Legal and accounting support for UK businesses and individuals
office@yudey.uk
HMRC enquiries and tax disputes guides · 5 min read

Protecting confidential information in tax correspondence

Tax correspondence can contain sensitive financial and personal information, so verify recipients and use an appropriate transfer method.

Jurisdiction: United Kingdom.

Tax correspondence can contain sensitive financial and personal information, so verify recipients and use an appropriate transfer method. Review the scope of requested disclosure and obtain advice on privilege or confidentiality issues before sending protected material.

Keep originals intact and document any lawful redaction. Do not assume that copying an accountant automatically makes every document legally privileged.

Identify why each document is being shared

Start with the tax question or formal request and identify the records needed to answer it. A correspondence pack may contain bank details, employee pay, customer information or family circumstances. The ICO's principles include purpose limitation, data minimisation, accuracy and accountability, so the handling process should have a clear purpose and a record of decisions. [1] Avoid sending an entire personal or business archive merely because a smaller relevant set has not been organised.

Create an index showing the document, subject, intended recipient and reason for disclosure. This helps the reviewer notice unrelated material before transmission. It also makes the tax response easier to follow. Where a record contains information about several people, identify that feature for review rather than assuming everyone mentioned must receive a copy or that the whole document can be freely circulated within the organisation.

Verify the recipient and permitted channel

Confirm the official HMRC contact or authorised adviser before sending sensitive files. Use an independently verified route if a new address, portal invitation or payment-related request appears unexpectedly. Check the actual recipient details rather than relying on an email display name. If a message changes established instructions, verify the change through a known contact before acting on it.

Agree the document-transfer method and who will have access. The ICO's security guidance emphasises appropriate organisational and technical measures for the information and risks involved. [2] In practice, use controlled access, suitable authentication and a transfer method appropriate to the sensitivity of the pack. Avoid placing confidential records behind a link that can be opened by anyone who receives or forwards it.

Review copies without altering the original evidence

Keep source records intact and create separate copies for any permitted redaction or extraction. Identify exactly what has been removed and why, with appropriate professional advice where the document responds to a legal requirement. Data protection is not a general permission to withhold information lawfully required by HMRC. Scope, confidentiality and legal privilege are distinct questions that should be assessed on their own basis.

Check spreadsheets for hidden sheets, comments, formulas and embedded data that may disclose more than the visible table suggests. Review scanned bundles for unrelated pages and personal identifiers in filenames. If an extract is supplied, make its scope clear so it does not misrepresent the underlying record. Responding to a request for tax information explains the separate assessment needed when a formal information notice requires particular documents or information.

Control access during preparation and review

Give access to the people who need to prepare, verify or approve the response, with an identified owner for the case folder. Use individual accounts where possible and remove unnecessary access when roles change. Keep a record of which version was approved and sent. A shared folder that changes without version control can make it difficult to establish exactly what information was disclosed at a particular time.

Do not put account passwords, one-time codes or recovery credentials into an evidence pack. An adviser or HMRC official should receive the records through the appropriate process, not control of a person's private accounts. Where someone needs help exporting information, agree a method that preserves access boundaries and produces the required records without sharing credentials across email, messaging applications or informal document notes.

Retain a submission record and handle mistakes promptly

Save the final pack, recipient details, date and delivery evidence in the case file. Apply a retention approach that reflects the tax records, ongoing dispute and applicable data obligations rather than keeping every working copy indefinitely. The ICO's principles include storage limitation, while its security guidance addresses protecting access and availability. [1] [2] Preserve material still needed for an enquiry or other legal obligation before any deletion decision.

If information is sent to the wrong recipient or exposed unexpectedly, follow the organisation's incident process promptly. Establish what was disclosed, to whom and whether access can be restricted, then obtain advice on any required notification. Do not conceal the event or assume that deleting your own sent email removes the recipient's copy. Keep a factual record of containment and follow-up actions.

For assistance organising confidential tax correspondence, see HMRC enquiry response support. Describe the document types and response deadline first, then agree a secure transfer route. The preparation should produce a relevant, accurate evidence pack with a clear disclosure history. That combination supports the tax response while reducing avoidable exposure of information unrelated to the matter being addressed.

Illustrative scenario

A business prepares records containing employee bank details alongside a tax schedule. Its adviser reviews relevance and the secure response format before disclosure, preserving an approved copy of what was sent.

Preparation checklist

  • Verify the recipient
  • Review disclosure scope
  • Protect unrelated personal data
  • Retain the approved response pack

Frequently asked questions

Does data protection automatically override an HMRC information requirement?

No. Assess the legal request and applicable safeguards properly; data protection, confidentiality and privilege are separate considerations.

Should I redact the original documents before review?

Preserve originals. Use separate reviewed copies for any justified redaction or extraction and record what was changed and why.

What should I check in a spreadsheet before sending it?

Review hidden sheets, comments, embedded data, filenames and access settings as well as the visible figures.

What if a confidential pack goes to the wrong person?

Act promptly under the incident process, establish the facts, contain access where possible and obtain advice on any notification duties.

Official sources

Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.

  1. ICO: Data protection principles
  2. ICO: A guide to data security

General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.

Report a correction