Certix

Professional services

Data protection for
administrative agencies and tax advisers

Administrative agencies and tax advisers access fiscal, employment and financial data belonging to their clients. Depending on the context, they may act as data controllers or as data processors, which requires specific contracts and proper documentation of the sub-processing chain.

Art. 28

GDPR — data processing agreement

4 years

retention of tax documentation

Art. 6.1.b

GDPR — performance of contract

24 h

personalised proposal

Sector challenges

General obligations for administrative agencies and advisers

Position as data processor

When an agency manages data relating to employees or third parties of its clients exclusively on their instructions, it may act as a data processor under art. 28 GDPR. The precise legal relationship depends on each case; it should be analysed and documented contractually.

Access to tax and employment data

Payslips, contracts, tax returns and financial data of clients' employees are particularly sensitive data requiring security measures and restricted access.

Sub-processing chain

Cloud-based accounting, payroll or labour management software may act as a sub-processor when it processes data exclusively on the agency's instructions. It is advisable to review each provider's terms and ensure they offer the guarantees required by art. 28 GDPR.

Remote access to client systems

Access to a client's IT systems for accounting or payroll management must be governed contractually and protected by adequate security measures.

Dual role: processor and controller

The agency is a data controller for processing its own clients' and employees' data, and a data processor with respect to the data of clients' employees and third parties.

Retention of historical documentation

Tax and employment documentation must be retained for the statutory periods (4 years under the General Tax Act) even after the client relationship has ended. Data must be blocked once those periods have elapsed.

The service

What is included in the service for your administrative agency or adviser

Record of Processing Activities

Differentiated RoPA (Record of Processing Activities): own processing activities (clients, employees) and processing on behalf of clients (payroll, bookkeeping, third-party tax filings).

Information clauses

First- and second-layer information for the services contract with clients and web forms.

Privacy policy and legal notice

Legal documentation tailored to the agency's website.

Data Processing Agreements (DPA)

Ready-to-sign DPA templates for each client that entrusts the processing of employee or third-party data.

Data breach protocol

Incident response procedure with notification to AEPD within 72 hours.

Data subject rights management

Documented procedure for handling requests from clients, clients' employees and third parties.

Document management platform

Access to a private platform with documents, templates and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO (where applicable)

As a general rule, administrative agencies are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your agency?

Tell us the number of clients and the type of services you provide. Proposal in under 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in administrative agencies

Is an administrative agency a data controller or a data processor?

It depends on the context. When an administrative agency manages data relating to employees or clients of another company solely to fulfil tax or employment obligations, it may act as a data processor (art. 28 GDPR). When it processes data relating to its own clients for the purposes of service delivery, it is a data controller. In practice, many agencies assume both roles simultaneously with different clients.

What contract must an administrative agency sign with its clients to comply with GDPR?

When an administrative agency acts as a data processor, it must formalise a Data Processing Agreement (art. 28 GDPR) with each client whose employee, worker or third-party data it manages. This agreement governs the subject matter of the processing, security measures, sub-processing and obligations in the event of a data breach.

Can an administrative agency access the payroll and employment data of its clients' employees?

Yes, but only within the scope of the data processing agreement and for the purposes defined therein. Agency staff accessing such data must be bound by a duty of confidentiality and may only use the data for the purpose agreed with the client.

Is cloud-based accounting or payroll software a sub-processor?

As a general rule, if the agency uses third-party software (cloud-based or SaaS) to process its clients' data, that provider may act as a sub-processor when it processes data exclusively on the agency's instructions. The exact legal relationship depends on each provider's contractual terms. In any case, it is advisable to review and formalise the relationship using the instruments of art. 28 GDPR and to notify clients if so required by the data processing agreement.

How long must an administrative agency retain clients' tax documentation?

Tax legislation sets a retention period of 4 years for documents with tax relevance (General Tax Act). In employment matters, payslips and contracts must be retained for at least 4 years. Once these periods have elapsed, data may be blocked or deleted unless there is another legal basis for retention.

Can an administrative agency access the client's IT systems remotely?

Yes, but such access must be governed by the data processing agreement: the systems to which access is granted, the purpose, security measures for remote access, and a confidentiality commitment from staff. Remote access without an updated agreement or without adequate security measures may constitute a GDPR infringement.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Professional services

GDPR compliance
for your agency.

An expert analyses your practice and proposes the appropriate solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.