Internal Office Rules
Basic Rules for Procedures Involving the Processing of Personal Data
Article 1
JUDr. Martin Friedrich Law Firm, Attorney at Law, Company ID No.: 423 19 528, with its registered office at Františkánska 5, 040 01 Košice, registered in the Slovak Bar Association’s list of attorneys under No. 6333 (hereinafter referred to as the “Law Firm”), in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; hereinafter referred to as “GDPR”), regularly reviews its own procedures for handling personal data and hereby declares the following basic rules.
The law firm ensures that all persons involved in its activities comply with these rules. For suppliers acting as intermediaries, it contractually requires adequate safeguards for the protection of personal data in accordance with Article 28 GDPR.
Article 2
The law firm processes personal data exclusively on the legal basis set forth at Article 6 GDPR and, in the case of special categories of data, also in accordance with Article 9 GDPR, only to the extent necessary and for as long as necessary. The purposes and durations of processing are documented for each specific area of practice in the records of processing activities in accordance with Article 30 GDPR.
Only those individuals who need access to personal data in order to perform their duties and responsibilities for the law firm are granted access to such data. These individuals are bound by a duty of confidentiality.
Article 3
In accordance with the Act on the Legal Profession, the Code of Conduct for the Processing of Personal Data by Attorneys, and customary standards of the legal profession, the law firm implements appropriate technical and organizational measures based on the nature and risks of the processing. These include, in particular:
- control of access to areas where personal data is processed, and the secure storage of documents,
- locking the premises and storage areas where personal data is stored,
- protecting access to information and communication technologies with strong individual passwords and protecting those passwords from being compromised,
- protecting devices from malware and updating them regularly,
- appropriate measures to protect portable devices and data storage media, in particular encryption, password protection, physical supervision, and secure handling,
- protection of files containing a larger volume of, specific categories of, or otherwise sensitive personal data during their electronic transmission; if a password is used, it is generally communicated through a different communication channel.
The law firm complies with its obligations under regulations governing archives and record-keeping, as well as statutory and professional retention periods and rules for document destruction.
Article 4
The law firm ensures that the rights of data subjects are upheld. It evaluates each request in light of the rules governing the practice of law, particularly the legal duty of confidentiality, the protection of client rights, and the rights of others.
The law firm primarily:
- maintains records of processing activities in accordance with Article 30 GDPR,
- ensures that data subjects are informed in accordance with Articles 12 to 14 of the GDPR,
- handles requests regarding the rights set forth in Articles 15 to 22 of the GDPR,
- records and, in accordance with the provisions of Articles 33 and 34 of the GDPR, reports or notifies personal data breaches.
Records, information, processed requests, complaints, and documentation of security incidents are kept at the law firm. Requests or complaints may be submitted by email tomartin@friedrich.sk or in writing to the law firm's registered office.
Article 5
The law firm assesses the risks associated with the processing of personal data and implements appropriate technical and organizational measures. If a specific type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the firm will conduct a data protection impact assessment in accordance with Article 35 GDPR prior to commencing such processing. As of the date of this update, no processing requiring such an assessment has been identified.
The law firm assessed the conditions in accordance with Article 37 GDPR. Given the nature and scope of its processing activities, it is not required to designate a data protection officer, and no data protection officer has been designated.
In addition to the records required under Article 30 GDPR, it maintains, as necessary, records of consents, assessments of legitimate interests, contracts with data processors, requests from data subjects, and cases of personal data breaches.
The law firm regularly—at least once a year—assesses its compliance with personal data protection rules, including technical and organizational measures, takes the necessary corrective actions, and updates the relevant documentation.
Rules adopted on May 25, 2018 · updated on July 17, 2026
JUDr. Martin Friedrich., Attorney at LawInformation for Data Subjects
Privacy Policy and Clients' Rights Regarding the Processing of Personal Data
Operator and Contact Information
Protecting the personal data of our clients and other individuals is important. These terms explain how we process personal data when providing legal servicesJUDr. Martin Friedrich Law Firm, Attorney at Law, ID No.: 423 19 528, with its registered office at Františkánska 5; 040 01 Košice, registered in the Slovak Bar Association’s list of attorneys under No. 6333 (hereinafter referred to as the “Law Firm” or “we”).
Questions and requests can be directed by phone to+421 55 303 01 11, by email atmartin@friedrich.sk or by mail to the law firm's registered office address.
When processing personal data, we are guided primarily by the GDPR, the applicable provisions of Act No. 18/2018 Coll. on the Protection of Personal Data, Section 18 of the Act No. 586/2003 Coll. on the Legal Profession, and other specific regulations. We also comply withCode of Conduct for the Processing of Personal Data by Attorneys, which explains in more detail how the GDPR applies to the legal profession.
