Data processing agreement for a bookkeeper

A data processing agreement for a bookkeeper or small accountancy practice to use with its clients, drafted for the bookkeeper with the privacy notice, for a fixed fee of £795 in five working days.

Share

Data processing agreement for a bookkeeper

A data processing agreement for a bookkeeping practice, drafted for the bookkeeper, covering controller or processor and why a bookkeeper is often both, the processor work and the DPA that covers it, the controller work and the obligations the bookkeeper carries alone, the cloud accounting platforms and the client's own logins, confidentiality, anti-money laundering and the records the law requires, and the end of the engagement and the data that goes with the client. £795 with the privacy notice, delivered in five working days.

Buy now, £795

A bookkeeper processes clients' sales and purchase ledgers, their customers' and suppliers' details, their payroll where it runs one and their bank transactions, and the question of whether it does so as the client's processor or as a controller in its own right has a different answer for different parts of the work: bookkeeping on the client's systems and instructions is processing on behalf; the bookkeeper's professional obligations, its anti-money laundering checks and its own records make it a controller. The DPA has to draw that line, cover the processor work with the mandatory terms, and leave the bookkeeper's own obligations to its own notice. A fixed £795 covers the data processing agreement and the privacy notice, drafted for the business with a note on the operational steps they assume and delivered in five working days.

Who this is for

Bookkeepers, small accountancy practices and outsourced finance providers in England and Wales working on clients' records, whether on the client's cloud accounting platform or their own.

What matters in a bookkeeper's data processing agreement

Controller or processor and why a bookkeeper is often both

A bookkeeper entering the client's transactions, reconciling the client's bank and maintaining the client's ledgers on the client's instructions is the client's processor, while a bookkeeper exercising professional judgement on the client's affairs (advising, preparing accounts under professional standards, making anti-money laundering checks under its own statutory duty, keeping its own working papers) is a controller for that processing, as the accountancy bodies' guidance recognises; the DPA should say which activities are processor work (covered by it) and which are controller work (covered by the bookkeeper's own privacy notice and engagement terms), because a bookkeeper that signs a DPA treating everything as processor work has agreed to delete records its professional body requires it to keep.

The processor work and the DPA that covers it

Under Article 28 of the UK GDPR the relationship between a controller and its processor must be governed by a written contract with the listed terms, and for the processor work the schedule should describe the client's customers, suppliers, employees and contacts whose data appears in the records, the ledger, bank, invoice, expense and payroll data, the bookkeeping, reconciliation, reporting and filing the bookkeeper performs, and the instructions (the engagement terms and the client's requests); the bookkeeper must act only as the client documents, keep the data confidential and secure under Article 32, authorise sub-processors properly and bind them to the same terms, help with data subject requests and the client's security, breach and impact assessment duties, delete or return the data at the end, and give the client the information and audits that show compliance.

The controller work and the obligations the bookkeeper carries alone

For the controller work the bookkeeper needs its own lawful basis (the engagement contract, legal obligation for the anti-money laundering checks under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 where the bookkeeper is supervised, legitimate interests for its working papers and its professional obligations), its own privacy notice to the client and the client's principals, its own retention (the period its professional body and the regulations require), and its own registration with the Information Commissioner's Office; the DPA should refer to the bookkeeper's notice for that work and should not purport to make the client the controller of the bookkeeper's due diligence file.

The cloud accounting platforms and the client's own logins

Most bookkeeping is done on a cloud accounting platform in the client's subscription, where the platform is the client's processor under the platform's terms and the bookkeeper is a user the client has authorised, or in the bookkeeper's practice subscription, where the platform is the bookkeeper's sub-processor needing authorisation and flow-down under Article 28(2) and (4); the DPA should say which arrangement applies, should deal with the bookkeeper's access (named logins, multi-factor authentication, removal on termination), with the receipt-capture, payment and payroll tools the bookkeeper connects, and with the international transfers under Article 46 of the UK GDPR for platforms hosted abroad, because the client rarely knows which subscription its data sits in.

Confidentiality, anti-money laundering and the records the law requires

The bookkeeper's confidentiality to the client sits alongside the DPA, and the DPA should carve out the disclosures the law requires (reports to the National Crime Agency under the Proceeds of Crime Act 2002, which the bookkeeper may not tell the client about, and responses to HMRC and the courts), the records the bookkeeper must keep under the 2017 Regulations and its professional body's rules for the periods they require, and the bookkeeper's professional obligations to its body; a client's instruction to delete everything cannot override those, and the DPA should say so.

The end of the engagement and the data that goes with the client

At the end of the engagement the DPA should provide for the hand-over of the client's records in a usable form (the platform's export, the working files, the year-to-date figures) to the client or the successor bookkeeper within a stated period, the removal of the bookkeeper's access to the client's subscription, the deletion of the processor-work data the bookkeeper holds within a fixed period, certified in writing, and the retention of the controller-work records for the periods the law and the professional body require; the professional clearance letter between bookkeepers is a separate convention the DPA can refer to, and data protection liability sits within the engagement terms' cap with liability under Article 82 of the UK GDPR resting on whichever party failed.

What it costs

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Are we a processor or a controller for our clients' books?

A processor for the bookkeeping done on the client's instructions, and a controller for the professional work, the anti-money laundering checks and the working papers. The DPA draws the line and covers the processor work; the bookkeeper's own notice covers the rest.

A client has told us to delete everything after we stop acting. Can we?

The processor-work data, yes, within a stated period with certification. The anti-money laundering records and the working papers the professional body requires must be kept for their periods, and the DPA says so.

We work in the client's accounting platform. Who is responsible for it?

The platform is the client's processor under the client's subscription terms, with the bookkeeper as an authorised user. Where the work is done in the bookkeeper's own subscription, the platform is the bookkeeper's sub-processor. The DPA states which.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.