The question that comes before all the others
An accounting firm handles the personal data of hundreds of companies, their employees and their collaborators. Before any document, the question to settle is in which capacity it handles them, because everything else follows from that.
For the professional activities you carry out under your own obligations — keeping the accounts, filing returns, the duties the law places on you — you are normally an independent controller: you determine purposes and means, and you answer to your own professional rules. You are not executing the client’s instructions.
For other activities, carried out on the client’s instructions and on their behalf, you may be a processor. Running payroll for a company is the typical case.
The two capacities coexist in the same firm, for different activities, and that is normal. What is not normal — and what we often find — is that nobody has ever made the distinction in writing, with the consequence that the appointment documents in circulation are formally wrong and protect nobody.
The most sensitive archive you hold
It is not the accounts: it is clients’ credentials. Portal logins, authorisations, tax gateway access, collected over the years and kept — in most of the firms we visit — in a shared spreadsheet, often unencrypted and reachable by anyone working there.
It is the point where a firm is more exposed than almost any other organisation, because an attacker who gets in does not obtain your data: they obtain access to your clients’ data, and responsibility for that access is yours.
Three measures move almost all of that risk and none is expensive: a credential manager with individual access and a record of who opens what, a second factor on mail and portals, and a periodic review of who has access to what — because most exposures come from access left open rather than from sophisticated attacks.
Payslips contain health data
This is an aspect almost everyone misses. Payslips and personnel files contain sickness absence, workplace accidents, leave tied to health conditions or to disability. These are special categories of data, and that raises the required standard: measures proportionate to the risk, access limited to those who genuinely need to see them, and lower thresholds for assessing a breach.
The practical consequence is not bureaucratic: it means the shared login to the payroll system, which we find in many firms, is not sustainable. You have to know who consulted what.
Documents and configurations are the same thing
Much of what the Regulation requires is not solved by writing: it is solved by configuring. The appropriate technical measures, to use its own words, are concrete things — who has access to what, the second factor, backups that genuinely restore, encrypted laptops, access revoked when somebody leaves the firm.
That is why treating compliance as paperwork for the consultant and IT as the technicians’ business produces two pieces of work that do not talk to each other: a beautifully written record of processing sitting on top of infrastructure nobody has looked at. With us the two go together, and it is also the logic GAPOFF was built on.
The rest
See also GDPR in practice for the general method, IT, AI and security for accounting firms, and AI for accounting firms, where the subject intersects with using artificial intelligence tools on clients’ documents.
The first step
A written picture: which data you handle and in which capacity, where it sits, who reaches it and which measures are already in place. Free and without obligation.