{"id":762,"date":"2026-07-22T12:31:41","date_gmt":"2026-07-22T07:01:41","guid":{"rendered":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/?p=762"},"modified":"2026-07-22T12:33:31","modified_gmt":"2026-07-22T07:03:31","slug":"data-security-outsourced-accounting-ireland","status":"publish","type":"post","link":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/data-security-outsourced-accounting-ireland","title":{"rendered":"Data Security in Outsourced Accounting: What Irish SMEs Should Actually Check Before Signing"},"content":{"rendered":"\n<p>Handing your bank feeds, payroll data, and revenue correspondence to a team you&#8217;ve never met in person feels risky, and most of what&#8217;s written about it doesn&#8217;t help much. The usual advice is \u201cmake sure they&#8217;re GDPR compliant&#8221;, as if that&#8217;s a box a provider ticks rather than a legal relationship with specific obligations attached. If you&#8217;re an Irish SME director, sole trader or in-house bookkeeper weighing up an outsourced provider, here&#8217;s what actually matters: who&#8217;s legally responsible for your data, what Irish law requires alongside GDPR, and the concrete questions to ask before you sign anything.<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who&#8217;s Actually Responsible for Your Data \u2014 Controller vs Processor<\/h2>\n\n\n\n<p>Under GDPR, a \u201ccontroller\u201d is whoever decides why and how personal data is processed. A \u201cprocessor\u201d carries out that processing on the controller&#8217;s instructions. In almost every outsourced bookkeeping, payroll or accounts arrangement, your business \u2014 or your accountant, if they&#8217;re the one instructing the outsourcing partner \u2014 is the controller. The outsourcing provider is the processor.<\/p>\n\n\n\n<p>This isn&#8217;t a technicality. It means legal responsibility for how the data is protected doesn&#8217;t transfer to the provider just because they&#8217;re the ones physically handling it. Engaging a processor requires a written contract \u2014 usually called a <a href=\"https:\/\/www.dataprotection.ie\/en\/dpc-guidance\/data-processing-agreements\" target=\"_blank\" rel=\"noopener\">&#8216;data processing agreement&#8217; (DPA)<\/a> \u2014 setting out things like what the processor is allowed to do with the data and for how long; a confidentiality commitment covering everyone with access to it; whether the processor can bring in sub-processors (and a requirement to disclose that); how quickly the processor has to notify you if something goes wrong; and what happens to the data when the engagement ends \u2014 deletion or return, on your instruction.<\/p>\n\n\n\n<p>If a provider can&#8217;t produce a data processing agreement or treats the request for one as unusual, that&#8217;s worth pausing on. You can&#8217;t outsource the underlying accountability for the data \u2014 only its day-to-day handling. This is the point every \u201cwe&#8217;re GDPR compliant\u201d badge on a website skips over.<\/p>\n\n\n\n<p>A quick way to see why this distinction matters: say an outsourced bookkeeping team accidentally emails your payroll file to the wrong client. Under GDPR, it&#8217;s still your business \u2014 the controller \u2014 that&#8217;s ultimately accountable to the affected employees and, if it&#8217;s serious enough, to the DPC. That&#8217;s exactly why the data processing agreement matters so much: it&#8217;s what obliges the processor to tell you quickly, cooperate with any investigation, and take responsibility for its own part in what went wrong, rather than leaving you to find out some other way.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Irish Regulatory Layer (Not Just \u201cGDPR Compliant\u201d)<\/h2>\n\n\n\n<p>\u201cGDPR compliant\u201d isn&#8217;t a certification anyone hands out \u2014 the regulation names one specific enforcing body. In Ireland, that&#8217;s the Data Protection Commission (DPC). It&#8217;s worth knowing this because the DPC is who you&#8217;d approach, or who would investigate, if something went wrong with how your data was handled \u2014 not some abstract \u201cGDPR authority&#8221;.<\/p>\n\n\n\n<p>But GDPR isn&#8217;t the only law shaping how an <a href=\"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/outsource-accounting-cost-ireland\">outsourced accounting provider<\/a> should handle your records, and this is where the Irish-specific detail actually matters.