Before using any third-party tool that touches client data, you need to understand exactly what data it processes and on what legal basis. PenaltyProof now monitors more than Companies House — it also tracks VAT, Corporation Tax, payroll, CIS, pension auto-enrolment, ICO renewals, MLR reviews, HMRC agent authorisations, and Charity Commission deadlines. This article explains precisely what data each part of the service reads and stores, what it never accesses, and the UK GDPR legal basis — so you can make an informed decision and satisfy any client or partner asking about your practice's data handling.
What the Companies House public API contains
Companies House operates a public register under the Companies Act 2006. All information on the register is, by definition, public — it is accessible to any person without authentication. The Companies House API makes this same public information available in a structured format.
The public API includes:
- Company name and company number
- Registered office address
- Director and officer names (where disclosed)
- Filing history (types of documents filed and dates)
- Confirmation statement due dates
- Annual accounts due dates and accounting reference period
- Company status (active, dissolved, liquidation, etc.)
- SIC codes and registered jurisdiction
The API does not contain, and Companies House does not publish, any financial figures from a company's accounts. Turnover, profit, balance sheet totals, tax records, payroll data, and bank account details are not available through the public register API.
What PenaltyProof reads and stores — and where it comes from
PenaltyProof uses two distinct sources of data:
1. Data fetched automatically from the Companies House public API
For each company number you add, PenaltyProof fetches the following from the public Companies House register on a daily basis:
- The next confirmation statement due date
- The next annual accounts due date
- The company name (for display in alerts)
- Company type (private or PLC, which affects the penalty schedule in alerts)
- Company status (to detect dissolution or strike-off)
No other fields from the CH API response are stored. This data comes from the public register — it is already publicly accessible to any person.
2. Obligation configuration data you enter
For HMRC and compliance alerts to work, PenaltyProof needs you to provide specific dates and settings for each client company. This is data you supply — PenaltyProof does not read it from HMRC or any other government system. The fields you can configure per company are:
- VAT: VAT stagger group (1, 2, or 3) and VAT scheme (standard, annual accounting, or cash accounting)
- Corporation Tax: CT period end date (and optional override for non-standard periods)
- Self Assessment: Whether the company is SA-registered
- Payroll / RTI: Whether PAYE is active and the usual pay day of the month
- P11D: Whether P11D expenses and benefits reporting applies
- CIS: Whether the company is a CIS subcontractor
- MTD ITSA: The quarterly election type (standard or calendar)
- Pension auto-enrolment: Staging date and, if applicable, re-declaration override date
- ECCTA: ID verification deadline (if applicable)
- ICO: Data Protection registration renewal date
- MLR: Date of last AML/MLR review
- HMRC agent authorisation: Date the 64-8 was granted
- Client contact email: An optional per-company email address for routing alerts to clients directly (distinct from your own accountant email)
All these fields are optional — you configure only the obligations relevant to each client. Fields you leave blank simply generate no alerts for that obligation type.
What PenaltyProof never sees or accesses
This is the critical point for accountants concerned about professional obligations under GDPR and client confidentiality:
- Client financial records. PenaltyProof has no access to your accounting software, client files, or any financial documents. It does not connect to Xero, QuickBooks, Sage, FreeAgent, or any bookkeeping platform.
- HMRC systems. PenaltyProof does not connect to HMRC's APIs or read any data from HMRC. The HMRC-related dates it stores (CT period end, VAT stagger group, pension staging date, etc.) are dates you enter — it has no automated feed from HMRC and cannot see your clients' tax returns, VAT submissions, payroll filings, or self-assessment records.
- Accounting records. Ledgers, trial balances, management accounts, and bookkeeping files are not involved in any way. The service is completely independent of any practice management software.
- Bank account information. No payment or banking data of your clients is accessed or stored at any point.
- Director, shareholder, or PSC personal data. PenaltyProof does not read or store any personal information about the individuals associated with the companies you monitor beyond what appears on the public Companies House register.
What data is stored, and where
PenaltyProof stores the following data about you and your monitored companies:
About you (the accountant):
- Your email address
- Your subscription plan and payment status (Stripe customer reference only — no card details)
- A log of alerts sent to you, with dates
Per monitored company — from the Companies House public register:
- Company number
- Company name and company type (private/PLC)
- Filing deadline dates (confirmation statement, annual accounts)
- Company status (active, dissolved, etc.)
Per monitored company — configured by you:
- VAT stagger group and VAT scheme (if VAT alerts are configured)
- Corporation Tax period end date (if CT alerts are configured)
- Self Assessment, P11D, RTI, CIS flags
- Payroll pay day (day of month)
- MTD ITSA quarterly election type
- Pension staging date and re-declaration override (if pension alerts are configured)
- ECCTA ID verification deadline (if applicable)
- ICO renewal date (if ICO alerts are configured)
- MLR review date (if MLR alerts are configured)
- HMRC agent authorisation date (if agent auth alerts are configured)
- Client contact email (optional — if provided, used for routing alerts)
All obligation-specific fields are optional and set to null unless you configure them. A company with no HMRC fields configured generates no HMRC alerts.