Why do we process personal data?
The processing of personal data is necessary, in particular, so that we can:
- provide legal services to clients and practice law,
- to comply with legal, professional, and contractual obligations,
- to protect the legitimate interests of the law firm, its clients, and other individuals.
For what purposes and on what legal grounds do we process personal data?
| Purpose of Processing | Legal Basis Under the GDPR | Related Regulations |
|---|---|---|
| Practice of a profession (provision of legal services) | Compliance with a legal obligation under Article 6 (1)(c); with regard to special categories of data, in particular the establishment, exercise, or defense of legal claims under Article 9 (2)(f) | The Act on the Legal Profession, the Rules of Professional Conduct for Attorneys, the Civil Code, the Commercial Code, and the relevant procedural regulations |
| Provision of Services Other Than Legal Services | Performance of a contract pursuant to Article 6 (1)(b), or compliance with a legal obligation pursuant to (c) | The Act on the Register of Public Sector Partners, the e-Government Act, the Civil Code, and the Commercial Code |
| Ensuring Compliance with Legal and Professional Regulations | Compliance with a legal obligation under Article 6 (1)(c), legitimate interests under (f), a task in the public interest under (e), or legal claims under Article 9 (2)(f) | The Act on the Legal Profession, the Rules of Professional Conduct for Attorneys, Act No. 297/2008 Coll. on Protection Against the Laundering of Proceeds from Criminal Activity, Act No. 54/2019 Coll. on the Protection of Whistleblowers, and the GDPR |
| Protection of Legitimate Interests and Legal Claims | Legitimate interest of the law firm, its clients, or third parties pursuant to Article 6 (1)(f) | GDPR, the Civil Code, the Commercial Code, the Criminal Code, the Code of Criminal Procedure, and the relevant civil and administrative procedural regulations |
| Marketing purposes | Consent of the data subject pursuant to Article 6 (1)(a), unless another legal basis applies | The Act on the Legal Profession, Act No. 452/2021 Coll. on Electronic Communications, the Act on Advertising, and Act No. 108/2024 Coll. on Consumer Protection |
| Statistical purposes, archiving in the public interest, and historical or scientific research | Article 89 GDPR and compliance with the legal obligation under Article 6(1)(c), if applicable | The GDPR and Act No. 395/2002 Coll. on Archives and Records Management |
| Human Resources and Payroll | Compliance with a legal obligation under Article 6 (1)(c), or a legitimate interest under (f) | The Labor Code, the Act on the Legal Profession, and regulations on social, pension, and health insurance |
| Accounting and Tax Purposes | Compliance with a legal obligation under Article 6 ods, Section 1(c) | Regulations on Accounting and Tax Administration |
| Website traffic measurement (Google Analytics 4) | Consent under Article 6(1)(a) GDPR; demonstrable consent under Section 109(8) of Act No. 452/2021 Coll. is required to store or access information on the terminal device | Google Analytics 4 and Act No. 452/2021 Coll. on Electronic Communications |
How do we use Google Analytics 4?
With your prior voluntary consent under Article 6(1)(a) GDPR and Section 109(8) of Act No. 452/2021 Coll. on Electronic Communications, we use Google Analytics 4, an analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The service provides us with aggregated statistics about visits to and use of the website.
With your consent, Google Analytics may process a first-party cookie identifier, information about the number of users and sessions, approximate geographic location, browser and device information, and selected interactions with the website.
We do not start analytics tags before consent. You may refuse consent or withdraw it later using the Privacy settings button.
The recipient and service provider is Google Ireland Limited and, where applicable, other Google group entities under the service terms. Transfers to third countries may occur; such transfers are subject to Chapter V GDPR and Google's applicable contractual and technical safeguards.
Data in Google Analytics is retained according to the retention setting of the relevant Google Analytics property. The consent choice is stored in the browser until it is deleted or changed. We do not send contact-form contents, email addresses, names, or custom analytics events to Google Analytics.
What legitimate interests do we pursue?
If the processing is based on Article 6 (1)(f) of the GDPR, we primarily seek to protect the rights and legal claims of the Law Firm, its clients, or other individuals, including the establishment, exercise, and enforcement of such claims. Prior to such processing, we assess the proportionality of the interference and the balance between the interest pursued and the rights and freedoms of the data subject.
To whom do we disclose your personal information?
We disclose the personal data of clients and other individuals only to the extent necessary and while maintaining confidentiality. Recipients may include, in particular, employees and authorized representatives of the Law Firm, persons authorized to perform specific legal services, representing or cooperating attorneys, accountants and other professional advisors, the Slovak Bar Association, and providers of software, hosting, cloud, or technical equipment and support.
