The data protection fee
- Tier 1, micro organisations
- Turnover up to £632,000 or no more than 10 staff: £52 (ICO)
- Tier 2, small and medium
- Turnover up to £36 million or no more than 250 staff: £78
- Tier 3, large
- Any organisation outside tiers 1 and 2: £3,763
- Direct Debit
- £5 off each tier
- Renewal
- Every year
Controller or processor
The ICO's guidance uses an accountant as its example: when a firm uses an accountant to do its books, the accountant is a controller of the personal data in the accounts, because accountants work under professional obligations that make them responsible for the data they process. The accountant cannot agree to hand those controller obligations to the client.
The suppliers a practice uses to hold or process that data, such as software, cloud storage or an outsourced payroll bureau, are processors when they act only on the practice's instructions. The ICO lists what the contract with a processor must include: the subject matter, duration, nature and purpose of the processing, the types of data and data subjects, processing only on documented instructions, confidentiality, security, rules on sub-processors, help with data subject rights and breaches, deleting or returning data at the end, and audits.
Privacy information
Privacy information is given when data is collected from the person, and within one month where it comes from someone else (ICO: right to be informed). It covers the purposes, the lawful basis, the recipients, the retention periods and the person's rights. A practice that runs a client's payroll gets employee data from the client, so the one-month rule applies to those employees.
Retention
UK GDPR sets no fixed retention periods. The ICO says a practice must be able to justify how long it keeps personal data, should have a policy with standard periods, and must erase or anonymise data it no longer needs. Keeping records because the law requires it, such as tax records, meets the test. The legal periods are listed in changing accounts software. Anti-money laundering records are kept for five years after the relationship ends and personal data is then deleted unless an exception applies (regulation 40).
Handling a personal data breach
Contain and assess
Find out what data was affected, whose, and the likely risk to them.
Report within 72 hours
A notifiable breach is reported to the ICO without undue delay and not later than 72 hours after becoming aware of it. Reasons are given if it takes longer (ICO).
Tell the people affected
Where the risk to them is high, tell them without undue delay.
Record every breach
Article 33(5) requires a record of the facts, effects and remedial action for every breach, reported or not. Failing to notify a reportable breach can bring a fine of up to £8.7 million or 2% of annual global turnover (ICO).
Questions
How long does a practice have to answer a subject access request?
One month from receipt, extendable by up to two further months if the request is complex or the person has made several. In most cases no fee can be charged, and a request can be made verbally or in writing, including on social media. The search must be reasonable and proportionate. The ICO's guide was updated on 16 July 2026 for the Data (Use and Access) Act 2025.
Who answers a request about data in a client's accounts?
The accountant, as controller of that data (ICO).
Does a practice need a data protection complaints procedure?
Yes. From 19 June 2026, under the Data (Use and Access) Act 2025, organisations must give people a clear way to make a data protection complaint, acknowledge it within 30 days, investigate without undue delay and tell the complainant the outcome (ICO).
In Accountin
Every Accountin login uses two-step sign-in, the audit log records every data export, and the owner can download one client's data as a zip file.
Accountin is opening to its first practices
Register your practice and we will contact you to set up your account.