LOCS:23
ICO-approved GDPR certification

The ICO-approved GDPR certification scheme for the legal industry.

Every chambers that has achieved LOCS:23 certification has been supported by Briefed. We know the standard from first-hand experience, with Briefed certified as a legal services supplier twice. We use these expertise to guide each client through the process.

ICO-approved UKAS-accredited audit 100% success rate Barrister-led
ADISA-certified chambers and law firms have been supported by Briefed.

ADISA is the independent, UKAS-accredited certification body for LOCS:23. Accredited to ISO 17065, ADISA's audit process is verified by UKAS through twice-yearly surveillance audits, ensuring the certification is rigorous, impartial, and consistent.

100%
Success rate across all certified organisations
1st
UK chambers to certify, supported by Briefed
Twice
Certified ourselves as a Legal Services Supplier
LOCS:23
Approved training provider
The standard

What LOCS:23 is and why it matters for the Bar.

The Legal Services Operational Privacy Certification Scheme (LOCS:23) is the first GDPR certification standard approved by the ICO specifically for the legal sector. Certification requires a thorough independent audit by ADISA against an 85-page standard covering data governance, subject rights, operational privacy, third-party management, and ongoing monitoring.

For barristers' chambers, it provides a recognised, independently audited, sector-specific standard that tells clients, regulators, and the BSB that your data protection practices have been externally verified.

Barristers' chambers Law firms In-house legal teams Legal software providers Legal solution providers

Certification at a glance

6 to 10 weeks to certification-readiness

Depending on size and current position

3-year certification

With annual reviews to maintain status

85-page standard

Covering five compliance strands

Independently audited by ADISA

Externally verified by a certification body.

Why now

Why chambers are pursuing LOCS:23 now.

Reduce ICO enforcement risk

An independently audited compliance standard provides documented evidence to help you mitigate against ICO enforcement action.

Win more work

Public sector clients and large organisations increasingly require evidence of data protection compliance in procurement. LOCS:23 is a recognised standard that simplifies that considerably.

Clearly evidence compliance

GDPR compliance is often asserted but rarely evidenced with rigour. LOCS:23 provides an independently verified benchmark.

The process

The full certification journey.

LOCS:23 certification involves five key stages. Briefed guides your organisation through the first two implementation stages, then ADISA independently audits and certifies you. The typical end-to-end timeline is 10 to 16 weeks. 6 to 10 weeks of implementation, followed by ADISA's Stage 1 and Stage 2 audits.

1

Free consultation

We explain the standard, assess your eligibility and current compliance position, agree timelines, and review your existing documentation.

No charge
2

Gap analysis and implementation

We identify gaps against the 85-page standard, implement missing measures, draft or update policies, deploy LOCS:23 approved training, and prepare you for audit.

4–8 weeks typical
3

ADISA Stage 1 audit

ADISA reviews your application and assesses your internal audit against the full LOCS:23 criteria. A documentation review to confirm readiness for the formal certification audit.

Independent audit
4

ADISA Stage 2 audit

A formal audit of your compliance documents and an on-site assessment to determine how data protection compliance is embedded in your organisation.

On-site visit
5

Certification and ongoing support

Certified status is granted for three years, with annual reviews to maintain it. Briefed provides ongoing training, advisory, and support through each annual review.

3-year certification
Stages 1–2: Briefed prepares your organisation
Stages 3–4: ADISA independently audits and certifies
Stage 5: Certified. Briefed supports ongoing compliance

About ADISA

ADISA is the independent, UKAS-accredited certification body that audits organisations against the LOCS:23 standard. Accredited to ISO 17065, ADISA's audit process is verified by the UK Accreditation Service through twice-yearly surveillance audits. Briefed is the implementation partner: we prepare your organisation for the audit. ADISA independently certifies it.

The standard

What LOCS:23 certification covers.

The 85-page standard is structured around five compliance strands, each independently assessed by ADISA.

Strand 1

Organisational and client file governance

A robust governance model for client file management, covering how data is created, stored, accessed, transferred, and deleted.

Strand 2

Data subject rights

A demonstrable process for managing and responding to the full spectrum of data subject rights within required timelines.

Strand 3

Operational privacy

Robust technical and organisational security measures, covering data security, breach response, privacy by design, and GDPR principles.

Strand 4

Third-party and data sharing

Evidence that all third parties handling data on your behalf offer equivalent data protection, including supplier assessments and Data Protection Agreements.

Strand 5

Monitor and review

A documented process of regular review to identify and address compliance gaps, ensuring the standard is maintained over time.

LOCS:23 approved training

Approved training is part of every certification we have supported.

GDPR training for all relevant staff is a required component of LOCS:23 certification. Briefed's training suite is LOCS:23 approved and has formed part of every successful certification we have supported. Organisations do not need to source training separately.

Browse GDPR training
Framework
GDPR Framework

For business owners and senior leadership. The full scope of organisational data protection responsibility and LOCS:23 governance requirements.

Certification
GDPR Certification

For senior management, directors, and HR professionals who handle personal data as a core part of their role.

Essentials
GDPR Essentials

For the majority of staff who process data day-to-day. Practical, accessible, and LOCS:23 accredited.