In brief: When a UK accountancy practice sends client books to a bookkeeping team in India, the practice remains the controller and the Indian firm acts as its processor. UK GDPR then asks for two things: an Article 28 processor contract, and a lawful mechanism for a restricted transfer to India — because India has no UK adequacy regulations. In practice that means the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, supported by a transfer risk assessment (TRA).
Many UK practices now use offshore capacity for bookkeeping, VAT workings and year-end preparation (see our note on the UK accountancy staffing gap). The commercial case is usually straightforward. The data protection paperwork is where engagements are often thin. This guide sets out what UK GDPR requires, in the order a practice owner would deal with it.
1. Who is the controller and who is the processor?
Your practice decides why client data is processed (to deliver accounts, returns and advice) and how the work is done. That makes the practice the controller. An Indian bookkeeping firm that posts transactions, reconciles bank accounts and prepares draft workings strictly on your instructions is a processor. It does not use the data for its own purposes.
The controller stays accountable to the client and to the Information Commissioner's Office (ICO). Outsourcing the work does not outsource the responsibility.
2. The Article 28 contract — compulsory terms
Article 28(3) UK GDPR requires a written contract between controller and processor. The ICO's guidance lists the terms it must contain:
| Term | What it means for an offshore bookkeeping engagement |
|---|---|
| Documented instructions | The processor acts only on your written instructions, including on any onward international transfer. |
| Confidentiality | Every staff member with access is bound by a duty of confidence. |
| Security (Article 32) | Appropriate technical and organisational measures — access control, MFA, encryption, device policy. |
| Sub-processors | No sub-processor without your prior specific or general written authorisation; equivalent obligations flow down. |
| Data subject rights | The processor helps you respond to access, rectification and erasure requests. |
| Assisting the controller | Help with security, breach notification, DPIAs and any prior consultation with the ICO. |
| End of contract | Delete or return all data at your choice, and delete existing copies unless law requires retention. |
| Audits and information | Make available all information needed to show compliance and allow audits by you or your appointed auditor. |
The ICO also expects the contract to state the subject matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects, and the controller's obligations and rights.
3. Why a transfer to India is a "restricted transfer"
Sending personal data from the UK to a recipient outside the UK — or giving an overseas team remote access to it — is a restricted transfer. Every restricted transfer needs a transfer mechanism.
The simplest mechanism is UK adequacy regulations. The UK Government's published list covers the EU/EEA states and a short list of others (including Japan, the Republic of Korea, Canada (partial) and the US under the Data Privacy Framework extension). India is not on that list. A UK practice therefore has to rely on an appropriate safeguard under Article 46.
4. IDTA or UK Addendum?
Both were issued by the ICO under section 119A of the Data Protection Act 2018 and came into force on 21 March 2022.
- IDTA — a standalone UK agreement. Usually the cleaner choice where the arrangement is UK practice to Indian processor only.
- UK Addendum — attached to the EU Standard Contractual Clauses. Useful where the Indian firm already signs EU SCCs for EU clients and one combined document is preferable.
Either way, the tables in the agreement must reflect the actual arrangement: parties, data categories, security measures, and the sub-processors in use.
5. The transfer risk assessment (TRA)
The ICO's guidance is direct: if you rely on a safeguard such as the IDTA, you must also complete a TRA. The TRA considers whether the protection given by UK GDPR is undermined in the destination — looking at the type and sensitivity of the data, the local legal framework (for India, including the Digital Personal Data Protection Act, 2023 and law-enforcement access powers), and the practical safeguards in place. Follow the ICO's TRA guidance; record the conclusion and revisit it when the arrangement changes.
Practical safeguards that usually strengthen a TRA for bookkeeping work:
- Data stays in your UK-hosted cloud ledger (Xero, QuickBooks, Sage); the Indian team works through named, MFA-protected user logins, with no local downloads.
- Data minimisation — no client passports, payroll bank details or special category data unless the task needs them.
- Role-based access, logged and reviewed; prompt removal of leavers.
- Encrypted file exchange instead of email attachments.
6. Sub-processors
Ask for a written list of every sub-processor the Indian firm uses — practice management tools, document portals, email and cloud storage providers. Each one must be authorised by you and bound by equivalent obligations, and the processor remains liable to you for their compliance. Under a general authorisation, the processor must notify you of changes and give you a chance to object.
7. Breach notification
Under Article 33(2), the processor must notify the controller without undue delay after becoming aware of a personal data breach. The controller then reports a notifiable breach to the ICO within 72 hours of becoming aware of it (Article 33(1)), and informs affected individuals where the breach is likely to result in a high risk to them. Contracts typically set a fixed internal window (for example, 24 hours) so your 72-hour clock is workable.
8. The Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 (c. 18) amends the UK's international transfer rules — section 85 and Schedule 7 replace the transfer provisions, including a new Article 44A on transfers approved by regulations and new provisions on transfers subject to appropriate safeguards. Existing IDTAs and Addenda remain the working tools for India transfers. Check the commencement status and the ICO's updated guidance before re-papering an arrangement.
9. Professional confidentiality
Data protection sits alongside professional duties. The ICAEW and ACCA codes of ethics both carry a fundamental principle of confidentiality, and member firms using outsourced providers remain responsible for the work and for protecting client information. Many practices also inform clients in their engagement letter or privacy notice that work may be carried out by an overseas service provider.
Practical checklist for UK practices
| # | Action |
|---|---|
| 1 | Record the controller–processor roles in your records of processing. |
| 2 | Sign an Article 28 data processing agreement with all compulsory terms. |
| 3 | Sign the IDTA (or UK Addendum with EU SCCs) and complete its tables. |
| 4 | Complete and file a TRA; diarise an annual review. |
| 5 | Obtain and approve the sub-processor list. |
| 6 | Agree a breach-notification window and contact route. |
| 7 | Review access controls: named logins, MFA, no local storage. |
| 8 | Update client engagement letters and privacy notices. |
| 9 | Agree deletion/return of data at exit, with written confirmation. |
Frequently asked questions
Is remote access from India a transfer even if data stays on UK servers?
Yes. The ICO treats making personal data accessible to a recipient outside the UK as a restricted transfer, so a transfer mechanism is still needed.
Does India have UK adequacy?
No. India is not on the UK Government's list of adequacy regulations, so the IDTA or UK Addendum is normally used.
Is a transfer risk assessment mandatory?
Where you rely on a safeguard such as the IDTA, the ICO says you must also complete a TRA.
Who reports a breach to the ICO?
The UK practice, as controller, within 72 hours of becoming aware. The Indian processor must notify the practice without undue delay.
Somesh Chandak & Associates provides outsourced bookkeeping and accounting support to accounting firms outside India, working under the client firm's data processing and transfer terms. Scope and process are set out on the outsourced bookkeeping and accounting for foreign firms page, or see consultation.
This article is general information on UK GDPR as at October 2026 and is not legal advice; take UK legal advice on your own arrangements.