ACSP

Privacy Notice (GDPR)

1) Who we are

JSA Partners London Ltd (“we”, “us”, “our”) is the controller of your personal data. We take your privacy and data security extremely seriously and handle your information in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are registered with the Information Commissioner’s Office (ICO).

If you have any questions about this notice or how we use your data, contact:

For consent-related queries you can also email: [email protected]

This notice applies to current and former clients, employees, workers and contractors. It does not form part of any contract. We may update this notice and may issue additional privacy notices for specific services.


2) Our data protection principles

We comply with the six core principles of UK GDPR. We will:

  1. Process personal data lawfully, fairly and transparently.
  2. Collect data for specified, explicit and legitimate purposes and not use it in incompatible ways.
  3. Limit processing to what is adequate, relevant and necessary.
  4. Keep data accurate and up to date.
  5. Keep data only as long as necessary.
  6. Keep data secure.

3) The data we collect

“Personal data” means information that identifies you. We may collect and use:

  • Contact details: name, title, address, email, phone.
  • Identifiers: date of birth, gender, marital status, National Insurance number, UTR, HMRC 64-8/authorisations.
  • Financial & payroll data: bank details, salary, tax/NIC, pension, benefits, leave.
  • Identity/KYC: copies of passport, driving licence or other photo ID, address proofs (for AML/KYC).
  • Employment records: roles, history, hours, training, memberships, P45/P60, prior salary, private pension info.
  • Business records (clients): income/expense details, engagement documentation.

Special category data (e.g., ethnicity, trade union membership) is collected only where strictly necessary and protected with higher safeguards.


4) How we collect your data

  • Directly from you during onboarding or service delivery.
  • Third parties (where lawful), e.g., Companies House, HMRC, screening/verification providers.
  • Ongoing engagement as we provide services (e.g., payroll, tax returns, accounts).

We are legally required to obtain and retain certain KYC/AML documents (photo ID and proof of address).


5) How and why we use your data (lawful bases)

We process personal data where one or more of the following apply:

  • Contract: to perform our engagement/letter of engagement or other contract with you.
  • Legal obligation: to meet legal, tax, AML/KYC and regulatory requirements.
  • Legitimate interests: to manage and grow our business (e.g., client service, audits), where your rights do not override these interests.

Typical purposes include:

  • Setting up and administering engagements; preparing accounts, tax returns, and payroll.
  • Liaising with pension providers (e.g., NEST) and HMRC; calculating tax/NIC.
  • Business management, accounting and auditing (for you and for us).
  • Handling queries, performance and service quality, and resolving disputes.
  • Fraud prevention and complying with AML regulations.

If you do not provide information we need to meet our legal or contractual duties, we may be unable to provide some or all services.


6) Special category data

We will only process special category data if:

  • you give explicit written consent;
  • it is necessary for legal obligations or the exercise of rights; or
  • it is required for reasons of substantial public interest (or for legal claims, vital interests, or where you have made the data public).

7) Automated decision-making

We do not routinely make decisions based solely on automated processing that have legal or similarly significant effects on you. If this changes, we will tell you and explain your rights (including the right to human review).


8) Sharing your data

We may share your data with:

  • Service providers/Processors (e.g., IT, payroll platforms, pension administrators) under contract and confidentiality.
  • Regulators and authorities (e.g., HMRC, ICO) where required by law.
  • Professional advisers (e.g., auditors, lawyers).
  • Another organisation in the event of a business sale or reorganisation.

All third parties must process your data only on our instructions and keep it secure.


9) International transfers

If we transfer personal data outside the UK/EEA, we will ensure an adequate level of protection using recognised safeguards (e.g., UK International Data Transfer Agreement or EU Standard Contractual Clauses with UK Addendum), or rely on adequacy regulations where available.


10) Data security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or loss. We maintain procedures to detect, respond to and notify (where legally required) any suspected data breach.


11) Data retention

We keep personal data only as long as necessary for the purposes set out above and to satisfy legal, accounting and regulatory requirements. When no longer needed, data is securely deleted or anonymised.


12) Your rights

You have rights under data protection law, including to:

  • Access your data (subject access).
  • Rectify inaccurate or incomplete data.
  • Erase your data (where applicable).
  • Object to processing based on legitimate interests or to direct marketing.
  • Restrict processing in certain circumstances.
  • Port your data to another controller (where technically feasible).

To exercise your rights, contact Mr Mark Hall – [email protected]. We may need to verify your identity. You won’t usually pay a fee; we may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive.

Withdrawing consent

Where we rely on your consent (limited situations), you can withdraw it at any time by emailing [email protected]. This won’t affect processing carried out before withdrawal if we have another lawful basis.

Complaints

You can complain to the ICO at any time. We would appreciate the chance to address your concerns first, so please contact us.


13) Changes to this notice

We may update this notice to reflect changes in law or our practices. We will post the latest version on our website and, where appropriate, notify you by email or within our engagement materials.


Controller: JSA Partners London Ltd
DPO/Data Protection Lead: Mr Mark Hall – [email protected]
General privacy/consent queries: [email protected]