OPRC Code of Practice — Proposed Standards
Introduction
This is a proposed Code of Practice. It has not been adopted. The Online Procedure Rule Committee (OPRC) is publishing it in draft to invite comment from providers, users and other organisations across the digital justice ecosystem.
This document sets out the top-level standards only. Detailed standards, guidance and criteria will follow in a later phase.
About this Code of Practice
Who the Code applies to
The Code applies to any organisation providing a service that helps people resolve disputes that could otherwise reach the civil, family or tribunal courts. This includes advice services, mediators, online dispute resolution platforms, law firms, and third-party services supporting them.
Applying the standards
All providers are expected to meet every standard. What meeting a standard requires will depend on who your users are and what is at stake in the cases you handle.
Services working directly with unrepresented or vulnerable people are held to a higher standard on access and inclusion than services used only by legal professionals.
Using your judgement
The Code sets out what a good service looks like. It does not prescribe how to achieve it, and it does not cover every situation you will meet.
Some cases will require you to weigh one standard against another. Interoperability and data minimisation may point in different directions, as may speed and safeguarding. Where you have to make that judgement, give precedence to the safety and interests of the user.
Existing legal and regulatory obligations
The Code is in addition to obligations you already have. It does not replace them. Meeting the Code does not discharge any duty you owe under your regulator's rules or under law.
Depending on the service you provide, you may already be subject to:
- the Equality Act 2010
- the Data Protection Act 2018 and UK GDPR
- the Privacy and Electronic Communications Regulations
- the Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018, if you are a public body
- the rules of a legal services regulator, such as the Solicitors Regulation Authority, the Bar Standards Board or CILEx Regulation
- the scheme rules of an ombudsman you are a member of
This list is not exhaustive. You are responsible for identifying which obligations apply to your service.
A. Access to justice
1.
Make sure your service can be used by everyone who needs it
Design and deliver your service so that it works for the full range of people who may need it, not just those who are already comfortable with digital or legal processes.
2.
Help users find the right way to resolve their problem
Support people to understand their options — whether that is advice, alternative dispute resolution, or court — and point them towards what is genuinely appropriate for their situation.
3.
Escalate cases that show risk or urgency
Where a case shows signs of safeguarding risk, vulnerability or urgency, move it beyond your standard process to appropriate support.
4.
Make users aware of time limits affecting their case
Explain any limitation period or procedural deadline that applies, and the risk that time spent in resolution may count against it.
5.
Direct users you cannot help to the support they need
Where a case falls outside what you offer, tell the user what kind of service or support would suit their situation.
B. Inclusion
6.
Design your service around the needs of real users
Involve people who face digital exclusion or intersecting disadvantage in designing and testing your service, rather than relying on assumptions about their needs.
7.
Meet or exceed public sector accessibility standards
Test your service with assistive technologies and against recognised accessibility standards.
What this means in practice
- Meet WCAG 2.2 to at least level AA across your service, including any documents and forms you issue
- Test with screen readers, magnification, speech input and keyboard-only navigation
- Test on low bandwidth and on older mobile devices, not only on current hardware
- Check colour contrast and provide adjustable text size and spacing
- Where you are a public body, the Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 apply and you must publish an accessibility statement
- Where you are not a public body, publishing an accessibility statement is still good practice
8.
Make reasonable adjustments
Anticipate what disabled and neurodivergent users will need and build it into your service. Provide a clear route for users whose needs your service does not already meet.
9.
Use clear language your users can understand
Write in plain, jargon-free language, and confirm clearly when something has been received or actioned.
10.
Support users who have limited English or Welsh language skills
Provide translation, interpretation or multilingual content appropriate to the communities your service reaches.
11.
Offer a non-digital or assisted-digital route
Make sure users who cannot use your service online have a way to use your service, whether through alternative services, assistance or non-digital routes. Take a broad view of who needs this.
12.
Support intermediaries acting on a user's behalf
Let advice workers, representatives and other intermediaries act for a user where the user wants them to, without loss of access or information.
C. Technology and data
13.
Use open, published standards to exchange information with other services
Enable other providers, and HM Courts & Tribunals Service (HMCTS), to exchange information with you through open, published interfaces, and offer an alternative — such as bulk transfer or paper — for organisations that cannot use them.
What this means in practice
- Describe your interfaces using OpenAPI, and publish the specification
- Follow the Government Digital Service (GDS) API technical and data standards
- Use eIDAS-conformant methods where you rely on electronic identification or trust services
- Where you expose your service to AI agents, use Model Context Protocol (MCP) so that access is scoped and auditable
- Use common data models and schemas so that information means the same thing to the service receiving it
- Version your interfaces, and give notice before making a breaking change
- Provide bulk transfer or another non-API route for organisations that cannot integrate directly
14.
Publish what your service covers, in a form other services can read
Make your jurisdiction, coverage, eligibility criteria and availability discoverable, in a standard machine-readable form.
15.
Protect your service and its users against attack and compromise
Apply encryption, strong authentication and secure identity verification, and keep them current as threats change.
16.
Limit the data you hold to what your service needs
Collect only what the service requires, use it only for the purpose it was collected for, and retain it no longer than necessary.
17.
Let users access and move their own data
Give users access to the data you hold on them, and release their case history promptly in a usable, portable form if they choose another provider.
18.
Maintain audit trails for data and decisions
Keep a record of what happened and why, including where generative AI has shaped a decision or document.
D. Responsible AI
19.
Use AI responsibly across your service
Apply the same standards of fairness, accuracy and accountability to AI-supported work as you would to work carried out by people, and take responsibility for its outcomes.
20.
Disclose when AI has shaped advice, a decision, or a document
Make clear to users when AI — including generative AI — has played a role in something that affects their case.
21.
Make sure AI agents acting on your behalf are identifiable and contained
Any AI agent operating on your behalf should be identifiable as such, and should not be able to act outside its authorised scope.
22.
Make a person answerable for decisions with legal consequence
Someone must be able to review, and be accountable for, any decision that carries legal consequence for a user.
23.
Check whether your use of AI disadvantages particular groups
Test for worse outcomes affecting users with protected characteristics or users in vulnerable circumstances, and address what you find.
E. Conduct and accountability
24.
Be transparent about your business
Disclose your fees, areas of expertise, limitations, data retention practices and any conflicts of interest.
25.
Declare who funds and owns your service
State any ownership, funding or commercial relationship that could bear on your impartiality — particularly with a party who may appear on one side of the disputes you handle.
26.
Publish data about the cases you handle for individuals
Report, in anonymised and aggregate form, on volumes, outcomes and drop-out rates for work involving unrepresented parties, members of the public, or public funding. Commercially sensitive work between represented businesses is out of scope.
27.
Maintain a clear complaints procedure
Give users an accessible way to raise concerns, and audit your service regularly.
28.
Tell users what redress is open to them
Explain how a user can challenge your handling of their case, including where to go if you are not covered by a regulator or ombudsman scheme.
29.
Plan for your service ending
If you close, withdraw or fail, make sure users mid-dispute keep their data and can move to another provider without losing their position.
30.
Adopt revised versions of these standards
Adopt updated versions of these standards within a reasonable time as they are revised and extended.