Free CRM for accountants & bookkeepersFree for two months (60-day trial) · no per-user fees
Access control & data protection
UK GDPR and Offshore Outsourcing: IDTA, DPAs and Transfer Risk Assessments
Most offshore destinations have no UK adequacy decision — here's what fills the gap
Built by a practising Chartered Accountant · Unlimited users · Free for 60 days
Quick answer
Outsourcing accounting work to most offshore destinations counts as a restricted international transfer under UK GDPR, because the UK has not made an adequacy decision for most of them. Firms typically need the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, a transfer risk assessment, and an Article 28 data processing agreement. [VERIFY] the exact position for your destination country before relying on this. Remindoo can send these documents for e-signature and restrict what the offshore team can access.
What does UK GDPR require when outsourcing accounting work offshore?
If personal data is transferred to a country the UK hasn't recognised as adequate, the firm generally needs an appropriate safeguard — usually the IDTA or the UK Addendum — plus a transfer risk assessment and a data processing agreement with the provider.
UK GDPR restricts transfers of personal data outside the UK unless one of a small number of conditions is met. The simplest is a UK adequacy regulation for the destination country — the UK government has made a set number of these, and most popular offshore accounting destinations aren't on the list. [VERIFY] the current list before assuming a specific country is or isn't covered, since adequacy regulations can change.
Without adequacy, firms typically rely on the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU's Standard Contractual Clauses, signed with the offshore provider, alongside a transfer risk assessment considering the destination country's data protection and access laws.
What goes wrong when firms skip the transfer paperwork
A firm starts sending client bookkeeping work to an offshore provider because a competitor recommended them. The commercial relationship moves fast — an email exchange, a fee agreed, work starts the following week.
Nobody stops to ask whether client personal data leaving the UK for that destination needs a transfer mechanism in place. There's no IDTA, no transfer risk assessment, and no Article 28 DPA — just an informal understanding that the provider will 'keep things confidential'.
A year later, during a routine review or a client query about where their data goes, the firm has no documentation to show it considered the transfer at all, let alone put appropriate safeguards in place — a gap that's far harder to close retrospectively than it would have been to avoid from day one.
Signs you've lost control
- You outsource offshore but have never signed an IDTA or UK Addendum with the provider
- There's no transfer risk assessment on file for the destination country
- The provider relationship has no Article 28 data processing agreement
- Nobody in the firm could explain, if asked, what legal basis covers the transfer
- The engagement letter doesn't mention that client work may be processed offshore
- You're not sure whether the destination country has a UK adequacy regulation
Steps to get the GDPR position right before outsourcing offshore
- 1
Check whether the destination has UK adequacy
Confirm on gov.uk/ICO guidance whether the country has a current UK adequacy regulation. [VERIFY] before relying on this for any specific country.
- 2
Put an IDTA or UK Addendum in place if not
Sign the ICO's IDTA or the UK Addendum to the EU SCCs with the offshore provider as the appropriate safeguard.
- 3
Complete a transfer risk assessment
Assess the destination country's data protection and government access laws before or alongside signing the transfer agreement.
- 4
Sign an Article 28 data processing agreement
Cover instructions, confidentiality, sub-processing and deletion requirements with the provider as processor.
- 5
Update engagement letters to mention offshore processing
Tell clients plainly that some work may be processed by an offshore team, consistent with professional body guidance on disclosure.
- 6
Keep the documentation on file, signed
Store the IDTA/Addendum, DPA and transfer risk assessment somewhere retrievable, not just as an email attachment.
- 7
Review annually or when the arrangement changes
Revisit if the provider, destination or scope of data being transferred changes.
Who owns each step of an outsourced job?
1. Assign
UK office
The UK office confirms the transfer paperwork is signed before any client data is sent offshore for a new engagement.
2. Prepare
Offshore team
The offshore team works only within the scope and access agreed in the DPA and role permissions.
3. Review
UK reviewer
A UK reviewer checks completed work as normal, on the task rather than by re-sending data elsewhere.
4. Approve
UK partner
A partner or DPO-equivalent periodically confirms the transfer documentation is still current.
5. Send
UK office
The UK office remains the point of contact for any client query about where their data is processed.
How does Remindoo support the GDPR side of offshore outsourcing?
Remindoo doesn't replace the legal transfer mechanism — you still need the IDTA or UK Addendum, transfer risk assessment and DPA in place — but it supports the operational side of keeping data under control. Proposals and letters of engagement with e-signature let you send your outsourcing agreement, NDA and DPA to the provider to sign online, with the signed documents kept on the client or provider record. Roles and permissions restrict which clients and data each offshore user can see, which supports the access-minimisation point in a transfer risk assessment. Client timeline shows the history of tasks, services and communications, giving you a record of what was actually processed and by whom if you ever need to demonstrate it. It's free for 60 days.
E-signatures
Clients sign online, no printing or scanning.
See featureProposals and letters of engagement
Send proposals and engagement letters by email.
See featureRoles and permissions
Control who sees and edits client data.
See featureClient timeline
Full history of notes, emails and actions.
