Skip to main content

B · Registrations & compliance

GDPR and ICO Registration for Accountancy Firms

Last updated:

Quick answer

Almost every accountancy practice processing personal data must pay the ICO's data protection fee and comply with UK GDPR: publish a privacy notice, sign data processing agreements with software suppliers, set retention periods, and report qualifying breaches to the ICO within 72 hours.

Key takeaways

  • Most firms must register (pay the fee) with the ICO unless a narrow exemption applies.
  • You need a privacy notice covering clients, staff and prospects.
  • Data processing agreements are required with every supplier who touches client data.
  • AML records require 5-year retention after the relationship ends, which sits alongside GDPR minimisation duties.
  • Notifiable breaches must be reported to the ICO within 72 hours of becoming aware.
  • Client portals and role-based access reduce the biggest practical risk: email.

Do accountants need to register with the ICO?

Yes. Almost all accountancy and bookkeeping practices process personal data electronically as controllers, which triggers the duty to pay the ICO data protection fee unless a specific exemption applies.

The Data Protection (Charges and Information) Regulations 2018 require most organisations that process personal data to pay the ICO a data protection fee, commonly called ICO registration. Accountancy and bookkeeping firms hold client names, addresses, National Insurance numbers, bank details and often family or health information relevant to tax affairs, so they process personal data as a controller in almost every case.

The fee is tiered by turnover and staff numbers, with small firms typically in the lowest tier. Check the current tier and amount on the ICO's self-assessment tool before paying, since figures change periodically.

Sole practitioners sometimes assume they are exempt because they are small. The exemptions are narrow (mainly staff administration, advertising/marketing or accounts/records for your own business) and do not cover client personal data processed for a fee. Check the ICO exemption checklist rather than assuming.

What must a firm's privacy notice cover?

A privacy notice must explain, in plain language, what personal data you collect, why, your lawful basis, how long you keep it and who you share it with, covering clients, staff and marketing contacts separately if the purposes differ.

UK GDPR's transparency principle means clients and staff are entitled to know how their data is used before or at the point it is collected. A single generic notice covering only your website is not enough; you need clauses addressing engagement data, AML checks, payroll and staff HR data, and marketing communications.

Core contents

  • Identity and contact details of the controller and, if appointed, a data protection contact.
  • Categories of personal data processed and the lawful basis for each purpose (contract, legal obligation, legitimate interests).
  • Retention periods, including the 5-year post-relationship retention required under the Money Laundering Regulations 2017.
  • Recipients or categories of recipient, including software providers, HMRC and Companies House.
  • Individuals' rights: access, rectification, erasure (subject to legal retention duties), objection to marketing.
  • How to complain, including the right to contact the ICO.

When do you need a data processing agreement?

You need a written data processing agreement (DPA) with every supplier that processes personal data on your behalf, such as practice management software, cloud accounting platforms, payroll bureaux and offshore outsourcers.

Article 28 UK GDPR requires a contract setting out the subject matter, duration, nature and purpose of processing, the type of data and categories of data subjects, and the processor's obligations (confidentiality, sub-processor approval, deletion or return of data, and assistance with security and breach obligations).

Most established software vendors publish a standard DPA you can accept online; check it exists before signing up to any tool that will hold client data, and keep a signed or accepted copy on file for each supplier.

Common suppliers requiring a DPA
Supplier typeExampleWhy a DPA is needed
Practice management / CRMClient and job data platformHolds full client personal data
Cloud accounting softwareBookkeeping platform used for clientsProcesses transactional and personal data
Payroll bureau/softwarePAYE processingProcesses employee personal data
Outsourced or offshore staffData entry, bookkeeping supportAccess to client records, often cross-border
Email and file storageCloud email/document storageStores correspondence and attachments

How long should you keep client personal data?

Keep AML identification and due diligence records for 5 years after the client relationship ends, and other records only as long as needed for tax, contractual or professional body requirements, then securely destroy or anonymise them.

GDPR's storage limitation principle says you should not keep personal data longer than necessary. For accountants this sits alongside statutory retention duties: HMRC generally expects records supporting a tax return kept for at least 22 months after the end of the tax year (longer if self-employed or under enquiry), and the Money Laundering Regulations 2017 require CDD and transaction records to be kept for 5 years after the relationship ends.

Build a retention schedule by document type (engagement letters, working papers, AML files, correspondence) rather than trying to apply one blanket period, and automate deletion where your systems allow it.

What counts as a reportable data breach?

A personal data breach is reportable to the ICO within 72 hours if it is likely to result in a risk to individuals' rights and freedoms, for example client tax or bank data sent to the wrong recipient or lost on an unencrypted device.

Common accountancy breach scenarios include emailing a tax return or payroll file to the wrong client, a stolen unencrypted laptop, or a phishing attack giving access to a mailbox containing client data. Assess likelihood and severity of harm quickly; if risk is likely, you must notify the ICO within 72 hours of becoming aware, and notify affected individuals without undue delay if the risk is high.

  1. Contain the breach (revoke access, recall the email, change passwords).
  2. Record what happened, when, and what data was involved, even if you decide not to report.
  3. Assess the risk to individuals using the ICO's severity guidance.
  4. Report to the ICO within 72 hours if risk is likely.
  5. Notify affected individuals if risk is high, explaining what happened and what to do.
  6. Review and fix the underlying cause (training, access controls, email checks).

