muckin Client login Talk to us
What we doHow it worksPricingCalculatorGuidesCompareAboutContactClient loginTalk to us
Guide

Data security, GDPR and confidentiality when you outsource

Controller and processor roles, what a data-processing agreement must cover, transfers, access controls, and ten questions to ask a provider.

22 August 20267 minute readWritten by people who run a practice
  • Your practice is the controller of client data. An outsourcer processing it on your instructions is a processor. That relationship needs a written agreement.
  • Transfers outside the UK are allowed under UK GDPR but only on a lawful basis. Check the current position on ico.org.uk; do not rely on what a provider tells you.
  • Individual logins, multi-factor authentication and least-privilege access in your own software. No shared credentials, no data on personal devices, no WhatsApp.
  • Keep the audit trail in your own systems, so offboarding is removing a user, not recovering a database.
  • Your professional body has its own confidentiality rules on top of the law. Read them.

The legal shape of it

Under UK GDPR, the organisation that decides why and how personal data is processed is the controller. The organisation that processes it on the controller's behalf, under instruction, is the processor. When your practice sends client records to an outsourced team, you are the controller and they are the processor. Your clients' employees, customers and suppliers are the data subjects, and most of them have no idea any of this is happening.

That matters for two reasons. First, the law requires a written contract between controller and processor containing specific terms, and the Information Commissioner's Office sets out what those are. Second, the responsibility for the data does not leave with it. If your processor loses it, the question comes to you. The ICO publishes guidance on controller and processor obligations; read the current version rather than relying on this guide, because it gets updated.

We are not lawyers and this is not legal advice. It is a practice owner's checklist of what to look for, and a description of what we do.

What a data-processing agreement should cover

Any provider worth using will have one ready and will expect you to read it. At minimum it should set out:

  • Subject matter and duration. What data, for what purpose, for how long.
  • Nature and purpose of processing. Bookkeeping, accounts preparation, payroll, and nothing else.
  • Types of personal data and categories of data subject. Client employees, customers, suppliers, directors. Payroll data is more sensitive than a sales ledger and the agreement should say so.
  • Processing only on documented instructions. The processor does what you tell it and nothing else with the data.
  • Confidentiality commitments from every person with access. Employees, not just the company.
  • Security measures. Described specifically, not "industry-standard security".
  • Sub-processors. Whether the provider uses any, who they are, and your right to object. A provider that subcontracts to freelancers you have never heard of is a sub-processor problem before it is anything else.
  • Assistance with data subject rights and breach notification. Who tells whom, how fast, in what form.
  • Deletion or return at the end. What happens to any data the processor holds when you leave.
  • Audit and inspection rights. You are entitled to check. Whether you ever do is your choice.
  • International transfer mechanism. See below.

If a provider cannot produce this, or produces one that is a page long and mentions none of the above, that tells you what you need to know.

International transfers

Most outsourced accounting work for UK practices is delivered from outside the UK. Ours is, from our own office in Pretoria. That is a restricted transfer under UK GDPR and it needs a lawful basis.

The mechanisms available depend on the country and on the current UK rules: adequacy regulations for some countries, and for others the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, plus a transfer risk assessment. We are deliberately not telling you which applies to South Africa, India or the Philippines today, because the lists and the tools change. Check the ICO's current guidance on international transfers and satisfy yourself, rather than taking a provider's word for it, including ours.

What you can insist on from any provider:

  • They name the country where the work is done and where any data is stored.
  • They tell you the transfer mechanism they rely on and give you the paperwork.
  • They confirm whether the data leaves your systems at all. The best answer is that it does not: the work is done inside your software, in your UK tenancy, by a person logging in from abroad. That does not make the transfer disappear, but it changes the risk picture materially and it is the model we use.

Access controls that actually work

The agreement is paper. These are the things that stop data walking out.

Individual logins, never shared credentials

Every person who touches your software has their own named user. Not "outsourcing@yourpractice.co.uk" with a password in a shared document. If a provider asks for your master login, say no and ask why they do not have a better answer.

Multi-factor authentication, everywhere

Xero, QuickBooks, Sage, FreeAgent, BrightPay, your practice management system, your email: all support it, all of it on. A provider that cannot commit to MFA on every account is not taking this seriously.

