The Reality of GDPR for Accountants
In terms of its significance, the ICO described the 2018 GDPR legislation as “game changing”. Although in many respects, the regime didn’t represent a break from the rules already in place. However, more stringent rules and responsibilities were introduced. Larger fines were also introduced for non-compliance. Fines have also been levied for failure to prove compliance.

However, many accountants simply believe that having a privacy notice is enough. Most are nowhere near compliant and many of these simply refuse to address the issue. Using templates is not compliance. A template is generic and not about a particular accountant’s processes. I wouldn’t defend them in court! GDPR for accountants is not a simple as you might think.
Controller or Processor?
In essence, whether a firm is a controller or processor will determine the extent of its GDPR obligations. The controller has the legal obligation to comply; processors only have to comply to the extent that the controller imposed contractual obligations upon it.
A controller incidentally is a person who alone, jointly or in common with others determines the purposes and way personal data is processed. The processor is someone who acts on behalf of the controller, such as a payroll provider.
Where accountancy and indeed wider professional services are involved, the ICO makes it clear that responsibility is with the practice hired by the client. Because an accountant, for example, “determines what information to obtain and process in order to do the work”, firms act as “controllers in common” with clients. However, this is not always the case.
Going forward, firms will need to ensure that client terms and conditions reflect this reality, potentially extending engagement terms to include data sharing-type provisions. A Data Processing or Joint Controller agreement will be needed, ideally as a separate document. GDPR for accountants is as both a controller and processor.
Handling client data
Under the GDPR, data subjects have many more rights around who can access and process their data. They also have the rights to know why the data is being processed and how the data is to be retained.
If an accountancy firm is deemed to be a data controller in respect of a client’s data subject, for example, an employee, this raises questions around the role of the firm in notifying and communicating with data subjects.
It is the responsibility of the client in this situation to inform their employees that another firm is processing their data and for what reason. Many firms also use external HR consultants and so the same privacy notice will apply.
Consent
Many firms place heavy reliance on consent in relation to both client data and internal data, such as employment contracts.
It is important that you establish a legal basis for processing. Processing employee data for payroll and HR matters does not require consent. The legal basis for processing is clearly ‘performance of a contract’.
Consent is only one of a number of alternative bases for processing personal data. A data audit will identify the types of personal data you process and reveal other valid bases, such as:
- Your legitimate interests (applicable to the processing of the client data subject’s data or why you need to monitor use of your IT systems by your workforce)
- Because it is necessary for the performance of the contract (to pay salary and benefits for example)
- Because of regulatory and legal obligations (statutory audits, security obligations and so on)
- Consent is the weakest of these
Identifying the gaps
GDPR for accountants exposes these pitfalls; acting to identify any gaps and shortcomings is critical. Get started by scoping the problem and mapping data flows.
Understanding what is in scope is important. So, look at your data and classify it so you can understand where the GDPR applies.
Data-mapping shows how data from information systems transfers to others. Audits assess practices by looking at whether there are effective policies and procedures and if they are followed.
Scoping and mapping are important because you cannot begin to comply until you work out what, when, where, how and why, you process personal data. This also includes where you send it and with whom you share it. This exercise will enable you to comply with the obligation to keep processing records. You must keep a Record of processing Activities (ROPA). This will help inform decisions about the legal basis for processing personal data (which informs the content of GDPR compliant privacy notices).
This exercise should encompass a cross-border inventory of data flows to inform your approach to overseas transfers. Also, a review of the third-party processors you engage. Audits will review what due diligence you have in place to vet third-party processors prior to appointment. It also involves reviewing and keeping under review, your data security arrangements.
Your business must consider Cyber Essentials also. We can help if you need to know more.
What Next?
This type of exercise will almost certainly throw up the need to address some or all of the following policies and practices (not an exhaustive list):
- Amending privacy notices. Who has access to the data, why, how long it will be held for, and data subject rights
- Moving away from consent and reviewing the effectiveness of consent already given
- Amending internal staff-oriented policies
- Renegotiating terms with third-party suppliers
- Reviewing training programmes
- Overhauling and testing security (a huge issue in its own right)
- Joining up and training specific teams to report and respond should there be an incident
- Creating a data asset register
- Assessing risk
If you need help or want to discuss your GDPR status, call us today on 03333 221011 or contact us.
Leave a Reply