What security measures do accountants need?

Appropriate technical and organisational measures for a small accountancy firm typically include encrypted devices, strong access controls, staff training, a client portal instead of email attachments, and a written incident response plan.

GDPR does not prescribe specific technology, but expects measures proportionate to the risk. For firms handling tax, banking and payroll data, that generally means device encryption, role-based access so staff only see clients they work on, strong account controls and a documented policy for staff leavers to remove access promptly.

Email remains the biggest practical risk in small practices, because attachments are easy to misaddress and hard to recall. A client portal for document exchange reduces this risk by keeping files behind login rather than in transit as attachments.

Does GDPR cover staff records too?

Yes, employee and contractor personal data, including payroll, HR files and performance records, is covered by the same principles and needs its own privacy notice, retention approach and access controls.

Firms sometimes focus their GDPR effort entirely on clients and overlook HR files, right-to-work checks and payroll data for their own staff, which carry the same obligations and often more sensitive categories of data such as sickness records.

How Remindoo helps

GDPR compliance is mostly about reducing risk in everyday client handling, and that's where your day-to-day systems matter more than the policy document. Remindoo's client portal replaces risky email attachments for document collection and exchange, so tax, payroll and bank data move through a logged, permission-controlled channel rather than an inbox. Roles and permissions mean staff only see the clients and files relevant to their work, which supports the access-control expectations under GDPR and limits the blast radius of any single compromised account. AML records held on the client record also help evidence what identification data you hold and why, supporting your retention and accountability documentation. None of this replaces your ICO registration or privacy notice, but it materially reduces the everyday risk that leads to breaches in the first place.

Frequently asked questions

How much is the ICO fee for a small accountancy firm?

The fee is tiered by turnover and staff numbers; small firms are usually in the lowest tier. Check the current amount using the ICO's online self-assessment tool, as fees are reviewed periodically [VERIFY].

Do sole traders need to register with the ICO?

Most sole practitioner accountants and bookkeepers must register because they process client personal data electronically for a fee. The narrow exemptions mainly cover paper-only or purely internal admin processing.

Is a DPA the same as an engagement letter?

No. An engagement letter governs your relationship with the client. A data processing agreement governs your relationship with a supplier who processes personal data on your behalf, such as software or outsourcing providers.

Do I need a Data Protection Officer?

Most small accountancy firms are not required to appoint a formal DPO under UK GDPR, but someone in the firm should own data protection compliance and be the point of contact for the ICO and clients.

How long should I keep old tax working papers?

Generally at least 22 months after the end of the tax year the return relates to, longer if the client is self-employed or under HMRC enquiry, and 5 years after the relationship ends for AML records.

What happens if I don't report a breach in time?

The ICO can take enforcement action, including fines, for failing to notify a reportable breach within 72 hours. Document your risk assessment even when you conclude reporting isn't required.

Can I use cloud software based outside the UK?

Yes, provided you have a DPA in place and the transfer mechanism (such as the UK's international data transfer addendum) is appropriate for the destination country.

Start your free Remindoo trial

Set up deadlines, onboarding and workflows for your new practice with a 60-day free trial.

Sources

Last updated 23 September 2026. General guidance, not legal or regulatory advice. Check with your professional body.

Why recording every task matters in an accountancy practice

Accounting firms run on deadlines: VAT returns, payroll, confirmation statements, accounts and Self Assessment. Recording every job as a task, with an owner and a date, is the simplest way to make sure nothing is missed.

Avoid penalties

HMRC and Companies House charge penalties for late filing. A task for every deadline, with an internal date before it, gives the team a buffer.

Nothing depends on memory

Recorded tasks mean work continues when someone is off sick, on leave or has left the firm.

Consistent quality

Subtask checklists make every job follow the same steps and reviews, whoever does the work.

Visibility for managers

Filters by owner, status and deadline show at a glance what is late, what is due and who needs help.

Practical tips from UK practice

  • Set an internal deadline two to four weeks before every statutory deadline.
  • Use recurring tasks for repeat work such as VAT, payroll and bookkeeping.
  • Break larger jobs into subtasks, including a review step.
  • Comment on the task instead of by email, so the history stays with the work.

Written and reviewed by Waqas Sagar ACA FCCA FMAAT, Chartered Accountant with 18+ years in practice. Founder and MD of Accotax, an ICAEW, ACCA and AAT regulated London practice that has served over 5,000 clients, and founder of Remindoo. Guidance is general; check current GOV.UK and professional body guidance for your firm.

What UK practices say about Remindoo

Read all reviews on Trustpilot
“With Remindoo, everything from the first enquiry to onboarding and ongoing client management is tracked in one place… It saves us hours and gives me, as a practice owner, complete visibility of where the firm stands.”
Shaz Israr
“The biggest benefit is having clients, tasks, deadlines, workflows, proposals and communication all organised in one place.”
Taxaccolega Chartered Accountants
“During my trial, the team were absolutely amazing. They helped onboard my clients, set up my settings and made sure everything was ready for me to use… they made the whole process completely stress-free.”
Afia Begum
“It brings client information, tasks, recurring deadlines, workflows and reminders together in one place, giving us much better visibility across the team.”
Premier Books Consultancy Ltd

Trusted by firms regulated by the following professional bodies