Why should accountants take notice of GDPR?

Once billed as the “most important change in data privacy regulation in 20 years”, the GDPR has been in force for over 4 years now. So, what is the regulation and what changes did it bring about? Why should accountants take notice?

What is the GDPR?

Approved by the EU parliament in April 2016, GDPR is an EU regulation that replaced the Data Protection Act of 1998 from a UK perspective. It was designed to harmonise data privacy laws across Europe, strengthening the protection of personal data.

GDPR General Data Protection Regulation

To what does the GDPR apply?

GDPR applies to all companies in the EU and UK (regardless of size) that process and hold personal data. Furthermore, it no longer matters if the processing of data takes place outside of the EU and UK. Controllers or processors outside the EU and UK are still subject to the regulation. This is if they offer goods or services to EU data subjects, or collect data on EU individuals. It also applies to individuals behaving as a business, for example, sole traders.

Definitions of a Controller and Processor

A controller is defined by the Information Commissioner’s Office as an individual or organisation that “determines the purposes and means of the processing of personal data”.

A processor is defined as an individual or organisation that processes personal data on behalf of a controller.

Sound simple doesn’t it? It practice it can be but where services are contracted out, sub-processors come into play. A processor will need permission from the Controller regarding the use of sub-processor. This is not always forthcoming. The Controller will issue a Data Processing Agreement to the processor where the terms of processing are set out.

However, a client and their accountant can be joint controllers of certain data. An agreement will be needed for this.

If an accountant does not offer bookkeeping services, it is likely they will contract out this service. A data processing agreement will be needed for this. Bookkeepers have GDPR responsibilities also. You can read about those responsibilities here.

Personal and sensitive data

GDPR applies to both personal data and sensitive personal data. Personal data includes any information from which a person can be identified, either directly or indirectly. This includes a name, email address, bank details, photo, medical information or computer IP address.

Sensitive personal data concerns “special categories” of data, including genetic and biometric data used to identify an individual. Special categories includes sexual orientation and behaviours, trades union membership and ethnicity. This data should not be gathered if not required to deliver the service.

The eight rights

The GDPR granted EU and UK data subjects extended rights over how their data is used. Your clients, their employees and your clients’ customer have these rights and are not afraid to exercise them. Right of access, including rights to restrict processing and the right of oversight where AI is used, are all part of these rights. Above all, you must be fair and transparent in your processing and clients should know how you intend to use their data.

One important right is the ‘right to be forgotten’. This is only really possible from marketing lists and data bases. Any person with whom you have transacted business or processed their data, for example, payroll, cannot be deleted from your systems.

You are obliged to have a policy for this and be able to demonstrate how you would meet the rights of individuals.

Data Protection Officers

Organisations that are public authorities, or undertake large scale systematic monitoring of individuals or large scale processing of sensitive personal data (or data on criminal convictions and offences) will be required to appoint a data protection officer (DPO). Smaller businesses should also consider appointing a DPO to ensure compliance is maintained.

A DPO will be responsible for advising an organisation and employees on GDPR compliance obligations; monitoring GDPR compliance, including training employees and conducting internal audits; and being the key contact for individuals whose data is processed as well as supervisory authorities.

Organisations should ensure that the DPO reports to the highest management level within an organisation that they are able to operate independently and that they have sufficient resources to carry out their GDPR duties.

What are the implications for accountants?

Accountants handle a vast amount of data, both client and employee, on a daily basis. Firms will need to ensure that their systems are robust enough to meet GDPR requirements. This means that the data must be protected in line with GDPR provisions. To determine whether operations comply with GDPR, firms may need to carry out an audit on current procedures in order to identify if and where they fall short of the required GDPR standards.

By failing to comply, accountants leave themselves open to significant penalties. Organisations in breach of the regulation could be fined. A standard penalty of €10m or 2% of annual global turnover, up to a maximum of 4% of annual global turnover, or €20m, whichever is greater, can be levied. Fines of this magnitude are rare however. 

As accountants position themselves as strategic advisers to clients, GDPR is an opportunity for firms to demonstrate to clients that they can securely hold and process information in line with data requirements, and that protection of client data is a priority for the practice. As a result, clients are likely to see their accountants as trusted professionals to whom they can entrust business and personal data, and with whom they can partner to drive their business forward.

Accounting firms are seen as trusted advisors to business. Accountants should really encourage their business clients to comply with the regulation. Not enough do so.

