Free CRM for accountants & bookkeepersFree for two months (60-day trial) · no per-user fees
Contracts with the provider
Get Your Outsourcing Partner to Sign an NDA and DPA Online
Don't start sending client data until both documents are signed
Built by a practising Chartered Accountant · Unlimited users · Free for 60 days
Quick answer
Before sending any client data to an offshore provider, a UK firm should have a signed NDA covering confidentiality and an Article 28 data processing agreement covering how personal data is handled. Both can be sent for e-signature rather than printed, scanned and emailed back and forth. Remindoo's proposals and letters of engagement with e-signature can be used to send these documents to a provider. Free for 60 days.
Why do you need both an NDA and a DPA with an outsourcing provider?
The NDA protects confidentiality generally, while the Article 28 DPA specifically covers how the provider must handle personal data as a processor under UK GDPR — they overlap but aren't interchangeable.
An NDA is a familiar document to most firms — it says, broadly, 'don't share what you learn about our business or our clients'. It's necessary but not sufficient for outsourcing, because it doesn't cover the specific obligations UK GDPR places on anyone processing personal data on your behalf.
The Article 28 data processing agreement fills that gap: instructions for processing, confidentiality of staff, sub-processor approval, assistance with data subject requests, breach notification and deletion or return of data at the end of the engagement. A firm outsourcing accounting work needs both documents, signed, before data starts moving.
What goes wrong without both documents signed and on file
A firm sends a first batch of client files to a new offshore provider to get started quickly, on the understanding that 'we'll sort the paperwork out properly once we know it's working'. The relationship continues for months on this basis.
No NDA is signed, no DPA is in place, and client personal data has already been processed by a provider with no binding confidentiality obligation and no documented instructions on how that data should be handled, retained or deleted.
If a data protection query or a confidentiality concern arises during those months, the firm has no signed document to point to — the 'we'll sort it out properly' intention never actually happened, and by then, real client data has already moved.
Signs you've lost control
- Client data has already started moving to a provider with no NDA or DPA signed
- The NDA and DPA, if they exist, were never actually signed, just discussed
- Nobody can locate a signed copy of either document when asked
- The DPA doesn't specifically reference sub-processors, breach notification or deletion
- The NDA was a generic template never adapted for an outsourcing relationship
- There's no process for renewing or reviewing either document
Steps to get the NDA and DPA signed before outsourcing starts
- 1
Prepare the NDA first
Cover confidentiality of client and firm information specifically, not just generic business confidentiality.
- 2
Prepare the Article 28 DPA
Cover processing instructions, confidentiality, sub-processing, assistance obligations, breach notification and deletion/return of data.
- 3
Reference the international transfer mechanism
Where relevant, tie the DPA to the signed IDTA or UK Addendum covering the actual data transfer.
- 4
Send both for e-signature
Avoid printing, scanning and emailing back and forth — get a clean, dated, signed copy of each.
- 5
Hold data until both are signed
Don't start sending real client data before the signed documents are on file, however time-pressured the start date feels.
- 6
File the signed copies somewhere retrievable
Store them against the provider record, not buried in an inbox.
- 7
Set a review date
Revisit both documents annually or when the scope of the relationship changes.
Who owns each step of an outsourced job?
1. Assign
UK office
The UK office prepares the NDA and DPA before the provider relationship formally starts.
2. Prepare
Offshore team
The provider reviews both documents and raises any queries before signing.
3. Review
UK reviewer
A UK reviewer or adviser checks the final wording, particularly the DPA's processing terms.
4. Approve
UK partner
A partner approves both documents before they're sent for signature.
5. Send
UK office
The UK office sends both for e-signature and holds off sending real client data until both are back, signed.
How does Remindoo help get the NDA and DPA signed quickly?
Remindoo's proposals and letters of engagement with e-signature can be used to send your NDA and data processing agreement to an offshore provider, so both come back signed and dated without printing, scanning or a lengthy email chain. The signed documents sit alongside the provider record, and proposal filters make it straightforward to find them again by stage, date or provider when you need to check they're current. Once both are signed, roles and permissions and detailed task assignment let you put the agreed access limits into practice immediately, so the paperwork and the day-to-day system access are consistent with each other. It's free for 60 days.
E-signatures
Clients sign online, no printing or scanning.
See featureProposals and letters of engagement
Send proposals and engagement letters by email.
See featureProposal filters
Find proposals by stage, owner and date.
See featureRoles and permissions
Control who sees and edits client data.
See featureDetailed task creation
Set priority, assignee and deadline on every job.