The duty of confidentiality restricts the disclosure of data to public authorities. This does not affect statutory obligations, in particular the obligation to prevent criminal offenses or obligations related to the prevention of money laundering and terrorist financing.
To which countries do we transfer your personal data?
We do not intend to transfer personal data to third countries outside the European Economic Area as a separate purpose of processing. If a transfer to a third country occurs when using a technical or cloud service, it may take place only if the conditions set forth in Chapter V of the GDPR are met, in particular on the basis of an adequacy decision or appropriate safeguards.
Automated Decision-Making
We do not engage in automated individual decision-making, including profiling, as defined at Article 22 GDPR.
How long do we retain your personal data?
We retain personal data only for as long as necessary for the purposes for which it is processed. When retaining data, we adhere to the statutory retention periods and the recommended retention periods set forth in Resolution No. 29/11/2011 of the Presidium of the Slovak Bar Association, in particular:
- Once the incoming and outgoing mail logs are full, the attorney shall retain them for ten years from the date of receipt or dispatch of the last item recorded in the log,
- The inventory list is archived for ten years from the date it was compiled,
- If the firm maintains a client roster and a log of client files electronically, it shall produce a printed copy of each for every calendar year and store it in the office indefinitely,
- The retention period for a client file is 10 years and begins on the date all conditions for archiving the file are met.
Shredding cannot be performed, in particular, if:
- The client file contains the originals of the documents provided to the client,
- these are client file records or client file lists,
- the file or part of it must be transferred to the state archives,
- there are ongoing judicial, administrative, criminal, or disciplinary proceedings that are substantively related to the client’s file or to an act or omission by the Attorney in the provision of legal services.
How do we collect your personal information?
If you are a client, we most often obtain your personal data directly from you. Providing this information is generally voluntary; however, depending on the circumstances, it may be necessary to provide legal services, comply with a legal obligation, or assess whether we can accept the legal matter. We may also obtain data from publicly available sources, from public authorities, or from other individuals.
If you are not a client, we most often obtain personal data from clients or from other public or legal sources, such as public authorities, public registries, or when gathering evidence on behalf of a client. Such data may also be obtained, to the extent necessary, without the consent of the data subject, based on our authority and obligation to practice law.
What rights do you have as a data subject?
Under the terms of the GDPR, you have the following rights, in particular:
- obtain confirmation as to whether your personal data is being processed and request access to it in accordance with Article 15 GDPR,
- request the correction of incorrect information or the completion of incomplete information in accordance with Article 16 GDPR,
- request the erasure of data in accordance with Article 17 GDPR or the restriction of processing in accordance with Article 18 GDPR,
- obtain personal data in a portable format under the terms and conditions at Article 20 GDPR,
- object to processing based on legitimate or public interest, and object to direct marketing at any time under Article 21 GDPR,
- withdraw consent at any time; such withdrawal does not affect the lawfulness of processing carried out prior to its withdrawal,
- file a complaint with the supervisory authority.
Individual rights do not apply unconditionally, and their scope is assessed based on the legal basis and the circumstances of the processing. When providing legal services, the right to object under Article 21 GDPR applies to processing based on Article 6 (1)(e) or (f), not to processing necessary to comply with a legal obligation or to establish, exercise, or defend legal claims.
When handling a request, we must protect the rights of the client and other individuals, as well as the attorney’s duty of confidentiality. Pursuant to Section 18(8) of the Act on the Legal Profession, a lawyer is not obligated to provide information regarding the processing of personal data or to allow access to or portability of personal data if doing so could result in a breach of the duty of confidentiality. The rights and freedoms of other individuals are also taken into account pursuant to Article 15 (4) and Article 20 (4) of the GDPR.
The application may be sent tomartin@friedrich.sk. A complaint may be filedOffice for Personal Data Protection of the Slovak Republic, Galvani Business Center II, Galvaniho 7/B, 821 04 Bratislava, or the Slovak Bar Association.
Is providing personal information mandatory?
The provision of certain personal data is required by law; other data is necessary to enter into or fulfill a contract for the provision of legal services. Without the data necessary to identify the client, assess conflicts of interest, comply with legal obligations, or provide legal services, it may not be possible to enter into a contract or continue providing the service. Before providing your data, you may request an explanation as to whether a specific piece of information is a legal or contractual requirement and what the consequences of not providing it would be.
Changes to the Privacy Policy
Information regarding the processing of personal data is subject to change. We may therefore update these terms and conditions in accordance with changes to our processing activities or legal requirements. We will notify you of any material changes in an appropriate manner, such as through a notice on this website or an individual notification, as appropriate.