GDPR Compliance (EU General Data Protection Regulation)
The General Data Protection Regulation (GDPR) is a regulation implemented by the European Union (EU) to protect the privacy and personal data of EU citizens. It came into effect on May 25, 2018, and applies to all organisations that process the personal data of EU residents, regardless of their location.
GDPR aligns data protection regulations with advancements in technology that have influenced the manner in which organisations and individuals engage with each other.
Mindspace places significant emphasis on safeguarding the privacy of personal data that enters and leaves our organisation. We have substantially invested in all areas in preparation for the implementation of the new data protection regime. We recognise and comply with GDPR guidelines, acknowledging our responsibility as both a data controller and a data processor, depending on the manner in which personal data is shared with us. Our commitment lies in securely processing our customers’ data while adhering to GDPR principles.
Mindspace has been strictly adhering to and ensuring compliance with the UK Data Protection Act for over 11 years. Our commitment to data protection and compliance remains steadfast as we transition to the new GDPR regulations.
While the GDPR builds upon the existing data protection framework, incorporating familiar concepts and principles, it also introduces new elements such as the accountability principle, enhanced rights for data subjects, direct obligations for data processors, and revised data breach notification requirements.
Although the fundamental principles of data protection remain consistent with the previous directive, the GDPR introduces certain changes and distinct features. These include:
- Secure storage and handling of data
- Right to be informed
- Right to delete information
- Limit the purpose of your information.
- Consent
Secure storage and handling of data
GDPR places a strong emphasis on the secure storage and handling of personal data. We have implemented appropriate security measures to protect our clients data from unauthorised access, loss, or theft. This includes using encryption for sensitive data, implementing access controls, regularly updating software and systems, and conducting periodic security audits to ensure data protection.
Right to be informed
Under GDPR, individuals have the right to be informed about the collection, use, and processing of their personal data. We provide clear and transparent information to our clients regarding how their data is processed, the purposes for which it is used (such as financial reporting or tax compliance), the legal basis for processing, the retention period, and any third parties with whom the data may be shared (such as tax authorities or auditors).
Right to delete information
Individuals have the right to request the deletion or removal of their personal data under certain circumstances. We have procedures in place to handle such requests promptly. This may involve securely deleting or anonymizing personal data that is no longer necessary for the purposes for which it was collected or when an individual withdraws their consent.
Limit the purpose of your information
GDPR emphasises the principle of purpose limitation. We collect and process personal data only for specific, explicit, and legitimate purposes related to our accounting services. We clearly define the purposes of data processing and ensure that we do not use the data for any purposes that are unrelated to or incompatible with the original purpose of collection.
Consent
We obtain consent through unambiguous and clear affirmative action. We provide a clear and easily accessible mechanism for individuals to withdraw their consent and ensure that it is as simple to withdraw as it was to give consent. We maintain records of individuals’ consent, including the information provided to them, the time and date of consent, and the method by which consent was obtained, which helps us demonstrate compliance if required.
By adhering to these principles, we ensure compliance with GDPR requirements, protect client data, and foster trust and transparency with our clients. We regularly review and update our data protection policies, implement appropriate technical and organisational measures, and provide ongoing training to employees to maintain compliance with GDPR as an accounting company.



















