Virtual Assistants for UK Consultancies: A Compliance-First Guide
It is 9:15 on a Thursday evening and the managing partner of a fourteen-person change consultancy in Bristol has four things open on one screen.
The first is a master services agreement with a financial services client. Clause 14.3 requires written notice before any subcontractor is given access to client materials, and she is fairly sure — not certain, which is the problem — that nobody sent that notice before the freelance researcher started pulling together the stakeholder map.
The second is a spreadsheet a client’s HR director emailed over three weeks ago. It contains 340 rows of employee names, job grades, line managers and exit-interview comments. It is sitting in her inbox. It has been forwarded twice.
The third is a proposal due at midday tomorrow, at 60% complete, which she will finish somewhere around 1 a.m.
The fourth is an unread email from her insurance broker with the subject line “PI renewal — AI usage questionnaire.”
None of these four things is consulting. All four of them are the business. And every one of them is the kind of task that gets pushed to the end of the day, done at speed, by the most expensive and most tired person in the firm.
This is the shape of the problem in UK consultancies right now. Not a shortage of expertise. Not a shortage of demand — <cite index=”31-1″>the MCA’s 2026 Annual Industry Report, produced with Oxford Economics, puts UK consulting at roughly £21.8bn, with member firms generating £10.9bn in fee income in 2025 and average fee income up 3%</cite>. <cite index=”26-1″>Firms are forecasting a 6% revenue increase in 2026 and 8% in 2027, with 88% expecting to grow this year</cite>. The problem is that the administrative and compliance load attached to each engagement has grown faster than anyone’s capacity to absorb it, and consultancies have been absorbing it by quietly donating evenings.
There is a way out of it. But for a consultancy, the way out has a condition attached: whoever takes the work on has to be someone you can put in front of a client’s procurement team without flinching. That condition rules out most of the obvious options, and it is why “get a VA” and “get a compliant VA” are two entirely different projects.
The Admin Load Nobody Prices Into a Day Rate
Start with the number that governs everything in a consultancy: utilisation.
<cite index=”3-1″>The 2025 Professional Services Maturity Benchmark put billable utilisation for consultants at 68.9%, below the 75% widely treated as the working ideal</cite>. <cite index=”6-1″>In management consulting, just under 70% is typical for firm-wide billable utilisation, and the trend has been downward across the board</cite>. For independents the picture is starker: <cite index=”2-1″>most consultants achieve 60–80% billable utilisation, meaning 20–40% of the working year disappears into business development, administration and keeping current</cite>.
Look at what that means in cash. <cite index=”5-1″>The median UK consulting day rate across specialisms sits at £550, with management consultants higher at £623, and most independents bill 180–220 days a year — the rest vanishing into proposals, invoices that take 45 days to clear, and the gaps between engagements</cite>. At a firm level the arithmetic is unforgiving: <cite index=”4-1″>moving from 65% to 75% utilisation for a consultant billing $100/hour adds over $20,000 in annual revenue per head, and misclassifying two or three hours per consultant per week can cost a ten-person firm $200,000 a year</cite>.
A consultancy that recovers five hours a week per fee-earner is not saving admin time. At £550 a day it is finding roughly £34,000 a year, per person, that was already inside the building.
Here is the part that gets missed. The admin doesn’t just cost the hours it takes. It costs the hours either side of it — the reorientation, the half-finished analysis you come back to cold, the proposal you write at 11 p.m. because the day was eaten. And in a consultancy, unlike in most businesses, a meaningful slice of that admin is not merely tedious. It is legally consequential. Getting the DPA wrong, the subcontractor notice wrong, or the data handling wrong does not produce a messy desk. It produces exposure.
Which is why, for consultancies specifically, the delegation conversation has to start at compliance and work backwards — not start at cost and hope compliance sorts itself out.
What “Compliance-First” Actually Means for a Consultancy
When a consultancy brings in outside support, three separate obligations switch on at once. They are frequently confused with one another, and confusing them is how firms end up technically in breach while feeling entirely comfortable.
Obligation one: data protection law. If a client’s personal data — employee records, customer lists, survey responses, interview transcripts — passes through your engagement, you are handling personal data under the UK GDPR and the Data Protection Act 2018. Your role may be controller, joint controller or processor depending on the engagement, and the answer changes what you owe. <cite index=”84-1″>The ICO can issue penalties up to the higher of £17.5m or 4% of global annual turnover for serious infringements, and breaches likely to risk people’s rights must be reported within 72 hours of awareness</cite>.
