Home › Data Protection Policy

Our Data GovernanceData Protection Policy

Effective: November 2025 Reviewed: September 2026 Next review: April 2027 Version: v1.0.4 Jurisdiction: England & Wales

This Policy sets out how we protect personal data and stay accountable under UK data protection law. It sits behind our Privacy Policy: the Privacy Policy tells you what we do with your data; this Policy is the governance behind it - our principles, security, retention, and how we handle requests and breaches.

1. Purpose and scope

In shortThe governance behind our Privacy Policy: how we protect data and stay accountable.

1.1 This Policy sets out Landlord Accounting’s approach to protecting personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

1.2 It applies to all personal data we process - data relating to clients, prospective clients, suppliers and professional contacts, whether collected online or offline.

1.3 It applies to everyone who processes personal data for or on our behalf, including any contractor or temporary assistant.

1.4 This document is internal governance guidance and does not create contractual rights for third parties.

2. Roles and responsibilities

In shortWe are controller for our own data and processor for client data; the business principal is responsible for data protection.

2.1 Our role. Landlord Accounting is a sole-trader business. We are the controller for our own business data - enquiries, website visitors, marketing contacts and suppliers. For the client bookkeeping data we process on a client’s instructions - including information about their tenants - we act as the client’s processor; the client is the controller. As a processor we act only on the client’s documented instructions, under our engagement terms, and we return or delete the data on instruction at the end of the engagement.

2.2 Responsibility for data protection rests with the business principal, who oversees day-to-day compliance, keeps records of processing, handles data-subject requests, and manages any breach. We aim to acknowledge a data-subject request promptly, and in any event without undue delay.

2.3 Contact for data protection matters: contact@landlordaccounting.co.uk · 07359 169970.

2.4 Landlord Accounting is registered with the Information Commissioner’s Office as a data controller; the registration is held in the business owner’s name and the reference is available on request.

2.4 Anyone handling personal data on our behalf must follow this Policy and complete proportionate data-protection training.

3. Lawful bases for processing

In shortThe legal reasons we are allowed to handle personal data.

3.1 Personal data is processed only where at least one lawful basis applies under Article 6 UK GDPR.

3.2 We principally rely on:

  • Contractual necessity - to deliver bookkeeping services.
  • Legal obligation - to meet record-keeping and other statutory duties, and anti-money-laundering requirements where they apply.
  • Legitimate interests - to run the business, manage relationships, keep it secure and maintain records, balanced against individuals’ rights.
  • Consent - for optional communications or specific activities; consent may be withdrawn at any time.

3.3 We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

4. Data protection principles

In shortThe core UK GDPR rules we follow with all personal data.

We handle personal data in line with the UK GDPR principles:

  • processed lawfully, fairly and transparently;
  • collected for specified, explicit and legitimate purposes, and not used in incompatible ways;
  • adequate, relevant and limited to what is necessary (data minimisation);
  • accurate and, where necessary, kept up to date;
  • kept in identifiable form no longer than necessary (storage limitation);
  • processed securely, protecting against unauthorised processing, loss, destruction or damage;
  • handled so we can demonstrate our compliance (accountability).

5. Categories of data

In shortContact details, bookkeeping records, correspondence and basic website data.

5.1 We typically process identity and contact details; property and transaction information; correspondence; and technical or usage data from website interactions (see our Cookie Policy).

5.2 We do not intentionally collect special-category data or criminal-offence data. If we receive it by accident, we minimise, restrict and delete it unless a lawful basis and appropriate safeguards apply.

6. Records of processing and DPIAs

In shortWe keep records of what we process and assess higher-risk activities.

6.1 We keep proportionate records of processing activities, covering purposes, categories, recipients, retention and safeguards.

6.2 We complete a Data Protection Impact Assessment where processing is likely to be high risk, including a Transfer Risk Assessment where an international transfer is involved.

7. Data sharing and processors

In shortAny provider we use is under a written contract. We never sell data.

7.1 Any third-party processor - for example, secure cloud hosting, IT support or document storage - is engaged under a written contract containing UK GDPR Article 28 terms.

