Introduction

The fee is agreed, and the trial jobs came back clean. Then the proposal reaches the compliance partner’s desk, or the MLRO’s, and the questions change. Where does our clients’ data actually go? Who can see it? What do we say if a client asks, or the ICO writes to us?

That objection stalls more outsourcing decisions than price or quality ever does, and it deserves a proper answer. A self assessment file holds a UTR, a National Insurance number, bank statements, and sometimes a medical invoice. A payroll file holds the same for every employee on it.

We have supported UK practices from India for over a decade, and data protection is the first serious conversation in almost every onboarding. This article is that conversation written down: controller and processor roles under UK GDPR, what your data processing agreement must contain, how transfers to India are made lawful after the 2026 changes, and what evidence to keep. Where it helps, we describe how we run our own engagements, so you have something concrete to hold other UK accounting outsourcing companies to.

One thing first. Accounting work outsourcing from UK practices to an overseas team is lawful. UK GDPR doesn’t prohibit it; it sets conditions. What you can’t outsource is accountability.

Controller, processor, sub-processor: get the roles right first

For accounts, tax and advisory work, your practice is normally the controller of your clients’ personal data. You decide why it’s processed and how. Your outsourcing provider is a processor: it handles the data only to do the work you instruct, never for its own purposes.

Three consequences follow:

  • You must choose carefully. Article 28(1) says a controller may only use processors that give “sufficient guarantees” of appropriate technical and organisational measures. Picking the cheapest quote without checking is hard to defend.
  • The processor has its own legal duties and can face enforcement, but that never transfers your accountability to clients or the ICO.
  • Anyone the provider brings in (a cloud host, a software tool, another team) is a sub-processor and needs your prior written authorisation.

One wrinkle compliance leads often spot: on some engagements, typically payroll bureau work, your practice may itself be acting as the client’s processor. Your outsourcer then becomes a sub-processor of your client, and you need the client’s written authorisation to use it. A general authorisation in the engagement letter normally covers this.

Our own position is set out in section 5 of the Probal Global privacy policy: you’re the controller, we’re the processor, we act only on your documented instructions, and we don’t engage sub-processors without your prior written consent.

What your data processing agreement must contain

An NDA is not a data processing agreement. We sign one before any file moves, but it only deals with confidentiality. Article 28(3) of UK GDPR requires a written contract with specific terms, and the ICO’s guidance on controller–processor contracts includes a checklist. In plain English, your DPA must cover:

  1. The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of people involved (clients, their employees, directors, tenants, subcontractors).
  2. Processing only on your documented instructions.
  3. A duty of confidentiality on everyone who handles the data.
  4. Appropriate security measures under Article 32.
  5. Sub-processors only with your authorisation, on equivalent terms.
  6. Help with subject access and other data rights requests.
  7. Help with security, breach notification and data protection impact assessments.
  8. Deletion or return of all personal data at the end, at your choice.
  9. Audits, inspections and whatever information you need to show compliance.

That’s the legal minimum. Four more terms are worth adding:

  • A breach notification window in hours. The law only says “without undue delay”. You have 72 hours to report a notifiable breach to the ICO, so agree a number (many practices ask for 24 hours) and named contacts on both sides.
  • Where processing happens, by country and legal entity.
  • The transfer mechanism, with the IDTA or UK Addendum incorporated.
  • A current sub-processor list, including the software the team uses.

International transfers: India, the UK Addendum and the 2026 test

The myth we hear most, sometimes from providers themselves: “Your data never leaves the UK. Our team just logs in to your systems.” Remote access is still a restricted transfer. The ICO’s definition covers making personal data accessible to a receiver outside the UK, not only sending it, and ICAEW has made the same point to members.

India is not covered by UK adequacy regulations, so the transfer needs an Article 46 safeguard. For most practices that means one of two ICO-issued documents:

  • The International Data Transfer Agreement (IDTA): a standalone UK agreement, and the simpler route if you only handle UK data.
  • The UK Addendum: attached to the EU Standard Contractual Clauses. Useful if you already use EU SCCs, for example for Irish clients. EU SCCs on their own aren’t valid for UK transfers.