Obligation two: contract. Your MSA, your framework agreement, your client’s supplier code. These almost always contain confidentiality provisions, subcontracting restrictions, security schedules and flow-down clauses that bite independently of statute. <cite index=”20-1″>Well-drafted outsourcing confidentiality terms restrict access to staff and subcontractors on a genuine need-to-know basis, deal expressly with offshore teams and sub-processors, set rules for storage, deletion and end-of-contract audit evidence, and include prompt breach notification obligations</cite>. A firm can be perfectly UK GDPR compliant and still be in repudiatory breach of its largest client contract.
Obligation three: professional and insurance standards. Professional indemnity cover, any institute or chartered body obligations, and increasingly a client’s own AI and third-party usage policies. <cite index=”18-1″>Indemnity clauses in confidentiality agreements function more like debt obligations than damages claims, making recovery against the breaching party easier — which is precisely why clients ask for them</cite>.
A compliance-first approach to virtual assistant support means addressing all three before anyone is given a login. Not after. The order matters, because the most common failure mode in this market is a firm that engages someone capable, gets good work for four months, and then discovers during a client audit that the arrangement was never papered.
The International Transfer Question, Answered Properly
This is the section most articles on offshore support skip, or fudge, or wave at with a reassuring sentence about “GDPR-compliant partners.” It deserves to be done properly, because it is the single question a client’s legal team will actually ask.
If you are a UK consultancy and you send personal data to someone outside the UK, you are making what the ICO calls a restricted transfer. <cite index=”15-1″>The ICO’s guidance — updated with a new brief guide to international transfers in January 2026 — sets out the sequence: rely on UK adequacy regulations if they cover the destination; if not, use an Article 46 safeguard such as the International Data Transfer Agreement, and complete a transfer risk assessment alongside it; if neither is available, an Article 49 exception must apply, and if none does, the transfer must not happen</cite>.
South Africa does not currently have UK adequacy status. That is not a disqualifier — it is a routing instruction. <cite index=”11-1″>As of March 2026, no adequacy decisions cover Brazil, China, India, or most of Africa, meaning organisations transferring personal data to those destinations rely on standard contractual clauses or binding corporate rules and maintain documented transfer impact assessments for each transfer</cite>. In other words: the overwhelming majority of the world’s offshore delivery locations sit in exactly the same position. The question is not whether adequacy exists. It is whether your provider has the paperwork.
The mechanics are well established. <cite index=”14-1″>The IDTA is a standalone contractual tool published by the ICO on 21 March 2022 for UK transfers to non-adequate countries; alternatively, organisations using the EU standard contractual clauses must append the ICO’s UK Addendum, also effective 21 March 2022, to satisfy UK requirements</cite>. <cite index=”17-1″>Since Schrems II, regulators expect a transfer risk assessment analysing the laws of the recipient country and the scope for government access — adequacy or SCCs alone are no longer sufficient</cite>.
Then there is the other direction, which almost nobody thinks about. South African law imposes its own conditions on data leaving South Africa. <cite index=”12-1″>POPIA, effective 1 July 2021, prohibits cross-border transfers unless the recipient is subject to laws, binding corporate rules or agreements providing protection substantially similar to POPIA, or the data subject consents, or the transfer is necessary for contract performance; it uniquely extends protection to juristic persons as well as natural ones, and carries administrative fines up to ZAR 10 million</cite>. <cite index=”13-1″>Under section 72, the responsible party remains liable even where the transfer is contractually papered</cite>.
The practical consequence for a UK consultancy is that a South African delivery partner is operating inside a regime that was built to be recognisable to a GDPR-trained lawyer. <cite index=”47-1″>POPIA aligns closely with GDPR standards, which puts South Africa among the small number of outsourcing destinations where UK businesses can maintain compliance without extensive legal contortion</cite>. That alignment does not remove the IDTA. It means the person on the other end of it already understands why it exists.
Adequacy is not the test. Documentation is the test. A provider who can hand you an executed IDTA, a completed transfer risk assessment, and a data processing agreement with named sub-processors has answered the only question your client’s counsel is going to ask.
The Clause in Your Client Contract You Probably Haven’t Read
Data protection law is the visible risk. Contractual risk is the one that actually bites consultancies, because consulting MSAs are unusually restrictive about who touches what.
