Short answer: Named, logged and removed at roll-off
Through named accounts, from managed devices or controlled jump servers, with multi-factor sign-in and logging. Access should be removed the day someone rolls off. Client data should stay in client systems and not be copied to laptops, internal tickets or chat.
What the law says
Section 8(5) and Rule 6 apply to your safeguards even where you are the processor.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Section 8(1)–(2): The organisation that decides why and how data is used (the Data Fiduciary) stays responsible, even when a vendor (Data Processor) does the work. A processor may be engaged only under a valid contract.
Steps
No shared client credentials.
MFA on all client access.
Jump servers or VDI for sensitive clients.
Roll-off removal the same day.
Quarterly access review per client.
Evidence to keep
Access lists per client
Review records
Roll-off removal reports
Common mistakes
Shared logins in team chat
Copying production data to laptops
Access left after roll-off
From each seat
CISO / Security head: This is where most IT-sector incidents start.
CIO / IT head: Fund jump servers or VDI for sensitive clients.
Delivery head: You approve access; you also remove it.
IT department: Run the roll-off removal report every week.
What a good answer from management sounds like
“All client access is named, logged and removed the day people roll off. Quarterly reviews show zero stale accounts.” Effort and time: Medium · 6 to 12 weeks.