How exposed is your client data?
Client data rarely leaves a firm through cinematic hacking. It leaves through settings nobody chose, accounts nobody remembered, and documents that outlived their purpose. Eleven questions show where that could be happening in yours.
By ZealiD, an EU Qualified Trust Service Provider listed on the EU Trusted List - audited annually under the same security standards this check draws on.
How exposed is your client data?
Your clients trust you with passports, contracts and financial records, and that trust is the firm's real asset. One weak login, one open sharing link or one forgotten account can expose all of it, and most firms find out months too late. This free 3-minute check shows where your firm stands today: twelve questions, an instant score across access, document handling and compliance, and a clear view of what to fix first.
By ZealiD, an EU Qualified Trust Service Provider listed on the EU Trusted List, audited annually under the same security standards this check draws on.
They log in.
Client data exposure is the sum of routes through which confidential documents can leave a firm without anyone noticing: unwatched logins, open sharing links, identity documents sitting in inboxes, and access that outlived the person or the matter. The regulator cases behind this check share one pattern — none involved sophisticated hacking. All involved a door that was already open.
The average breach runs for months
That's the mean time to identify and contain a breach. One UK law firm learned it had lost 32GB of client files only when the National Crime Agency called.
One account, no second factor
The ICO's fine after attackers entered a law firm through a single administrator login without multi-factor authentication.
The clock GDPR puts on you
Time allowed to notify the regulator after discovering a breach. The firm above took 43 days — and the delay became part of the case.
Common questions
Is it safe to send confidential documents by email?
Not by itself. An email attachment proves nothing about who sent or received it, cannot be recalled once sent, and stays in inboxes long after the matter closes. Firms that must exchange sensitive documents use a channel where recipients are identity-verified and access can be revoked.
Is a password-protected attachment secure enough?
Less than it feels. Password protection on office files and PDFs is routinely broken with widely available tools, and the password usually travels by the same insecure channel as the file. It is better than nothing, but it is not a substitute for a channel that controls who can open the document in the first place.
Can we use Dropbox, Google Drive or OneDrive for client files?
The tools are not the problem; the settings are. A link set to "anyone with the link" is a copy of client data you cannot see, expire or take back, and that is often the default. If your firm uses consumer cloud storage, external sharing must be restricted to named recipients with expiring access — and for regulated client work, a portal that verifies who is on the other side gives you what a link never can: proof.
How do data breaches at professional firms actually happen?
Mostly through ordinary routes: logins without a second factor, unpatched legacy systems, misdirected emails, and credentials held by third parties. In the recent regulator cases behind this check, nobody bypassed security — attackers signed in through doors that were already open.
What is the GDPR 72-hour rule?
Article 33 of the GDPR requires a firm to notify its supervisory authority within 72 hours of becoming aware of a personal data breach. The clock starts at awareness, not certainty, which is why a written, rehearsed response plan matters.
How long can a firm keep client identity documents?
No longer than needed for the purpose they were collected for — that is GDPR Article 5(1)(e). In practice it means a defined retention period per document type, actual deletion on schedule, and clearing identity documents out of inboxes once verification is complete. Regulators have cited indefinite retention as an aggravating factor after breaches.
What does this check measure?
Eleven questions across access controls, document handling, and governance — scored against the specific control failures documented in European enforcement cases. You get an instant score, a breakdown by area, and an optional plain-language fix-it guide by email.
Who sees my answers?
Nobody, unless you request the fix-it guide at the end — in that case your answers travel with your email so the guide can point you to the right sections. Details in the ZealiD privacy policy.