AGIDAT – Datenschutz | Informationssicherheit

Data Protection for Tax Advisors & Law Firms

Client data, professional secrecy, DATEV & co. — reconciling GDPR with professional rules.

Data protection in tax advisory and law firms

Firms process highly sensitive data every day: annual financial statements, tax returns, asset statements, clients' personal life circumstances. Professional secrecy under § 57 of the German Tax Consultancy Act (StBerG) and § 43a of the German Federal Lawyers' Act (BRAO) protects this information under criminal law.

Yet professional secrecy and GDPR are not opposites — they complement each other. GDPR creates the data protection framework, professional secrecy the professional-conduct framework. Both must be complied with.

Client data under GDPR

Every client is a data subject within the meaning of GDPR. Processing their data is generally based on the engagement (contract performance, Art. 6(1)(b)) and on statutory obligations (e.g., tax retention obligations).

Information obligations

Clients must be informed about data processing under Art. 13 GDPR — ideally when the engagement is accepted. This information can be integrated into the engagement letter or provided as a separate document.

Retention and deletion

Statutory tax retention periods (6–10 years) overlap with the data protection principle of storage limitation. Once these periods expire, client files must be deleted — systematically and with documentation.

A deletion concept for firms takes into account: tax law deadlines, commercial law deadlines, ongoing legal matters, and the firm's own interest in legal protection.

DATEV and firm software

DATEV is at the heart of many tax advisory firms. Using DATEV services (accounting software, Mein DATEV Portal, document management system) requires:

  • A DPA with DATEV: DATEV provides standard contracts that firms must enter into
  • Clarifying data categories: which client data flows into DATEV systems?
  • Rules for DATEV staff: DATEV technicians can theoretically access client data — this must be contractually regulated

The same applies to other firm software (Addison, AGENDA, Simba) and cloud services (Microsoft 365, Google Workspace).

Electronic files and cloud storage

More and more firms work with electronic files and cloud-based document management. This is generally permissible under data protection law, but subject to requirements:

  • Encryption: client data in the cloud must be transmitted and stored encrypted
  • Server location: ideally EU data centers; special requirements apply to US providers
  • Access protection: strong authentication (2FA) for all firm staff
  • DPA: with every cloud provider that has access to client data

Employee data in the firm

Firm staff — tax assistants, bookkeepers, administrative staff — must be bound to the confidentiality of client data. This is not just a GDPR requirement, but also required under professional-conduct rules.

Written confidentiality undertakings are standard — and, where relevant, should also cover the use of private devices and remote-work arrangements.

Client communication by email

Most firms communicate with clients by email. This is sensitive from a data protection perspective:

  • Unencrypted emails can be intercepted
  • Tax and legal documents deserve particular protection
  • Clients should be informed of the risks and, where necessary, asked for consent to unencrypted communication

Alternatives: client portals (DATEV Mein DATEV Portal, other secure file-transfer solutions).

Our offering for firms

We advise tax advisory and law firms pragmatically: with an understanding of the professional-conduct particularities, the role of DATEV in day-to-day firm operations, and the reality of small and mid-sized firm structures.

On request, we take on the external DPO function and serve as the first point of contact for all data protection matters — including when clients request information.