See featureWhat changes when you move off email and WhatsApp?
| Area | Email, WhatsApp and spreadsheets | Remindoo |
|---|---|---|
| Transfer mechanism | Assumed or absent | IDTA/UK Addendum signed and filed |
| Transfer risk assessment | Not completed | Completed and reviewed periodically |
| Processor agreement | Verbal understanding | Signed Article 28 DPA |
| Client disclosure | Not mentioned | Stated in the engagement letter |
| Access to data | Broad, unrestricted | Restricted by role and task |
| Record of processing | Scattered or absent | Client timeline history |
See your offshore set-up working
A 30-minute walkthrough of teams, roles, time budgets and review steps.
What does 'no UK adequacy' actually mean in practice?
It means the UK government hasn't formally decided the destination country's data protection laws are broadly equivalent to the UK's, so an extra legal safeguard is needed before personal data can be sent there.
Adequacy regulations are a small, specific list published by the UK government, covering a limited number of countries and, for some, only certain types of transfer. Popular offshore accounting destinations for UK firms are generally not on this list. [VERIFY] the current position directly on gov.uk before relying on it for a specific country, since the list is reviewed and can change.
| Situation | Typical requirement |
|---|---|
| Destination has UK adequacy | Transfer can generally proceed without extra safeguards, but check specific conditions |
| No UK adequacy | IDTA or UK Addendum, plus a transfer risk assessment |
| Any offshore transfer | Article 28 DPA with the processor regardless of adequacy |
Who should carry out the transfer risk assessment?
Ultimately the firm, as data controller, is responsible, though many firms take legal advice or use ICO tools and templates to structure it.
The transfer risk assessment considers the destination country's laws on government access to data, the safeguards the provider itself has in place, and the sensitivity of the data being sent. It's a judgement exercise rather than a form to tick, and firms without in-house data protection expertise commonly take advice for anything beyond a straightforward, low-risk arrangement.
General guidance, not legal advice. Take advice on your contracts and data transfers.
Frequently asked questions
Does every offshore outsourcing arrangement need an IDTA?
If the destination country doesn't have UK adequacy, yes, in the great majority of cases — take advice on your specific arrangement, and [VERIFY] the current adequacy list.
Is the UK Addendum the same as the IDTA?
No — the UK Addendum is used alongside the EU's Standard Contractual Clauses, while the IDTA is the ICO's own standalone agreement. Either can work as an appropriate safeguard; take advice on which fits your provider's existing documentation.
Do we need a separate transfer risk assessment for each provider?
Generally yes, since the assessment considers the specific destination country and provider, not just the fact that a transfer is happening.
What is an Article 28 DPA and is it different from the IDTA?
The Article 28 DPA covers the processor relationship — instructions, confidentiality, sub-processing, deletion. The IDTA/Addendum covers the international transfer itself. Most offshore arrangements need both.
Should clients be told their data is processed offshore?
Professional body guidance generally supports disclosure, commonly through wording in the engagement letter, so clients aren't surprised to learn about it later.
What happens if we've been outsourcing without any of this in place?
Take advice promptly and put the missing documentation in place going forward — this is a compliance gap worth closing quickly rather than leaving unresolved.
Does Remindoo handle the IDTA or transfer risk assessment for us?
No — those are legal documents and assessments you complete with your provider and advisers. Remindoo can send the signed agreements for e-signature and restrict data access, but it isn't a substitute for the legal work.
Ready to run a calmer practice?
See Remindoo with your own clients, or start free for 60 days with unlimited users.
Sources
Last updated: . General guidance, not legal advice. Take advice on your contracts and data transfers.
Why recording every task matters in an accountancy practice
Accounting firms run on deadlines: VAT returns, payroll, confirmation statements, accounts and Self Assessment. Recording every job as a task, with an owner and a date, is the simplest way to make sure nothing is missed.
Avoid penalties
HMRC and Companies House charge penalties for late filing. A task for every deadline, with an internal date before it, gives the team a buffer.
Nothing depends on memory
Recorded tasks mean work continues when someone is off sick, on leave or has left the firm.
Consistent quality
Subtask checklists make every job follow the same steps and reviews, whoever does the work.
Visibility for managers
Filters by owner, status and deadline show at a glance what is late, what is due and who needs help.
Practical tips from UK practice
- Set an internal deadline two to four weeks before every statutory deadline.
- Use recurring tasks for repeat work such as VAT, payroll and bookkeeping.
- Break larger jobs into subtasks, including a review step.
- Comment on the task instead of by email, so the history stays with the work.
Related Remindoo features
Written and reviewed by Waqas Sagar ACA FCCA FMAAT, Chartered Accountant with 18+ years in practice. Founder and MD of Accotax, an ICAEW, ACCA and AAT regulated London practice that has served over 5,000 clients, and founder of Remindoo. Guidance is general; check current GOV.UK and professional body guidance for your firm.
What UK practices say about Remindoo
Read all reviews on Trustpilot“With Remindoo, everything from the first enquiry to onboarding and ongoing client management is tracked in one place… It saves us hours and gives me, as a practice owner, complete visibility of where the firm stands.”
“The biggest benefit is having clients, tasks, deadlines, workflows, proposals and communication all organised in one place.”
“During my trial, the team were absolutely amazing. They helped onboard my clients, set up my settings and made sure everything was ready for me to use… they made the whole process completely stress-free.”
“It brings client information, tasks, recurring deadlines, workflows and reminders together in one place, giving us much better visibility across the team.”