Data is stored in a PostgreSQL database hosted on Railway (infrastructure based in the USA). Card payment details are held exclusively by Stripe and are never seen by PenaltyProof systems. Email delivery is handled by Resend.
International transfers to Railway, Stripe, and Resend (US-based sub-processors) are covered by Standard Contractual Clauses (SCCs) under Article 46 UK GDPR. The full sub-processor list and the SCCs we rely on are referenced in the Data Processing Agreement.
No data from your account is shared with third parties for marketing, analytics, or any other commercial purpose.
UK GDPR legal basis
Under UK GDPR (as retained in domestic law by the Data Protection Act 2018), processing requires a lawful basis. PenaltyProof relies on the following bases:
- Contract performance (Article 6(1)(b)). Processing your email address and the company data you provide is necessary to deliver the monitoring service you have contracted for. Without your email address, alerts cannot be delivered; without company numbers and obligation dates, the service cannot function.
- Legitimate interests (Article 6(1)(f)). Sending service communications (account confirmations, deadline alerts) and maintaining security logs serves the legitimate interests of both PenaltyProof and its users, and does not override your rights or freedoms.
The obligation-specific dates you configure (CT period end, pension staging date, ICO renewal date, etc.) relate to the compliance obligations of legal entities — companies, not individuals. The only personal data involved is your email address, and optionally a client contact email per company if you choose to provide it. PenaltyProof does not process special category data.
Your rights under UK GDPR
As a data subject, you have the right to access, rectify, and erase your personal data. You can delete your account from within your account settings at any time, which removes your email address and all associated company numbers from the database. For data requests, contact is available via the details in the Data Processing Agreement.
The Data Processing Agreement
A Data Processing Agreement (DPA) is available at /dpa. If your practice requires a signed DPA before using any third-party service — which is good practice under UK GDPR Article 28 — the DPA sets out the subject matter, duration, nature, and purpose of processing, the type of personal data involved, and your rights as controller.
Because PenaltyProof processes only your email address and company numbers (not client personal data), the DPA scope is limited. However, for practices that prefer formal documentation of every sub-processor relationship, the DPA provides that structure.
Is this different from tools that access client accounting software?
Yes, meaningfully so. Tools that integrate with bookkeeping software (Xero, QuickBooks, Sage, FreeAgent) require OAuth access to your clients' financial records and may process turnover, bank transactions, payroll, and tax data. The GDPR obligations for those integrations are substantially more complex — they likely require client consent or a formal controller-to-controller agreement. We compare integration-light vs. integration-heavy approaches in free and paid Companies House reminder tools.
PenaltyProof does not require any such access. Because it reads only the public Companies House register — information that is already in the public domain — the data handling obligations it places on your practice are minimal. You are not sharing client data with PenaltyProof; you are asking it to read information that is already publicly available and tell you when deadlines are approaching.
Summary
For accountants assessing PenaltyProof against GDPR requirements, the key facts are:
- It reads CH filing deadline dates from the public Companies House register — no client financial, accounting software, or HMRC system access.
- It stores your email address and, per company: CH deadline dates (from the public register) plus any HMRC/compliance dates you configure.
- HMRC-related dates (VAT stagger group, CT period end, pension staging, etc.) are entered by you — PenaltyProof does not connect to HMRC systems.
- An optional client contact email can be stored per company for alert routing.
- Card payment details are held by Stripe, not PenaltyProof systems.
- The legal basis is contract performance and legitimate interests.
- A Data Processing Agreement is available at /dpa.
Product data-handling note, not legal advice: this article describes how PenaltyProof processes data. Your practice should still complete its own controller assessment and review the DPA before adopting any processor.
If the processing boundary above fits your practice, you can trial PenaltyProof with company numbers only — no accounting software access, no HMRC login, and no client financial records. Try Starter (£29/month, up to 50 companies) free for 30 days with advance alerts 30 days, 14 days, and 7 days before each deadline, plus due-date and overdue alerts. Cancel any time during the trial.
Start a low-data trial →or monitor free for up to 5 companies with Companies House monitoring (no card).
Related guides
Charity Commission Annual Return Deadlines Explained
How Charity Commission annual return deadlines work, why they differ from Companies House, and what UK accountants must file for charitable companies.
From Spreadsheets to a Monitoring Tool: 200 Clients
How to migrate a 200-client accounting book from a deadlines spreadsheet to a monitoring tool without losing dates, context or client trust.
UK Accountant's 2026 Deadline Calendar
Every key 2026 deadline for UK accountants in one calendar: Corporation Tax, VAT, PAYE, P11D, Self-Assessment and Companies House filings.
Filing Deadline Alert Tools for UK Accountants (2026 Comparison)
Comparing the free CH reminder service, practice management software, and dedicated monitoring tools — with obligation coverage across CH, HMRC, CIS, pension, and compliance.