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Anti-money laundering recordkeeping<\/strong><\/h3>\n\n\n\n<p>Accountants and bookkeepers in Ireland are \u201cdesignated persons\u201d under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010. When your provider carries out customer due diligence on your business \u2014 verifying who you are and who owns and controls the company \u2014 they&#8217;re required to keep records evidencing that process, along with records of the services and transactions carried out for you, for five years. That&#8217;s a separate legal clock from anything GDPR sets, tied specifically to the AML obligations that apply to anyone providing accountancy services in Ireland.<\/p>\n\n\n\n<p>This is easy to miss because it doesn&#8217;t appear in most GDPR checklists at all \u2014 it&#8217;s a distinct obligation that sits alongside data protection law, not a subset of it. In practice, it means your provider should be able to tell you, plainly, how they store the identity and beneficial-ownership documents they collected when they onboarded you and for how long they&#8217;ll hold onto them after the engagement ends. A provider who&#8217;s never had to think about this hasn&#8217;t fully reckoned with what \u201cdesignated person\u201d status actually requires.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Companies Act 2014 retention<\/strong><\/h3>\n\n\n\n<p>Separately, your own accounting records \u2014 the ones your outsourced provider is compiling, filing or storing on your behalf \u2014 need to be kept for six years after the end of the financial year they relate to, under <a href=\"https:\/\/revisedacts.lawreform.ie\/eli\/2010\/act\/6\/section\/55\/revised\/en\/html\" target=\"_blank\" rel=\"noopener\">Section 285 of the Companies Act 2014<\/a>. Failing to keep adequate accounting records is a criminal offence, and directors can be held personally liable in some circumstances, so this isn&#8217;t a minor administrative point. It&#8217;s worth asking your provider directly how and where these six-year records are stored, not just how long they&#8217;re kept.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>ROS agent-linking<\/strong><\/h3>\n\n\n\n<p>If your outsourced provider is filing your CT1 corporation tax return or your <a href=\"https:\/\/www.aoneoutsourcing.com\/ie\/self-assessment-tax-services\">Form 11 self-assessment<\/a>, they need to be linked to you as your registered agent on Revenue&#8217;s systems. Revenue changed how this works in 2025: instead of a paper authorisation form, agent-linking now runs through an e-linking process, where the agent submits the link request through ROS, and you approve it separately through ROS or myAccount within 30 days. It&#8217;s a small operational detail, but it means you keep direct, visible control over who&#8217;s authorised to file on your behalf with Revenue \u2014 and it&#8217;s worth confirming that any provider you&#8217;re evaluating is using this current process rather than an outdated paper form.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">If the Work Crosses Borders \u2014 What to Ask About International Transfers<\/h2>\n\n\n\n<p>Many<a href=\"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/top-accounting-outsourcing-firms-ireland\"> outsourced accounting providers <\/a>deliver at least some of their work from outside Ireland and the EEA. That&#8217;s not automatically a problem, but it does trigger specific requirements under GDPR&#8217;s rules on international transfers, and it&#8217;s worth being direct about rather than skating past.<\/p>\n\n\n\n<p>Where personal data is transferred outside the EEA to a country that doesn&#8217;t have an adequacy decision from the European Commission, the transfer needs a safeguard \u2014 most commonly, <a href=\"https:\/\/commission.europa.eu\/law\/law-topic\/data-protection\/international-dimension-data-protection\/standard-contractual-clauses-scc_en\" target=\"_blank\" rel=\"noopener\">Standard Contractual Clauses (SCCs)<\/a> built into the contract between you (or your accountant) and the provider. A properly run provider should also be able to speak to a transfer impact assessment: essentially, whether the destination country&#8217;s laws could undermine the protections the SCCs are meant to provide.<\/p>\n\n\n\n<p>This isn&#8217;t a purely theoretical requirement \u2014 European courts have taken a much closer look at international data transfers in recent years, and regulators, including the DPC, have shown they&#8217;re willing to act where safeguards are missing or inadequate. None of that means outsourcing outside the EEA is off the table; it means the safeguard must actually exist and be something a provider can point to, rather than being assumed to be fine because \u201ceveryone does it this way&#8221;.