You also need a transfer risk assessment (TRA), and this is where 2026 changed things. Most of the data protection changes in the Data (Use and Access) Act 2025 took effect on 5 February 2026. The test is now whether protection for the transferred data would be “not materially lower” than in the UK, replacing the old “essentially equivalent” standard. UK law calls this the data protection test; the ICO’s updated TRA guidance still uses the TRA label.

In practice:

  • A compliant IDTA or Addendum doesn’t need re-papering because of the Act.
  • A TRA done under earlier ICO guidance doesn’t need redoing, but review it whenever something changes: a new provider, a new service line, a different access model.
  • The TRA should record what data goes, how it’s accessed, which controls apply and why the remaining risk is acceptable.

We’ll sign your preferred transfer agreement before work begins, and our own transfer impact assessment is available on request. Treat it as input to your TRA, not a replacement. The assessment belongs to you as the exporter.

Retention and deletion: two clocks

Practices get into trouble when the outsourcer quietly becomes a second archive.

Your clock. Retention decisions sit with you as controller: HMRC record-keeping periods, your PI-driven file retention policy and, for AML records, regulation 40 of the Money Laundering Regulations 2017. CDD records must be kept for five years after the business relationship ends, and the personal data then deleted unless an exception applies. HMRC’s AML guidance adds that delegating record-keeping to a third party doesn’t delegate the responsibility. For MLROs, the cleanest control is to keep CDD documents outside the outsourcer’s scope unless a specific job needs them.

The processor’s clock. Your provider should hold working copies only while the job needs them. Our standard is deletion or return within 30 days of project completion or engagement end, following your written instructions. Whoever you use, ask for written confirmation when it happens, and ask how backups are handled. Data in a backup is still data.

Watch the middle of an engagement too. A year of bank statements sitting in a downloads folder after the VAT return has been filed is a retention problem, even if nobody ever opens it.

Access, transfer and device controls

In July 2026 ICAEW reminded members that the confidentiality principle in its Code of Ethics applies inside a firm as well as outside it. That’s a useful way to treat an offshore team: inside your confidentiality circle, under the same access discipline as your own staff. Here’s what that looks like, with the relevant ISO 27001:2022 Annex A references for your IT adviser.

Role-based access

  • One named login per person. Shared credentials destroy your audit trail.
  • Access only to assigned clients, removed the day someone moves off the file.
  • Multi-factor authentication on every system.
  • The lowest software role that does the job. Someone reconciling bank feeds in Xero or QuickBooks for bookkeeping doesn’t need payroll permissions.

We assign named team members to each engagement rather than drawing from a rotating pool (more on how we work), which keeps your access list short and stable. Access is role-based, and every login to our systems and to client platforms uses MFA.

Encrypted transfer

Email attachments are where most accidental disclosures happen. Agree one channel and keep to it: your client portal, your document management system or VPN-protected remote access. We encrypt data in transit and at rest to AES-256, and client data never travels through personal email, personal WhatsApp or any other unencrypted channel.

Device controls

Our team doesn’t store client data on personal devices, client files sit in dedicated client environments, remote access runs through VPN, and we carry out regular internal security audits. When questioning any provider, the controls to ask about are A.8.1 (user endpoint devices), A.7.7 (clear desk and clear screen), A.8.12 (data leakage prevention), A.8.24 (use of cryptography), and A.8.10 (information deletion).

Be precise about certification language. “ISO 27001 aligned” means controls designed to the standard. “ISO 27001 certified” means an accredited body has audited a defined scope. Ask which you’re being offered and what it covers. Our controls are aligned to ISO 27001, and our server infrastructure is housed in ISO 27001-certified data centres.

Shared drives versus portal access

How the team reaches the data matters as much as the paperwork.

