Register

AI tools and UK data protection for accountants

Client records hold personal data, so an AI tool that reads them is processing personal data under the UK GDPR. The Information Commissioner's Office (ICO) has guidance on AI and data protection, now under review after the Data (Use and Access) Act 2025.

Accountin · Last checked 2 October 2026

Status of the ICO guidance

The ICO's guidance on AI and data protection carries a notice that it is under review because of changes made by the Data (Use and Access) Act, and may change. Its last full update was 15 March 2023 (ICO: guidance on AI and data protection). The underlying duties in the UK GDPR still apply, and the points below follow the current text.

Who is the controller

A practice using an AI tool on client records decides why the data is processed and how, so it is a controller for that processing. The ICO says an organisation that decides the purposes and means of processing is a controller regardless of how a contract describes it. A supplier that only provides the tool and processes data on the practice's instructions is likely to be a processor. A supplier that uses the data for its own purposes, such as training its own systems, is acting as a controller for that use (ICO: accountability and governance in AI).

Lawful basis

The ICO says it is the organisation's responsibility to decide which lawful basis applies, for each separate purpose, and to record it before processing starts. Developing or training a system and using it are treated as separate purposes. Where the basis is legitimate interests, the organisation should carry out and record a legitimate interests assessment. Special category data needs both a lawful basis and a separate condition under Article 9 (ICO: lawfulness in AI).

For a practice, the purpose for using a tool on a client's bank data is the service in the engagement letter. A tool supplier that wants to use the same data to improve its own product needs its own basis, and the practice should know whether that is happening.

Data protection impact assessments

The ICO says that in most cases the use of AI will involve processing likely to result in a high risk to individuals' rights and freedoms, so a data protection impact assessment (DPIA) is needed. It also says senior management cannot delegate these questions to technical staff (ICO: accountability and governance in AI).

A DPIA for a small practice can be short. It describes the tool, what client data goes in, where it is processed, who can see it, how long it is kept, how output is reviewed before it affects anyone, and the steps that reduce the risks found.

Transparency

Privacy information must cover the purposes of processing, retention periods and who data is shared with. Where data is collected from the person, the information is given at the time of collection, before the data is used in an AI system (ICO: transparency in AI). A practice's privacy notice should name the kinds of AI tools used and the suppliers who receive client data.

Accuracy

The ICO separates the accuracy principle, which requires personal data to be correct and up to date, from statistical accuracy, which is how often a system's output is right. Where output is a prediction or inference about a person, records should show that it is a statistically informed guess and not a fact (ICO: accuracy and statistical accuracy). A tool's guess at a client's income source or residence status is not a fact to file.

Automated decisions

The Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with Articles 22A to 22D. A decision is based solely on automated processing if there is no meaningful human involvement in it, and it is a significant decision if it has a legal or similarly significant effect on the person. Article 22A is in force in full from 5 February 2026 (legislation.gov.uk: UK GDPR Article 22A).

Where solely automated significant decisions are made, the ICO's summary says the organisation must give the person information about the decision and let them make representations, obtain human intervention and contest it. Special category data can be used only with consent or for substantial public interest reasons (ICO: summary of the changes). The ICO consulted on new guidance on automated decision-making from 31 March 2026 to 29 May 2026 (ICO consultation).

In practice work, a decision such as refusing to act for someone after a due diligence check is a significant decision. A person reviewing the tool's result and deciding keeps it out of the solely automated category, provided the review is real.

Processors and contracts

Where an AI supplier is a processor, Article 28 requires a written contract. The ICO lists the terms: processing only on documented instructions, a duty of confidence, security measures, conditions for using sub-processors, help with data subjects' rights and with the controller's own obligations, deletion or return of data at the end, and audits and inspections (ICO: what needs to be in the contract). Standard terms of service for a consumer tool may not contain these terms.

International transfers

Many AI tools process data outside the UK. A restricted transfer needs adequacy regulations, an appropriate safeguard such as the International Data Transfer Agreement or the Addendum, or an exception. The ICO says that a business relying on a safeguard must also complete a transfer risk assessment (ICO: international transfers). Ask the supplier where data is processed and stored, and which mechanism covers it.

Questions

Is anonymising data before it goes into a tool enough?

The PCRT AI guidance says data put into public tools should be anonymised and generic, and warns that a client may still be identifiable from details such as an unusual line of business (PCRT AI topical guidance). If a client can be identified, the data is still personal data.

What if a supplier has a breach?

The ICO says a notifiable breach must be reported without undue delay and no later than 72 hours after becoming aware of it, and all breaches should be recorded whether reported or not (ICO: personal data breaches). The processor contract should require the supplier to tell the practice promptly.

In Accountin

In Accountin, the practice owner can download everything the practice holds, or one client's records, and every download is written to the audit log.

Accountin is opening to its first practices

Register your practice and we will contact you to set up your account.

Register your practice