{"id":1554,"date":"2018-05-01T02:50:57","date_gmt":"2018-05-01T02:50:57","guid":{"rendered":"https:\/\/qxaccounting.com\/uk\/?p=1554"},"modified":"2025-09-22T16:24:46","modified_gmt":"2025-09-22T16:24:46","slug":"is-your-accounting-outsourcing-provider-gdpr-compliant","status":"publish","type":"post","link":"https:\/\/qxaccounting.com\/uk\/blog\/is-your-accounting-outsourcing-provider-gdpr-compliant\/","title":{"rendered":"Is your accounting outsourcing provider GDPR compliant?"},"content":{"rendered":"\n<p>The General Data Protection Regulation (GDPR) will become reality on&nbsp;May 25, 2018, and organisations across the globe are preparing to meet the extensive&nbsp;requirements of the new regime.<\/p>\n\n\n<div class=\"wp-block-aioseo-table-of-contents\"><ul><li><a class=\"aioseo-toc-item\" href=\"#aioseo-the-roles-of-data-processors-and-data-controllers\">The roles of\u00a0\u2018data processors\u2019 and \u2018data controllers&#039;<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-choosing-an-outsourcing-provider-gdpr-supplier-checklist\">Choosing an outsourcing provider (GDPR Supplier checklist)<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-how-is-qxas-protecting-your-personal-data\">How is QXAS protecting your personal data?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-first-gdpr-compliant-knowledge-process-outsourcing-kpo-company-in-india\">First GDPR compliant knowledge process outsourcing (KPO) company in India<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-what-does-it-mean-to-be-a-bs10012-certified-service-provider\">What does it mean to be a BS10012 certified service provider?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-why-is-this-important-to-accounting-practices-outsourcing-to-india\">Why is this important to accounting practices outsourcing to India?<\/a><\/li><\/ul><\/div>\n\n\n<p>As an evolution of the 1995 Data Protection Directive, GDPR introduces a new concept of accountability, which requires businesses that deal with EU data to &#8220;demonstrate compliance&#8221;&nbsp;with the core principles of data protection.<\/p>\n\n\n\n<p>While the change stems from Europe, organisations around the world must comply if they offer goods and services to the EU.<\/p>\n\n\n\n<p>This includes implementing a more prescriptive&nbsp;data processing arrangement. However, it doesn\u2019t stop at how the data is processed within your practice. It also includes how data moves to and between the companies you work with, right from payroll bureaus, cloud providers, to outsourcing companies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"aioseo-the-roles-of-data-processors-and-data-controllers\">The roles of&nbsp;\u2018data processors\u2019 and \u2018data controllers&#8217;<\/h3>\n\n\n\n<p>If you are an accountancy practice you are the data controller. That is because as a&nbsp;data controller you determine the purposes and means of processing personal data. In plain English, you decide what the data is for and what&#8217;s going to happen to it. But a data processor&nbsp;has a distinct meaning under GDPR. It refers to the person or body who is separate from you (i.e. not an employee) and who processes personal data on your behalf. In plain English, the controller gives the processer a specific job to to and the processor does it. This&nbsp;in our case would be an outsourcing company like QXAS.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"aioseo-choosing-an-outsourcing-provider-gdpr-supplier-checklist\">Choosing an outsourcing provider (GDPR Supplier checklist)<\/h3>\n\n\n\n<p>GDPR marks a huge&nbsp;change in the balance of responsibility between data controller and data processor. Under the new regulations, outsourcing companies will have more responsibility to protect their clients&#8217; data. Which means as data controllers accountancy firms will have to start questioning their current or potential outsourcing partners if they meet GDPR requirements and how they can demonstrate it.<\/p>\n\n\n\n<p>To help you ensure your outsourcing provider is complying with GDPR, use our three-pronged supplier checklist, which takes into account the legal, operational and technological perspective:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>GDPR compliant:<\/strong>&nbsp;Understand if the outsourcer is GDPR compliant? Or if they plan to be compliant before May 25, 2018. You should be confident that the outsourcing company has conducted internal data protection impact assessments (Article 35), signed a written data processing agreement with you (Article 28),&nbsp; implemented appropriate security standards (Article 32), and are compliant with the provisions on international data transfers (Chapter V).<\/li>\n\n\n\n<li><strong>Business Contracts:<\/strong>&nbsp;Article 28 of the GDPR provides a long list of obligations that controllers will need to impose on the processors. With the risk of non-compliance far greater than ever before, such clauses will need to be covered off in your business contracts with the outsourcer. Find out if your suppliers have renewed contracts\/written agreements with their current clients so both meet the requirements of GDPR.<\/li>\n\n\n\n<li><strong>Focus on security<\/strong>: There are questions about the storage of data, but the crucial point is whether your suppliers have appropriate safeguards and security procedures that meet the GDPR standards. For example, if outsourcers are storing data outside the EU, your client&#8217;s personal data attributes would need to be anonymised, encrypted, archived and deleted (data life cycle management).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"aioseo-how-is-qxas-protecting-your-personal-data\">How is QXAS protecting your personal data?<\/h3>\n\n\n\n<p>Trust is the foundation of our relationship with our accounting clients. We value the confidence they put in us and take full responsibility of protecting their information seriously.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>ISO 27001 &amp; BS 1002:2017.