What Client Information Should a Law Firm Collect During Automated Intake?
Secure automated intake begins with restraint. Law firms should collect only the information needed for the next decision, delay sensitive questions until justified, control access and retention, and ensure every intake field has a clear, documented and proportionate business purpose.
What Client Information Should a Law Firm Collect During Automated Intake?
Secure automated client intake begins by deciding what the firm does not need to collect. A prospective client may be willing to disclose detailed personal, financial or medical information immediately, but that does not mean the firm should request or retain it at the first point of contact. Law firms should collect enough information to understand the broad nature of the enquiry, assess preliminary suitability and arrange an appropriate next step. More sensitive questions should be introduced only when there is a defined purpose, appropriate protection and a genuine need for the information.
TL;DR: Key takeaways
- Automated intake should collect only the information required for the next legitimate step.
- Preliminary qualification is different from formal matter acceptance, conflict checking and onboarding.
- Sensitive information should not be requested simply because the technology can collect it.
- Every intake question should have a documented purpose, owner and retention decision.
- Security depends on question design and data governance as well as technical safeguards.
What information should automated law firm intake collect?
At the initial enquiry stage, a law firm should normally collect the minimum information needed to:
- Identify and contact the prospective client.
- Understand the broad service being requested.
- Establish whether the enquiry appears to fall within the firm’s scope.
- Identify the appropriate team or review route.
- Recognise relevant dates that the firm has decided are necessary for preliminary handling.
- Arrange a consultation where the firm’s criteria permit it.
The exact information will depend on the practice area and the firm’s approved process. The principle should remain consistent: collect what is necessary for the current purpose, not everything that might become useful later.
The Information Commissioner’s Office guidance on data minimisation explains that personal information should be adequate, relevant and limited to what is necessary for the purpose.
This means a firm should be able to explain why every field, question and upload request appears in its intake process.
Why is collecting too much information a problem?
Length is not the only concern. Excessive collection creates operational, privacy and confidentiality risks.
More information can mean:
- A greater volume of sensitive material to secure.
- Wider access to information that employees may not need.
- Increased exposure if an account or system is compromised.
- More complicated retention and deletion requirements.
- Greater difficulty responding to data-subject requests.
- Increased abandonment during the intake journey.
- Confidential details arriving before the firm knows whether it can act.
The Solicitors Regulation Authority’s guidance on client confidentiality advises SRA-regulated firms to consider limiting the confidential information obtained before a conflict check has been completed and the firm has established that it can act.
That guidance applies specifically within the SRA’s regulatory jurisdiction. Firms in Northern Ireland, Scotland or the Republic of Ireland should also check the requirements of their own regulator and applicable data-protection regime.
The broader operational lesson is useful across jurisdictions. Preliminary intake should not become a full collection of matter information before the firm has decided what it needs and whether it can proceed.
Use staged collection rather than one extensive intake form
A secure intake process should collect information in stages. Each stage should have a distinct purpose and defined boundary.
Stage one: Establish the nature of the enquiry
The first stage should gather enough information to understand what the person is seeking and how the firm can contact them.
This may include:
- Name.
- Preferred contact method.
- Contact details.
- Broad service or matter category.
- Relevant jurisdiction or location.
- A concise description of the assistance being sought.
The description field should be framed carefully. An unrestricted request to “tell us everything” can encourage disclosure that is unnecessary at this point.
Stage two: Assess preliminary suitability
Once the broad service is understood, the system can ask approved questions that help determine whether the enquiry appears to meet the firm’s initial criteria.
Questions should be linked to a defined routing or qualification decision. If an answer does not affect what happens next, the firm should ask whether the question belongs at this stage.
Automated suitability assessment should not be presented as confirmation that the firm can act. Formal acceptance may still depend on human review, conflicts, identity verification, regulatory checks and other internal requirements.
Stage three: Prepare the human interaction
Where an enquiry can progress, the system may collect the information needed to arrange and prepare an initial consultation.
This should focus on giving the receiving professional enough context to conduct a useful conversation. It should not attempt to collect the full matter file in advance unless the firm has established a lawful, proportionate and secure reason for doing so.
Stage four: Complete formal onboarding
Detailed documents, identity information, payment information and full matter evidence should be handled through the firm’s approved onboarding process.
Separating this stage from preliminary intake reduces unnecessary collection from people the firm may not ultimately represent.
It also makes the distinction between an enquiry and an accepted instruction clearer.
Which categories of information require particular care?
Some information creates greater risk because of its sensitivity, the potential impact of disclosure or the rights of other people mentioned within it.
Health and other special-category data
Legal enquiries can reveal health, ethnicity, religious beliefs, trade-union membership, sexual orientation or other protected information.
The ICO explains that special-category data receives additional protection because its use can create significant risks to an individual’s rights and freedoms.
A firm should identify which intake routes are likely to involve this information and assess the relevant lawful basis, condition, access controls and retention arrangements.