Three clauses are worth pulling up tonight.
Subcontractor consent. Most MSAs require either prior written consent or advance notification before a third party is given access to client confidential information. Engaging a freelancer through a marketplace, without notice, is a breach — regardless of how well the freelancer performs. <cite index=”24-1″>Once an NDA is signed, the parties named in it cannot disclose the specified information to anyone unauthorised to receive it</cite>. A subcontractor who is not named and not covered is, by default, unauthorised.
Flow-down. Client obligations on security, confidentiality, retention and deletion typically have to be imposed on anyone downstream. That means your VA arrangement needs its own NDA, its own DPA, and its own security commitments that are at least as strict as the ones you gave the client.
Liability and indemnity. This is where the money is. And the regulatory picture has shifted meaningfully in the last two years in a way that should concentrate minds.
Historically, controllers carried the regulatory risk and processors sat behind them. That is no longer safe to assume. <cite index=”83-1″>The ICO’s notice of intent to fine Advanced Computer Software Group £6.09m was the first instance of the regulator pursuing a processor for breach of its own obligations, under Article 32, for failing to implement appropriate technical and organisational measures — with absence of multi-factor authentication on a customer account alleged to have enabled the attack</cite>. <cite index=”79-1″>The final penalty of £3.07m confirmed that processors can face enforcement where deficiencies in their security measures caused or contributed to a breach</cite>. <cite index=”85-1″>Under the UK GDPR, processors can be held equally or more liable than controllers depending on relative negligence and culpability</cite>.
Enforcement has continued in that direction. <cite index=”81-1″>In the final quarter of 2025 the ICO issued GDPR fines totalling £15 million against Capita, Capita Pension Solutions and LastPass UK — with the LastPass calculation based on the global revenue of its holding company, producing a penalty representing around 8.5% of turnover</cite>. <cite index=”82-1″>Every major 2025 UK GDPR fine cited the same root causes — missing MFA, slow containment, inadequate vulnerability management, weak segmentation, incomplete security testing — and 2026 enforcement is expected to keep its focus on processors and supply-chain suppliers following the Advanced precedent</cite>.
For a consultancy, the read-across is direct. Your client is thinking about supply chain. Your client’s insurer is thinking about supply chain. The support arrangement you treat as an internal convenience is, in their eyes, part of the chain.
The Human in the Loop
There is a version of this article that ends here with “so use AI instead — no transfers, no subcontractors, no NDAs.” That version is wrong, and 2025 provided the case study that proves it.
<cite index=”41-1″>Deloitte’s Australian member firm agreed a partial refund on a A$440,000 report for the Department of Employment and Workplace Relations after it was found to contain references to non-existent academic papers and a fabricated quote attributed to a federal court judgment</cite>. <cite index=”38-1″>The errors in the 237-page report included fabricated academic references complete with non-existent experts and studies, a made-up quotation from a Federal Court judgment with the judge’s name misspelled, and references to fictitious case law — flagged by Dr Chris Rudge of the University of Sydney</cite>. <cite index=”36-1″>Deloitte acknowledged using an LLM, Azure OpenAI GPT-4o, and updated the report, noting the revisions did not change its overall findings or recommendations</cite>.
Read that as a consultancy rather than as a spectator. A tier-one firm, with tier-one review processes, on a politically sensitive brief, shipped fabricated citations to a government client. The failure was not the model. The failure was the absence of a person whose job was to check.
The Deloitte incident was not an AI failure. It was a supervision failure that an AI made visible. In consulting, the deliverable is credibility — and credibility is checked line by line or it isn’t checked at all.
Industry commentary landed in the same place. <cite index=”68-1″>One analysis framed it as a governance gap where firms adopted generative tools without formalising roles, verification frameworks, transparency protocols and human-in-the-loop oversight — with the observation that the race to be first needs to be a race to be right</cite>.
The confidentiality dimension is worse, and quieter. <cite index=”63-1″>One large security monitoring firm found that roughly 11–12% of the information employees paste into ChatGPT is confidential</cite>. <cite index=”64-1″>In November 2025 the Upper Tribunal considered the conduct of a solicitor who had put client emails and official decision letters into ChatGPT to improve drafting and summarise documents for clients; he had recognised it as a data breach himself</cite>. <cite index=”61-1″>And in early 2026, researchers documented a previously unknown vulnerability enabling silent data leakage from ChatGPT conversations without user knowledge or consent — since resolved, but a reminder that AI tools should not be assumed secure by default</cite>.
