DATA PROTECTION & GDPR NOTICE

How we protect personal information

MBS Accounting Ltd provides accounting, tax and business advisory services. Providing those services means that clients trust us with information that can be personal, financial and sometimes particularly sensitive.

This Data Protection & GDPR Notice explains how we handle personal information in connection with our professional services and business relationships. It complements our website Privacy Policy and provides additional information relevant to clients, client personnel and other individuals whose information may appear in the records we process.

Our approach is simple: we aim to ask only for information that is relevant to the work we perform or the obligations we must meet, explain why it is needed, restrict access appropriately and handle it with care throughout the relationship.
Organisation MBS Accounting Ltd
Company number 09831038
Data protection contact support@mbsaccounting.com
Legal framework UK data protection law

Who this Notice applies to

This Notice may apply where MBS Accounting processes personal information relating to people connected with a client, prospective client or professional engagement.

Clients

Individuals and contacts

Individual clients, prospective clients and the people who communicate or work with us on their behalf.

Organisations

Owners and management

Directors, partners, trustees, shareholders, beneficial owners and other responsible persons.

Workforce

Employees and workers

Employees, workers, contractors and pension members whose information we process when providing payroll, accounting or related services.

Transactions

Customers and suppliers

Individuals whose names, payments, invoices or other details appear within client accounting records.

Professional network

Advisers and third parties

Accountants, lawyers, agents, banks, pension providers, suppliers and other professional contacts.

Compliance

Relevant third parties

Individuals whose information is relevant to tax, regulatory, anti-money-laundering or other lawful compliance requirements.

When MBS Accounting is a controller or processor

Our data-protection role depends on the particular information and processing activity. It is determined by what we actually do with the information, not simply by the wording used in a contract.

C
When we are a controller

MBS Accounting acts as a controller where we determine why personal information is needed and the key purposes for which it is processed.

This may include client onboarding, engagement administration, billing, anti-money-laundering checks, regulatory compliance, legal obligations, professional record keeping, security and management of our business.

P
When we are a processor

In some engagements, MBS Accounting may process personal information on a client’s documented instructions rather than for purposes that we determine ourselves.

This may arise in certain outsourced bookkeeping, payroll, administrative or data-handling activities. In those circumstances, the client will generally determine the purpose of the processing and our engagement or data-processing terms will govern our processor responsibilities.

The same engagement can involve different roles for different processing activities. Where necessary, we will clarify the relevant responsibilities in our engagement documentation.

Personal information we may process

The information involved depends on the services requested and the nature of the client. We do not necessarily process every category listed below for every engagement.

Identity and contact information
Names, addresses, email addresses, telephone numbers, dates of birth and other identifying or contact details.
Financial information
Bank details, payments, income, expenditure, invoices, expenses, balances, financial statements and other financial records.
Tax information
Tax references, National Insurance numbers, tax records, calculations, submissions and correspondence relating to taxation.
Payroll and employment information
Pay, deductions, tax codes, employment details, pension information, leave information and other data required for payroll or employment-related accounting services.
Corporate and ownership information
Directorships, shareholdings, beneficial ownership, company roles and information relating to the ownership or control of an organisation.
Accounting and transactional records
Supplier, customer, contractor and other third-party information contained in bookkeeping systems, invoices, receipts, statements and supporting documentation.
Engagement and communications data
Emails, correspondence, instructions, meeting notes, queries, records of advice and information about the professional services provided.
Compliance information
Identity-verification records, ownership information, risk assessments and information required for anti-money-laundering, fraud prevention or other regulatory obligations.

Where personal information comes from

We may receive personal information directly from the person concerned, but accounting work frequently requires us to receive information from other legitimate sources.

You directly, including information you provide during enquiries, onboarding or an engagement.
A client organisation, where it provides information about its directors, staff, customers, suppliers or other persons.
Previous accountants or professional advisers, where information is transferred with appropriate authority.
HM Revenue & Customs, Companies House and other public bodies or official registers.
Banks, payment providers, pension providers and other organisations relevant to the services being provided.
Accounting, payroll, bookkeeping, document-management or other business systems to which we are given authorised access.
Publicly available information where it is appropriate and lawful to use it.
Regulators, law-enforcement bodies or other authorities where applicable.

Why we use personal information

Where MBS Accounting acts as a controller, we identify an appropriate lawful basis for each processing purpose. The basis used depends on the particular circumstances.

Enquiries and onboarding
To respond to requests, understand requirements, prepare quotations and take appropriate steps before establishing an engagement.
Contract / legitimate interests
Providing professional services
To perform agreed accounting, tax, bookkeeping, payroll and advisory work and administer the professional relationship.
Contract / legitimate interests
Legal and regulatory compliance
To meet applicable obligations relating to anti-money-laundering, taxation, professional record keeping and other legal requirements.
Legal obligation
Fraud and crime prevention
To protect our firm, clients and others against fraud, misuse and unlawful activity and to meet relevant reporting obligations.
Legal obligation / legitimate interests
Business administration
To manage client relationships, invoices, communications, quality control, internal records, complaints, professional insurance and our legitimate business operations.
Legitimate interests
Security
To protect our systems, accounts, records, communications and confidential information.
Legitimate interests / legal obligations
Marketing communications
Where permitted, to provide relevant news, updates or information about our services. Marketing preferences can be changed at any time.
Consent / legitimate interests where applicable
Where MBS Accounting acts only as a processor, the relevant client controller is responsible for determining the lawful basis for that processing. We process the information in accordance with the client’s lawful instructions and our contractual obligations.

More sensitive personal information

Some professional services can involve information that receives additional protection under data-protection law. We only process this type of information where it is necessary, relevant and supported by the required legal condition.

