AOPA Association of Practising Accountants in the UK

Privacy Policy

How we collect, use and protect your personal data.

Last updated: July 2026

This Privacy Policy explains how the Association of Practising Accountants UK (“AOPA”, “we”, “us”) collects, uses and protects your personal data when you use our website and services. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are (data controller)

AOPA is the data controller for the personal data described in this policy. You can contact us at [email protected] or by post at 1 Fleet Place, London EC4M 7RA, United Kingdom.

2. The data we collect

  • Membership & account data — name, email, phone, city, firm name and designation (individuals); firm name, contact details, professional body, offices, team and services (firms).
  • Transaction data — payment references and any proof of payment you upload for paid packages or events.
  • Usage data — pages visited and similar analytics, collected only where you consent to analytics cookies (see our Cookie Policy).
  • Communications — messages you send us and your newsletter preferences.

3. How and why we use your data (lawful bases)

  • To provide membership and directory services — performance of a contract with you.
  • To display firm listings publicly — your consent, given when you activate the listing.
  • To send service emails (verification codes, receipts, renewal reminders) — contract / legitimate interests.
  • To send newsletters — your consent, which you may withdraw at any time via the unsubscribe link.
  • To keep records and meet legal obligations — legal obligation / legitimate interests.

4. Sharing your data

We do not sell your personal data. Firm directory details you choose to publish are visible to the public. We share data with service providers who help us operate (for example email delivery and website hosting) under appropriate contracts, and with authorities where required by law.

5. International transfers

Where a provider processes data outside the UK, we rely on adequacy regulations or appropriate safeguards (such as the International Data Transfer Agreement) to protect your data.

6. Retention

We keep personal data for as long as you hold membership or an account with us, and thereafter only as long as necessary for our legitimate business and legal obligations, after which it is securely deleted.

7. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. To exercise any of these rights, email [email protected].

8. Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit and access controls. No method of transmission over the internet is completely secure, but we work to protect your data and to notify you and the regulator of any breach where required.

9. Cookies

We use essential and (with your consent) analytics cookies. See our Cookie Policy for details and how to change your choice.

10. Complaints

If you have a concern about how we handle your data, please contact us first. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

11. Changes

We may update this policy from time to time; the current version is always available on this page.

For any privacy question, contact [email protected].