Our Policies

Transparency, trust and compliance are at the heart of how GCD Global Consultants operates.

GCD Global Consultants is committed to protecting the privacy and personal data of all clients, website visitors, and business partners. This Privacy Policy explains how we collect, use, store, and protect your information.

1. Information We Collect

We collect personal information only with your prior approval and consent, and only to the extent necessary to deliver our services. With that approval, the categories we may collect include:

  • Identity data: name, date of birth, PAN, passport, national ID
  • Contact data: email address, telephone numbers, postal address
  • Financial data: bank details, income information, tax records
  • Technical data: IP address, browser type, usage data from our website
  • Business data: company registration details, financial statements, contracts

2. How We Use Your Information

We process your personal information solely for the following purposes:

  • Providing taxation, accounting, compliance, and advisory services
  • Communicating updates, deadlines, and regulatory changes relevant to your engagement
  • Fulfilling statutory obligations under applicable tax and corporate laws
  • Improving our website and service delivery

3. Legal Basis for Processing

We process your data on the basis of: (a) performance of a contract, (b) compliance with legal obligations, and (c) your explicit consent. We will never sell or rent your personal data to third parties for marketing purposes.

4. Data Sharing

Your data may be shared only with: regulatory authorities (Income Tax Department, GST authorities, MCA, FTA, HMRC, IRS) as required by law; professional advisors bound by confidentiality; and technology service providers operating under strict data processing agreements.

5. Data Retention

Client data is retained for a minimum of 7 years in accordance with Indian, UAE, UK, and US statutory requirements. After this period, data is securely deleted or anonymised unless a longer retention period is required by law.

6. Your Rights

You have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data subject to legal obligations; withdraw consent at any time; and lodge a complaint with the relevant data protection authority.

7. Data Security

We implement industry-standard technical and organisational measures including encryption, access controls, firewalls, and regular security audits to protect your data against unauthorised access, disclosure, or loss.

8. Cookies

Our website uses essential cookies to ensure proper functionality. We do not use tracking or advertising cookies without your consent. You may manage cookie preferences through your browser settings.

9. Contact Us

For any privacy-related queries, to exercise your rights, or to report a concern, please contact us at: info@gcdglobal.in

Last updated: May 2025  |  Version 1.0

GCD Global Consultants provides offshore accounting, tax and advisory services and, in doing so, processes personal and financial information on behalf of its clients across India, the United Kingdom, the United Arab Emirates and the United States. This Data Protection Policy sets out the standards we apply to that information and demonstrates our alignment with the Digital Personal Data Protection Act, 2023 (India), the UK GDPR and Data Protection Act 2018, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and Internal Revenue Code §7216 (United States). Our commitment is simple: client data is handled only through authorised channels, is never disclosed to unauthorised persons, and is managed with full transparency and accountability.

1. Purpose & Scope

This policy applies to all personal data and client information that GCD Global Consultants collects, receives, stores, processes, transmits or returns in the course of any engagement, and to every partner, employee, contractor and associate who handles that data. It covers data in every form, electronic, cloud-hosted and physical, and across every stage of its lifecycle, from receipt through to secure deletion or return.

2. Regulatory Alignment

We design our processing to meet the requirements of each jurisdiction in which our clients operate:

  • India, the Digital Personal Data Protection Act, 2023 (DPDP Act), under which we act as a Data Processor for our clients as Data Fiduciaries.
  • United Kingdom, the UK GDPR and the Data Protection Act 2018, under which we act as a processor on the controller’s documented instructions.
  • United Arab Emirates, the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, and its data-protection principles.
  • United States, Internal Revenue Code §7216 and §6713, governing the use and disclosure of tax return information by preparers and their associates.

3. Our Role as a Processor

In almost all engagements GCD Global Consultants acts as a data processor or service provider, not as the owner of the data. We process personal and financial information strictly on the documented instructions and authorisation of our client, who remains the controller, data fiduciary or taxpayer. We do not determine the purposes of processing, and we do not use client data for any purpose of our own.

4. Authorised Channels Only

Client data is received, stored, accessed, processed and returned only through channels that the client has authorised and approved. These include encrypted client portals and secure file-transfer tools, invited-accountant access to the client’s own accounting software, and agreed, secured communication channels. Our people are prohibited from using personal email accounts, personal devices, removable media or any unapproved third-party application to handle client data. At no point in an engagement does data move outside an authorised channel.

