Privacy Notice
The Little Bookkeeping Company — Last updated: 1st September 2026
Who we are
The Little Bookkeeping Company ("we", "us", "our") provides bookkeeping, payroll, and Self-Assessment tax services to sole traders and small businesses. We are the data controller for the personal data described in this notice — meaning we decide how and why your personal data is processed, and we are responsible for complying with data protection law in relation to it.
As a sole practice, we don't have separate staff or an appointed Data Protection Officer — Molly Harrington is both the data controller and the point of contact for any data protection query or concern.
The data protection principles we follow
In handling your personal data, we follow the principles set out in UK GDPR. Your data will be:
- Processed lawfully, fairly, and transparently
- Collected only for the specific purposes explained in this notice
- Adequate, relevant, and limited to what's necessary for those purposes
- Kept accurate and up to date
- Kept only for as long as necessary (see "How long we keep your data" below)
- Kept secure, with appropriate technical and organisational protections in place
What personal data we collect
- Contact details — name, address, phone number, email
- Business details — business name and structure, UTR, VAT number, National Insurance number
- Financial data — bank and credit card statements, transaction data, invoices, payroll records
- ID verification data — passport or driving licence, proof of address, collected for anti-money laundering (AML) checks
- Software access data — login or access permissions to your cloud accounting software (e.g. Xero, QuickBooks, FreeAgent)
- Communication records — emails, call notes, and other correspondence with us
We do not intentionally collect special category data (such as health, racial or ethnic origin, or religious belief data). Where payroll processing incidentally involves a reason connected to special category data (for example, statutory sick pay), we use only what's strictly necessary to process that entry correctly, and do not use it for any other purpose.
How we collect it
- Through the discovery call form on our website
- Directly from you, by email, secure upload, or onboarding form
- From your cloud accounting software once you've granted us access
- From your previous accountant or bookkeeper, only with your explicit permission, for professional clearance
- From HMRC or Companies House where relevant to the services we provide
Why we process your data, and our lawful basis
| Purpose |
Lawful basis |
| Providing the bookkeeping, payroll, or tax services you've engaged us for |
Contract |
| Carrying out ID verification / AML checks |
Legal obligation (Money Laundering Regulations 2017) |
| Filing with HMRC and holding agent authorisation |
Legal obligation |
| Contacting your previous accountant/bookkeeper for clearance |
Your explicit consent |
| Keeping financial and compliance records |
Legal obligation |
| Responding to your queries and requests |
Legitimate interest (providing you with a responsive service) |
We only process your data for the purposes set out here. If we ever needed to use it for a new purpose not covered by this notice, we would contact you first to explain and, where required, ask for your consent.
Who we may share your data with
- HMRC, for filing and agent authorisation purposes
- Cloud accounting software providers (e.g. Xero, QuickBooks, FreeAgent) that you choose to use
- Google Workspace Drive, used as our secure file transfer service, for receiving ID documents and financial and personal records
- DocuSeal, used for securely signing agreements between you and us
- The Institute of Certified Bookkeepers (ICB), our professional body, where required for compliance
- Your previous accountant or bookkeeper, only with your explicit written permission, for professional clearance
- Our professional indemnity insurer, only if ever required in connection with a claim
We do not sell your personal data to third parties, and we do not use your data for marketing purposes.
International transfers
Some of the third-party providers we use may store data outside the UK or EEA. Where this happens, we only use providers with appropriate safeguards in place, such as a UK adequacy decision or Standard Contractual Clauses.
How long we keep your data
- Financial and accounting records — a minimum of 5–6 years, in line with HMRC record-keeping requirements
- AML/customer due diligence records (ID documents, risk assessments) — 5 years from the end of our business relationship, as required under the Money Laundering Regulations 2017
- General correspondence — kept only as long as necessary for the purpose it was collected for
Once data is no longer needed for any of the above purposes, we take reasonable steps to securely delete or destroy it.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Ask us to correct inaccurate or incomplete data
- Ask us to delete your data ("right to be forgotten"), subject to our legal retention obligations
- Restrict or object to certain processing
- Request your data in a portable format, or transferred to another data controller
- Not be subject to decisions based solely on automated processing (we do not carry out any automated decision-making or profiling)
- Be notified without undue delay if a data breach affects your rights and freedoms
- Withdraw consent where we rely on it (e.g. contacting a previous accountant)
To exercise any of these rights, contact us using the details above.
Verifying your identity
If you contact us by phone to request or discuss your personal data, we may need to confirm your identity before disclosing anything, or ask you to put the request in writing. This is to make sure your information is only ever given to you.
Responding to your request
We will respond within one month of receiving your request. If a request is particularly complex, we may extend this by up to two further months and will explain why. We do not charge a fee for reasonable requests; a small administrative fee may apply only if a request is manifestly unfounded, excessive, or repetitive.
How we keep your data secure
- User-restricted, password-protected file transfer for ID, personal, and financial documents, via Google Workspace Drive
- Access to client records and cloud accounting software is password-protected
- Two-factor authentication enabled on all devices holding sensitive data
- Any paper records are kept in a locked location and disposed of by secure shredding once no longer needed
- We only share your data with the specific third parties listed above, and only to the extent needed for the purposes described
Complaints
If you're unhappy with how we've handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Changes to this notice
We may update this notice from time to time. The latest version will always be available on our website.