Controller and processor roles
A controller determines why and how personal data is processed; a processor handles it on the controller’s behalf. Compliant expects to act as processor for contracted client-case work and as an independent controller for limited business-administration, security, accounting and legal records. The engagement documents must confirm the real arrangement.
What the written terms should cover
- Subject matter, duration, nature and purpose of processing
- Types of personal data and categories of data subject
- Documented instructions and confidentiality duties
- Security measures, access and authentication
- Subprocessor approval and contractual flow-down
- Help with rights requests, breaches, DPIAs and regulator enquiries
- Return or deletion at the end of the service and audit information
Special-category and high-risk case data
Paraplanning cases may contain health, vulnerability, identity, bank and source-of-funds information. Firms should minimise the pack to what the agreed work actually needs, identify the relevant lawful basis and special-category condition, provide appropriate transparency, and complete a DPIA where the processing is likely to result in high risk.
Compliant data-handling boundary
- No client data through the public website or its forms
- Client material only through the approved secure adviser route after onboarding
- Individual access for authorised users
- Retention and deletion governed by written terms, legal requirements and documented exceptions
- The adviser firm retains the official regulatory record
Frequently asked questions
Is the adviser firm always the controller and the paraplanner always the processor?
No. Roles depend on who determines the purposes and means of each processing activity. The common case-work model may be firm-as-controller and paraplanner-as-processor, but the parties must assess and document the facts.
Is client permission enough to share data with an outsourced paraplanner?
No. Permission or transparency may be relevant, but it does not replace a lawful-basis assessment, data minimisation, security, transparency duties or the written processor terms required where Article 28 applies.
How long will Compliant keep working copies?
Retention and deletion requirements are governed by the written engagement terms, applicable legal requirements and documented exceptions. The engaging firm remains responsible for the regulatory record.
Primary sources
This is general information, not a firm-specific UK GDPR assessment or legal advice.