If you’ve heard about GDPR you are probably fed up with the hype. If you’ve not heard of it then you are at risk of playing catch up.

GDPR really stands for the General Data Protection Regulation which comes into effect on 25 May 2018 and applies to all of us who are processing personal data.

If you’re in practice then you almost certainly are processing personal data – whether for clients, staff, website visitors, prospects or influencers.

Processes and procedures

The size and nature of your practice will affect the processes and procedures you will need to put in place to evidence your compliance with GDPR.

We will only be able to show we are compliant (as is required by GDPR) if we prepare adequately ahead of the deadline.

Last year I was asked to raise awareness of the topic during the ICAEW autumn practice roadshows. That meant researching things so that I could highlight the key points. I made clear then, as I do here, that I don’t claim to be an expert and I’m certainly not a lawyer.

Genuinely practical guidance

More recently I am aware that many people are offering summaries of the background to GDPR, of the legal position and are explaining in great detail how it will impact accountants and their clients.  On the other hand, there hasn’t been much in the way of genuinely practical guidance.

One key reason for the dearth of authoritative practical guidance for accountants has been that we are still waiting for formal guidance from the Information Commissioner’s Office (ICO) on key topics. Until this is received some GDPR experts are advising extreme caution.

Four things we can all do

I’m hopeful the reality won’t be quite as bad. In the meantime there are four things we can all do:

  1. Register as a data controller with the Information Commissioner’s Office (www.ico.org.uk), if you’ve not already done so. It costs £35pa and is NOT a new obligation!
  2. Audit your systems and processes so you are clear about how you obtain, use and retain personal data. You need to be clear and to keep a record as to how you obtain all personal data you hold, where it is held, who has access to it, who you share it with, how long you retain it, how you keep it uptodate and how secure it is (in all the various places it can be accessed).
  3. If you have staff, brainstorm the issue with them as they will need to be aware of the new obligations too. They will need training in the obligations imposed by GDPR just as they need to understand their obligations under the anti-money laundering legislation.
  4. Start to plan what you will do to evidence your compliance with GDPR as of 25 May. I have created a list of the most common documents most firms of accountants will need to prepare. You can get a copy here