<\/strong>&nbsp;We have a track record of staying ahead of the compliance game \u2013 for example, our security practices have for years complied with ISO 27001 &#8211; the most widely accepted standard for data privacy and protection.&nbsp; On 26 April, 2018 we also became the first outsourcing company in India to be GDPR compliant via the British Standards ISO BS1002:2017 framework (more on what this means below). To better understand our security procedures, you can refer to our&nbsp;Security page.<\/li>\n\n\n\n<li><strong>Dedicated DPO.<\/strong>&nbsp; We have dedicated data protection officer (DPO) and a supporting&nbsp;team who are involved in designing and maintaining our privacy framework and policies to safeguard clients\u2019 data in line with the requirements of GDPR.<\/li>\n\n\n\n<li><strong>Data flows<\/strong>. QX\u2019s DPO conducted a comprehensive data-mapping exercise, which tracks how our clients\u2019 personal data flows throughout our systems and services. Our data maps have been finalised.<\/li>\n\n\n\n<li><strong>Business Contracts.&nbsp;<\/strong>Our business agreements and contracts now incorporate data processing clauses to help our accounting clients comply with GDPR. We are also committed to help our clients prepare for the obligations under GDPR. For more information on how we can support your compliance journeys please email contact@qxas.co.uk<\/li>\n\n\n\n<li><strong>Data subject rights.&nbsp;<\/strong>We have developed procedures to deal with key \u2018data subject\u2019 rights, like subject access requests (SAR), and the right to request data erasure. More details can be found in our privacy policy.<\/li>\n\n\n\n<li><strong>Consent Management system.<\/strong>&nbsp;Our cross-functional GDPR team&nbsp;have put together a comprehensive&nbsp;consent management system&nbsp;to ensure our marketing communications only go out to businesses who have opted-in.<\/li>\n\n\n\n<li><strong>Privacy policy.<\/strong>&nbsp;We also updated our&nbsp;Privacy Policy&nbsp;on&nbsp;<strong>April 6, 2018<\/strong>&nbsp;to give our website users more clarity about the information we collect, how we use it and the rights they have in relation to this information.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"aioseo-first-gdpr-compliant-knowledge-process-outsourcing-kpo-company-in-india\">First GDPR compliant knowledge process outsourcing (KPO) company in India<\/h3>\n\n\n\n<p>QXAS met with the requirements of GDPR on&nbsp;<strong>26 April 2018&nbsp;<\/strong>via the ISO&nbsp;<a href=\"https:\/\/www.bsigroup.com\/en-GB\/BS-10012-Personal-information-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">BS 10012:2017<\/a>&nbsp;framework \u2013 it\u2019s the only available industry code of conduct that aligns with GDPR requirements. We are the&nbsp;first outsourcing company in India&nbsp;to have been awarded the standard \u2013 exactly a month before the deadline comes into effect!<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"aioseo-what-does-it-mean-to-be-a-bs10012-certified-service-provider\">What does it mean to be a BS10012 certified service provider?<\/h3>\n\n\n\n<p>It means we has developed and deployed standard processes to ensure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>QX has a legal basis to process personal data<\/li>\n\n\n\n<li>QX limits data processing only to the agreed purpose<\/li>\n\n\n\n<li>QX transfers\/shares only what is agreed and only though approved channels<\/li>\n\n\n\n<li>QX collects and processes minimum necessary data<\/li>\n\n\n\n<li>QX securely disposes data after the defined retention period<\/li>\n\n\n\n<li>QX has applied adequate information security and cyber security controls<\/li>\n\n\n\n<li>QX has appointed a certified Data Protection Officer (DPO)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"aioseo-why-is-this-important-to-accounting-practices-outsourcing-to-india\">Why is this important to accounting practices outsourcing to India?<\/h3>\n\n\n\n<p>By working with non-compliant outsourcing companies post May 25, 2018, you expose yourself to a risk which has the potential for reputational damage, not to mention significant new fines which are up to \u20ac20 million or 4% of a company\u2019s global annual turnover, whichever is higher.<\/p>\n\n\n\n<p>If you have any additional questions regarding GDPR, we\u2019ll be happy to have a member of our team assist you. Please contact us at&nbsp;<a href=\"mailto:contact@qxas.co.uk\">contact@qxas.co.uk&nbsp;<\/a><\/p>\n\n\n\n<p>Give QXAS accounts outsourcing a try. Get started with a&nbsp;<a href=\"https:\/\/qxaccounting.com\/contact\/\">free-trial<\/a>.<\/p>\n\n\n\n<p><strong><em>Disclaimer<\/em><\/strong><em>&nbsp;\u2013 This blog is intended to provide helpful guidance on GDPR and does not constitute legal advice.&nbsp; You should undertake your own steps to ensure compliance.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The General Data Protection Regulation (GDPR) will become reality on&nbsp;May 25, 2018, and organisations across the globe are preparing to meet the extensive&nbsp;requirements of the new regime. As an evolution of the 1995 Data Protection Directive, GDPR introduces a new concept of accountability, which requires businesses that deal with EU data to &#8220;demonstrate compliance&#8221;&nbsp;with the [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":8802,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[187],"tags":[6,4],"class_list":["post-1554","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-accounting","tag-accountants","tag-outsourcing"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/posts\/1554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/comments?post=1554"}],"version-history":[{"count":0,"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/posts\/1554\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/media\/8802"}],"wp:attachment":[{"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/media?parent=1554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/categories?post=1554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qxaccounting.com\/uk\/wp-json\/wp\/v2\/tags?post=1554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}