The existing clause on data protection in our standard terms of business is as follows:-

“Data Protection Act 1998

18. We confirm that we will comply with the provisions of the Data Protection Act 1998 when processing personal data about you and your family. In order to carry out the services of this engagement and for related purposes such as updating and enhancing our client records, analysis for management purposes and statutory returns, legal and regulatory compliance and crime prevention we may obtain, process, use and disclose personal data about you.”

This is now being replaced with:-

“General Data Protection Regulation (GDPR)

18. We confirm that we will comply with the General Data Protection Regulation, which replaces the Data Protection Act 1998 from 25th May 2018. In order to carry out the services of this engagement and for related purposes such as updating and enhancing our client records, analysis for management purposes and statutory returns, legal and regulatory compliance and crime prevention we may obtain, process, use and disclose personal data about you.

When processing personal data for accounting, auditing, taxation and related services, we act as the data controller. We confirm that we will comply with the obligations the GDPR places on us as a data controller.

For services such as payroll and auto-enrolment, you are the data controller and we act as the data processor, processing data on your behalf. We confirm that we will comply with the obligations the GDPR places on us a data processor.

You will also ensure that any disclosure of personal data to us complies with the GDPR. If you supply us with personal data or confidential information you shall ensure you have full informed consent to pass it to us.

In order to comply with our obligation to provide you with ‘fair processing information’, we have produced a GDPR Policy Document  which can be found on our company website. This policy document includes:-

  • Our lawful bases for processing personal data
  • A description of our processing activities
  • Our obligations as a data controller
  • Our obligations as a data processor
  • Your rights as the data subject
  • The security measures and practical guidelines we have in place to protect personal data
  • Our procedures for recording and reporting a data breach

We will answer your reasonable enquiries to enable you to monitor compliance with this clause.”

Read our GDPR Policy Document

Address

England & Company
7 & 8 Church Street
Wimborne
Dorset
BH21 1JH

Contact

Tel: 01202 880384
Fax: 01202 842814

 

Company Registration Number: 4521252

Registered in England and Wales
VAT: 798123494

 

 


JoinEngland and Company on LinkedIn   Follow England and Company on Twitter

Site by Atomic Agency