Remote access into your environment (a virtual desktop or your cloud practice software). Data stays on your infrastructure, and you keep the logs. You can switch off clipboard sharing, drive mapping, printing, and downloads at your end. It’s still a restricted transfer, but exposure is lowest. We recommend it for payroll and for clients with special category data, such as GP and dental practices.

Portal or secure file exchange. You send only what each job needs, which is data minimisation in practice. Use expiring links and view-only access for reference documents. Downloads are harder to prevent, but what was shared is easy to evidence.

Synced shared drives (OneDrive, Dropbox or Google Drive syncing to laptops). This is the model we steer practices away from. Full copies land on endpoints, folders sprawl and proving deletion becomes close to impossible. If you use Microsoft 365 or Google Workspace, ask your IT provider to give outsourced users browser-only access and block sync and downloads on their accounts.

Screenshots. Nothing technical stops a phone camera, and no honest provider will claim otherwise. What works is layering: screen-capture and clipboard restrictions in the virtual desktop where your platform supports them, clear-screen rules, and logging that makes misuse detectable. We’re happy for practices to lock our accounts down as tightly as their systems allow. The tighter the environment, the easier your TRA is to write.

What to tell clients in your engagement letter

Quiet outsourcing sits badly with UK GDPR’s transparency principle, and ICAEW’s view is that your engagement letter should reflect the possibility of an overseas transfer. ICAEW also refreshed its engagement letter templates in March 2026, including material on data protection, confidentiality and due diligence on technology providers, so it’s a good moment to update yours.

In most cases, you’re informing clients, not asking permission: the lawful basis for doing their accounts is your contract with them, not consent. Some practices still prefer an explicit opt-in. Either way, decide in advance what happens if a client objects. Usually their work simply stays in-house.

Your letter, backed by your privacy notice, should say that you use third-party providers including a team outside the UK (name the country), that they act only on your instructions under a written contract, that transfers are protected by UK-approved safeguards, that your firm remains responsible for the work, and, where relevant, that the client authorises sub-processors generally.

A short example you can adapt:

“We may use carefully selected third-party service providers, including a team based in India, to help prepare your work. They act only on our instructions under a written contract requiring confidentiality and appropriate security, and any transfer of your information outside the UK is protected by safeguards recognised under UK data protection law. We remain responsible for the work we do for you. Our privacy notice explains this in more detail.”

One more change to reflect: since 19 June 2026, individuals have a statutory right to complain to the controller first, and you must acknowledge a complaint within 30 days. Make sure your privacy notice explains how to complain, and that your DPA obliges the provider to help you investigate promptly.

How to evidence it when a client asks or the ICO enquires

An ICO enquiry turns on accountability: what you knew, when you knew it and what you did. Keep a single outsourcing file containing:

  • the signed NDA, DPA and transfer agreement, with version dates;
  • the TRA, its date and its review trigger;
  • your due diligence record: security questionnaire, policies, certificates and their scope;
  • an access register showing who can see which clients, with start and removal dates;
  • the agreed transfer channels and access model;
  • an incident log, including incidents you decided not to report and why;
  • deletion confirmations;
  • the engagement letter and privacy notice wording, and when clients received it;
  • annual review notes and your complaints record.

Most clients are satisfied by a one-page summary drawn from that file. If the ICO asks, you hand over the file itself. And the regulator does act on outsourcing security: it fined Capita £14 million in October 2025 over security failures. If it happens with your provider, the clients and the reputational damage are still yours.

Where to go from here

When comparing accounting outsourcing services, UK partners should ask every shortlisted provider for the same pack: DPA, transfer agreement, TRA, security overview, sub-processor list and a clear description of the access model. Providers who send it without fuss usually run it properly. Our resources section covers wider due diligence on offshore partners.

If you’d like to see these controls working on a real job, start with a free trial. We sign your NDA and DPA before a file moves, you choose the access model, and you can test us on bookkeeping, VAT returns, year-end accounts, or a CT600. Or talk to our team, and we’ll take your compliance partner or MLRO through our set-up.


