Conformité et contrats · Luxembourg

Personal data and fiduciary services: governing document exchanges

Organise the data exchanged with your fiduciary service provider: GDPR roles, necessary documents, access, retention, service providers and response to incidents.

Données personnelles et fiduciaire : encadrer les échanges de documents : Cartographier les données et les usages réels, Déterminer les responsabilités par traitement, Organiser les accès et les échanges
Les trois premiers repères du guide ; la méthode complète est détaillée ci-dessous.

Invoices, salaries, bank details and identity documents often circulate in a fiduciary services file. The question is not only to find a place to upload them. You need to know why each piece of information is useful, who can view it and what happens when the engagement ends. Clear organisation protects individuals and also makes day-to-day work easier.

Mapping data and actual uses

Start with the engagements: accounting, payroll, filings, file preparation or advisory services. For each one, list the data subjects and the categories of data that are useful. A payroll file and a supplier invoice do not have the same access requirements. Also identify the channels actually used, including documents that arrive by email even though a portal had been planned.

Apply data minimisation: request the necessary items without routinely collecting an entire personal file. This rule does not justify deleting legally required supporting documents. If in doubt, ask for an explanation of the purpose of the request and the applicable basis. Consent is not a universal solution: certain processing operations are based on a contract, a legal obligation or another basis provided for by the Regulation.

Determining responsibilities for each processing operation

The controller determines the purposes and essential means. The processor within the meaning of the GDPR processes data on its behalf. The same commercial relationship may involve several situations. For example, it is necessary to analyse separately the performance of a service on instructions and the processing carried out by the firm for its own obligations. Do not sign off on a general classification without checking what it covers.

Where processing is outsourced, the written arrangement provided for by Article 28 must specify the processing and the respective obligations. Have the clauses adapted to the data, services and tools actually used. A generic annex that describes neither the recipients nor what happens to the files at the end of the engagement is of little help in resolving a specific incident. Also provide for how requests to exercise rights will be forwarded and handled.

Organising access and exchanges

Define the persons authorised to upload, view, amend or approve documents. Prefer individual access and review it when an engagement changes or when a person leaves the team. Also check the ability to restore data and the method for tracking exchanges. A tool presented as secure is not sufficient if a link is then shared too widely or if everyone uses the same account.

For administrative procedures, consult the MyGuichet access guide. Some invitations give visibility beyond the specific procedure envisaged. Prepare a precise process for payroll documents and sensitive information, then test the organisation with demonstration files. Instructions must be simple enough for people to apply them even during the year-end closing period or an absence.

Reviewing service providers and processing locations

Ask which other parties or tools contribute to the service and under what conditions. A solution may store files in one country and allow remote support from another. Identify the transfers or access involved and have the applicable mechanisms reviewed. The word “cloud” alone, just like the sole mention of European hosting, does not describe the entire processing chain.

Specify how changes to processors will be announced and reviewed where the processor regime applies. Request specific information on protection measures appropriate to the risk, without requiring an accumulation of labels unrelated to the engagement. The answers must make it possible to understand who processes which data, for what purpose and subject to which obligations. Keep the version of the contractual documentation that actually applies.

Preparing retention, exit and incidents

Set retention periods or criteria for each category of documents, taking account of legal obligations and justified needs. The end of the engagement does not always require the immediate deletion of all documents; nor does it justify unlimited retention. Organise the return of data, readable formats, withdrawal of access and handling of copies. The GDPR must be taken into account throughout this transition.

In the event of an incorrect transmission, loss or unauthorised access, immediately alert the designated contacts and preserve facts useful for the analysis. The controller must consider notification to the authority, in principle without undue delay and, where feasible, within 72 hours after becoming aware of it, unless there is no risk within the meaning of the Regulation. The processor shall inform the controller without waiting for that deadline. Document the incident and separately consider informing individuals where the risk is high.

The table to take action

Specific questions to incorporate at the start of the engagement.
TopicUseful questionExpected outcome
DataWhy is this document necessary?Justified scope
RolesWho decides and who carries out the work?Classification by processing operation
AccessWho can view the files?Appropriate and reviewable rights
End of engagementWhat should be returned, retained or deleted?Documented organisation
IncidentWho should be notified without delay?Known contact and procedure

A wrong recipient should trigger an organised response

Fictional example: a file containing remuneration information is sent to a contact who was not supposed to receive it. The team does not merely resend the file to the correct recipient. It alerts those responsible, seeks to limit exposure, retains information about the transmission and assesses the data and individuals concerned. The notification decision depends on the risk assessment and applicable rules. The example shows why an identified contact and a short procedure are useful before any incident occurs.

Your preparation checklist

  • Describe the engagements and data used.
  • Check necessity and the applicable basis.
  • Classify roles for each processing operation.
  • Adapt the data processing agreement if required.
  • Limit and review access.
  • Review parties involved and transfers.
  • Prepare retention and return of data.
  • Designate contacts in the event of an incident.

Frequently asked questions

Is a fiduciary service provider always a processor?

The classification depends on the processing actually carried out. Services performed on behalf of the client must be distinguished from the firm's own purposes.

Does the GDPR require everything to be deleted when the client leaves?

No. What happens to the data must take account of statutory retention obligations, the roles of the parties and the applicable contractual framework.

Do all errors result in the same notification?

The facts and the risk must be analysed and documented. Notification to the authority and informing individuals are subject to separate conditions.

Useful terms in this guide

Questions to ask the professional

  • Which processing operations do we each carry out and in what role?
  • Who has access to the data and from where?
  • How are the return of data and alerting handled in the event of an incident?

To specify the engagement to be entrusted, also consult our accounting page.

And for your situation?

Prepare the list of engagements, tools and documents exchanged. Search our directory for a professional to clarify the organisation of the file with your team and, where necessary, with your data protection adviser.

Sources and verification

References consulted on 20 September 2026. Official procedures specify the applicable conditions and exceptions.

This guide explains a general process. The applicable rules depend on your situation; it does not constitute personalised advice. Report a correction.

Your next step

A specific need deserves the right contact

Accounting, taxation, company formation or payroll: prepare your questions, then search the directory for the professional who can review your situation. Check their assignments and status before entrusting them with your file.

Find a professional