Data Processing & Security Statement
UK GDPR Article 28 Framework & Cross-Border Governance
1. Operating as a Data Processor
When a UK accountancy practice engages Ferret BizServe Pvt. Ltd. to perform bookkeeping reconciliations, VAT preparations, or year-end accounts support, the UK practice acts as the Data Controller and Ferret BizServe acts as the Data Processor under Article 28 of the UK General Data Protection Regulation (UK GDPR).
Ferret processes client financial records and personal identifiers strictly on the documented, written instructions of the UK practice, and never for our own commercial purposes.
2. Article 28 Processor Commitments
In accordance with UK GDPR Article 28(3), Ferret contractually commits that it shall:
- Process personal data only on documented instructions from the controller, including regarding international data transfers.
- Ensure that all personnel authorised to process personal data have committed themselves to strict non-disclosure obligations.
- Take all technical and organisational measures required pursuant to Article 32 (Security of Processing).
- Not engage any subprocessor without the prior specific or general written authorization of the UK practice.
- Assist the controller by appropriate technical and organisational measures in responding to data subjects exercising their Chapter III rights.
- Assist the controller in ensuring compliance with Articles 32 to 36 (security, breach notification, impact assessments).
- At the choice of the controller, delete or return all personal data after the end of the provision of services.
- Make available to the controller all information necessary to demonstrate compliance and allow for audits conducted by the controller.
3. UK International Data Transfer Agreement (IDTA)
Because production occurs in India, international transfers are governed by the Information Commissioner’s Office (ICO) approved International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs).
We provide a standardized Transfer Risk Assessment (TRA) pack that details our compensating security controls, ensuring UK practice compliance files are complete and audit-ready.
4. Subprocessor Register Policy
Ferret BizServe operates its core production support through directly employed staff in our access-controlled facilities. We maintain an up-to-date Subprocessor Register covering third-party infrastructure providers (e.g. enterprise cloud email and document management tools).
No client accounting work is ever subcontracted to freelance individuals or external third-party production agencies without express written consent from the contracting practice.
5. Data Breach Notification SLA
In the event of a confirmed or suspected personal data security incident affecting client data, Ferret BizServe guarantees notification to the contracting UK practice within 24 hours of confirmation, accompanied by technical details and remedial actions taken.