Outsourcing and UK GDPR: what a practice actually has to do
Your firm stays the data controller. Most of what follows comes from that fact, and it is why your regulator will not accept “our provider is compliant” as an answer.
Data security is the first objection most practices raise about outsourcing, and it is a fair one to raise first. It is also often answered badly: providers wave a certificate and firms accept it.
Start with who is responsible, because that matters more than the technology. When your practice sends client data to a provider, you remain the data controller and the provider becomes a processor acting on your documented instructions. Responsibility does not transfer with the data. If personal data is compromised, the obligation to your clients, your regulator and the ICO remains yours.
The six things that need to exist
1. A written Article 28 agreement
UK GDPR Article 28 requires a written contract between controller and processor. A services agreement with a confidentiality clause does not satisfy it. The contract must cover the subject matter and duration of processing, the nature and purpose, the types of personal data and categories of data subject, and it must impose specific obligations on the processor: to process only on your documented instructions, to ensure confidentiality, to implement appropriate security measures, to engage sub-processors only with authorisation, to assist with data subject rights and breach notification, and to delete or return data at the end of the engagement.
Ask any prospective provider for their draft DPA before you discuss price. How quickly it arrives, and how much of the above it contains, tells you a good deal.
2. A lawful basis that still holds
You had a lawful basis for processing your client's data when you took them on. Extending that processing to a third party outside the UK does not automatically invalidate it, but you do need to check that it still holds and that the processing remains within what the client would reasonably expect.
3. A transfer mechanism and a transfer risk assessment
Where processing happens outside the UK, you need an appropriate transfer mechanism and a documented transfer risk assessment. This is the step most often skipped. It requires you to assess the legal regime in the destination country, the practical risk to the data, and the supplementary measures in place (encryption, access control, contractual protection) that address the gap.
Accountancy data routinely includes special category data, and your assessment should reflect that. Client records are not ordinary business information.
4. Engagement letters and privacy notice that reflect reality
Your engagement letter should contemplate the possibility of work being transferred to a third party, and your privacy notice should describe the categories of recipient and the fact of international transfer. What you must disclose is the arrangement. You do not have to name the provider to clients (that remains a commercial decision), but you must not leave them with an inaccurate picture.
5. Professional confidentiality, considered separately
Data protection and professional confidentiality are two distinct obligations that happen to overlap. The ICAEW and ACCA Codes of Ethics impose confidentiality duties on all information acquired through a professional relationship, which is a broader category than personal data. Satisfying UK GDPR does not automatically satisfy your Code, and both bodies publish guidance specific to outsourcing that is worth reading before you sign the contract.
6. A breach procedure that runs at your speed
Your notification clock to the ICO starts when you become aware of a breach. If your provider investigates for a week and then sends you a tidy summary, they have used up your notification window. The agreement needs to require notification without undue delay and in a timescale that leaves you able to meet your own obligation, and the procedure should pass you facts as they emerge instead of conclusions at the end.
Questions that separate providers
- Does client data leave our systems, or do your teams work inside ours under named logins we control?
- Who specifically can see our data, and how are environments segregated between your clients?
- What is on the delivery floor: personal devices, phones, removable media, printers?
- Who are your sub-processors, and how are we notified before that changes?
- What is the breach notification timescale in the contract, in hours?
- What happens to our data when we leave, and is there a charge for its return?
A provider who answers these precisely and in writing is showing you that the controls are part of daily practice. A certificate only shows that they passed an audit on a date in the past.
On certificates
ISO 27001 certification means something: it confirms an information security management system was independently audited against a standard. It does not confirm that a specific engagement is well run, that your data stays in your systems, or that the contract protects you. Treat it as one input into your due diligence.
A provider without certification is not automatically ruled out, provided it is straightforward about that and can evidence the underlying controls. Rule out a provider that is vague about where data is processed, who can see it, or what happens when something goes wrong.
Talk it through
Bring this to a scoping call
If any of the above matches a decision you are currently making, a thirty-minute conversation will be more useful than another article. We will give you a straight view, including where we are not the right answer.
Also worth reading
More from B4ES
MTD for Income Tax has quadrupled your client contact, but not your team.
Roughly 780,000 taxpayers entered quarterly reporting in April 2026, and the threshold falls twice more before 2028. The technical work is manageable. The strain comes from the number of reporting cycles set against the size of the team.
Read SelectionHow to run an outsourcing pilot that tells you something
Most pilots are designed to succeed. The practice sends easy jobs, the provider gives them extra attention, both sides call it a success, and the real position shows up in January. A pilot can be designed to give you information you can use.
Read CommercialWhy the cheapest outsourcing quote is usually the most expensive
Headline rates in this market mean very little without context. This framework compares quotes on what you will end up paying, which is often not the figure you were quoted.
Read