5. No Disclosure to Unauthorised Persons

GCD Global Consultants does not forward, disclose, sell, publish or otherwise share client data with any unauthorised person or third party. Access is restricted to the specific, authorised team members assigned to an engagement, strictly on a need-to-know basis, and each is bound by confidentiality obligations. Where US tax return information is involved, we obtain the taxpayer’s consent in the form required by §7216 before any use or disclosure beyond preparing the return, and we handle identifiers such as Social Security Numbers in accordance with those rules.

6. Lawful Basis, Consent & Authorisation

We process data only where there is a lawful basis and a clear authorisation to do so. Where the applicable law requires consent, for example under the DPDP Act, or under §7216 for the disclosure or use of tax return information, that consent is obtained, recorded and honoured, and it may be withdrawn by the client or data principal at any time.

7. Data Minimisation & Purpose Limitation

We collect and process only the data necessary to deliver the agreed services, and we use it solely for the purpose for which it was provided. Client data is never repurposed, profiled or used for marketing without explicit authorisation.

8. Cross-Border Processing & Transfers

Because our delivery teams are based in India, data belonging to clients in the United Kingdom, the United Arab Emirates and the United States may be processed in India. Such transfers are carried out under appropriate safeguards, including data-processing agreements and recognised transfer mechanisms such as the UK International Data Transfer Agreement or Addendum, contractual safeguards under the UAE PDPL, and the taxpayer consents required under §7216 for the offshore handling of US tax return information.

9. Security Safeguards

We protect data with layered technical and organisational measures, including:

  • Encryption of data in transit and at rest
  • Role-based access controls and multi-factor authentication
  • Secured, access-restricted networks and devices
  • Signed confidentiality and data-protection agreements with all personnel
  • Ongoing staff training and periodic access reviews
  • Secure disposal and certified deletion of data

10. Retention & Deletion

We retain client data only for as long as it is needed to deliver the engagement and to meet legal, regulatory and professional record-keeping requirements. On completion of the engagement, or on the client’s instruction, data is securely returned or permanently and irrecoverably deleted.

11. Rights of Data Principals & Data Subjects

We respect the rights granted to individuals under each applicable law, including the rights to access, correct, update and erase personal data, and to withdraw consent. As a processor, we promptly assist our clients in responding to and fulfilling any such request from a data principal or data subject.

12. Sub-Processors

We engage sub-processors only where necessary, only with the client’s authorisation, and only under contractual obligations equivalent to those in this policy. We remain accountable for the data-protection performance of any sub-processor we appoint.

13. Personal Data Breach Response

In the unlikely event of a personal data breach, we act immediately to contain it and notify the affected client without undue delay, providing the information the client needs to meet any regulatory notification deadline under the DPDP Act, UK GDPR, UAE PDPL or other applicable law.

14. Transparency & Accountability

Accountability is built into how we operate. We maintain records of our processing activities, train our people, review access regularly, and make a named point of contact available for any data-protection question or concern. Clients may request information about how their data is handled, and we welcome reasonable audits and assurances of our practices.

15. Contact

For any question about this policy, to exercise a data-protection right, or to raise a concern, please contact us at info@gcdglobal.in.

This policy reflects the commitments and practices of GCD Global Consultants and is provided for transparency. It does not constitute legal advice, and the specific data-protection obligations of any engagement are set out in the applicable services agreement and data-processing terms.

Last updated: June 2026  |  Version 2.0

GCD Global Consultants treats the security of the client, financial and personal data entrusted to us as fundamental to our business. This Information Security Policy summarises the technical and organisational controls we maintain to keep that data confidential, accurate and available, and complements our Data Protection Policy.

1. Purpose & Scope

This policy applies to all systems, devices, networks and people involved in delivering our services, and to all client and firm data in every form. Its objective is to protect the confidentiality, integrity and availability of that data throughout its lifecycle.

2. Governance & Responsibility

Information security is owned at leadership level, with clear accountability for setting controls, reviewing risks and responding to incidents. Every partner, employee, contractor and associate is responsible for following this policy, and security expectations are written into their engagement terms.

3. Access Control

  • Access granted on a least-privilege, need-to-know basis, aligned to each person’s role on an engagement
  • Unique user accounts and strong authentication, with multi-factor authentication on key systems
  • Prompt provisioning and, critically, prompt removal of access when people join, change roles or leave
  • Regular review of who has access to what

4. Encryption

Client data is encrypted in transit using secure protocols and protected at rest. Credentials and sensitive identifiers are stored and transmitted only through protected, encrypted means.

