Preparing your firm for the introduction of new data protection regulations

23 Apr 2018

On 25 May 2018, the new General Data Protection Regulation (GDPR) will come into effect. A lack of knowledge will not be deemed an acceptable excuse for not having safeguards in place.

The GDPR replaces the existing Data Protection Act (DPA) 1998, and governs how individuals’ personal data is managed. It applies to all businesses in the EU. Even though the UK will be leaving the EU, it will not affect the commencement of the GDPR, which is set to be placed into UK law post-Brexit.

The GDPR is needed due to developments in internet and cloud technologies. There are now many ways to collect and store personal data. New measures are therefore required to ensure personal data is kept safe, and is only kept for legitimate purposes. All businesses, small and large will be required to comply with the GDPR.

There are several key areas that you need to be aware of based on the fundamental principles of the GDPR.

The GDPR places a strong emphasis on accountability and transparency, and holds businesses accountable for safeguarding the collection, usage and storage of a client’s personal data. If you use third party software such as payroll and accounts packages, you will need to ensure these are listed and that the systems are GDPR compliant.

Accountants who are already compliant with the DPA will need to supply evidence of their compliance with the new GDPR. Firms are required to identify a lawful basis for processing clients’ personal data: this must be processed fairly and accurately, and be kept in a form which permits the identification of data subjects for no longer than is necessary.

You will need to ensure that your members of staff are aware of the new GDPR rules, and that you provide them with thorough training ahead of the 25 May introduction date. You may wish to assign a Data Protection Officer – however, this will be a requirement in specific cases. 

Making use of adequate procedures to prevent data breaches

Finally, accountants are advised to make sure that they have detailed procedures in place to detect, report and investigate a personal data breach. Certain types of data breach will need to be reported to the Information Commissioner’s Office (ICO). You may wish to create new policies for your staff members to follow in the event of a data breach, and ensure that these are communicated to your employees well in advance of the GDPR implementation date.

Penalties for non-compliance

Failing to prevent a data breach can result in fines of up to 4% of total annual worldwide revenue, or up to €20 million, whichever is the greater.

Further guidance in relation to complying with the GDPR requirements can be found on the ICO website.

How we can help

Our GDPR email product will help make sure you are prepared for the introduction of the new regulation. We will:

  1. Email all of your contacts on your behalf, encouraging them to opt-in to receive further communications from you
  2. Provide information within the email which details the requirement
  3. Create a form and system that collects your contact responses
  4. Supply you with a record of contacts who have not responded/opted-in to your emails
  5. Remove all contacts who have unsubscribed
  6. Clean your website contacts data on your approval to make you compliant

To find out more about our GDPR email service, please call 0800 181 343, or email

To place an order, please visit

View more posts from our archive