Handing your bank feeds, payroll data, and revenue correspondence to a team you’ve never met in person feels risky, and most of what’s written about it doesn’t help much. The usual advice is “make sure they’re GDPR compliant”, as if that’s a box a provider ticks rather than a legal relationship with specific obligations attached. If you’re an Irish SME director, sole trader or in-house bookkeeper weighing up an outsourced provider, here’s what actually matters: who’s legally responsible for your data, what Irish law requires alongside GDPR, and the concrete questions to ask before you sign anything.
Who’s Actually Responsible for Your Data — Controller vs Processor
Under GDPR, a “controller” is whoever decides why and how personal data is processed. A “processor” carries out that processing on the controller’s instructions. In almost every outsourced bookkeeping, payroll or accounts arrangement, your business — or your accountant, if they’re the one instructing the outsourcing partner — is the controller. The outsourcing provider is the processor.
This isn’t a technicality. It means legal responsibility for how the data is protected doesn’t transfer to the provider just because they’re the ones physically handling it. Engaging a processor requires a written contract — usually called a ‘data processing agreement’ (DPA) — setting out things like what the processor is allowed to do with the data and for how long; a confidentiality commitment covering everyone with access to it; whether the processor can bring in sub-processors (and a requirement to disclose that); how quickly the processor has to notify you if something goes wrong; and what happens to the data when the engagement ends — deletion or return, on your instruction.
If a provider can’t produce a data processing agreement or treats the request for one as unusual, that’s worth pausing on. You can’t outsource the underlying accountability for the data — only its day-to-day handling. This is the point every “we’re GDPR compliant” badge on a website skips over.
A quick way to see why this distinction matters: say an outsourced bookkeeping team accidentally emails your payroll file to the wrong client. Under GDPR, it’s still your business — the controller — that’s ultimately accountable to the affected employees and, if it’s serious enough, to the DPC. That’s exactly why the data processing agreement matters so much: it’s what obliges the processor to tell you quickly, cooperate with any investigation, and take responsibility for its own part in what went wrong, rather than leaving you to find out some other way.
The Irish Regulatory Layer (Not Just “GDPR Compliant”)
“GDPR compliant” isn’t a certification anyone hands out — the regulation names one specific enforcing body. In Ireland, that’s the Data Protection Commission (DPC). It’s worth knowing this because the DPC is who you’d approach, or who would investigate, if something went wrong with how your data was handled — not some abstract “GDPR authority”.
But GDPR isn’t the only law shaping how an outsourced accounting provider should handle your records, and this is where the Irish-specific detail actually matters.
Anti-money laundering recordkeeping
Accountants and bookkeepers in Ireland are “designated persons” under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010. When your provider carries out customer due diligence on your business — verifying who you are and who owns and controls the company — they’re required to keep records evidencing that process, along with records of the services and transactions carried out for you, for five years. That’s a separate legal clock from anything GDPR sets, tied specifically to the AML obligations that apply to anyone providing accountancy services in Ireland.
This is easy to miss because it doesn’t appear in most GDPR checklists at all — it’s a distinct obligation that sits alongside data protection law, not a subset of it. In practice, it means your provider should be able to tell you, plainly, how they store the identity and beneficial-ownership documents they collected when they onboarded you and for how long they’ll hold onto them after the engagement ends. A provider who’s never had to think about this hasn’t fully reckoned with what “designated person” status actually requires.
Companies Act 2014 retention
Separately, your own accounting records — the ones your outsourced provider is compiling, filing or storing on your behalf — need to be kept for six years after the end of the financial year they relate to, under Section 285 of the Companies Act 2014. Failing to keep adequate accounting records is a criminal offence, and directors can be held personally liable in some circumstances, so this isn’t a minor administrative point. It’s worth asking your provider directly how and where these six-year records are stored, not just how long they’re kept.
ROS agent-linking
If your outsourced provider is filing your CT1 corporation tax return or your Form 11 self-assessment, they need to be linked to you as your registered agent on Revenue’s systems. Revenue changed how this works in 2025: instead of a paper authorisation form, agent-linking now runs through an e-linking process, where the agent submits the link request through ROS, and you approve it separately through ROS or myAccount within 30 days. It’s a small operational detail, but it means you keep direct, visible control over who’s authorised to file on your behalf with Revenue — and it’s worth confirming that any provider you’re evaluating is using this current process rather than an outdated paper form.
