When you appoint an accounting firm, you may provide far more than figures for a tax return.
The firm might receive bank statements, identification documents, payroll records, business accounts, details of overseas assets and correspondence from HMRC.
Together, these records can reveal a detailed picture of your personal or business finances.
It is therefore reasonable to ask how the firm protects that information.
Client data protection involves more than installing antivirus software or placing documents behind a password. A professional firm should combine secure technology with clear procedures, controlled access, staff training and careful supervision of outside providers.
No system can remove every risk. However, an accounting firm should understand the information it holds, identify how problems could arise and use safeguards appropriate to those risks.
What Information Does an Accounting Firm Need to Protect?
Depending on the services provided, an accounting firm may hold:
- names, addresses and dates of birth;
- passports and other identity documents;
- National Insurance and Unique Taxpayer Reference numbers;
- bank statements and account details;
- tax returns and business accounts;
- payroll and employee information;
- details of income, property and investments;
- information about directors and shareholders;
- HMRC correspondence; and
- records connected with tax enquiries or investigations.
Some information may be sensitive from a personal perspective. Other records could be commercially valuable if they reached a competitor or fraudster.
The firm must therefore consider both personal-data protection and its wider professional duty of confidentiality.
What Legal and Professional Duties Apply?
The UK GDPR requires organisations to process personal data securely by using appropriate technical and organisational measures.
There is no single security system that every accounting firm must use. Instead, the firm should consider the nature of the information, the way it processes that information and the harm that a loss or misuse could cause.
The Information Commissioner’s Office describes three important aims:
- Confidentiality: only authorised people can access or use the data.
- Integrity: the information remains accurate and protected from unauthorised changes.
- Availability: the firm can access and recover the information when it needs it.
Professional accountants may also have confidentiality obligations under the ethical rules of their professional body.
For example, ICAEW guidance emphasises that firms should protect client information both outside and inside the organisation. ACCA also identifies confidentiality as one of the fundamental ethical principles for professional accountants.
How Do Firms Control Who Can Access Client Information?
Not everyone working at an accounting firm should automatically see every client file.
Instead, a firm may use role-based access. This means that staff receive access according to their responsibilities.
For example:
- payroll staff may access payroll records;
- the tax team may access tax returns and calculations;
- a supervising partner may review complex work;
- compliance staff may access identity and anti-money laundering records; and
- IT administrators may have limited technical access when supporting systems.
The firm should also review access when someone changes role or leaves the organisation. Otherwise, an old user account could continue providing access that the person no longer needs.
How Does Secure Technology Help?
Accounting firms often store information across several digital systems, including:
- cloud accounting software;
- tax and payroll platforms;
- document-management systems;
- client portals;
- email services; and
- customer relationship management systems.
A firm should assess each system rather than assuming that cloud software is automatically secure.
Depending on the risks, safeguards may include:
- strong and unique passwords;
- multi-factor authentication;
- encryption;
- restricted administrator access;
- software and security updates;
- secure backups;
- device-management controls;
- access logs; and
- monitoring for suspicious activity.
Encryption can help protect information when the firm stores it or sends it electronically. However, encryption alone is not enough. A member of staff could still send information to the wrong person or give access to someone who does not need it.
Therefore, technology must work alongside clear procedures and responsible behaviour.
Why Do Secure Client Portals Matter?
Email is convenient, but it can create risks.
An address may be entered incorrectly, a message may be forwarded, or a criminal may imitate a genuine client or adviser.
For particularly sensitive documents, a secure client portal may offer better protection. A portal can provide controlled access, authentication and a clearer record of document exchange.
However, clients also have a role to play. They should protect their login details, use multi-factor authentication where available and contact the firm through a trusted number if a request for money or confidential information seems unusual.
How Should Staff Protect Client Data?
Many data incidents begin with human error rather than a sophisticated cyberattack.
For example, a member of staff might:
- attach the wrong document to an email;
- fall for a phishing message;
- discuss a client matter where others can hear;
- leave papers unattended;
- use an unapproved device or application; or
- fail to check the identity of a caller.
Consequently, staff training forms an important part of data protection.
A firm should explain how to recognise phishing attempts, check recipients, verify callers, report incidents and handle confidential papers. It should also provide refresher training because risks and working practices change.
Policies alone do not protect information. Staff need to understand and follow them in everyday work.
What About Outside Software Providers and Contractors?
An accounting firm may use outside organisations to provide software, payroll processing, IT support, document storage or specialist advice.
The firm should understand:
- what information the provider receives;
- where the provider stores it;
- which security measures apply;
- whether subcontractors are involved;
- how the provider handles a data incident;
- what happens when the contract ends; and
- whether information may leave the UK.
Where a provider processes personal data for the firm, the UK GDPR may require appropriate contractual terms.
Using a well-known provider does not remove the firm’s responsibility to carry out suitable checks.
Can Accounting Firms Use AI With Client Information?
Artificial intelligence can help with research, document analysis, drafting and administrative work. However, staff should not enter confidential client information into an AI tool simply because it is convenient.