The serious response is not abstinence. It is architecture. <cite index=”65-1″>A tiered containment model is emerging as the professional-services standard: firm-hosted AI with no external API calls for the most confidential work; enterprise AI with a contractual prohibition on training for general client work; and public tools only for non-client internal tasks — with enterprise agreements contractually barring training on submitted data</cite>. <cite index=”66-1″>Every use case needs a defined human review layer calibrated to acceptable error rates</cite>.
That review layer is a person. Not a policy document, not a setting. Someone who knows which client’s data may go into which tool, who checks whether a citation exists before it reaches a deck, who notices that the summary of the stakeholder interview has invented a job title. Automation is genuinely good at producing volume. It is structurally incapable of holding accountability, and accountability is the entire product a consultancy sells.
A trained assistant operating the software, inside your policy, under supervision, gives you the throughput of the tool and the judgement of a human. Pure automation gives you throughput and a refund letter.
The South African Advantage
Given all of the above, the destination question becomes specific: which talent market gives a UK consultancy the compliance posture, the working-day overlap, and the communication register it can put in front of a client?
Timezone: a working day, not a handover
South Africa runs on GMT+2. <cite index=”50-1″>That is two hours ahead of the UK, producing a full 6–8 hour overlap every working day — real-time collaboration on Teams, Slack and Zoom with no overnight gaps</cite>. South Africa does not observe daylight saving, so the gap moves between one and two hours across the year and never inverts.
For consultancy work this matters more than it does almost anywhere else, because consultancy admin is iterative. A proposal goes through four rounds before it goes out. A deck gets restructured after the client call. A data request comes back incomplete and needs chasing the same afternoon. In the Philippines, at GMT+8, each of those round trips costs a day. In South Africa, the assistant is at their desk when your client emails at 10 a.m. London time — and can also take an 8 a.m. handover, since 8 a.m. in London is 10 a.m. in Cape Town, mid-morning rather than pre-dawn.
There is a second-order effect worth naming: the extended day. Work handed over at 5 p.m. London time lands with someone who is finishing at 7 p.m. their time. A tender formatted overnight, a research pack assembled, an invoice run prepared — waiting at 8:30 the next morning.
English, and the register underneath it
Fluency is table stakes. Register is the differentiator, and consultancy is a register-heavy business. <cite index=”48-1″>South Africa operates under common law inherited from British legal history, English is the primary business language, and South Africans are educated in British-influenced academic systems — with the country ranking among the top ten globally for English proficiency on EF’s index</cite>.
Anyone can write “please find attached.” Far fewer can judge when a client’s silence on a scope question means agreement and when it means a problem, or write a chase email to a FTSE 250 procurement contact that is firm without being brittle. British professional communication runs on understatement, hedging and implication. Getting it wrong in a proposal doesn’t just read oddly — it costs the bid. <cite index=”50-1″>VAConnect matches client-facing placements for exactly this, and trains its people on the tools UK firms actually run: Xero, HubSpot, Monday.com and Microsoft 365</cite>.
Compliance fluency, not just compliance paperwork
This is the part that is difficult to buy elsewhere. <cite index=”48-1″>A virtual assistant in Manila might speak excellent English but lack the legal and cultural framework to understand UK regulatory requirements intuitively — whereas a South African VA trained in POPIA, which closely mirrors GDPR, recognises the documentation requirements of a subject access request and understands the one-month response window immediately</cite>.
<cite index=”46-1″>POPIA and GDPR share architecture: both establish frameworks for data subject rights, processing limitations and accountability. When a UK business shares a customer list with a South African VA, POPIA’s baseline provides assurance that simply does not exist in jurisdictions with no equivalent legislation</cite>. <cite index=”46-1″>VAConnect addresses security through specific mechanisms — all VAs sign comprehensive non-disclosure agreements, system access follows the principle of least privilege, and the company carries professional indemnity insurance — in contrast to the gig-platform model, where freelancers work from home offices with minimal security infrastructure and no contractual relationship with the platform itself</cite>. <cite index=”49-1″>South African VAs operate under data processing agreements aligned to UK GDPR requirements, with documented right-to-audit provisions and breach notification protocols</cite>. <cite index=”48-1″>Continuous training on both frameworks runs through VAVarsity, VAConnect’s proprietary learning platform</cite>.
