LOCS:23 — the ICO-approved UK GDPR certification for legal-service providers
LOCS:23 is one of five sets of certification criteria the ICO has approved under Article 42(5) UK GDPR, and the only one written for the legal sector. It lets a law firm or chambers have its handling of client-file personal data certified by an accredited body.
- Published by
- Criteria owned by 224Protect Ltd (previously trading as 2Twenty4 Consulting Ltd), Hastings; approved by the ICO.
- Type
- UK GDPR certification scheme criteria (Art. 42(5)); not an ISO-type standard.
- Versions and language
- LOCS:23 Standard v12.3, as labelled on the ICO register. English.
- Jurisdiction
- United Kingdom.
- Primary audience
- Law firms, solicitors, barristers and chambers, legal-process providers; their DPOs; clients’ procurement.
- Topic tags
- certification · Art. 42 · legal services · accountability · processor assurance
- Availability
- The criteria document is free on the ICO register; certification itself is a paid service from the certification body.
Why it matters
Certification under Article 42 is one of the few accountability tools UK GDPR names expressly: Articles 24(3) and 28(5) allow an approved certification to be used as an element to demonstrate compliance, and Article 46(2)(f) allows it, with binding and enforceable commitments, as a transfer safeguard. What gives it substance is the structure the ICO requires — criteria approved by the ICO, certification issued only by a body accredited by UKAS against those criteria, and a public register of who is certified. For LOCS:23 the certification body is ADISA Certification Ltd (UKAS accreditation 23831), which also publishes the register of certified organisations.
Two things to carry. First, the ICO’s own notice that approvals on the register remain valid but are under review and may be subject to change following the Data (Use and Access) Act 2025. Second, certification is evidence, not a defence — the ICO’s guidance is explicit that it does not reduce the controller’s responsibility. EU divergence: ICO approval carries no status in the EU; the EU-wide equivalent is a scheme adopted by the EDPB, such as Europrivacy, listed on the same directory page.
Related: the ADISA ICT Asset Recovery Certification (same certification body); individual practitioner credentials sit in Certifications.