Frequently asked questions

Yes. UK GDPR doesn’t stop you from processing personal data overseas; it sets conditions. You need a written Article 28 contract with the provider, a valid transfer safeguard (the IDTA or UK Addendum, since India isn’t covered by UK adequacy regulations), a transfer risk assessment, appropriate security and honest disclosure to clients. Buying outsourced accounting services from a UK-registered firm that uses an offshore team doesn’t remove the transfer. It only changes who signs the transfer paperwork, so check that it exists.

Is our outsourcing provider a data controller or a data processor?

Normally a processor. Your practice decides why and how client data is used, so you’re the controller, and the provider acts only on your instructions. If a provider used the data for its own purposes, it would become a controller for that use, which your contract should prohibit. Where your practice is itself the client’s processor (payroll bureau work, for example), the outsourcer is a sub-processor.

Usually not as a lawful basis. You process client data to perform your contract and meet legal obligations, so consent isn’t the basis. What you do need is transparency: tell clients in your engagement letter and privacy notice that you use third-party providers, including overseas, and how their data is protected. Where you act as the client’s processor, you need their written authorisation to use a sub-processor.

What must a data processing agreement include under UK GDPR?

The processing details (subject matter, duration, purpose, data types, categories of people), processing only on your documented instructions, staff confidentiality, Article 32 security, controls on sub-processors, help with data rights requests, breaches and DPIAs, deletion or return at the end, and audit rights. In practice, also add a breach notification deadline in hours, the processing locations, the transfer mechanism, and a sub-processor list.

Is an NDA enough on its own?

No. An NDA covers confidentiality but not the Article 28 terms or the international transfer. You need three things, which are often combined in one document: confidentiality, a compliant DPA, and a transfer safeguard such as the IDTA or UK Addendum.

Does India have UK adequacy status?

Not at the time of writing, so transfers to India need an Article 46 safeguard plus a transfer risk assessment. The Secretary of State can make new adequacy regulations (sometimes called data bridges), so check the government’s current list before relying on this.

What’s the difference between the IDTA and the UK Addendum?

Both are standard clauses issued by the ICO. The IDTA is a standalone UK agreement and suits practices that only handle UK data. The UK Addendum is attached to the EU Standard Contractual Clauses and suits firms that already use EU SCCs, for example with Irish clients. EU SCCs alone aren’t valid for UK transfers.

If the offshore team only logs in to our UK systems, is that still an international transfer?

Yes. The ICO treats making personal data accessible to someone outside the UK as a restricted transfer, even if the data stays on UK servers. Remote access usually lowers the risk, which helps your TRA, but it doesn’t remove the need for a safeguard.

What is a transfer risk assessment, and did it change in 2026?

A TRA is your documented assessment that transferred data will stay adequately protected. Since 5 February 2026, under the Data (Use and Access) Act 2025, the test is whether protection is “not materially lower” than in the UK, replacing “essentially equivalent”. TRAs completed under earlier ICO guidance don’t need redoing, but review yours when your provider, services, or access model change.

Who is responsible if the outsourcing provider has a data breach?

You remain accountable as controller. You assess the breach and, if it’s likely to put individuals at risk, report it to the ICO within 72 hours of becoming aware, and tell affected individuals if the risk is high. The processor must notify you without undue delay and can be liable for its own failings. It’s also worth confirming your PI insurer knows you outsource.

How quickly should a provider tell us about a breach?

The law says “without undue delay”. That’s too vague when your own ICO clock is 72 hours, so put a specific window in the DPA (many practices ask for 24 hours), with named contacts and a list of the information the provider must give you.

How long should an outsourcing provider keep our clients’ data?

Only as long as each job needs; then it should be returned or deleted on your instructions. Our standard is deletion or return within 30 days of project completion or engagement end. Your own retention obligations, such as HMRC record periods and five years for MLR customer due diligence records, stay with your practice.

How does outsourcing affect our AML and MLR obligations?

It doesn’t transfer them. Keep CDD records under your control; Regulation 40 requires them to be kept for five years after the relationship ends and then deleted unless an exception applies. Agree how the offshore team flags anything unusual: to your MLRO, never to the client. If a provider helps with ID checks, for example on company secretarial work, the CDD decision and records are still yours.

