GDPR in an accounting practice: a practical guide to sensitive client data

Two colleagues discussing printed accounting reports at a desk
In short: accounting and legal practices sit on salaries, bank details and family circumstances, which puts them in the demanding end of GDPR without any of the compliance staffing a bank would have. Four things carry most of the weight: knowing whether you are controller or processor on each engagement, keeping a record of processing, reviewing who has access, and putting real clauses in your subcontractor contracts.

Practices handling accounting and legal work process an unusually dense concentration of personal data. Payroll files carry salaries and social security identifiers. Client records carry bank details, addresses and, in family or insolvency matters, circumstances people would strongly prefer stayed private. GDPR applies to all of it with full force, and the supervisory authority pays particular attention to the categories a practice handles daily.

This applies wherever the practice is established in the EU, and it applies to a practice outside the EU handling data on people inside it. Nothing here is specific to France, though French practices additionally answer to the CNIL, the national supervisory authority, which publishes sector guidance worth reading.

Controller or processor

The first question on every engagement is which role you occupy, because it decides who is answerable for what. Where the client determines the purpose and you execute it, running payroll on their instructions, you are a processor. Where you decide the purpose yourself, your own prospect database, or advisory work you scope, you are a controller.

Practices commonly hold both roles simultaneously across different assignments for the same client. That is normal and not a problem, provided it is written down. It becomes a problem during an inspection, when the question is asked and nobody has an answer that matches the engagement letter.

Mapping the data and keeping the record

Close-up of a rack server front panel with status lights

Start by listing where data actually sits. Production accounting software, document management, payroll systems, the shared drive, and email. Email is the one that gets skipped and the one holding the most uncontrolled copies: attachments with payroll files, scans of identity documents, bank details forwarded between colleagues.

Each flow goes into a record of processing activities. This is a required document and it is also the only artefact that lets you answer an inspector's questions without a week of archaeology. For each processing operation it states who accesses the data, for what purpose, on what legal basis, and for how long it is kept.

Retention is where practices are weakest. Tax and employment law set minimum periods, and firms tend to treat those as licences to keep everything forever. They are not. Once the statutory period expires, personal data should be deleted or anonymised. A file from 2009 sitting on a shared drive is a liability with no offsetting benefit.

Access control and technical security

A screen showing green terminal text reading data transfer complete above a backlit keyboard

Restrict access to the people who need it for their assignment. In small practices the default is usually that everyone can see everything, which is convenient until a payroll file is opened by someone with no reason to open it.

Strong passwords and multi-factor authentication are no longer optional in any serious assessment. Encryption of data at rest limits the damage when a laptop is stolen, which is the incident that actually happens as opposed to the sophisticated attack people plan for.

Review access rights on a schedule. Every audit of a small practice turns up active accounts belonging to people who left eighteen months ago, and interns whose access outlived their placement by years. Twenty minutes a quarter closes this, and nobody does it because no client is asking for it.

Your subcontractors are your problem

Practices lean on outside tools for data entry, payroll processing and document storage. Under GDPR those providers are your processors, and their failures land on you. The obligation is to verify that they meet the requirements, not to assume they do because they are large.

Contracts need real clauses: what each party must do on security, how and how fast a breach is reported to you, where the data is hosted, what happens to it at the end of the contract. Boilerplate that says the provider "complies with applicable data protection law" is not a clause, it is a sentence.

One point that has grown more relevant: if any provider processes your client data with AI features, ask specifically whether that content can be used to improve their models. The answer is frequently different on the consumer tier and the business tier of the same product.

Transparency and client rights

Clients whose data you hold are entitled to know what you collect and how long you keep it, and to exercise rights of access, rectification and erasure. In practice, an information note annexed to the engagement letter discharges most of the transparency duty, provided it describes what you actually do rather than a template of what practices generally do.

The harder part is being able to respond when someone exercises a right. A request for access has a one-month deadline, and meeting it requires knowing where every copy of that person's data lives, which brings you back to the record of processing. Everything in GDPR compliance for a practice routes through that document, which is why it is worth doing properly once rather than reconstructing it under pressure.

Want a clear-eyed review of how your practice handles client data?
The initial conversation is free and without obligation.

Discover AI diagnostics & audit

FAQ

Is the practice responsible for its clients' data?

Yes, from the moment it processes personal data as part of an engagement. Whether it acts as controller or as processor depends on the assignment, and that determines who answers for what.

What has to be kept after a file closes?

Retention follows the applicable tax and employment law periods. Once those expire, personal data must be deleted or anonymised rather than kept indefinitely.

Does an accounting practice need a data protection officer?

A DPO is required where the practice processes personal data on a large scale or handles special categories regularly. Payroll work across a substantial client book usually points that way.

How should intern and temporary staff access be handled?

Access limited to what the assignment requires, and revoked on the last day rather than at the next review. Dormant accounts are the most common finding in a practice audit.

What do you do after a data breach?

Document the incident, contain it, and notify the supervisory authority within 72 hours where the breach poses a risk to the individuals concerned. Inform those individuals directly where the risk is high.