Bookkeepers and the GDPR

As a bookkeeper, you may run a payroll service. Consequently, you will store large amounts of personal data. You must ensure that personal data is kept secure. Your processes must be GDPR compliant. But are they? Have you established a legal basis for processing? Are you compliant with the data minimisation principle?

Running a payroll process involves accessing and storing an individual’s personal information. This will include information on starters and leavers, changes of address and status. Other data will include the normal cyclical information like receiving timesheets, notification of pay changes, bonuses and other changes.

So how should bookkeepers dealing with substantial amounts of data address the requirements of the GDPR?

GDPR and Bookkeepers

It is important you understand what data you hold. How is out held? And why? If you are outsourced, you must ask the Data Controller to issue you with a Data Processing Agreement. If in-house, you can skip this step.

Then ask the following questions:

  • Data location?
    • The Cloud is not the right answer. In which country is the data is held? Never assume, check!!!
  • Why is this information needed?
  • Is the information secure?
    • Yes, is a great answer but you must check this. Ask for proof.
  • Are we holding the data in the best way?
    • This is an important consideration of the GDPR. Many firms use the excuse ‘this is always how we have done it’. If it is not compliant, then it needs to change.
  • How do we transmit or move the data?
    • The body of an email should NEVER contain personal data. The data should be sent in an attachment. However, the attachment must be password protected. Don’t add the password to the email however! Many people do add the password.

Information Stored

Running a payroll and/or automatic enrolment means high risk personal data. This includes name, date of birth, NI number, address, salary and bank details. Other data such as emergency contact numbers may not be necessary. The bookkeeper should go through each item of data held on an individual. Then ask the question ‘Is this needed for the payroll or auto-enrolment process?’ Be strict, and if the answer is ‘no’ then delete the data. This meets the data minimisation principle of the GDPR and is very important.

The need for Information

Data not needed to process payroll should be discarded. HR departments should hold other personal data relating to employees.

  • If the bookkeeper is an employee and performs HR duties as well as payroll, then information on next of kin, emergency contact details and similar information would still fall within the bookkeeper’s control.
  • If the bookkeeper acts in an agent role, there may not be the need to keep that level of data. If the data relates to HR matters, this information will be held by the employer.
  • Where is the data being shared? This will be HMRC and a pension company at the very least.

The bookkeeper should identify their role and store or delete information as necessary. As a bookkeeper, your role is that of a data controller or processor. Data accuracy is a key principle of the GDPR. Therefore, you will have an appropriate process in place to ensure this.

Information Security

The Information Commissioner’s Office (ICO) has a lot of information on their website, some of which is specifically for the small organisation. The information covers basic steps to take such as keeping passwords secure, individuals logging off computers when away from their desks, shredding confidential papers as well as updating software programmes and anti-virus programmes.

The ICO also suggests using a procedure called pseudonymisation to disguise an individual’s identity and protect their personal data. The sender and designated receiver of the information have the keys to unlock the information. However, there are other methods to protect information. This includes anonymisation.

Information Transfer

Currently the most common forms of information transfer are emails. However, memory sticks should not be used in your business. Data is stolen by using them frequently. They often simply disappear. Notes written on paper and posted or handed to the recipient are not much better. Emails are often sent to an unintended recipient.

Pieces of paper inexplicably go missing. However, storing information in the cloud is also problematic. You must understand the cloud provider’s data security. The data in the cloud is your responsibility. If your provider loses your data, it is YOUR responsibility.

Therefore, what can the bookkeeper do to secure individual data and comply with the GDPR? The ICO have written a document on these matters, aimed at small organisations. ‘11 practical ways to keep your IT systems safe and secure’ outlines 11 practical ways to keep your IT systems secure. It covers the following areas:

  • Threats and risks to the data held by the business
  • Different types of IT security available
  • Moving, securing and backing up of data
  • Staff training and awareness
  • Identifying that an attack has taken place
  • Minimising data and data breaches
  • Checking third party compliance

By following these suggestions, the personal data held by the bookkeeper will be much more secure and GDPR compliant.

Security

Your cyber security can be improved by certification with the Cyber Essentials scheme. The government-backed cyber security scheme will reduce threats by up to 70%.

It will never be possible to ensure total data security. However, all you, the bookkeeper, can do is minimise the chance of a leak by understanding the GDPR. Correspondingly, you make the necessary safeguards to meet the requirements.

If you are unsure, please contact us and we will be happy to help.