Yes, outsourcing can be UK GDPR compliant, including when the team sits outside the UK. The outsourcing GDPR position is straightforward: your practice usually stays the controller, the supplier acts as your processor under a written Article 28 contract, and if the supplier can reach client data from abroad you are making a restricted transfer that needs a lawful transfer mechanism.
In short: a UK practice meets the outsourcing GDPR requirements for offshore client work if three things are in place. A processing contract that meets Article 28, a transfer mechanism for any country without UK adequacy regulations (usually the IDTA or the Addendum plus a transfer risk assessment), and security controls that you can evidence.
Key points
- The ICO treats remote access to your UK systems by a separate organisation abroad as a restricted transfer, even if no file is ever sent.
- Ghana, India and the Philippines are not covered by UK adequacy regulations, so the same safeguards apply to all three.
- The outsourcing GDPR step most often missed is updating your privacy notice and records of processing.
Outsourcing GDPR roles: controller or processor
A controller is the organisation that decides why and how personal data is processed. A processor handles personal data only on a controller’s documented instructions. When you hand AML chasing, Companies House admin or bookkeeping preparation to an outside team, your practice normally remains the controller for that client data and the supplier acts as your processor. ACCA’s guidance for practices outsourcing overseas reaches the same view: the practice will usually be the controller and the overseas provider a processor (ACCA, data protection when outsourcing).
Accountability for outsourcing GDPR compliance therefore stays with you: you choose the supplier, set the instructions and remain answerable to clients and the ICO.
What an Article 28 processing contract must contain
A data processing agreement (DPA) is the written contract between a controller and a processor required by Article 28(3) UK GDPR. It is the core outsourcing GDPR document, and the ICO lists the details and minimum terms it must include (ICO, what needs to be included in the contract). The ICO notes this guidance is under review following the Data (Use and Access) Act, so check it again before you sign.
| Article 28(3) requirement | What it looks like in an accounting practice |
|---|---|
| Subject matter, duration, nature and purpose | For example: “AML evidence collection and Companies House filings for the practice’s company clients, for the term of the services agreement” |
| Types of data and categories of people | Names, addresses, ID documents, UTRs, NI numbers, bank details; clients, directors, PSCs, employees on payroll |
| Documented instructions only (28(3)(a)) | Task instructions kept in writing, for example in your practice management system or by email, so there is a saved record |
| Confidentiality of people processing (28(3)(b)) | Every team member with access has signed a confidentiality commitment |
| Security under Article 32 (28(3)(c)) | Named logins, multi-factor authentication, no local copies, prompt removal of access |
| Sub-processors (28(3)(d)) | No onward subcontracting without your prior written authorisation |
| Help with data subject rights and breaches (28(3)(e) and (f)) | Agreed contact route and response time if a client makes a subject access request or a breach is suspected |
| Deletion or return at the end (28(3)(g)) | Access revoked and any working copies deleted on exit, with written confirmation |
| Audit and information (28(3)(h)) | The supplier provides the information you need to show compliance and allows audits |
Restricted transfers: why remote access counts
A restricted transfer is sending personal information to, or making it accessible to, a separate organisation located outside the UK, where UK GDPR applies to the processing and you initiate the transfer. The ICO’s three step test asks whether UK GDPR applies, whether you are initiating the transfer and whether the receiver is a separate legal entity (ICO, a brief guide to international transfers).
The ICO’s own example is close to an outsourced practice team: a UK business lets an organisation in India access personal information held on its own systems, sends nothing, and is still making a restricted transfer. The ICO adds that the rules apply to all restricted transfers, even small, infrequent ones. ACCA says the same about outsourced staff abroad: their remote access to the practice’s data is a restricted transfer, because they are employed by the outsourcing company (ACCA, adequacy regulations).
This is the point that shapes the outsourcing GDPR analysis. Your own employee logging in from abroad is not a restricted transfer, because they are part of the same legal entity. A supplier’s staff are not, so working inside your systems does not remove the transfer, although it makes the risk assessment easier.
Adequacy: what applies to Ghana, India and the Philippines
Adequacy regulations (sometimes called data bridges) are UK government regulations confirming that a country’s protection is “not materially lower” than UK law, so data can flow there without extra safeguards. Before the Data (Use and Access) Act 2025, the ICO described this standard as “sufficiently similar” (ICO, is the restricted transfer covered by adequacy regulations?).
The ICO’s current list covers the EEA, countries such as Switzerland, New Zealand and Israel, partial adequacy for Canada and Japan, South Korea, and the UK-US data bridge. Ghana, India and the Philippines are not on it (our comparison of outsourcing to Ghana, India or the Philippines covers the other practical differences). If your supplier is in any of those countries, your outsourcing GDPR paperwork needs appropriate safeguards or, rarely, an exception.
The IDTA, the Addendum and the transfer risk assessment
The IDTA (International Data Transfer Agreement) is the ICO’s standard contract for restricted transfers. The Addendum is the ICO’s add-on that lets you use the European Commission’s 2021 standard contractual clauses for UK transfers. Either can be signed alongside your commercial contract, and Part 3 of the IDTA can carry the Article 28 processor terms (ICO, the UK IDTA and the Addendum).