If the Work Crosses Borders — What to Ask About International Transfers
Many outsourced accounting providers deliver at least some of their work from outside Ireland and the EEA. That’s not automatically a problem, but it does trigger specific requirements under GDPR’s rules on international transfers, and it’s worth being direct about rather than skating past.
Where personal data is transferred outside the EEA to a country that doesn’t have an adequacy decision from the European Commission, the transfer needs a safeguard — most commonly, Standard Contractual Clauses (SCCs) built into the contract between you (or your accountant) and the provider. A properly run provider should also be able to speak to a transfer impact assessment: essentially, whether the destination country’s laws could undermine the protections the SCCs are meant to provide.
This isn’t a purely theoretical requirement — European courts have taken a much closer look at international data transfers in recent years, and regulators, including the DPC, have shown they’re willing to act where safeguards are missing or inadequate. None of that means outsourcing outside the EEA is off the table; it means the safeguard must actually exist and be something a provider can point to, rather than being assumed to be fine because “everyone does it this way”.
You don’t need to become a GDPR transfer specialist to evaluate this. Three questions do most of the work in a call with a prospective provider:
- Where, physically, is our data processed and stored — which country or countries?
- If any of that is outside the EEA, what safeguard is in place — Standard Contractual Clauses, or something else?
- Can we see the data processing agreement, including anything covering international transfers, before we sign?
A provider that answers these plainly, rather than deflecting to a general compliance statement, is telling you something useful about how seriously they take the rest of this.
If Something Goes Wrong: What Breach Notification Actually Looks Like
Most of what’s written about data breaches focuses on prevention. Worth spending a moment on what actually happens if something does go wrong, because it’s where the controller/processor split covered earlier stops being theoretical and starts having a clock attached to it.
Under GDPR, if your business is the controller, you — not your outsourced provider — are the one legally required to notify the Data Protection Commission, and you have to do it within 72 hours of becoming aware of the breach, where feasible. That 72-hour clock starts the moment there’s reasonable certainty a breach has occurred, not once an investigation is finished. If the breach is likely to pose a high risk to the people whose data was involved — employees on a payroll file, for instance — you may also need to notify them directly, without undue delay.
This is exactly why the processor’s breach notification obligation matters so much in the outsourcing context. Under GDPR, a processor is required to notify the controller without undue delay once it becomes aware of a breach — and your data processing agreement should say specifically how quickly that has to happen and what information it needs to include, rather than leaving “without undue delay” undefined. If your outsourced provider only tells you about an incident once they’ve completed their own internal review, you could already be behind on a deadline you didn’t know was running. The practical ask, then, isn’t “Do you have a security policy?” — it’s “How many hours after you notice something do we hear about it, and in what format?”
It’s also worth knowing that not every incident needs to be reported to the DPC—a low-risk incident, like a password reset triggered by a suspicious login with no actual data accessed, generally doesn’t. But every incident, reportable or not, needs to be logged in a breach register, recording what happened, its effects, and what was done about it. Ask your provider whether they maintain this kind of record even for incidents they judge don’t meet the reporting threshold — it’s a good indicator of whether breach handling is a genuine internal process or something improvised only when it’s unavoidable.
The Technical and Operational Controls That Should Back All of This Up
None of the above works without decent technical hygiene sitting underneath it, so it’s worth naming briefly: data encrypted both in transit and at rest, access limited to the specific people actually working on your file rather than the whole organisation, multi-factor authentication on any client portal or shared drive, and an audit trail showing who accessed what and when. These are table stakes at this point—any provider handling financial data should already have them without being asked, and most competent providers will happily describe them in some detail.
The real differentiator isn’t whether a provider has encryption; it’s whether they can also show you the legal and regulatory pieces covered above — the data processing agreement, the AML and Companies Act retention practices, and, if relevant, the cross-border safeguard. A provider that leads with certifications and struggles with the rest hasn’t necessarily done anything wrong, but it’s a sign the conversation needs to go further before you sign.
A Due-Diligence Checklist Before You Sign
Everything covered above translates into a short, practical list. You don’t need to memorise the legislation behind each point—you just need a straight answer to each question below before you sign anything:
- Can I see a written data processing agreement before I sign anything?
- Who, specifically, will have access to our data — a named team, or anyone in the organisation?
- Do you use any sub-processors, and will you tell us if that changes?
- Where is our data physically processed and stored?
