Why should accountants take notice of GDPR?

Once billed as the “most important change in data privacy regulation in 20 years”, the GDPR has been in force for over 4 years now. So, what is the regulation and what changes did it bring about? Why should accountants take notice?

What is the GDPR?

Approved by the EU parliament in April 2016, GDPR is an EU regulation that replaced the Data Protection Act of 1998 from a UK perspective. It was designed to harmonise data privacy laws across Europe, strengthening the protection of personal data.

GDPR General Data Protection Regulation

To what does the GDPR apply?

GDPR applies to all companies in the EU and UK (regardless of size) that process and hold personal data. Furthermore, it no longer matters if the processing of data takes place outside of the EU and UK. Controllers or processors outside the EU and UK are still subject to the regulation. This is if they offer goods or services to EU data subjects, or collect data on EU individuals. It also applies to individuals behaving as a business, for example, sole traders.

Definitions of a Controller and Processor

A controller is defined by the Information Commissioner’s Office as an individual or organisation that “determines the purposes and means of the processing of personal data”.

A processor is defined as an individual or organisation that processes personal data on behalf of a controller.

Sound simple doesn’t it? It practice it can be but where services are contracted out, sub-processors come into play. A processor will need permission from the Controller regarding the use of sub-processor. This is not always forthcoming. The Controller will issue a Data Processing Agreement to the processor where the terms of processing are set out.

However, a client and their accountant can be joint controllers of certain data. An agreement will be needed for this.

If an accountant does not offer bookkeeping services, it is likely they will contract out this service. A data processing agreement will be needed for this. Bookkeepers have GDPR responsibilities also. You can read about those responsibilities here.

Personal and sensitive data

GDPR applies to both personal data and sensitive personal data. Personal data includes any information from which a person can be identified, either directly or indirectly. This includes a name, email address, bank details, photo, medical information or computer IP address.

Sensitive personal data concerns “special categories” of data, including genetic and biometric data used to identify an individual. Special categories includes sexual orientation and behaviours, trades union membership and ethnicity. This data should not be gathered if not required to deliver the service.

The eight rights

The GDPR granted EU and UK data subjects extended rights over how their data is used. Your clients, their employees and your clients’ customer have these rights and are not afraid to exercise them. Right of access, including rights to restrict processing and the right of oversight where AI is used, are all part of these rights. Above all, you must be fair and transparent in your processing and clients should know how you intend to use their data.

One important right is the ‘right to be forgotten’. This is only really possible from marketing lists and data bases. Any person with whom you have transacted business or processed their data, for example, payroll, cannot be deleted from your systems.

You are obliged to have a policy for this and be able to demonstrate how you would meet the rights of individuals.

Data Protection Officers

Organisations that are public authorities, or undertake large scale systematic monitoring of individuals or large scale processing of sensitive personal data (or data on criminal convictions and offences) will be required to appoint a data protection officer (DPO). Smaller businesses should also consider appointing a DPO to ensure compliance is maintained.

A DPO will be responsible for advising an organisation and employees on GDPR compliance obligations; monitoring GDPR compliance, including training employees and conducting internal audits; and being the key contact for individuals whose data is processed as well as supervisory authorities.

Organisations should ensure that the DPO reports to the highest management level within an organisation that they are able to operate independently and that they have sufficient resources to carry out their GDPR duties.

What are the implications for accountants?

Accountants handle a vast amount of data, both client and employee, on a daily basis. Firms will need to ensure that their systems are robust enough to meet GDPR requirements. This means that the data must be protected in line with GDPR provisions. To determine whether operations comply with GDPR, firms may need to carry out an audit on current procedures in order to identify if and where they fall short of the required GDPR standards.

By failing to comply, accountants leave themselves open to significant penalties. Organisations in breach of the regulation could be fined. A standard penalty of €10m or 2% of annual global turnover, up to a maximum of 4% of annual global turnover, or €20m, whichever is greater, can be levied. Fines of this magnitude are rare however. 

As accountants position themselves as strategic advisers to clients, GDPR is an opportunity for firms to demonstrate to clients that they can securely hold and process information in line with data requirements, and that protection of client data is a priority for the practice. As a result, clients are likely to see their accountants as trusted professionals to whom they can entrust business and personal data, and with whom they can partner to drive their business forward.

Accounting firms are seen as trusted advisors to business. Accountants should really encourage their business clients to comply with the regulation. Not enough do so.