Register

Data protection for accountancy practices

An accountancy practice holds personal data about clients, their employees and their customers. It pays the ICO's data protection fee unless exempt, and as a controller it answers for that data under UK GDPR.

Accountin · Last checked 2 October 2026

The data protection fee

Tier 1, micro organisations
Turnover up to £632,000 or no more than 10 staff: £52 (ICO)
Tier 2, small and medium
Turnover up to £36 million or no more than 250 staff: £78
Tier 3, large
Any organisation outside tiers 1 and 2: £3,763
Direct Debit
£5 off each tier
Renewal
Every year

Controller or processor

The ICO's guidance uses an accountant as its example: when a firm uses an accountant to do its books, the accountant is a controller of the personal data in the accounts, because accountants work under professional obligations that make them responsible for the data they process. The accountant cannot agree to hand those controller obligations to the client.

The suppliers a practice uses to hold or process that data, such as software, cloud storage or an outsourced payroll bureau, are processors when they act only on the practice's instructions. The ICO lists what the contract with a processor must include: the subject matter, duration, nature and purpose of the processing, the types of data and data subjects, processing only on documented instructions, confidentiality, security, rules on sub-processors, help with data subject rights and breaches, deleting or returning data at the end, and audits.

Privacy information

Privacy information is given when data is collected from the person, and within one month where it comes from someone else (ICO: right to be informed). It covers the purposes, the lawful basis, the recipients, the retention periods and the person's rights. A practice that runs a client's payroll gets employee data from the client, so the one-month rule applies to those employees.

Retention

UK GDPR sets no fixed retention periods. The ICO says a practice must be able to justify how long it keeps personal data, should have a policy with standard periods, and must erase or anonymise data it no longer needs. Keeping records because the law requires it, such as tax records, meets the test. The legal periods are listed in changing accounts software. Anti-money laundering records are kept for five years after the relationship ends and personal data is then deleted unless an exception applies (regulation 40).

Handling a personal data breach

  1. Contain and assess

    Find out what data was affected, whose, and the likely risk to them.

  2. Report within 72 hours

    A notifiable breach is reported to the ICO without undue delay and not later than 72 hours after becoming aware of it. Reasons are given if it takes longer (ICO).

  3. Tell the people affected

    Where the risk to them is high, tell them without undue delay.

  4. Record every breach

    Article 33(5) requires a record of the facts, effects and remedial action for every breach, reported or not. Failing to notify a reportable breach can bring a fine of up to £8.7 million or 2% of annual global turnover (ICO).

Questions

How long does a practice have to answer a subject access request?

One month from receipt, extendable by up to two further months if the request is complex or the person has made several. In most cases no fee can be charged, and a request can be made verbally or in writing, including on social media. The search must be reasonable and proportionate. The ICO's guide was updated on 16 July 2026 for the Data (Use and Access) Act 2025.

Who answers a request about data in a client's accounts?

The accountant, as controller of that data (ICO).

Does a practice need a data protection complaints procedure?

Yes. From 19 June 2026, under the Data (Use and Access) Act 2025, organisations must give people a clear way to make a data protection complaint, acknowledge it within 30 days, investigate without undue delay and tell the complainant the outcome (ICO).

Is the fee optional for a small practice?

No. The ICO says organisations, including sole traders, that use personal information must pay the fee under the Data Protection (Charges and Information) Regulations 2018 unless they are exempt. AAT licence conditions also require it (AAT).

In Accountin

Every Accountin login uses two-step sign-in, the audit log records every data export, and the owner can download one client's data as a zip file.

Accountin is opening to its first practices

Register your practice and we will contact you to set up your account.

Register your practice