Vai al contenuto

GDPR for accounting firms

A firm handles data belonging to hundreds of companies. The question everything depends on is in which capacity.

In breve

An accounting firm handles data belonging to hundreds of companies and their employees, and the first thing to establish is in which capacity: for professional obligations it is normally an independent controller, for certain activities carried out on the client's instructions it is a processor. Appointments, register, measures and liability all follow from that distinction. Xion keeps the documentary and the technical sides together.

Controller or processor

It is the question everything else depends on, and it is often got wrong. The two capacities coexist in the same firm, for different activities.

You hold the keys to hundreds of companies

Clients' credentials are the most sensitive archive a firm owns, and they are almost never treated as such.

Documents and configurations together

Much of what the Regulation requires is not solved with a document, but with access control, verified backups and encryption.

The question that comes before all the others

An accounting firm handles the personal data of hundreds of companies, their employees and their collaborators. Before any document, the question to settle is in which capacity it handles them, because everything else follows from that.

For the professional activities you carry out under your own obligations — keeping the accounts, filing returns, the duties the law places on you — you are normally an independent controller: you determine purposes and means, and you answer to your own professional rules. You are not executing the client’s instructions.

For other activities, carried out on the client’s instructions and on their behalf, you may be a processor. Running payroll for a company is the typical case.

The two capacities coexist in the same firm, for different activities, and that is normal. What is not normal — and what we often find — is that nobody has ever made the distinction in writing, with the consequence that the appointment documents in circulation are formally wrong and protect nobody.

The most sensitive archive you hold

It is not the accounts: it is clients’ credentials. Portal logins, authorisations, tax gateway access, collected over the years and kept — in most of the firms we visit — in a shared spreadsheet, often unencrypted and reachable by anyone working there.

It is the point where a firm is more exposed than almost any other organisation, because an attacker who gets in does not obtain your data: they obtain access to your clients’ data, and responsibility for that access is yours.

Three measures move almost all of that risk and none is expensive: a credential manager with individual access and a record of who opens what, a second factor on mail and portals, and a periodic review of who has access to what — because most exposures come from access left open rather than from sophisticated attacks.

Payslips contain health data

This is an aspect almost everyone misses. Payslips and personnel files contain sickness absence, workplace accidents, leave tied to health conditions or to disability. These are special categories of data, and that raises the required standard: measures proportionate to the risk, access limited to those who genuinely need to see them, and lower thresholds for assessing a breach.

The practical consequence is not bureaucratic: it means the shared login to the payroll system, which we find in many firms, is not sustainable. You have to know who consulted what.

Documents and configurations are the same thing

Much of what the Regulation requires is not solved by writing: it is solved by configuring. The appropriate technical measures, to use its own words, are concrete things — who has access to what, the second factor, backups that genuinely restore, encrypted laptops, access revoked when somebody leaves the firm.

That is why treating compliance as paperwork for the consultant and IT as the technicians’ business produces two pieces of work that do not talk to each other: a beautifully written record of processing sitting on top of infrastructure nobody has looked at. With us the two go together, and it is also the logic GAPOFF was built on.

The rest

See also GDPR in practice for the general method, IT, AI and security for accounting firms, and AI for accounting firms, where the subject intersects with using artificial intelligence tools on clients’ documents.

The first step

A written picture: which data you handle and in which capacity, where it sits, who reaches it and which measures are already in place. Free and without obligation.

Frequently asked questions

Is an accountant a controller or a processor?

Normally an independent controller for the professional activities carried out under their own obligations - keeping the accounts, filing returns, the duties the law places on them - because there they determine purposes and means independently and answer to their own professional rules. They may instead be a processor for activities carried out on the client's instructions, such as running payroll for a company. The two capacities coexist in the same firm, and distinguishing them is the premise for everything else.

Does a small firm need a record of processing activities?

Yes, practically always. The exemption below two hundred and fifty employees does not apply where processing is not occasional or involves special categories of data - and a firm processes data systematically, daily, and often health data contained in payslips. Beyond the obligation, without the record nobody knows where the data sits, and without knowing that you cannot answer a request or assess an incident.

Do we need to appoint a data protection officer?

In most firms, no. The obligation applies to public bodies, to those carrying out large-scale systematic monitoring, and to those processing special categories of data on a large scale. An accounting firm of ordinary size falls into none of the three. Appointing one anyway is possible but brings the full set of rules with it, including the absence of any conflict of interest.

Does the IT supplier have to be appointed as a processor?

Yes, if they process personal data on your behalf - and whoever manages your servers, your mail or your support does so by definition. You need a written instrument saying what they may do, with which security measures, whether they may rely on other suppliers, and what happens to the data at the end of the relationship. It is a document many firms discover they do not have when somebody asks for it.

What happens if a client suffers a breach because of us?

It depends on the capacity in which you were handling that data and on which measures you had adopted. That is exactly why the distinction between controller and processor is not a formality: it determines who had to do what and who answers. Documented technical measures - individual logins, a second factor, verified backups, encrypted devices - are the part that protects you.

Looking for a partner to manage your IT?

Tell us what you need: a Xion consultant will get back to you quickly, and the initial assessment visit is free of charge.