A transfer risk assessment (TRA) is your reasoned check that people’s protection is not materially lower after the transfer. Since the Data (Use and Access) Act, legislation calls this the “data protection test”, and the ICO confirms that a TRA completed under its earlier guidance still meets it (ICO, what’s a transfer risk assessment?).
Exceptions under Article 49 exist, but the ICO says you generally need to show that relying on one is necessary and proportionate. In our view that is hard to argue for routine, ongoing outsourced work, so build your outsourcing GDPR approach on safeguards.
A practical outsourcing GDPR order of work for a practice:
- Map the data: which clients, which systems, which fields the supplier will see.
- Confirm roles: practice as controller, supplier as processor, and any sub-processors.
- Check adequacy for the supplier’s country on the ICO list.
- If there is none, agree the IDTA or the Addendum with the supplier.
- Complete and record a TRA, including the technical controls that reduce risk.
- Sign the Article 28 terms (in the IDTA Part 3 or a separate DPA).
- Update your privacy notice and your records of processing.
- Review the arrangement when scope, systems or the supplier’s location changes.
A step that is easy to miss: your privacy notice and records
ACCA’s outsourcing guidance points out that your privacy notice should tell clients you may use overseas service providers, naming the countries if possible, and describe the safeguards for international transfers. It also expects the arrangement to appear in your records of processing activities under Article 30. Many practices sign a supplier contract and treat outsourcing GDPR as done, without touching their client-facing documents. If you use ICAEW-style terms of business, check that the data protection clauses mention subcontractors and transfers.
Practical controls that make the risk assessment easier
A TRA is easier to support when the supplier’s people can see only what they need, only inside your systems. Controls worth writing into any outsourcing GDPR arrangement:
- Named, individual logins issued by the practice, never shared accounts.
- Multi-factor authentication on every system the team uses.
- Work done inside your software (practice management, payroll, bookkeeping, HMRC and Companies House portals), with no client files saved to local devices.
- Access limited to the clients and modules the task needs.
- Activity you can review, such as audit logs in your practice software.
- A written leaver and exit process: you revoke access the same day.
Outsourcing GDPR checklist: questions to ask any supplier
| Question | Why it matters |
|---|---|
| Which country will your team work from, and is any work subcontracted? | Sets the adequacy position and the sub-processor terms |
| Will you sign Article 28 processing terms before access starts? | Required before any processing |
| Which transfer mechanism do you support: IDTA or Addendum? | Needed where there is no adequacy |
| Do you work only in our systems, or copy data to yours? | Copies widen the risk and the TRA |
| How do you handle a suspected breach, and how quickly will you tell us? | Reportable breaches must go to the ICO within 72 hours of becoming aware (ICO, report a breach) |
| What happens to access and data when we end the contract? | Article 28(3)(g) deletion or return |
Related reading: what practices can safely hand off in HMRC and Companies House admin and AML checks in-house versus outsourced.
How Virtual Service Assists approaches this
Virtual Service Assists is a team based in Ghana, so the outsourcing GDPR rules above apply to any practice that works with us. We work inside your own systems, using logins your practice issues and can revoke, over secure connections and with GDPR-conscious handling procedures. We agree processing terms in writing before access is set up, covering what data we handle and for which tasks. Your practice keeps its controller decisions, including the choice of transfer mechanism and your TRA, so take your own advice on the paperwork. More on how the arrangement works is on our virtual assistant for accountants page.
FAQs
Is it GDPR compliant to use an offshore team for UK client data?
It can be. UK GDPR does not ban offshore processing. To meet the outsourcing GDPR requirements, the practice needs a written Article 28 contract with the supplier, a lawful basis for the transfer (adequacy regulations, or safeguards such as the IDTA or Addendum backed by a transfer risk assessment), suitable security controls, and an updated privacy notice telling clients that overseas providers may be used.
Does remote access count as transferring data outside the UK?
Yes, when the person accessing works for a separate organisation abroad. The ICO’s guidance gives the example of a UK business letting an Indian service provider access data held on its UK systems: nothing is sent, but it is still a restricted transfer. Your own employee logging in from abroad is different, because they are part of the same legal entity.
Do we need an IDTA if the supplier only works in our systems?
If the supplier is a separate organisation in a country without UK adequacy regulations, you need appropriate safeguards such as the IDTA or the Addendum, or an exception. Working only in your systems does not remove the transfer, but it supports your transfer risk assessment because data stays in your software under your access controls.
Does Ghana have a UK adequacy decision?
No. The ICO’s list of countries covered by UK adequacy regulations does not include Ghana, India or the Philippines. Ghana has its own Data Protection Act, 2012 (Act 843), overseen by its Data Protection Commission, but that does not replace UK safeguards. For outsourcing GDPR purposes, a UK practice working with a team in Ghana needs the IDTA or the Addendum and a transfer risk assessment.
What is a transfer risk assessment?
A transfer risk assessment is a documented check that people’s personal data will be protected to a standard not materially lower than in the UK after a restricted transfer. Since the Data (Use and Access) Act 2025 the legislation calls it the data protection test. The ICO publishes a TRA tool and says assessments made under its earlier guidance still count.
Next step
If you are weighing up an outside team for compliance admin and want to see how access, scope and the outsourcing GDPR paperwork are set up before anything starts, read our virtual assistant for accountants page or see what Virtual Service Assists does for UK practices. When you are ready, book a consultation.



