Global Privacy Notice

Last update: September 2026

Introduction

This Privacy Notice applies to Murgitroyd & Company Limited, its branch offices, affiliated professional entities and associated companies within the Murgitroyd group (collectively referred to as "Murgitroyd", "we", "us" or "our").

Murgitroyd is an international intellectual property firm providing patent, trade mark, design, legal and related professional services to clients throughout the world.

This Privacy Notice explains:

  • what personal data we collect and process;
  • how we use personal data;
  • the legal bases on which we rely;
  • how personal data is shared within the Murgitroyd group and with third parties;
  • how we protect personal data; and
  • the rights available to individuals whose personal data we process.

We are committed to protecting personal data and processing personal data in accordance with:

  • the UK General Data Protection Regulation ("UK GDPR");
  • the Data Protection Act 2018;
  • Regulation (EU) 2016/679 ("EU GDPR");
  • applicable national data protection laws within the European Economic Area ("EEA"); and
  • applicable professional and regulatory obligations.
     

 

Who We Are

The Murgitroyd group includes, among others:

  • Murgitroyd & Company Limited (United Kingdom);
  • the German branch of Murgitroyd & Company Limited;
  • the French branch of Murgitroyd & Company Limited;
  • affiliated professional entities established in Germany and France;
  • branch offices in Italy and Finland; and
  • other associated entities involved in providing intellectual property and related professional services.

Murgitroyd operates on an integrated international basis. The services provided to clients may involve professionals located in multiple jurisdictions.

 

Data Controllers

For most client engagements, the principal controller of personal data is:

Murgitroyd & Company Limited
165–169 Scotland Street
Glasgow G5 8PL
United Kingdom

Murgitroyd provides services through an integrated international structure comprising branches and affiliated professional entities in multiple jurisdictions.

Where professional services are provided through affiliated professional entities in Germany or France, or where those entities act before intellectual property offices, courts, authorities or other official bodies, they may process personal data in connection with their own professional, legal and regulatory obligations.

Accordingly, depending on the nature of the processing activity, the relevant Murgitroyd entity may act as:

  • an independent controller;
  • a joint controller; or
  • a processor acting on behalf of another Murgitroyd entity.

For questions relating to data protection, individuals may contact us using the details set out in Section 16.
 

 

Local Offices and Professional Entities

To provide our services, Murgitroyd utilises patent attorneys, trade mark attorneys, lawyers and other professionals located in multiple jurisdictions.

The Murgitroyd group currently includes:

  • Murgitroyd & Company Limited (United Kingdom);
  • the German branch of Murgitroyd & Company Limited;
  • the French branch of Murgitroyd & Company Limited;
  • affiliated professional entities established in Germany and France;
  • branch offices in Italy and Finland; and
  • other associated entities within the Murgitroyd group.

For most client engagements, the contractual relationship is maintained through Murgitroyd & Company Limited. However, the provision of services may involve professionals employed by or working through local branches and professional entities.

The affiliated professional entities in Germany and France may participate in the performance of client engagements, provide advice on national law and practice, and act before intellectual property offices, courts, tribunals and authorities in their respective jurisdictions.

The branches in Germany, France, Italy and Finland form part of Murgitroyd & Company Limited and are not separate legal persons.

Depending upon the nature of the services provided and applicable legal and professional obligations, entities within the Murgitroyd group may process personal data as independent controllers, joint controllers or processors.

Personal data may be shared between Murgitroyd entities where necessary for the provision of professional services, regulatory compliance, quality assurance, risk management, business administration and information technology support.
 

Categories of Personal Data

We may process the following categories of personal data.

Identity Data

  • name;
  • title;
  • date of birth;
  • nationality;
  • identification information.

Contact Data

  • postal address;
  • email address;
  • telephone numbers;
  • professional contact details.

Client Due Diligence Data

  • identity verification information;
  • anti-money laundering information;
  • sanctions screening data;
  • source of funds information where required by law.

Intellectual Property Matter Data

  • inventor information;
  • applicant information;
  • rights holder information;
  • representative information;
  • licensing information;
  • dispute and litigation information;
  • correspondence and filing history.

Financial Data

  • billing information;
  • bank account information;
  • payment information.

Technical Data

  • IP addresses;
  • browser and device information;
  • website usage information;
  • system logs.

Marketing and Communications Data

  • subscription preferences;
  • event registrations;
  • seminar attendance information;
  • feedback and communications.

 

Sources of Personal Data

We may obtain personal data from:

  • you directly;
  • our clients;
  • employers and organisations with whom you are associated;
  • intellectual property offices;
  • courts and public authorities;
  • foreign associates and professional advisers;
  • public registers;
  • company registries;
  • publicly available websites and business directories;
  • sanctions and compliance databases;
  • service providers; and
  • publicly available professional networking platforms.