What should our engagement letter say about outsourcing?

That you use third-party providers, including a team outside the UK (name the country), that they act only on your instructions under a written contract, that transfers are protected by UK-approved safeguards, and that your firm remains responsible. Include a general sub-processor authorisation where you act as the client’s processor, and point to your privacy notice for detail.

Can outsourced staff use personal laptops or work from home?

Ask every provider directly and write the answer into your TRA. Our team doesn’t store client data on personal devices, and access runs through a VPN with multi-factor authentication. Whatever the model, insist that client data is only reached from managed, secured devices.

Does an outsourcing provider need ISO 27001 certification?

It isn’t a legal requirement. UK GDPR requires appropriate security, and the ICO treats compliance with recognised industry standards as one sign of “sufficient guarantees”. Know the difference: “aligned” means controls built to the standard, while “certified” means an accredited audit of a defined scope. Ask which applies and what the scope covers.

How can we stop the offshore team downloading or screenshotting client data?

Use layers. Give access through a virtual desktop or your cloud software with clipboard, printing, and downloads switched off where your platform allows. Avoid synced shared drives, use browser-only access on Microsoft 365 or Google Workspace, and keep logging on. Nothing stops a phone camera, so clear-screen rules and monitoring matter too.

Do we need a DPIA before outsourcing?

A DPIA is mandatory where processing is likely to result in high risk. Routine outsourcing of accounts work won’t always meet that threshold, but if you’re sending large volumes of special category data, such as healthcare payrolls, a DPIA is sensible. Either way, your TRA and due diligence file should record the risks and controls.

What does India’s own data protection law mean for UK client data?

India’s Digital Personal Data Protection Act 2023 and its 2025 Rules are being phased in over 18 months from November 2025. The Act largely exempts processing of data about people outside India carried out under a contract with a foreign business, although the duty to keep reasonable security safeguards still applies. Your clients’ protection rests mainly on UK GDPR, your DPA and your transfer agreement.

Has the Data (Use and Access) Act changed anything for practices that outsource?

Two things matter most. From 5 February 2026, the transfer test became “not materially lower” rather than “essentially equivalent”. From 19 June 2026, individuals can complain to the controller first, and you must acknowledge complaints within 30 days. Existing compliant IDTAs and Addendums don’t need re-signing.

What will the ICO ask for if it looks into our outsourcing?

Expect questions on accountability: the signed DPA and transfer agreement, your TRA, due diligence records, who had access to what, how data moved, your incident log, deletion evidence, and what you told clients. Keeping these in one outsourcing file makes the answer straightforward.

Which work should we outsource first if data security is the main worry?

Start with work that carries less personal data, such as bookkeeping, VAT returns or year-end accounts for limited companies, prove the controls, then extend to payroll and self assessment. Our services page shows the full range.

What should we ask UK accounting outsourcing companies before signing?

Ask for their DPA, transfer agreement, TRA, security overview, certificates and scope, sub-processor list, breach process, deletion process and access model, plus references from UK practices. See how we answer those questions on our About Us and privacy policy pages, or ask us for the full pack.

Need help outsourcing this to a specialist team?

We handle bookkeeping, VAT, payroll, and year end accounts for UK accounting firms from India. Start with a free trial. No commitment required.

Start Free Trial+918866157880

More articles

How Large Accounting Firms Structure Offshore Delivery, and What Smaller Practices Can Copy
Accounting

How Large Accounting Firms Structure Offshore Delivery, and What Smaller Practices Can Copy

28 Sept 2026 · 13 min read

CIS deduction statements
Accounting

CIS Deduction Statements: What They Must Show and the 14-Day Rule

25 Sept 2026 · 16 min read

White Label Dental Bookkeeping UK
Accounting

White Label Bookkeeping and Monthly Management Accounts for UDA-Based Dental Practices

25 Sept 2026 · 26 min read