B · Registrations & compliance
GDPR and ICO Registration for Accountancy Firms
Last updated:
Quick answer
Almost every accountancy practice processing personal data must pay the ICO's data protection fee and comply with UK GDPR: publish a privacy notice, sign data processing agreements with software suppliers, set retention periods, and report qualifying breaches to the ICO within 72 hours.
Key takeaways
- Most firms must register (pay the fee) with the ICO unless a narrow exemption applies.
- You need a privacy notice covering clients, staff and prospects.
- Data processing agreements are required with every supplier who touches client data.
- AML records require 5-year retention after the relationship ends, which sits alongside GDPR minimisation duties.
- Notifiable breaches must be reported to the ICO within 72 hours of becoming aware.
- Client portals and role-based access reduce the biggest practical risk: email.
Do accountants need to register with the ICO?
Yes. Almost all accountancy and bookkeeping practices process personal data electronically as controllers, which triggers the duty to pay the ICO data protection fee unless a specific exemption applies.
The Data Protection (Charges and Information) Regulations 2018 require most organisations that process personal data to pay the ICO a data protection fee, commonly called ICO registration. Accountancy and bookkeeping firms hold client names, addresses, National Insurance numbers, bank details and often family or health information relevant to tax affairs, so they process personal data as a controller in almost every case.
The fee is tiered by turnover and staff numbers, with small firms typically in the lowest tier. Check the current tier and amount on the ICO's self-assessment tool before paying, since figures change periodically.
Sole practitioners sometimes assume they are exempt because they are small. The exemptions are narrow (mainly staff administration, advertising/marketing or accounts/records for your own business) and do not cover client personal data processed for a fee. Check the ICO exemption checklist rather than assuming.
What must a firm's privacy notice cover?
A privacy notice must explain, in plain language, what personal data you collect, why, your lawful basis, how long you keep it and who you share it with, covering clients, staff and marketing contacts separately if the purposes differ.
UK GDPR's transparency principle means clients and staff are entitled to know how their data is used before or at the point it is collected. A single generic notice covering only your website is not enough; you need clauses addressing engagement data, AML checks, payroll and staff HR data, and marketing communications.
Core contents
- Identity and contact details of the controller and, if appointed, a data protection contact.
- Categories of personal data processed and the lawful basis for each purpose (contract, legal obligation, legitimate interests).
- Retention periods, including the 5-year post-relationship retention required under the Money Laundering Regulations 2017.
- Recipients or categories of recipient, including software providers, HMRC and Companies House.
- Individuals' rights: access, rectification, erasure (subject to legal retention duties), objection to marketing.
- How to complain, including the right to contact the ICO.
When do you need a data processing agreement?
You need a written data processing agreement (DPA) with every supplier that processes personal data on your behalf, such as practice management software, cloud accounting platforms, payroll bureaux and offshore outsourcers.
Article 28 UK GDPR requires a contract setting out the subject matter, duration, nature and purpose of processing, the type of data and categories of data subjects, and the processor's obligations (confidentiality, sub-processor approval, deletion or return of data, and assistance with security and breach obligations).
Most established software vendors publish a standard DPA you can accept online; check it exists before signing up to any tool that will hold client data, and keep a signed or accepted copy on file for each supplier.
| Supplier type | Example | Why a DPA is needed |
|---|---|---|
| Practice management / CRM | Client and job data platform | Holds full client personal data |
| Cloud accounting software | Bookkeeping platform used for clients | Processes transactional and personal data |
| Payroll bureau/software | PAYE processing | Processes employee personal data |
| Outsourced or offshore staff | Data entry, bookkeeping support | Access to client records, often cross-border |
| Email and file storage | Cloud email/document storage | Stores correspondence and attachments |
How long should you keep client personal data?
Keep AML identification and due diligence records for 5 years after the client relationship ends, and other records only as long as needed for tax, contractual or professional body requirements, then securely destroy or anonymise them.
GDPR's storage limitation principle says you should not keep personal data longer than necessary. For accountants this sits alongside statutory retention duties: HMRC generally expects records supporting a tax return kept for at least 22 months after the end of the tax year (longer if self-employed or under enquiry), and the Money Laundering Regulations 2017 require CDD and transaction records to be kept for 5 years after the relationship ends.
