WhatsApp
Scenario · Financial services · Cross-border discovery · London and New York

Answering a US subpoena from a London headquarters without breaching UK GDPR

Typical client: A London financial services firm

A composite scenario based on the kind of work we are instructed on. Identifying details are removed and it does not describe a specific client.

How we would help a London firm respond to US discovery requests while keeping personal data handling lawful under UK GDPR.

The challenge
A London headquartered financial services firm receives a subpoena from a US court asking for emails and chat messages from a dozen London staff. Its general counsel must respond on a tight US timetable, but a careless bulk export of staff communications could breach UK data protection law.
Our approach
We would scope the request with the legal team, then collect only the relevant custodians' mailboxes, Teams and chat data. In our London lab we would process and de-duplicate the data, apply search terms and technology-assisted review, and redact personal and privileged content before production. Every step, from collection to export, would be logged so the firm can show regulators and the US court exactly what was done and why.
The outcome
The firm would meet the US deadline with a focused, reviewed production, a defensible record of the process, and a transfer that respects UK GDPR, without diverting its own staff from daily operations.