<\/p>\n\n\n\n<p>You don&#8217;t need to become a GDPR transfer specialist to evaluate this. Three questions do most of the work in a call with a prospective provider:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Where, physically, is our data processed and stored \u2014 which country or countries?<\/li>\n\n\n\n<li>If any of that is outside the EEA, what safeguard is in place \u2014 Standard Contractual Clauses, or something else?<\/li>\n\n\n\n<li>Can we see the data processing agreement, including anything covering international transfers, before we sign?<\/li>\n<\/ul>\n\n\n\n<p>A provider that answers these plainly, rather than deflecting to a general compliance statement, is telling you something useful about how seriously they take the rest of this.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">If Something Goes Wrong: What Breach Notification Actually Looks Like\u00a0<\/h2>\n\n\n\n<p>Most of what&#8217;s written about data breaches focuses on prevention. Worth spending a moment on what actually happens if something does go wrong, because it&#8217;s where the controller\/processor split covered earlier stops being theoretical and starts having a clock attached to it.<\/p>\n\n\n\n<p>Under GDPR, if your business is the controller, you \u2014 not your outsourced provider \u2014 are the one legally required to notify the Data Protection Commission, and you have to do it within 72 hours of becoming aware of the breach, where feasible. That 72-hour clock starts the moment there&#8217;s reasonable certainty a breach has occurred, not once an investigation is finished. If the breach is likely to pose a high risk to the people whose data was involved \u2014 employees on a payroll file, for instance \u2014 you may also need to notify them directly, without undue delay.<\/p>\n\n\n\n<p>This is exactly why the processor&#8217;s breach notification obligation matters so much in the outsourcing context. Under GDPR, a processor is required to notify the controller without undue delay once it becomes aware of a breach \u2014 and your data processing agreement should say specifically how quickly that has to happen and what information it needs to include, rather than leaving &#8220;without undue delay&#8221; undefined. If your outsourced provider only tells you about an incident once they&#8217;ve completed their own internal review, you could already be behind on a deadline you didn&#8217;t know was running. The practical ask, then, isn&#8217;t &#8220;Do you have a security policy?&#8221; \u2014 it&#8217;s &#8220;How many hours after you notice something do we hear about it, and in what format?&#8221;<\/p>\n\n\n\n<p>It&#8217;s also worth knowing that not every incident needs to be reported to the DPC\u2014a low-risk incident, like a password reset triggered by a suspicious login with no actual data accessed, generally doesn&#8217;t. But every incident, reportable or not, needs to be logged in a breach register, recording what happened, its effects, and what was done about it. Ask your provider whether they maintain this kind of record even for incidents they judge don&#8217;t meet the reporting threshold \u2014 it&#8217;s a good indicator of whether breach handling is a genuine internal process or something improvised only when it&#8217;s unavoidable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Technical and Operational Controls That Should Back All of This Up<\/h2>\n\n\n\n<p>None of the above works without decent technical hygiene sitting underneath it, so it&#8217;s worth naming briefly: data encrypted both in transit and at rest, access limited to the specific people actually working on your file rather than the whole organisation, multi-factor authentication on any client portal or shared drive, and an audit trail showing who accessed what and when. These are table stakes at this point\u2014any provider handling financial data should already have them without being asked, and most competent providers will happily describe them in some detail.<\/p>\n\n\n\n<p>The real differentiator isn&#8217;t whether a provider has encryption; it&#8217;s whether they can also show you the legal and regulatory pieces covered above \u2014 the data processing agreement, the AML and Companies Act retention practices, and, if relevant, the cross-border safeguard. A provider that leads with certifications and struggles with the rest hasn&#8217;t necessarily done anything wrong, but it&#8217;s a sign the conversation needs to go further before you sign.