Industry GDPR documentation

Written and maintained by Chris Haycock, GDPRQuick.com/CliqTo Ltd
Last reviewed Not yet reviewed


GDPR for accountants & bookkeepers

Accountants and bookkeepers hold some of the most detailed personal data a small business can collect: payroll records, tax references, bank details, identity documents, director information, self-assessment records, invoices, bookkeeping entries, AML checks, and correspondence with HMRC. This page explains the GDPR decisions your practice needs to document, and how GDPRQuick turns those answers into practical records.

Let's begin.

What personal data accountants and bookkeepers handle

Accountancy records are not just business data. A sole trader's accounts, a director's loan account, a payroll file, or an AML identity check can all contain personal data.

Typical personal data in an accountancy or bookkeeping practice includes:

  • Client contact details, addresses, tax references, and Companies House information
  • Payroll records, salary details, pensions, benefits, sickness, and statutory pay records
  • Self-assessment information, dividends, director records, and partner details
  • Bank details, invoices, receipts, bookkeeping entries, and expense claims
  • Identity documents, proof of address, and AML verification checks
  • Correspondence with HMRC, Companies House, banks, lenders, and software providers
  • Staff records for your own practice, including contracts, pay, appraisals, and leave records

Your GDPR documentation should explain what data is collected for each service line, where it comes from, which systems hold it, and how long it is retained.

Lawful basis for tax, payroll and bookkeeping work

Most accounting work is not based on consent. Clients ask you to provide a professional service, but payroll, tax, bookkeeping, company filing, and statutory reporting usually rely on contract, legal obligation, legitimate interests, or a combination of those bases.

The key is to document the decision clearly. Payroll processing may be necessary for contract and legal obligation. Tax return preparation may involve contract and legal obligation. Practice administration, conflict checks, and professional file keeping may rely on legitimate interests.

Why consent can be the wrong answer

If a client withdraws consent, you may still need to keep records to comply with tax, AML, limitation, insurance, or professional body requirements. That is why consent is usually a poor fit as the main lawful basis for ordinary accountancy services.

Payroll data needs extra care

Payroll data is detailed and often sensitive in context. It may include salary, tax code, National Insurance number, pension contributions, student loan deductions, statutory sick pay, maternity pay, court orders, and bank details.

If you process payroll for clients, your documentation should explain whether you act as a processor for the employer, what payroll data you receive, who has access, how payslips are delivered, and how long records are kept.

  • Control access to payroll files and reports
  • Use secure channels for payslips, bank details, and payroll changes
  • Document how payroll data is transferred to HMRC, pension providers, and payment systems
  • Separate your own staff payroll records from client payroll records

Not sure what applies to your accountants & bookkeepers?

Take the quick risk check before you get too deep into the detail.

Take the 2-minute check

AML checks and identity documents

Anti-money laundering checks are a normal part of accountancy practice, but they create a specific GDPR issue: you may need to collect identity documents and proof of address, then retain them because AML rules require it.

Your privacy information should explain why these checks are needed, what documents may be collected, who verifies them, which third-party verification providers are used, and how long evidence is retained.

Keep AML evidence controlled

Identity documents should not be left in general email folders or open client files forever. They should be stored deliberately, accessed only by people who need them, and deleted when the retention period has expired.

Client portals, cloud bookkeeping and software suppliers

Modern practices rely on Xero, QuickBooks, Sage, FreeAgent, Dext, Hubdoc, payroll platforms, client portals, e-signature tools, cloud storage, email, and practice management systems. These tools may all process client personal data.

Your GDPR records should list the categories of suppliers you use, what data each one handles, where the data is stored, and whether appropriate processor terms or data processing agreements are in place.

  • Bookkeeping and accounts production software
  • Payroll, pension, and auto-enrolment systems
  • AML verification providers
  • Client portals and document signing tools
  • Cloud storage, email, backup, and IT support providers

Retention periods for accountancy records

Accountants and bookkeepers often have strong reasons to keep records for several years: tax rules, AML obligations, limitation periods, insurance requirements, professional body expectations, and client service history.

GDPR does not ban long retention, but it does require a clear reason. Your retention policy should distinguish between tax records, payroll files, AML evidence, working papers, correspondence, quotes, inactive prospects, and your own practice records.