Before approving an AI system, a firm should consider:
- whether the provider retains prompts or uploaded documents;
- whether it uses information to train its models;
- who can access the data;
- where processing takes place;
- what contractual safeguards apply; and
- how the firm checks the output.
The firm should also decide which information staff may enter and whether they need to remove identifying details first.
ICAEW guidance makes clear that digital tools and AI do not reduce an accountant’s confidentiality obligations.
How Long Can a Firm Keep Client Information?
Accounting firms may need to retain records after the work has finished.
Tax, accounting, anti-money laundering, regulatory and legal requirements can all affect retention. The firm may also need records to answer later questions or defend a professional claim.
However, it should not keep personal data indefinitely without a valid reason.
The ICO’s storage-limitation guidance says organisations should determine and justify retention periods. They should also review information and delete or anonymise it when they no longer need it.
The appropriate period may differ between tax records, identity documents, correspondence and internal working papers.
What Happens If There Is a Data Breach?
A personal data breach does not only mean that a hacker has stolen information.
It could also involve:
- sending information to the wrong person;
- losing a laptop or paper file;
- unauthorised access by a member of staff;
- ransomware preventing access to records;
- accidental deletion without a usable backup; or
- revealing information during a telephone call.
The firm should act promptly to contain the incident, understand what happened and assess the possible effect on the people involved.
Where a breach is likely to create a risk to people’s rights and freedoms, the firm must notify the ICO as soon as possible and, where feasible, within 72 hours. If the risk is high, it may also need to tell the affected people without undue delay.
Not every error requires notification. However, the firm should assess the incident and document its decision.
Practical Guide
If you want to understand how an accounting firm protects your information, consider asking:
- Do you use a secure portal for confidential documents?
- How do you control access to client files?
- Do you use multi-factor authentication?
- Do outside contractors or software providers process my information?
- Do you use AI tools when working with client data?
- Where do your systems store information?
- How long will you retain my records?
- What should I do if I receive a suspicious request that appears to come from your firm?
- How can I report a confidentiality or security concern?
A professional firm should answer reasonable questions clearly. However, it may avoid disclosing detailed security information that could make its systems easier to attack.
| Safeguard | What It Helps Protect Against |
| Role-based access | Unnecessary internal access |
| Multi-factor authentication | Stolen or guessed passwords |
| Encryption | Unauthorised reading of stored or transmitted data |
| Secure client portal | Misdirected or intercepted email |
| Staff training | Phishing, mistakes and improper disclosure |
| Supplier checks | Risks created by outside providers |
| Backups and recovery procedures | Loss of access after an incident |
| Retention controls | Keeping unnecessary information for too long |
Frequently Asked Questions
Is email safe for sending tax documents?
Email can be suitable in some circumstances, but it carries risks. For highly sensitive documents, a secure client portal may provide stronger control. Follow the firm’s instructions and check unusual requests before sending information.
Can everyone at an accounting firm see my records?
They should not. A firm should normally restrict access to people who need the information for a legitimate professional, legal or business purpose.
Can an accounting firm store my information in the cloud?
Yes, provided the firm assesses the provider and uses appropriate legal, organisational and security safeguards. Cloud storage is not automatically secure or insecure; the arrangements matter.
Can my accountant use an outside contractor?
Potentially, yes. The firm should have a proper reason, carry out appropriate checks and protect your information through suitable controls and contractual terms.
Can I ask an accounting firm to delete my information?
You can ask, but the firm may need to retain some records for tax, regulatory, anti-money laundering or legal reasons. It should explain why it still needs the information and how long it expects to keep it.
What should I do if I think my information has been disclosed improperly?
Contact the firm promptly and ask what happened, which information was involved and what action it is taking. If the response does not resolve your concern, you may need guidance from the ICO or the accountant’s professional body.
Where to Find Official HMRC Information
HMRC explains how it uses and protects personal information in its privacy notice. Wider guidance on data security, access controls and breaches comes from the Information Commissioner’s Office. Professional bodies also publish confidentiality requirements for accountants.
- HMRC Privacy Notice
- ICO: A Guide to Data Security
- ICO: Access Control
- ICO: Reporting a Personal Data Breach
- ICO: Storage Limitation
- ICAEW: Protecting Client Confidentiality
- ACCA Rulebook and Code of Ethics
💡 Key Takeaway
Accounting firms protect client data through a combination of technology, procedures and professional judgement.
Secure systems matter, but so do trained staff, controlled access, careful supplier checks and clear rules about retention and disclosure.
No firm can promise that a security incident will never happen. However, it should understand the risks, use appropriate safeguards and respond properly if something goes wrong.
Clients can also help by using secure portals, protecting passwords and checking unexpected requests before sending money or confidential information.
Need Help?
If you are dealing with a sensitive UK tax matter, Accounts Tax Group understands the importance of handling your information carefully and confidentially.
We assist individuals, company directors and businesses with HMRC enquiries, historic disclosures, tax investigations, outstanding returns and tax debts.
Call 020 8499 8065 or email info@accountstaxgroup.co.uk for a confidential, no-obligation conversation.
For regular updates, you can follow our company page on LinkedIn, or explore our in-depth visual guides shared via our director’s profile.