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A Due-Diligence Checklist Before You Sign<\/h2>\n\n\n\n<p>Everything covered above translates into a short, practical list. You don&#8217;t need to memorise the legislation behind each point\u2014you just need a straight answer to each question below before you sign anything:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Can I see a written data processing agreement before I sign anything?<\/li>\n\n\n\n<li>Who, specifically, will have access to our data \u2014 a named team, or anyone in the organisation?<\/li>\n\n\n\n<li>Do you use any sub-processors, and will you tell us if that changes?<\/li>\n\n\n\n<li>Where is our data physically processed and stored?<\/li>\n\n\n\n<li>If any work happens outside the EEA, what safeguard \u2014 SCCs or otherwise \u2014 covers that transfer?<\/li>\n\n\n\n<li>How quickly will you notify us of a data breach, and how?<\/li>\n\n\n\n<li>How do you meet the five-year AML recordkeeping requirement for customer due diligence, and where are those records kept?<\/li>\n\n\n\n<li>How do you handle the<a href=\"https:\/\/www.irishstatutebook.ie\/eli\/2014\/act\/38\/section\/285\/enacted\/\" target=\"_blank\" rel=\"noopener\"> six-year accounting records<\/a> retention requirement under the Companies Act 2014?<\/li>\n\n\n\n<li>Are you using Revenue&#8217;s current ROS agent-linking process, and will we retain visibility over that link?<\/li>\n\n\n\n<li>What happens to our data \u2014 deletion, return, or something else \u2014 if we end the engagement?<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">What This Looks Like in Practice<\/h2>\n\n\n\n<p>At Aone, this plays out across bookkeeping, <a href=\"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/corporation-tax-guide-ireland\">corporation tax (CT1)<\/a> filing, self-assessment (Form 11), and <a href=\"https:\/\/www.aoneoutsourcing.com\/ie\/year-end-accounting-ireland\">year-end accounts finalisation<\/a> for Irish clients. In practice, the client \u2013 or their accountant \u2013 remains the data controller, and Aone operates as the processor under a written data processing agreement. Access to a client&#8217;s records is limited to the specific team working on that file, not the wider organisation.&nbsp;<\/p>\n\n\n\n<p>Where CT1 or Form 11 filings are involved, Aone is linked to the client through Revenue&#8217;s current ROS agent-linking process, which means the client approves that access directly rather than it happening behind the scenes.<\/p>\n\n\n\n<p>Onboarding follows the same logic: customer due diligence documents collected at the start of an engagement are retained in line with the five-year AML requirement, separately from the six-year retention that applies to the accounting records themselves, so the two don&#8217;t get conflated or handled on the same schedule by mistake. None of this removes the questions worth asking of any provider you&#8217;re evaluating \u2014 it&#8217;s simply what a properly structured engagement looks like when those questions have already been answered, rather than something being worked out for the first time after a problem comes up.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>Security in outsourced accounting isn&#8217;t a certificate displayed on a website \u2014 it&#8217;s a clearly defined legal relationship, backed by a handful of concrete questions answered honestly. If a provider can tell you who the controller is, who the processor is, where your data physically sits, and how long different records need to be kept under Irish law, you&#8217;re in a good position to make a decision.&nbsp;<\/p>\n\n\n\n<p>If they can&#8217;t, that&#8217;s not necessarily a red flag on its own \u2014 but it&#8217;s a reason to keep asking before you commit anything sensitive to them. If you&#8217;re weighing up <a href=\"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/bookkeeping-services-small-business-guide\">outsourced bookkeeping<\/a>, tax or accounts support in Ireland and want to talk through how this works in practice, Aone&#8217;s team is happy to walk through it on a call.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>FAQs<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Who is the data controller when I outsource my bookkeeping in Ireland?<\/strong><\/h3>\n\n\n\n<p>In almost every case, your business \u2014 or your accountant, if they instruct the outsourcing partner on your behalf \u2014 remains the data controller. The outsourcing provider acts as the data processor, handling the data on your instructions under a written data processing agreement.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Does my outsourced accountant need to be GDPR registered with the DPC?