The Reality of GDPR for Accountants

In terms of its significance, the ICO described the 2018 GDPR legislation as “game changing”. Although in many respects, the regime didn’t represent a break from the rules already in place. However, more stringent rules and responsibilities were introduced. Larger fines were also introduced for non-compliance. Fines have also been levied for failure to prove compliance.

GDPR for Accountants
Credit: Canstock photo

However, many accountants simply believe that having a privacy notice is enough. Most are nowhere near compliant and many of these simply refuse to address the issue. Using templates is not compliance. A template is generic and not about a particular accountant’s processes. I wouldn’t defend them in court! GDPR for accountants is not a simple as you might think.

Controller or Processor?

In essence, whether a firm is a controller or processor will determine the extent of its GDPR obligations. The controller has the legal obligation to comply; processors only have to comply to the extent that the controller imposed contractual obligations upon it.

A controller incidentally is a person who alone, jointly or in common with others determines the purposes and way personal data is processed. The processor is someone who acts on behalf of the controller, such as a payroll provider.

Where accountancy and indeed wider professional services are involved, the ICO makes it clear that responsibility is with the practice hired by the client. Because an accountant, for example, “determines what information to obtain and process in order to do the work”, firms act as “controllers in common” with clients. However, this is not always the case.

Going forward, firms will need to ensure that client terms and conditions reflect this reality, potentially extending engagement terms to include data sharing-type provisions. A Data Processing or Joint Controller agreement will be needed, ideally as a separate document. GDPR for accountants is as both a controller and processor.

Handling client data

Under the GDPR, data subjects have many more rights around who can access and process their data. They also have the rights to know why the data is being processed and how the data is to be retained.

If an accountancy firm is deemed to be a data controller in respect of a client’s data subject, for example, an employee, this raises questions around the role of the firm in notifying and communicating with data subjects.

It is the responsibility of the client in this situation to inform their employees that another firm is processing their data and for what reason. Many firms also use external HR consultants and so the same privacy notice will apply.

Many firms place heavy reliance on consent in relation to both client data and internal data, such as employment contracts.

It is important that you establish a legal basis for processing. Processing employee data for payroll and HR matters does not require consent. The legal basis for processing is clearly ‘performance of a contract’.

Consent is only one of a number of alternative bases for processing personal data. A data audit will identify the types of personal data you process and reveal other valid bases, such as:

  • Your legitimate interests (applicable to the processing of the client data subject’s data or why you need to monitor use of your IT systems by your workforce)
  • Because it is necessary for the performance of the contract (to pay salary and benefits for example)
  • Because of regulatory and legal obligations (statutory audits, security obligations and so on)
  • Consent is the weakest of these

Identifying the gaps

GDPR for accountants exposes these pitfalls; acting to identify any gaps and shortcomings is critical. Get started by scoping the problem and mapping data flows.

Understanding what is in scope is important. So, look at your data and classify it so you can understand where the GDPR applies.

Data-mapping shows how data from information systems transfers to others. Audits assess practices by looking at whether there are effective policies and procedures and if they are followed.

Scoping and mapping are important because you cannot begin to comply until you work out what, when, where, how and why, you process personal data. This also includes where you send it and with whom you share it. This exercise will enable you to comply with the obligation to keep processing records. You must keep a Record of processing Activities (ROPA). This will help inform decisions about the legal basis for processing personal data (which informs the content of GDPR compliant privacy notices).

This exercise should encompass a cross-border inventory of data flows to inform your approach to overseas transfers. Also, a review of the third-party processors you engage. Audits will review what due diligence you have in place to vet third-party processors prior to appointment. It also involves reviewing and keeping under review, your data security arrangements.

Your business must consider Cyber Essentials also. We can help if you need to know more.

What Next?

This type of exercise will almost certainly throw up the need to address some or all of the following policies and practices (not an exhaustive list):

  • Amending privacy notices. Who has access to the data, why, how long it will be held for, and data subject rights
  • Moving away from consent and reviewing the effectiveness of consent already given
  • Amending internal staff-oriented policies
  • Renegotiating terms with third-party suppliers
  • Reviewing training programmes
  • Overhauling and testing security (a huge issue in its own right)
  • Joining up and training specific teams to report and respond should there be an incident
  • Creating a data asset register
  • Assessing risk

If you need help or want to discuss your GDPR status, call us today on 03333 221011 or contact us.

