Controller and processor roles, what a data-processing agreement must cover, transfers, access controls, and ten questions to ask a provider.
Under UK GDPR, the organisation that decides why and how personal data is processed is the controller. The organisation that processes it on the controller's behalf, under instruction, is the processor. When your practice sends client records to an outsourced team, you are the controller and they are the processor. Your clients' employees, customers and suppliers are the data subjects, and most of them have no idea any of this is happening.
That matters for two reasons. First, the law requires a written contract between controller and processor containing specific terms, and the Information Commissioner's Office sets out what those are. Second, the responsibility for the data does not leave with it. If your processor loses it, the question comes to you. The ICO publishes guidance on controller and processor obligations; read the current version rather than relying on this guide, because it gets updated.
We are not lawyers and this is not legal advice. It is a practice owner's checklist of what to look for, and a description of what we do.
Any provider worth using will have one ready and will expect you to read it. At minimum it should set out:
If a provider cannot produce this, or produces one that is a page long and mentions none of the above, that tells you what you need to know.
Most outsourced accounting work for UK practices is delivered from outside the UK. Ours is, from our own office in Pretoria. That is a restricted transfer under UK GDPR and it needs a lawful basis.
The mechanisms available depend on the country and on the current UK rules: adequacy regulations for some countries, and for others the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, plus a transfer risk assessment. We are deliberately not telling you which applies to South Africa, India or the Philippines today, because the lists and the tools change. Check the ICO's current guidance on international transfers and satisfy yourself, rather than taking a provider's word for it, including ours.
What you can insist on from any provider:
The agreement is paper. These are the things that stop data walking out.
Every person who touches your software has their own named user. Not "outsourcing@yourpractice.co.uk" with a password in a shared document. If a provider asks for your master login, say no and ask why they do not have a better answer.
Xero, QuickBooks, Sage, FreeAgent, BrightPay, your practice management system, your email: all support it, all of it on. A provider that cannot commit to MFA on every account is not taking this seriously.
A bookkeeper does not need to see payroll. A payroll processor does not need to change bank feed settings. An accounts preparer does not need practice-wide admin. Every platform has roles. Use the narrowest one that lets the work get done, and review the list quarterly.
If the provider wants you to upload client files to their portal, the data has left your control and you are now relying on their security for everything. If the work is done inside your own Xero, your own payroll platform, your own document system, the data has not moved and the audit trail is yours. This is how Muckin works, and it is the main reason we built it that way. See how it works.
Provider-managed devices only. No client data on a personal laptop or phone. No payroll queries over WhatsApp, no bank statements on a personal email. It is convenient and it is how breaches happen. Our team works from managed machines in our own office; nobody works from a kitchen table with a family laptop.
Because the work is in your systems, every change is logged against a named user in software you control. If something goes wrong you can see who did what and when, without asking anybody's permission.
When a person leaves the provider or the arrangement ends, their access is removed the same day. Because the data never left your tenancy, offboarding is deleting a user, not chasing a copy of your client database. Ask any provider what happens on their side when someone leaves. The answer should be immediate and specific.
A good provider answers all ten without hesitation. A weak one gets vague at question three.
UK GDPR is the floor. If you are regulated by ICAEW, ACCA, AAT, CIMA, CIOT or another body, you also have professional confidentiality obligations and, in most cases, specific rules about using outsourced service providers: telling clients, keeping responsibility, supervising the work. These differ between bodies and get updated, so check your own body's current guidance rather than relying on a summary here. The usual themes are that you remain responsible for the work, you should be transparent with clients about outsourcing, and you must have satisfied yourself about confidentiality. Anti-money-laundering supervision adds its own record-keeping requirements on top.
One practical point: your letter of engagement should say that you may use third-party providers to deliver the work, and say where. If it does not, update it before you outsource.
Our team are employees in our own Pretoria office. They work inside your software under individual logins with MFA, on managed devices, with access scoped to the job. Nothing is downloaded to our systems. Every job is reviewed and signed off in the UK before it reaches you. We provide a data-processing agreement and the transfer documentation before any access is set up, and we expect you to read both. Pricing is on the pricing page; the security arrangements are the same on every seat, from a part-time Accounts seat to a full-time senior.
Work out how much you are likely to outsource with the capacity calculator, then read the ICO guidance linked above and your professional body's outsourcing rules. When you are ready, contact us and ask for the data-processing agreement first. We would rather you read it before we talk about anything else. We muck in, but not with your clients' data on somebody's phone.
Published 22 August 2026. Tax rules and rates change โ check current figures on gov.uk before relying on anything here. This is general information for practice owners, not advice.
Yes. Your practice decides why and how client data is processed, so you are the controller and the outsourcer is a processor acting on your instructions. You remain responsible for the data.
It can be, provided there is a lawful transfer mechanism in place under UK GDPR. Check the current adequacy and transfer-tool position on ico.org.uk rather than relying on a provider's assurance.
Every individual should have their own named login with multi-factor authentication and the narrowest role that lets them do the job. Never share your master credentials.
Why most practice websites produce no enquiries, what to publish instead, a 12-month plan, and how to get it done without the partner writing it.
Read itWhat UK practices outsource, the four models, where the work is done, what each costs, and how to start without betting the firm.
Read itThe all-in cost of a part-qualified, built up line by line from salary to cost per productive hour, and set against a dedicated seat.
Read itTell us what's piling up. We'll come back within one working day with who we'd put on it and what it costs.