Criminal allegations and offence information
Information about criminal allegations, proceedings and convictions is governed by separate requirements from special-category data.
The firm should avoid inviting detailed disclosure unless it has determined why the information is necessary and how it will be handled.
Third-party information
Prospective clients may provide information about family members, employees, opponents, witnesses or other parties.
The fact that the person submitting the enquiry volunteers this information does not remove the firm’s responsibility to consider how it is collected, accessed, used and retained.
Identity and financial information
Identity documents, bank details and detailed financial records should not be gathered during preliminary intake without a clear need and appropriate controls.
A contact form or conversational interface should not become a general document repository.
Original documents
Requesting document uploads can create risks involving file security, malware, retention, access and accidental collection of unnecessary information.
The firm should determine when documents are genuinely required and which approved environment should receive them.
Apply a purpose test to every intake question
Before approving a question, the firm should be able to answer:
- What specific decision does this information support?
- Is the information required at this stage?
- Could the purpose be achieved with less detail?
- Is the answer likely to contain sensitive or third-party information?
- Who needs access to it?
- How long will it be retained if the enquiry does not progress?
- What will happen if the person declines to answer?
- Does the person understand why the information is being requested?
- Can the question be delayed until after human review?
- Is the answer being used to make or support an automated decision?
A weak answer to these questions suggests that the field should be removed, revised or moved to a later stage.
Build privacy into the intake process from the beginning
Data protection should shape the process before implementation.
The ICO’s guidance on data protection by design and by default states that organisations should consider privacy at the design stage and throughout the lifecycle of a system or process.
For automated client intake, that should include:
- Mapping which information enters the process.
- Recording the purpose for collecting it.
- Restricting access according to role.
- Establishing retention and deletion rules.
- Reviewing where information is stored and processed.
- Checking which suppliers or subprocessors can access it.
- Testing the handling of incomplete or unusual enquiries.
- Establishing a process for correcting inaccurate information.
- Reviewing questions when services or qualification rules change.
- Monitoring whether staff download or duplicate information unnecessarily.
The relevant ICO pages currently note that some guidance is under review following the Data (Use and Access) Act 2025. Firms should check the latest regulatory guidance when designing or reviewing their process.
This article provides general educational information rather than legal, regulatory or data-protection advice.
What should firms ask an intake-technology provider?
A provider should be able to explain how the product handles the information placed into it.
The firm should establish:
- Which data the system collects.
- Where the data is processed and stored.
- Who can access it.
- Whether customer information is used to train AI models.
- Which third parties or subprocessors are involved.
- How long enquiry information is retained.
- How deletion and access requests are handled.
- What contractual and organisational safeguards apply.
- How security incidents are managed.
- What control the firm has over questions and qualification criteria.
A polished interface is not evidence of appropriate data governance. The answers should be documented and reviewed by the people responsible for compliance, information security and professional standards.
How Auvia supports structured client intake
Auvia is an AI-powered client-intake platform built for professional-services firms, including law firms.
Auvia responds to new enquiries, asks qualifying questions, identifies enquiries that appear to meet the firm’s configured criteria, books suitable consultations and provides the fee earner with a briefing before the meeting.
This structure can help a firm replace open-ended enquiry collection with a more deliberate question journey.
The firm must still decide which questions are appropriate, what information is necessary, when human review is required and how data-protection and professional obligations are met.
Auvia should not be treated as performing conflict checks, anti-money-laundering checks, identity verification or legal-risk assessment unless any such capability has been separately confirmed.
Conclusion
Secure automated intake is not achieved by collecting every possible detail and protecting it afterwards. It begins with asking for less.
Law firms should divide intake into clear stages, restrict early questions to the next legitimate decision and delay sensitive collection until it is necessary. Technical controls remain important, but they cannot compensate for an intake process that gathers excessive information without a defined purpose.
To explore how Auvia could help your firm create a more structured and proportionate enquiry journey, book an Auvia demo.
Frequently asked questions
Does data minimisation mean collecting as little information as possible?
No. It means collecting enough information to fulfil the defined purpose, but no more. The firm must balance the need for useful qualification with the obligation to avoid unnecessary collection.
Can a prospective client submit sensitive information voluntarily?
They can, but the firm should not encourage unnecessary disclosure. Clear question wording and visible guidance can help the person understand what information is appropriate at the preliminary stage.
Should a law firm allow document uploads during initial intake?
Only where the firm has identified a genuine need and implemented appropriate security, access and retention controls. Document collection should not be enabled merely for convenience.
How long should unsuccessful enquiry information be retained?
There is no single retention period suitable for every firm. The period should reflect the purpose, legal and professional requirements, risk and the firm’s documented retention policy.
Is an automated qualification decision the same as matter acceptance?
No. Preliminary qualification indicates that an enquiry appears to meet configured criteria. Matter acceptance may require conflicts, regulatory checks, professional judgement and formal confirmation from the firm.