generated: '2026-07-19' method: searched source: https://lawhive.co.uk/legal/privacy-policy notes: >- Lawhive publishes no public API, so the API-level cross-cutting standards below are recorded as not-applicable rather than non-conforming. The conformance that IS published is regulatory: SRA authorisation of the affiliate law firm, ICO registration, and a UK GDPR / DPA 2018 compliance statement in the privacy policy. standards: - id: sra-authorisation conforms: true scope: Lawhive Legal Ltd (affiliate law firm) identifier: 'SRA ID 8003766' evidence: >- Site footer: "Lawhive Legal Ltd, which is authorised and regulated by the Solicitors Regulation Authority (ID number: 8003766) and is a company registered in England & Wales (Company number: 14651095)." source: https://lawhive.co.uk/ - id: ico-registration conforms: true scope: Lawhive Ltd (data controller) identifier: 'ICO registration ZB292127' evidence: >- Privacy policy: "We are registered with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues. Our registration number is ZB292127." source: https://lawhive.co.uk/legal/privacy-policy - id: uk-gdpr conforms: true evidence: >- Privacy policy: "This version was adopted to ensure compliance with the EU General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA 2018)." source: https://lawhive.co.uk/legal/privacy-policy - id: dpa-2018 conforms: true evidence: privacy policy compliance statement source: https://lawhive.co.uk/legal/privacy-policy - id: oauth2 conforms: null evidence: no public API or OpenAPI available to assess - id: oidc conforms: null evidence: no public API; /.well-known/openid-configuration is a soft 404 - id: rfc9457-problem-details conforms: null evidence: no public API or OpenAPI available to assess - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns the marketing HTML shell (soft 404) - id: soc2 conforms: false evidence: no SOC 2 claim published on the public site - id: iso-27001 conforms: false evidence: no ISO 27001 claim published on the public site