Special category information Certain payroll, employment or other records may, for example, reveal health information or other special category data. Where this occurs, the additional legal requirements applying to that information must also be satisfied.
Criminal-offence information We may encounter information concerning suspected or actual criminal conduct in connection with anti-money-laundering, fraud-prevention, regulatory or legal matters. Such information is subject to additional safeguards and legal conditions.

Children and other vulnerable individuals

Some organisations we support may provide services to children or other vulnerable individuals. Their accounting, payroll or transactional records may therefore occasionally contain personal information relating to those individuals.

Where MBS Accounting processes such information as part of an engagement, we aim to limit the processing to what is genuinely required for the accounting or professional purpose, restrict access appropriately and apply the relevant data-protection safeguards.

Where we act as a processor, this information is processed on the instructions of the client organisation unless the law requires otherwise.

Who we may share information with

We do not sell personal information. Information is disclosed only where there is an appropriate reason connected with the services, our business operations, your instructions or our legal and regulatory obligations.

International data transfers

Some technology providers or other service providers used in the course of our business may process or store personal information outside the United Kingdom.

Where UK data-protection law requires safeguards for an international transfer, we take steps to ensure an appropriate transfer mechanism or other lawful protection is in place. This may include UK adequacy arrangements or approved contractual safeguards.

If you would like further information about safeguards relevant to your personal information, contact support@mbsaccounting.com .

How we protect information

Financial and business information requires careful handling. We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure, destruction or unauthorised access.

Access controls
Secure business systems
Authentication controls
Encryption where appropriate
Confidentiality controls
Secure backups
System monitoring
Controlled data sharing
Provider due diligence

Access is limited to persons and service providers who require the information for a legitimate purpose and who are subject to appropriate confidentiality or contractual obligations.

No system can guarantee absolute security, but we review our approach in light of the nature of the information, available technology and relevant risks.

How long we keep information

We do not keep personal information indefinitely simply because it has been provided to us. Retention is based on the purpose for which information is held, professional requirements, legal obligations and the need to establish or defend legal rights.

Normally 6 years
Client, accounting and tax records
Normally retained for six years after the relevant financial period or engagement ends, or longer where a legal, regulatory, professional or other legitimate requirement applies.
5 years
Anti-money-laundering records
Relevant customer-due-diligence and AML records are generally retained for five years after the end of the business relationship or completion of the relevant transaction, subject to applicable rules and exceptions.
Relevant period
Payroll and employment-related records
Retention depends on the type of record, the services provided, client requirements and applicable statutory or professional obligations.
As required
Disputes, investigations and claims
Information may be retained for longer where reasonably necessary for a dispute, investigation, legal claim, regulatory matter or other lawful requirement.

Your data-protection rights

The rights available to you depend on the circumstances and the lawful basis on which information is being processed. They are not absolute in every situation.

Access Ask for access to personal information we hold about you.
Rectification Ask us to correct inaccurate or incomplete information.
Erasure Ask us to delete personal information where the legal conditions for erasure apply.
Restriction Ask us to restrict processing in certain circumstances.
Data portability Request relevant information in a portable format where the legal requirements for portability are met.
Withdraw consent Where processing depends on consent, withdraw that consent at any time without affecting earlier lawful processing.
Object Object to certain processing carried out on the basis of legitimate interests or for direct marketing.
Automated decisions Rights may apply where a decision is made solely by automated means and produces legal or similarly significant effects.
Important — your right to object

You have the right to object to processing based on legitimate interests in circumstances recognised by data-protection law.

You also have the right to object at any time to the use of your personal information for direct marketing.

To exercise a data-protection right, email support@mbsaccounting.com .

We may need to confirm your identity before acting on a request. We will respond within the applicable legal timeframe and will not normally charge a fee.

Requests involving client-controlled data

If you contact us about personal information that MBS Accounting processes solely on behalf of one of our clients, the client may be the relevant controller responsible for your request.

In that situation, we may refer the request to the relevant client or assist the client in responding in accordance with our contractual and legal responsibilities.

This does not reduce any direct obligations that apply to MBS Accounting where we act as a processor.

Automated decision-making

Unless we tell you otherwise in a specific context, MBS Accounting does not make decisions about individuals based solely on automated processing where those decisions produce legal or similarly significant effects.

If this changes for a relevant processing activity, we will provide the additional information and safeguards required by applicable data-protection law.

Personal data breaches

We maintain procedures for identifying, containing, investigating and documenting personal data breaches.

1

Identify

Establish what happened and what information may have been affected.
2

Contain

Take reasonable steps to secure information and reduce potential harm.
3

Assess

Evaluate the likely risk to the rights and freedoms of affected individuals.
4

Notify where required

Notify the Information Commissioner and/or affected individuals where data-protection law requires us to do so.

Questions or concerns about your information

If something about the way your personal information has been handled concerns you, we encourage you to contact us. We would like the opportunity to understand the issue and address it appropriately.

You also have the right to raise a concern with the Information Commissioner’s Office, the UK’s independent data-protection regulator.

Information Commissioner’s Office: ico.org.uk/make-a-complaint

Related MBS Accounting policies

This Notice should be read alongside the other information relevant to our website and professional relationship.

Changes to this Notice

We may update this Data Protection & GDPR Notice from time to time to reflect changes in our services, systems, legal obligations or data-protection requirements.

The latest version will be published on this page. Where appropriate, significant changes will also be brought to the attention of relevant individuals.

Data protection enquiries

If you have a question about this Notice, how MBS Accounting handles personal information or your data-protection rights, please contact us.

MBS Accounting Ltd

Company number: 09831038

Registered office: Spencer House, 23 Sheen Road, Richmond, London, England, TW9 1BN

Website: mbsaccounting.com

Data protection contact: support@mbsaccounting.com

Last updated: 8 August 2026