5. Network & Device Security

  • Secured, access-restricted networks and managed devices
  • Endpoint protection, firewalls and timely security patching
  • A prohibition on using personal devices, personal accounts or removable media to handle client data
  • Clear-desk and clear-screen discipline

6. Secure Data Handling & Transfer

In line with our Data Protection Policy, client data is received, stored, processed and returned only through client-authorised, secure channels, encrypted portals, secure file transfer and invited access to client systems. Data never moves through unauthorised or personal channels, and is never forwarded to unauthorised persons.

7. People & Confidentiality

  • Confidentiality and data-protection agreements signed by all personnel
  • Appropriate screening of staff who handle sensitive data
  • Regular security-awareness training and updates
  • A culture in which raising a security concern is expected and supported

8. Monitoring & Logging

Access to systems and client data is logged and periodically reviewed so that unusual activity can be identified and addressed, and so that access remains appropriate over time.

9. Incident Response

We maintain a defined process to detect, contain and resolve security incidents. If an incident affects client data, we notify the affected client without undue delay and provide the information they need to meet their own regulatory obligations.

10. Business Continuity & Backup

Client data is backed up securely and regularly, with tested recovery procedures and resilience built into our delivery, so that engagements can continue and data can be restored in the event of disruption.

11. Third-Party & Vendor Security

Any sub-processor or technology provider we rely on is selected with care and held to security and confidentiality standards equivalent to our own. We remain accountable for the security of data we entrust to them.

12. Continuous Improvement

We review our controls in line with recognised information-security principles, including those underpinning ISO/IEC 27001, and improve them as risks, technology and client expectations evolve. We welcome reasonable security due diligence from clients and partners.

13. Reporting a Security Concern

To report a security concern or request information about our controls, please contact us at info@gcdglobal.in.

This policy describes the security commitments and practices of GCD Global Consultants and is provided for transparency; it does not form part of any contract unless expressly incorporated, and the specific security terms of an engagement are set out in the applicable agreement.

Last updated: June 2026  |  Version 1.0

These Terms of Use govern your access to and use of the GCD Global Consultants website. By using this website you agree to these terms. If you do not agree, please do not use the site.

1. About These Terms

This website is operated by GCD Global Consultants. These terms apply to all visitors and users of the site and should be read together with our Privacy Policy, Cookie Policy and Data Protection Policy.

2. Use of the Website

You may use this website for lawful, personal and business-information purposes. You agree not to misuse the site, including attempting to gain unauthorised access, disrupting its operation, or using it to transmit unlawful or harmful material.

3. No Professional Advice

The content on this website is provided for general information only and does not constitute accounting, tax, legal, financial or other professional advice. It should not be relied upon for decisions without taking advice specific to your circumstances, and using this website does not create a client or advisory relationship with GCD Global Consultants.

4. Accuracy of Information

We take care to keep the information on this site accurate and current, but laws, rates and requirements across India, the UK, the UAE and the USA change frequently. We make no warranty that all content is complete, current or error-free, and we may update it without notice.

5. Intellectual Property

All content on this website, including text, graphics, logos and design, is owned by or licensed to GCD Global Consultants and is protected by intellectual-property laws. You may not copy, reproduce, republish or distribute it without our prior written permission.

6. Third-Party Links

This site may contain links to third-party websites for convenience. We do not control and are not responsible for the content, accuracy or practices of those sites, and a link does not imply endorsement.

7. Limitation of Liability

This website is provided on an ’as is’ and ’as available’ basis. To the fullest extent permitted by law, GCD Global Consultants is not liable for any loss or damage arising from your use of, or reliance on, this website or its content.

8. Privacy & Data

Your use of this website is also governed by our Privacy Policy, Cookie Policy and Data Protection Policy, which explain how we handle personal data and cookies.

9. Governing Law

These terms are governed by the laws of India. Any dispute relating to this website or these terms is subject to the exclusive jurisdiction of the courts of Delhi, India.

10. Changes & Contact

We may revise these terms from time to time, and the current version will always be available on this page. For any question about these terms, please contact us at info@gcdglobal.in.

Last updated: June 2026  |  Version 1.0

Credentials & Affiliations

Qualified, Registered & Partnered

ICAI Chartered Accountants of India
ACCA UK Professional Body
AICPA US Professional Body
Xero Certified Partner
QuickBooks ProAdvisor
Zoho Authorised Partner