See featureWhat changes when you move off email and WhatsApp?
| Area | Email, WhatsApp and spreadsheets | Remindoo |
|---|---|---|
| Signing process | Print, sign, scan, email | Sent and signed online |
| Starting data flow | Begins before paperwork is finished | Held until both documents are signed |
| Finding signed copies later | Buried in an inbox | Filed against the provider, filterable |
| DPA content | Generic or missing | Covers instructions, sub-processing, deletion |
| NDA scope | Generic business confidentiality | Specific to client data and outsourcing |
| Review cadence | Never revisited | Set review date on file |
See your offshore set-up working
A 30-minute walkthrough of teams, roles, time budgets and review steps.
What should a compliant Article 28 DPA actually include?
At minimum: the subject matter and duration of processing, the nature and purpose, the type of data and categories of individuals, the controller's obligations and rights, and the processor's obligations including confidentiality, sub-processing, assistance and deletion.
Article 28 UK GDPR sets out specific content a processor contract must contain. It's not enough for a DPA to say 'the provider will keep data confidential and secure' in general terms — it needs to address sub-processor approval, assistance with data subject access requests, breach notification timelines, and what happens to the data when the engagement ends.
[VERIFY] the exact drafting with a solicitor or a reputable DPA template — this is a legal document with specific statutory content requirements.
General guidance, not legal advice. Take advice on your contracts and data transfers.
Frequently asked questions
Can we combine the NDA and DPA into one document?
It's possible, though many firms keep them separate so the DPA's specific UK GDPR content can be reviewed and updated independently of general confidentiality terms.
Is a DPA a legal requirement or just best practice?
It's a requirement under Article 28 UK GDPR whenever a processor handles personal data on a controller's behalf — outsourcing accounting work to a provider typically falls into this category.
Should we sign the NDA before or after the DPA?
There's no fixed order, but neither should be skipped, and ideally both are signed before any real client data is shared.
Does e-signature make these documents less valid than a wet signature?
No — e-signatures are widely recognised as legally valid in the UK for this type of commercial document, though [VERIFY] if your specific circumstances raise any doubt.
What should happen to client data when the DPA ends?
The DPA should specify return or secure deletion of the data within an agreed period, and this should be checked, not just assumed to have happened.
Do we need a new DPA for every offshore provider we use?
Yes — each processor relationship needs its own DPA, even if the underlying template is similar across providers.
How does this relate to the transfer risk assessment and IDTA?
The DPA covers the processor relationship; the IDTA or UK Addendum covers the international transfer itself. Both are typically needed together for an offshore provider without UK adequacy.
Ready to run a calmer practice?
See Remindoo with your own clients, or start free for 60 days with unlimited users.
Sources
Last updated: . General guidance, not legal advice. Take advice on your contracts and data transfers.
Why recording every task matters in an accountancy practice
Accounting firms run on deadlines: VAT returns, payroll, confirmation statements, accounts and Self Assessment. Recording every job as a task, with an owner and a date, is the simplest way to make sure nothing is missed.
Avoid penalties
HMRC and Companies House charge penalties for late filing. A task for every deadline, with an internal date before it, gives the team a buffer.
Nothing depends on memory
Recorded tasks mean work continues when someone is off sick, on leave or has left the firm.
Consistent quality
Subtask checklists make every job follow the same steps and reviews, whoever does the work.
Visibility for managers
Filters by owner, status and deadline show at a glance what is late, what is due and who needs help.
Practical tips from UK practice
- Set an internal deadline two to four weeks before every statutory deadline.
- Use recurring tasks for repeat work such as VAT, payroll and bookkeeping.
- Break larger jobs into subtasks, including a review step.
- Comment on the task instead of by email, so the history stays with the work.
Related Remindoo features
Written and reviewed by Waqas Sagar ACA FCCA FMAAT, Chartered Accountant with 18+ years in practice. Founder and MD of Accotax, an ICAEW, ACCA and AAT regulated London practice that has served over 5,000 clients, and founder of Remindoo. Guidance is general; check current GOV.UK and professional body guidance for your firm.
What UK practices say about Remindoo
Read all reviews on Trustpilot“With Remindoo, everything from the first enquiry to onboarding and ongoing client management is tracked in one place… It saves us hours and gives me, as a practice owner, complete visibility of where the firm stands.”
“The biggest benefit is having clients, tasks, deadlines, workflows, proposals and communication all organised in one place.”
“During my trial, the team were absolutely amazing. They helped onboard my clients, set up my settings and made sure everything was ready for me to use… they made the whole process completely stress-free.”
“It brings client information, tasks, recurring deadlines, workflows and reminders together in one place, giving us much better visibility across the team.”