Cost against quality, and the trap in between
The UK numbers are the numbers. <cite index=”77-1″>Glassdoor puts the average UK executive assistant salary at £43,389 as of June 2026, with a typical range of £34,172 to £55,892</cite>, and <cite index=”75-1″>Lily Shippen’s 2026 survey places London EA salaries between £50,000 and £70,000 with a median around £54,500</cite>. Then add the loading. <cite index=”71-1″>Employer National Insurance increases from April 2025, rising to 15%, added roughly 2–3% to the total cost of permanent hires, and average time-to-hire for senior EA roles moved from six weeks in 2023 to eight weeks in 2025</cite>. <cite index=”50-1″>Against a London PA at £35K–£50K plus NI, pension and office space, VAConnect’s model removes PAYE, employer NI and auto-enrolment administration entirely — employment and compliance sit on their side</cite>.
But cost is the wrong headline for a consultancy, and it is worth saying plainly. If the cheapest option produces a confidentiality breach on a regulated client’s data, the saving is irrelevant within a week. <cite index=”46-1″>One documented pattern is telling: UK firms typically discovered they were non-compliant only when enforcement arrived — a Manchester e-commerce company found its email marketing breached GDPR after a £15,000 penalty, and a Bristol consulting firm learned its retention policies breached POPIA when a complaint reached the Information Regulator</cite>. In that second case the reported damage was not the fine. It was losing three major clients who no longer believed the firm could protect data.
What a Consultancy VA Actually Handles
Six workflows, in the order most firms should hand them over.
1. Bid and proposal coordination. Assembling the response pack, populating the standard sections, chasing CVs and case studies from fee-earners, formatting to the client’s template, tracking portal deadlines, managing the clarification-questions log. The partner writes the win themes. The VA does everything around them.
2. Client onboarding and the compliance pack. Issuing and tracking NDAs, chasing countersignatures, maintaining the DPA register, logging which client requires subcontractor notification and whether it was given, keeping the sub-processor list current, filing security questionnaires and diarising renewal dates. This is a register-keeping job, and register-keeping is exactly what gets skipped at 9 p.m.
3. Research and deliverable production. Desk research, source verification, data gathering, deck build and formatting, version control, appendix assembly. Note the second item on that list. In a post-Deloitte market, “check that every citation resolves to a real document” is a named task with a named owner.
4. Diary, travel and stakeholder logistics. Multi-party workshop scheduling across client organisations, room and travel booking, pre-reads circulated 24 hours ahead, actions captured and distributed the same day.
5. Time capture, invoicing and credit control. Chasing timesheets before month-end rather than after, preparing draft invoices against the engagement letter, submitting through client portals, and running polite, persistent aged-debt follow-up. Given that most independents wait around 45 days for payment, this workflow frequently pays for the VA outright.
6. CRM and knowledge hygiene. Keeping the pipeline current, logging conversations, maintaining the case study and credentials library so the next bid does not start from a blank page, and enforcing retention and deletion schedules at engagement close.
What a VA Must Not Do
A compliance-first guide that only lists capabilities is not a compliance-first guide. The boundary matters as much as the scope.
A virtual assistant does not exercise professional judgement on a client engagement. They do not sign off a deliverable, approve a recommendation, determine a lawful basis for processing, decide what falls inside a scope variation, or give advice of any kind to a client. They do not act as your data protection officer, and they are not the person who decides whether a transfer risk assessment is adequate.
They prepare, coordinate, verify, chase and document. You decide.
The principle underneath this is worth stating in one line, because it is the line firms get wrong: delegating the task is not delegating the accountability. The regulator, the client and the professional indemnity insurer will all look to the firm. A good support arrangement makes that accountability easier to discharge — better records, fewer missed dates, cleaner evidence trails. It never transfers it.
The First 90 Days
Weeks 0–2, before any access is granted. NDA executed. Data processing agreement in place with named sub-processors. IDTA or UK Addendum executed, with a completed transfer risk assessment on file. Client contracts reviewed for subcontractor notification requirements, and notices sent where required. Tool policy written down: which client data may go into which system, and which systems are prohibited. Access provisioned on least privilege, logged and reviewable.
