your firm's broader complaints procedure but cleanly named so they don't conflict.
06
DSR workflow with AI-drafted responses
Subject access request comes in? AI drafts a response from your ROPA, with legal reasoning and ICO references. You review, edit, send. The requester gets a private page to follow it on, and Rowpa tracks one calendar month from the point identity is settled.
07
Public Trust Center URL
Share in client onboarding packs and tender responses. ROPA summary, sub-processors, security overview, privacy policy, DSR submission, complaints intake.

How this fits with what you already do

We're not replacing your COLP, your DPO consultant, or your insurer. We're producing the documents and tracking the deadlines they all want you to have.

COLP can produce a real ROPA on demand for an SRA inspection. DPO consultant gets a working baseline to advise on rather than building from scratch. Insurer sees a documented complaints procedure and a recent ROPA review date. Junior fee earner who used to spend a Friday afternoon on the GDPR folder gets that time back.

Pricing

Business £79/mo for typical 2-15 fee-earner firms. Includes everything in Starter plus site scanner, DPIA tool, breach response planner. Business Plus £159/mo for firms asked every week: unlimited users, 36 questionnaires a year, your own domain and branding on published pages. Starter (£34) is technically available but most firms will need Business.

Start free See all plans

Common questions

Is Rowpa a legal compliance tool?
No. It is a working tool that produces compliance documentation. We don't give legal advice and don't claim to replace your DPO consultant or counsel.
Does it cover SRA-specific requirements?
We cover GDPR. SRA-specific rules (record-keeping obligations under the SRA Codes of Conduct and Accounts Rules) sit alongside what Rowpa produces.
How does this work with iManage / NetDocuments / Clio?
Our vendor library includes the major legal practice management and DMS tools with their DPAs, sub-processor lists, and transfer mechanisms. You add them to your ROPA in two clicks.
What about privileged data?
Privilege is a matter for your firm and the courts. Rowpa documents data-protection compliance. The two layers coexist; we don't ask you to disclose privileged content to use the product.
Can we host Rowpa in the UK rather than the EU?
The current database is in Frankfurt and application compute is in London. Other processing locations and any UK-only option require confirmation against the active service configuration and agreement.
How does this prepare for a peer review?
Export a compliance report as a PDF at any time. ROPA snapshot, vendor DPAs, privacy notice, breach register, DSR log, complaints log, audit trail.
The next client questionnaire is coming. Your firm can be ready in an afternoon.

Sort it once. Show it to the SRA, your insurer, and your clients.

Ask me anything