 

Purposes of Processing

We process personal data for the following purposes:

Provision of Professional Services

Including:

  • patent prosecution;
  • trade mark prosecution;
  • design protection;
  • opposition proceedings;
  • appeals;
  • litigation;
  • licensing;
  • portfolio management;
  • IP strategy and advisory services.

Representation Before Authorities

Including representation before:

  • national intellectual property offices;
  • the European Patent Office (EPO);
  • the European Union Intellectual Property Office (EUIPO);
  • the Unified Patent Court (UPC);
  • national courts and tribunals.

Regulatory Compliance

Including compliance with:

  • anti-money laundering requirements;
  • sanctions requirements;
  • tax and accounting obligations;
  • professional conduct rules;
  • court and regulatory obligations.

Business Administration

Including:

  • relationship management;
  • invoicing;
  • records management;
  • quality assurance;
  • conflict checking.

Security and Risk Management

Including:

  • cybersecurity;
  • fraud prevention;
  • system monitoring;
  • business continuity;
  • information security compliance.

Marketing and Events

Including:

  • newsletters;
  • legal updates;
  • seminars;
  • webinars;
  • conferences;
  • client relationship activities.

 

Depending upon the circumstances, we rely on one or more of the following legal bases:

  • performance of a contract;
  • compliance with legal obligations;
  • legitimate interests;
  • consent;
  • establishment, exercise or defence of legal claims.

Where we rely on legitimate interests, these include:

  • providing professional services;
  • operating our business efficiently;
  • maintaining information security;
  • managing client relationships;
  • preventing fraud;
  • protecting legal rights;
  • improving our services.

 

Special Categories of Personal Data

In certain matters we may process special categories of personal data where necessary for:

  • legal proceedings;
  • intellectual property disputes;
  • employment-related inventions;
  • regulatory compliance;
  • the establishment, exercise or defence of legal claims; or
  • where otherwise permitted by applicable law.

Such processing will only be undertaken where an appropriate condition under applicable law applies.

 

Recipients of Personal Data

Personal data may be disclosed to:

  • entities within the Murgitroyd group;
  • patent and trade mark offices;
  • courts and tribunals;
  • public authorities;
  • foreign associate firms;
  • external lawyers and legal counsel;
  • barristers;
  • translation providers;
  • renewals and validation providers;
  • IT and cloud service providers;
  • insurers;
  • banks;
  • auditors;
  • tax advisers;
  • regulators and supervisory authorities.

Personal data will be disclosed only where necessary for the purposes described in this Privacy Notice or where required by law.

 

International Transfers

Due to the international nature of intellectual property protection, personal data may be transferred between jurisdictions.

Where personal data is transferred outside the EEA or the United Kingdom, we will ensure that appropriate safeguards are in place, including where applicable:

  • adequacy regulations or adequacy decisions;
  • the European Commission Standard Contractual Clauses;
  • UK International Data Transfer Agreements (IDTAs);
  • UK Addenda to Standard Contractual Clauses; and
  • other safeguards recognised under applicable law.

 

Data Security

We have implemented appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Access to personal data is restricted to individuals who require such access for legitimate business, professional or regulatory purposes.

 

Data Retention

We retain personal data only for as long as necessary to:

  • provide professional services;
  • comply with legal and regulatory obligations;
  • satisfy professional record-keeping requirements;
  • resolve disputes; and
  • protect legal rights and interests.

Retention periods vary depending on the nature of the engagement, applicable legal obligations and limitation periods.

 

Automated Decision-Making

We do not make decisions producing legal or similarly significant effects based solely on automated processing.

 

Your Rights

Subject to applicable law, individuals may have the right to:

  • access personal data;
  • rectify inaccurate personal data;
  • erase personal data;
  • restrict processing;
  • object to processing;
  • receive personal data in a portable format;
  • withdraw consent where consent is relied upon.

Requests may be submitted using the contact details below.

 

Contact Details

For any questions regarding this Privacy Notice or our processing of personal data, please contact:

Data Protection Officer / Privacy Team
Murgitroyd & Company Limited
165–169 Scotland Street
Glasgow G5 8PL
United Kingdom


Email:GDPR@murgitroyd.com
Telephone: +44 [0]141 307 8400

 

Complaints

Individuals in the United Kingdom may lodge a complaint with the UK Information Commissioner's Office ("ICO").

Individuals within the European Economic Area may lodge a complaint with the supervisory authority in the Member State of their habitual residence, place of work or place of the alleged infringement of data protection law.

 

Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in legal requirements, regulatory guidance, business practices or services.

The latest version of this Privacy Notice will always be available on our website.

 

Version Control

Version

Approved By

Date

Changes

1.0

Thomas Gibb

02.01.25

Policy updated

1.1

Thomas Gibb

28.04.25

Update to "International Transfers"

1.2

Thomas Gibb

03.02.26

Policy updated

1.3

Thomas Gibb

22.09.26

Policy updated