7.2 Processors may act only on our documented instructions and must apply appropriate technical and organisational measures.

7.3 We do not sell or rent data. Any disclosure to an authority (for example HMRC or law enforcement) is limited to what the law requires.

7.4 We carry out proportionate due diligence on processors at onboarding and when material changes occur, including their security measures and any sub-processors.

8. International transfers

In shortData is normally processed and stored in the UK.

8.1 Personal data is normally processed and stored in the UK.

8.2 Where an international transfer occurs, we use an adequacy regulation, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and complete a Transfer Risk Assessment as appropriate.

9. Security measures

In shortEncryption, multi-factor login, least-privilege access and backups.

9.1 Our technical and organisational measures include: encrypted communications and secure cloud storage; multi-factor authentication where available and strong passwords; role-based access on a need-to-know basis; anti-malware, patching and regular backups; and secure configuration of devices and applications. Access is granted on a least-privilege basis and reviewed at least annually.

9.2 Cloud storage must encrypt data at rest and in transit. Personal data is not stored on unmanaged personal devices; where a personal device is used, it must be approved, secured and capable of being wiped remotely.

9.3 Any paper records are stored securely with restricted access and locked away when unattended.

10. Retention and disposal

In shortWe keep data only as long as needed, then delete it securely.

10.1 Personal data is kept only as long as necessary for its purpose and to meet legal, accounting or reporting requirements.

10.2 Client records are generally kept for six years from the end of the relevant financial year or service, unless the law requires longer.

10.3 Non-client enquiries and general correspondence are normally kept for up to 12 months, unless longer is needed to establish, exercise or defend a legal claim.

10.4 Secure disposal includes cryptographic wiping of media, deletion from backups per our backup-retention approach, and certified shredding for paper.

11. Data subject rights requests

In shortWe handle requests to see, correct or delete data within a month.

11.1 Individuals have rights of access, rectification, erasure, restriction, portability and objection, plus the right to withdraw consent where consent is used.

11.2 Requests should be sent to the contact above and are acknowledged promptly. We may verify identity before acting.

11.3 We respond within one month of receipt, extendable by up to two further months for complex or numerous requests (we will tell you if we extend).

12. Personal data breaches

In shortAny breach is assessed and, if serious, reported to the ICO, where the breach is likely to result in a risk to individuals, within 72 hours of becoming aware.

12.1 Any suspected personal data breach must be reported immediately to the business principal.

12.2 We assess the risk and, where a breach is notifiable, report it to the ICO within 72 hours of becoming aware, and inform affected individuals without undue delay where required.

12.3 We keep an incident log and apply the lessons learned to prevent recurrence.

13. Training, monitoring and audit

In shortAnyone handling data is trained, and compliance is checked periodically.

13.1 Anyone handling personal data completes proportionate data-protection training and refreshers, and is kept informed of policy updates and key risks.

13.2 Compliance with this Policy is monitored and reviewed periodically, and corrective action is taken where any shortfall is found.

14. Complaints and escalation

In shortRaise a data concern with us, or complain to the ICO.

14.1 Complaints about our data protection practices should be sent to the contact above; see also our Complaints & Feedback Policy.

14.2 You also have the right to complain to the Information Commissioner’s Office: www.ico.org.uk · 0303 123 1113.

15. Review and maintenance

In shortWe review this policy regularly and date every change.

15.1 We review this Policy at least once a year, or sooner if the law or our processing changes. The effective date and version appear at the top; material changes are highlighted where appropriate.

16. Contact

In shortHow to reach us about data protection.

Landlord Accounting - data protection contact

Email: contact@landlordaccounting.co.uk

Phone: 07359 169970

Post: Landlord Accounting
c/o David Smith & Co., Accountants
7 Grosvenor Gardens
London SW1W 0BD

Website: www.landlordaccounting.co.uk

17. Important information

In shortWe keep records, not tax advice. This is internal governance guidance.

Landlord Accounting provides property bookkeeping services only. We do not prepare or file tax returns and we do not provide tax or legal advice. This Policy is internal governance guidance and does not confer third-party rights.

This Policy is governed by the laws of England and Wales and subject to the exclusive jurisdiction of its courts.