Retention should not mean keeping everything forever

A good policy explains what is kept, why, for how long, and what happens when the retention period ends. It should also cover backups and archived client systems, because old data can otherwise sit forgotten for years.

Subject access requests and client files

Clients, employees of client businesses, and your own staff may have rights to access personal data. In an accountancy context this can be awkward because records may mix company information, personal data, third-party data, professional notes, and legally privileged or confidential material.

Your process should explain who handles requests, where searches are performed, how third-party information is reviewed, and how deadlines are tracked.

  • Search email, document management, payroll systems, bookkeeping software, and practice management systems
  • Review whether information about other people needs to be redacted
  • Keep a record of the request, search steps, response, and decision
  • Avoid treating every client file as automatically disclosable without review

Data breaches in an accountancy practice

A breach in an accountancy practice might be a payroll report sent to the wrong employer, bank details emailed to the wrong client, a laptop containing client files stolen, a compromised email account, or an incorrect portal permission exposing documents.

Because accountancy records can contain financial and identity data, breach assessment needs to be calm, quick, and documented.

Have a written breach plan before it happens

The plan should say who investigates, how access is contained, how clients are told, how the ICO reporting threshold is assessed, and how the internal breach record is completed even if the incident is not reportable.

What GDPR documents does an accountancy practice need

A practical GDPR pack for accountants and bookkeepers should reflect the real flow of client and payroll data through the practice.

  • A privacy notice covering clients, client employees, prospects, suppliers, and practice staff
  • A Record of Processing Activities for tax, payroll, bookkeeping, AML, marketing, practice administration, and staff data
  • A processor list covering software, portals, IT support, payroll tools, AML providers, and cloud storage
  • A retention policy for tax records, payroll records, AML evidence, working papers, and inactive clients
  • A breach response process for misdirected emails, portal access issues, device loss, and supplier incidents
  • A subject access request process for mixed client files and payroll records
  • A lawful basis record for each service line and practice activity

The documents should be specific to the services the practice actually provides. A bookkeeping-only practice should not need the same wording as a larger firm handling audit, payroll, tax, advisory, and company secretarial work.

Build your accountancy GDPR documents from your own answers

GDPRQuick guides you through questions about your practice: what services you provide, what systems you use, whether you process payroll, how you handle AML checks, where client files are stored, and how long records are kept.

Your answers become the wording for your GDPR statement, processing records, action plan, and supporting forms. You can update the documents later when you add a service, change software, or alter your retention policy.

GDPRQuick.com UI Platform Screenshot

Check your GDPR risk first.

Use the GDPRQuick risk calculator to get an indicative view of where your accountants & bookkeepers data protection work may need attention.

Start the risk calculator

Questions about GDPR for accountants & bookkeepers

Do accountants need GDPR documentation?

Most accountancy and bookkeeping practices should keep GDPR documentation because they handle client, payroll, tax, identity, supplier, and staff data regularly.

Is client tax information personal data?

It can be. Information about sole traders, directors, partners, employees, and individuals in payroll or tax records can identify people and should be treated as personal data.

Can accountants keep client records for several years?

Yes, where there is a clear tax, AML, contractual, professional, insurance, or limitation reason. The period should be documented and followed.

Are accountants controllers or processors?

It depends on the activity. A practice may be an independent controller for tax advice and professional file keeping, while acting as a processor for some client payroll or bookkeeping tasks.

Do AML checks need to be mentioned in a privacy notice?

Yes. Clients should understand that identity and verification information may be collected and retained to meet anti-money laundering obligations.

What if payroll data is sent to the wrong person?

That is a personal data breach in principle. The practice should contain it, assess the risk, record the incident, and decide whether it must be reported to the ICO or affected people.

Do cloud accounting platforms make GDPR the supplier's problem?

No. Software providers may be processors, but the practice still needs to choose appropriate suppliers, understand what data is handled, and document its own responsibilities.

Can a client ask for all data in their file?

They can make a subject access request for their personal data, but mixed client files may need careful review because they can include company data, third-party data, confidential information, and professional notes.

Is GDPRQuick a replacement for legal advice?

No. GDPRQuick helps you create and maintain practical documentation. It does not certify compliance, and your organisation remains responsible for its own policies, processes, security measures, and legal decisions.