Build a retention schedule by document type (engagement letters, working papers, AML files, correspondence) rather than trying to apply one blanket period, and automate deletion where your systems allow it.
What counts as a reportable data breach?
A personal data breach is reportable to the ICO within 72 hours if it is likely to result in a risk to individuals' rights and freedoms, for example client tax or bank data sent to the wrong recipient or lost on an unencrypted device.
Common accountancy breach scenarios include emailing a tax return or payroll file to the wrong client, a stolen unencrypted laptop, or a phishing attack giving access to a mailbox containing client data. Assess likelihood and severity of harm quickly; if risk is likely, you must notify the ICO within 72 hours of becoming aware, and notify affected individuals without undue delay if the risk is high.
- Contain the breach (revoke access, recall the email, change passwords).
- Record what happened, when, and what data was involved, even if you decide not to report.
- Assess the risk to individuals using the ICO's severity guidance.
- Report to the ICO within 72 hours if risk is likely.
- Notify affected individuals if risk is high, explaining what happened and what to do.
- Review and fix the underlying cause (training, access controls, email checks).
What security measures do accountants need?
Appropriate technical and organisational measures for a small accountancy firm typically include encrypted devices, strong access controls, staff training, a client portal instead of email attachments, and a written incident response plan.
GDPR does not prescribe specific technology, but expects measures proportionate to the risk. For firms handling tax, banking and payroll data, that generally means device encryption, role-based access so staff only see clients they work on, strong account controls and a documented policy for staff leavers to remove access promptly.
Email remains the biggest practical risk in small practices, because attachments are easy to misaddress and hard to recall. A client portal for document exchange reduces this risk by keeping files behind login rather than in transit as attachments.
Does GDPR cover staff records too?
Yes, employee and contractor personal data, including payroll, HR files and performance records, is covered by the same principles and needs its own privacy notice, retention approach and access controls.
Firms sometimes focus their GDPR effort entirely on clients and overlook HR files, right-to-work checks and payroll data for their own staff, which carry the same obligations and often more sensitive categories of data such as sickness records.
How Remindoo helps
GDPR compliance is mostly about reducing risk in everyday client handling, and that's where your day-to-day systems matter more than the policy document. Remindoo's client portal replaces risky email attachments for document collection and exchange, so tax, payroll and bank data move through a logged, permission-controlled channel rather than an inbox. Roles and permissions mean staff only see the clients and files relevant to their work, which supports the access-control expectations under GDPR and limits the blast radius of any single compromised account. AML records held on the client record also help evidence what identification data you hold and why, supporting your retention and accountability documentation. None of this replaces your ICO registration or privacy notice, but it materially reduces the everyday risk that leads to breaches in the first place.
Frequently asked questions
How much is the ICO fee for a small accountancy firm?
The fee is tiered by turnover and staff numbers; small firms are usually in the lowest tier. Check the current amount using the ICO's online self-assessment tool, as fees are reviewed periodically [VERIFY].
Do sole traders need to register with the ICO?
Most sole practitioner accountants and bookkeepers must register because they process client personal data electronically for a fee. The narrow exemptions mainly cover paper-only or purely internal admin processing.
Is a DPA the same as an engagement letter?
No. An engagement letter governs your relationship with the client. A data processing agreement governs your relationship with a supplier who processes personal data on your behalf, such as software or outsourcing providers.
Do I need a Data Protection Officer?
Most small accountancy firms are not required to appoint a formal DPO under UK GDPR, but someone in the firm should own data protection compliance and be the point of contact for the ICO and clients.
How long should I keep old tax working papers?
Generally at least 22 months after the end of the tax year the return relates to, longer if the client is self-employed or under HMRC enquiry, and 5 years after the relationship ends for AML records.
What happens if I don't report a breach in time?
The ICO can take enforcement action, including fines, for failing to notify a reportable breach within 72 hours. Document your risk assessment even when you conclude reporting isn't required.
Can I use cloud software based outside the UK?
Yes, provided you have a DPA in place and the transfer mechanism (such as the UK's international data transfer addendum) is appropriate for the destination country.
Start your free Remindoo trial
Set up deadlines, onboarding and workflows for your new practice with a 60-day free trial.
Sources
Last updated 23 September 2026. General guidance, not legal or regulatory advice. Check with your professional body.