Bookkeepers and the GDPR

As a bookkeeper, you may run a payroll service. Consequently, you will store large amounts of personal data. You must ensure that personal data is kept secure. Your processes must be GDPR compliant. But are they? Have you established a legal basis for processing? Are you compliant with the data minimisation principle?

Running a payroll process involves accessing and storing an individual’s personal information. This will include information on starters and leavers, changes of address and status. Other data will include the normal cyclical information like receiving timesheets, notification of pay changes, bonuses and other changes.

So how should bookkeepers dealing with substantial amounts of data address the requirements of the GDPR?

GDPR and Bookkeepers

It is important you understand what data you hold. How is out held? And why? If you are outsourced, you must ask the Data Controller to issue you with a Data Processing Agreement. If in-house, you can skip this step.

Then ask the following questions:

  • Data location?
    • The Cloud is not the right answer. In which country is the data is held? Never assume, check!!!
  • Why is this information needed?
  • Is the information secure?
    • Yes, is a great answer but you must check this. Ask for proof.
  • Are we holding the data in the best way?
    • This is an important consideration of the GDPR. Many firms use the excuse ‘this is always how we have done it’. If it is not compliant, then it needs to change.
  • How do we transmit or move the data?
    • The body of an email should NEVER contain personal data. The data should be sent in an attachment. However, the attachment must be password protected. Don’t add the password to the email however! Many people do add the password.

Information Stored

Running a payroll and/or automatic enrolment means high risk personal data. This includes name, date of birth, NI number, address, salary and bank details. Other data such as emergency contact numbers may not be necessary. The bookkeeper should go through each item of data held on an individual. Then ask the question ‘Is this needed for the payroll or auto-enrolment process?’ Be strict, and if the answer is ‘no’ then delete the data. This meets the data minimisation principle of the GDPR and is very important.

The need for Information

Data not needed to process payroll should be discarded. HR departments should hold other personal data relating to employees.

  • If the bookkeeper is an employee and performs HR duties as well as payroll, then information on next of kin, emergency contact details and similar information would still fall within the bookkeeper’s control.
  • If the bookkeeper acts in an agent role, there may not be the need to keep that level of data. If the data relates to HR matters, this information will be held by the employer.
  • Where is the data being shared? This will be HMRC and a pension company at the very least.

The bookkeeper should identify their role and store or delete information as necessary. As a bookkeeper, your role is that of a data controller or processor. Data accuracy is a key principle of the GDPR. Therefore, you will have an appropriate process in place to ensure this.

Information Security

The Information Commissioner’s Office (ICO) has a lot of information on their website, some of which is specifically for the small organisation. The information covers basic steps to take such as keeping passwords secure, individuals logging off computers when away from their desks, shredding confidential papers as well as updating software programmes and anti-virus programmes.

The ICO also suggests using a procedure called pseudonymisation to disguise an individual’s identity and protect their personal data. The sender and designated receiver of the information have the keys to unlock the information. However, there are other methods to protect information. This includes anonymisation.

Information Transfer

Currently the most common forms of information transfer are emails. However, memory sticks should not be used in your business. Data is stolen by using them frequently. They often simply disappear. Notes written on paper and posted or handed to the recipient are not much better. Emails are often sent to an unintended recipient.

Pieces of paper inexplicably go missing. However, storing information in the cloud is also problematic. You must understand the cloud provider’s data security. The data in the cloud is your responsibility. If your provider loses your data, it is YOUR responsibility.

Therefore, what can the bookkeeper do to secure individual data and comply with the GDPR? The ICO have written a document on these matters, aimed at small organisations. ‘11 practical ways to keep your IT systems safe and secure’ outlines 11 practical ways to keep your IT systems secure. It covers the following areas:

  • Threats and risks to the data held by the business
  • Different types of IT security available
  • Moving, securing and backing up of data
  • Staff training and awareness
  • Identifying that an attack has taken place
  • Minimising data and data breaches
  • Checking third party compliance

By following these suggestions, the personal data held by the bookkeeper will be much more secure and GDPR compliant.

Security

Your cyber security can be improved by certification with the Cyber Essentials scheme. The government-backed cyber security scheme will reduce threats by up to 70%.

It will never be possible to ensure total data security. However, all you, the bookkeeper, can do is minimise the chance of a leak by understanding the GDPR. Correspondingly, you make the necessary safeguards to meet the requirements.

If you are unsure, please contact us and we will be happy to help.