Weeks 2–4. Start with the lowest-sensitivity, highest-volume workflow — usually diary, travel and invoicing. Standard operating procedures documented as the work is done rather than in advance, because the SOP that survives is the one written from live execution. First measurable output typically lands inside week one; full rhythm at two to four weeks.
Weeks 4–8. Expand into bid coordination and the compliance register. This is where the firm usually notices the change, because it is the first time proposal deadlines stop being personal crises.
Weeks 8–12. Research and deliverable production, with verification protocols explicit. By this point the assistant knows the clients, the templates and the register. Run a review: what came back, what is still landing on partners, what should move next.
<cite index=”50-1″>If the placement is not performing, VAConnect replaces them — no fees, no friction — and most matches fill within two to three weeks</cite>.
The Gap Is Wider Than It Looks
What is genuinely surprising, looking across the sector in 2026, is not that some consultancies use offshore support and others don’t. It is how far apart the two groups have drifted on the same underlying economics.
<cite index=”31-1″>The MCA’s data shows a sector averaging 3% growth in 2025 — but that average conceals a split, with 52% of member firms reporting growth and 46% recording a decline</cite>. The firms in the top half are not, in the main, better consultants than the firms in the bottom half. They have solved a different problem. They have got the non-billable load off the fee-earners without creating a compliance liability in the process, which means their utilisation is higher, their bids go out finished rather than filed at 11:59, their invoices leave on time, and their partners are thinking about client problems on Thursday nights instead of clause 14.3.
The firms in the bottom half are doing all of it themselves, or handing it to whoever was cheapest on a marketplace, and hoping the client never audits.
<cite index=”29-1″>The MCA notes that 77% of firms have now integrated AI into their systems or enabled employees to use AI models</cite>. Nearly everyone has the tools. The differentiator was never the tools. It is whether there is a trained, contracted, supervised human standing behind them — and whether that human’s presence is something you can document to a client rather than something you hope nobody asks about.
That gap is not narrowing. It compounds, quarter by quarter, in the accounts.
DIY vs Generic Freelancer vs VAConnect
| DIY / In-House Scramble | Generic Freelancer or AI Tool | VAConnect Managed Consultancy VA | |
|---|---|---|---|
| Who does the admin | Fee-earners, after hours | Whoever is available that week | Dedicated, named assistant |
| Effect on utilisation | Drags 20–40% off billable time | Marginal; management overhead offsets gains | Recovers fee-earner hours directly |
| NDA coverage | Ad hoc, often unsigned | Platform terms only, rarely firm-specific | Comprehensive NDA signed before access |
| Data processing agreement | Usually absent | Rarely offered | In place, aligned to UK GDPR |
| International transfer paperwork | Not considered | Not considered | IDTA / UK Addendum plus transfer risk assessment |
| Regime alignment | N/A | Varies wildly by jurisdiction | POPIA — structurally close to GDPR |
| Access control | Shared logins, informal | Broad access, unlogged | Least privilege, logged and auditable |
| Subcontractor notice to clients | Frequently missed | Frequently missed | Documented, named, notifiable |
| Timezone overlap with UK | N/A | Often 7–8 hrs out (APAC) | GMT+2 — 6–8 hrs overlap, no DST drift |
| English register | N/A | Fluent but often US-inflected | British-matched, trained for client-facing work |
| Training | None | Self-taught, variable | VAVarsity before touching client systems |
| Continuity when absent | Work simply stops | Freelancer vanishes mid-bid | Managed cover and free replacement |
| AI oversight | Informal, undocumented | The tool is the process | Human verification layer inside firm policy |
| Professional indemnity | Firm carries all | None | Provider carries PI cover |
| Employment admin | PAYE, NI, pension, holiday cover | Contractor status questions | Handled entirely by VAConnect |
| Cost against a London EA | £43K–£70K plus ~15% employer NI, pension, space | Cheap per hour, expensive per error | Materially lower total cost, managed |
| Time to productive | 8+ weeks to hire, then ramp | Immediate, then unpredictable | Most matches filled in 2–3 weeks |
If your consultancy is running proposals at midnight, carrying client personal data in an inbox, and hoping nobody asks who else has seen it — the fix is not more discipline. It is a properly papered pair of hands in your working day.
Book a call → and we will walk you through the compliance pack before we talk about anything else.
This article is general information about operational and compliance practice and does not constitute legal advice. Firms should take their own advice on data protection obligations and contractual terms.