- If any work happens outside the EEA, what safeguard — SCCs or otherwise — covers that transfer?
- How quickly will you notify us of a data breach, and how?
- How do you meet the five-year AML recordkeeping requirement for customer due diligence, and where are those records kept?
- How do you handle the six-year accounting records retention requirement under the Companies Act 2014?
- Are you using Revenue’s current ROS agent-linking process, and will we retain visibility over that link?
- What happens to our data — deletion, return, or something else — if we end the engagement?
What This Looks Like in Practice
At Aone, this plays out across bookkeeping, corporation tax (CT1) filing, self-assessment (Form 11), and year-end accounts finalisation for Irish clients. In practice, the client – or their accountant – remains the data controller, and Aone operates as the processor under a written data processing agreement. Access to a client’s records is limited to the specific team working on that file, not the wider organisation.
Where CT1 or Form 11 filings are involved, Aone is linked to the client through Revenue’s current ROS agent-linking process, which means the client approves that access directly rather than it happening behind the scenes.
Onboarding follows the same logic: customer due diligence documents collected at the start of an engagement are retained in line with the five-year AML requirement, separately from the six-year retention that applies to the accounting records themselves, so the two don’t get conflated or handled on the same schedule by mistake. None of this removes the questions worth asking of any provider you’re evaluating — it’s simply what a properly structured engagement looks like when those questions have already been answered, rather than something being worked out for the first time after a problem comes up.
Conclusion
Security in outsourced accounting isn’t a certificate displayed on a website — it’s a clearly defined legal relationship, backed by a handful of concrete questions answered honestly. If a provider can tell you who the controller is, who the processor is, where your data physically sits, and how long different records need to be kept under Irish law, you’re in a good position to make a decision.
If they can’t, that’s not necessarily a red flag on its own — but it’s a reason to keep asking before you commit anything sensitive to them. If you’re weighing up outsourced bookkeeping, tax or accounts support in Ireland and want to talk through how this works in practice, Aone’s team is happy to walk through it on a call.
FAQs
Who is the data controller when I outsource my bookkeeping in Ireland?
In almost every case, your business — or your accountant, if they instruct the outsourcing partner on your behalf — remains the data controller. The outsourcing provider acts as the data processor, handling the data on your instructions under a written data processing agreement.
Does my outsourced accountant need to be GDPR registered with the DPC?
There’s no separate “GDPR registration” with the DPC for most businesses — the DPC is the regulator that oversees compliance and investigates complaints, rather than a body that issues compliance certificates. What matters is whether your provider can demonstrate the practical elements of compliance: a data processing agreement, appropriate security measures, and clear breach notification procedures.
Is it safe to outsource accounting if the team isn’t based in Ireland or the EEA?
It can be, provided the right safeguard is in place. Where data are transferred outside the EEA to a country without an adequacy decision, the GDPR requires a mechanism, such as standard contractual clauses, to cover that transfer. Ask any provider directly where your data is processed and what safeguards apply if that’s outside the EEA.
How long does an outsourced provider need to keep my accounting records?
Two different retention periods can apply. Accounting records generally need to be kept for six years after the end of the relevant financial year under the Companies Act 2014. Separately, records relating to AML customer due diligence — verifying who you are and who owns the business — are subject to a five-year retention requirement.
What happens to my data if I end the relationship with an outsourced provider?
This should be set out in your data processing agreement. Typically, the processor is required to delete or return your data at the end of the engagement, on your instruction — though records subject to statutory retention periods (such as the six-year Companies Act requirement) may need to be retained separately for that period regardless of when the engagement ends.
What counts as a data breach in outsourced accounting, and does every incident need to be reported?
A breach is any incident that compromises the security of personal data — not just cyberattacks, but things like an email sent to the wrong recipient or a lost laptop. Not every incident has to be reported to the DPC: If it’s genuinely unlikely to pose a risk to the people involved, it doesn’t meet the threshold. It still needs to be logged in an internal breach register, so ask your provider whether they keep one.
How quickly should my outsourced provider tell me if something’s gone wrong with my data?
There’s no fixed number of hours set by GDPR itself. Still, the law requires the processor to notify the controller “without undue delay” once it becomes aware of an incident, and because you, as the controller, may have only 72 hours to notify the DPC, that “without undue delay” needs to be short in practice. This should be spelt out as a specific timeframe in your data processing agreement, not left as a vague commitment.
Australia
USA
UK
Canada