Least privilege

A bookkeeper does not need to see payroll. A payroll processor does not need to change bank feed settings. An accounts preparer does not need practice-wide admin. Every platform has roles. Use the narrowest one that lets the work get done, and review the list quarterly.

Work in your software, not theirs

If the provider wants you to upload client files to their portal, the data has left your control and you are now relying on their security for everything. If the work is done inside your own Xero, your own payroll platform, your own document system, the data has not moved and the audit trail is yours. This is how Muckin works, and it is the main reason we built it that way. See how it works.

No personal devices, no consumer messaging

Provider-managed devices only. No client data on a personal laptop or phone. No payroll queries over WhatsApp, no bank statements on a personal email. It is convenient and it is how breaches happen. Our team works from managed machines in our own office; nobody works from a kitchen table with a family laptop.

Audit trail stays in the practice

Because the work is in your systems, every change is logged against a named user in software you control. If something goes wrong you can see who did what and when, without asking anybody's permission.

Offboarding

When a person leaves the provider or the arrangement ends, their access is removed the same day. Because the data never left your tenancy, offboarding is deleting a user, not chasing a copy of your client database. Ask any provider what happens on their side when someone leaves. The answer should be immediate and specific.

Ten questions to ask a provider

  1. Are the people doing the work your employees, or subcontractors and freelancers?
  2. In which country is the work done, and where is any data stored?
  3. What is your international transfer mechanism, and can you send me the documents?
  4. Will the work be done inside my software, or do I send files to you?
  5. Does every person get an individual login, and is MFA mandatory?
  6. What devices does your team use, and who manages them?
  7. Do you use any sub-processors? Name them.
  8. What is your breach notification process, and how fast?
  9. What happens to access and data when a team member leaves, or when I leave?
  10. Can I see your data-processing agreement before I sign anything else?

A good provider answers all ten without hesitation. A weak one gets vague at question three.

Your professional body's rules

UK GDPR is the floor. If you are regulated by ICAEW, ACCA, AAT, CIMA, CIOT or another body, you also have professional confidentiality obligations and, in most cases, specific rules about using outsourced service providers: telling clients, keeping responsibility, supervising the work. These differ between bodies and get updated, so check your own body's current guidance rather than relying on a summary here. The usual themes are that you remain responsible for the work, you should be transparent with clients about outsourcing, and you must have satisfied yourself about confidentiality. Anti-money-laundering supervision adds its own record-keeping requirements on top.

One practical point: your letter of engagement should say that you may use third-party providers to deliver the work, and say where. If it does not, update it before you outsource.

What this looks like at Muckin

Our team are employees in our own Pretoria office. They work inside your software under individual logins with MFA, on managed devices, with access scoped to the job. Nothing is downloaded to our systems. Every job is reviewed and signed off in the UK before it reaches you. We provide a data-processing agreement and the transfer documentation before any access is set up, and we expect you to read both. Pricing is on the pricing page; the security arrangements are the same on every seat, from a part-time Accounts seat to a full-time senior.

Where to start

Work out how much you are likely to outsource with the capacity calculator, then read the ICO guidance linked above and your professional body's outsourcing rules. When you are ready, contact us and ask for the data-processing agreement first. We would rather you read it before we talk about anything else. We muck in, but not with your clients' data on somebody's phone.

Published 22 August 2026. Tax rules and rates change โ€” check current figures on gov.uk before relying on anything here. This is general information for practice owners, not advice.

Questions

Straight answers.

Am I the data controller if I outsource bookkeeping?

Yes. Your practice decides why and how client data is processed, so you are the controller and the outsourcer is a processor acting on your instructions. You remain responsible for the data.

Is it legal to send client data to a team outside the UK?

It can be, provided there is a lawful transfer mechanism in place under UK GDPR. Check the current adequacy and transfer-tool position on ico.org.uk rather than relying on a provider's assurance.

Should an outsourcer have their own login to my software?

Every individual should have their own named login with multi-factor authentication and the narrowest role that lets them do the job. Never share your master credentials.

Also worth reading

More like this.

Ready for a team that mucks in?

Tell us what's piling up. We'll come back within one working day with who we'd put on it and what it costs.