<\/strong><\/h3>\n\n\n\n<p>There&#8217;s no separate \u201cGDPR registration\u201d with the DPC for most businesses \u2014 the DPC is the regulator that oversees compliance and investigates complaints, rather than a body that issues compliance certificates. What matters is whether your provider can demonstrate the practical elements of compliance: a data processing agreement, appropriate security measures, and clear breach notification procedures.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Is it safe to outsource accounting if the team isn&#8217;t based in Ireland or the EEA?<\/strong><\/h3>\n\n\n\n<p>It can be, provided the right safeguard is in place. Where data are transferred outside the EEA to a country without an adequacy decision, the GDPR requires a mechanism, such as standard contractual clauses, to cover that transfer. Ask any provider directly where your data is processed and what safeguards apply if that&#8217;s outside the EEA.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How long does an outsourced provider need to keep my accounting records?<\/strong><\/h3>\n\n\n\n<p>Two different retention periods can apply. Accounting records generally need to be kept for six years after the end of the relevant financial year under the Companies Act 2014. Separately, records relating to AML customer due diligence \u2014 verifying who you are and who owns the business \u2014 are subject to a five-year retention requirement.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What happens to my data if I end the relationship with an outsourced provider?<\/strong><\/h3>\n\n\n\n<p>This should be set out in your data processing agreement. Typically, the processor is required to delete or return your data at the end of the engagement, on your instruction \u2014 though records subject to statutory retention periods (such as the six-year Companies Act requirement) may need to be retained separately for that period regardless of when the engagement ends.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What counts as a data breach in outsourced accounting, and does every incident need to be reported?<\/strong><\/h3>\n\n\n\n<p>A breach is any incident that compromises the security of personal data \u2014 not just cyberattacks, but things like an email sent to the wrong recipient or a lost laptop. Not every incident has to be reported to the DPC: If it&#8217;s genuinely unlikely to pose a risk to the people involved, it doesn&#8217;t meet the threshold. It still needs to be logged in an internal breach register, so ask your provider whether they keep one.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How quickly should my outsourced provider tell me if something&#8217;s gone wrong with my data?<\/strong><\/h3>\n\n\n\n<p>There&#8217;s no fixed number of hours set by GDPR itself. Still, the law requires the processor to notify the controller &#8220;without undue delay&#8221; once it becomes aware of an incident, and because you, as the controller, may have only 72 hours to notify the DPC, that &#8220;without undue delay&#8221; needs to be short in practice. This should be spelt out as a specific timeframe in your data processing agreement, not left as a vague commitment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Handing your bank feeds, payroll data, and revenue correspondence to a team you&#8217;ve never met in person feels risky, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":763,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[38],"tags":[109,110,111,106,108,107],"class_list":["post-762","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-accounting","tag-confidentiality-outsourced-accountant-ireland","tag-data-protection-outsourced-accounts-ireland","tag-data-security","tag-data-security-in-outsourced-accounting-ireland","tag-gdpr-outsourced-bookkeeping-ireland","tag-is-outsourcing-accounting-safe-ireland"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/posts\/762","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/comments?post=762"}],"version-history":[{"count":2,"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/posts\/762\/revisions"}],"predecessor-version":[{"id":765,"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/posts\/762\/revisions\/765"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/media\/763"}],"wp:attachment":[{"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/media?parent=762"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/categories?post=762"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aoneoutsourcing.com\/ie\/blog\/wp-json\/wp\/v2\/tags?post=762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}