
Invoices, salaries, bank details and identity documents often circulate in a fiduciary services file. The question is not only to find a place to upload them. You need to know why each piece of information is useful, who can view it and what happens when the engagement ends. Clear organisation protects individuals and also makes day-to-day work easier.
The framework to review
The GDPR applies to data relating to identified or identifiable natural persons. The roles of controller and processor depend on the purposes, the means and the facts, not only on the title of the contract. Professional confidentiality and statutory retention obligations must be reconciled with data protection. This guide helps prepare exchanges; it does not constitute certification of the firm's or the client's compliance.
Mapping data and actual uses
Start with the engagements: accounting, payroll, filings, file preparation or advisory services. For each one, list the data subjects and the categories of data that are useful. A payroll file and a supplier invoice do not have the same access requirements. Also identify the channels actually used, including documents that arrive by email even though a portal had been planned.
Apply data minimisation: request the necessary items without routinely collecting an entire personal file. This rule does not justify deleting legally required supporting documents. If in doubt, ask for an explanation of the purpose of the request and the applicable basis. Consent is not a universal solution: certain processing operations are based on a contract, a legal obligation or another basis provided for by the Regulation.
Determining responsibilities for each processing operation
The controller determines the purposes and essential means. The processor within the meaning of the GDPR processes data on its behalf. The same commercial relationship may involve several situations. For example, it is necessary to analyse separately the performance of a service on instructions and the processing carried out by the firm for its own obligations. Do not sign off on a general classification without checking what it covers.
Where processing is outsourced, the written arrangement provided for by Article 28 must specify the processing and the respective obligations. Have the clauses adapted to the data, services and tools actually used. A generic annex that describes neither the recipients nor what happens to the files at the end of the engagement is of little help in resolving a specific incident. Also provide for how requests to exercise rights will be forwarded and handled.
Organising access and exchanges
Define the persons authorised to upload, view, amend or approve documents. Prefer individual access and review it when an engagement changes or when a person leaves the team. Also check the ability to restore data and the method for tracking exchanges. A tool presented as secure is not sufficient if a link is then shared too widely or if everyone uses the same account.
For administrative procedures, consult the MyGuichet access guide. Some invitations give visibility beyond the specific procedure envisaged. Prepare a precise process for payroll documents and sensitive information, then test the organisation with demonstration files. Instructions must be simple enough for people to apply them even during the year-end closing period or an absence.
Reviewing service providers and processing locations
Ask which other parties or tools contribute to the service and under what conditions. A solution may store files in one country and allow remote support from another. Identify the transfers or access involved and have the applicable mechanisms reviewed. The word “cloud” alone, just like the sole mention of European hosting, does not describe the entire processing chain.
Specify how changes to processors will be announced and reviewed where the processor regime applies. Request specific information on protection measures appropriate to the risk, without requiring an accumulation of labels unrelated to the engagement. The answers must make it possible to understand who processes which data, for what purpose and subject to which obligations. Keep the version of the contractual documentation that actually applies.
Preparing retention, exit and incidents
Set retention periods or criteria for each category of documents, taking account of legal obligations and justified needs. The end of the engagement does not always require the immediate deletion of all documents; nor does it justify unlimited retention. Organise the return of data, readable formats, withdrawal of access and handling of copies. The GDPR must be taken into account throughout this transition.
In the event of an incorrect transmission, loss or unauthorised access, immediately alert the designated contacts and preserve facts useful for the analysis. The controller must consider notification to the authority, in principle without undue delay and, where feasible, within 72 hours after becoming aware of it, unless there is no risk within the meaning of the Regulation. The processor shall inform the controller without waiting for that deadline. Document the incident and separately consider informing individuals where the risk is high.
The table to take action
| Topic | Useful question | Expected outcome |
|---|---|---|
| Data | Why is this document necessary? | Justified scope |
| Roles | Who decides and who carries out the work? | Classification by processing operation |
| Access | Who can view the files? | Appropriate and reviewable rights |
| End of engagement | What should be returned, retained or deleted? | Documented organisation |
| Incident | Who should be notified without delay? | Known contact and procedure |
A wrong recipient should trigger an organised response
Fictional example: a file containing remuneration information is sent to a contact who was not supposed to receive it. The team does not merely resend the file to the correct recipient. It alerts those responsible, seeks to limit exposure, retains information about the transmission and assesses the data and individuals concerned. The notification decision depends on the risk assessment and applicable rules. The example shows why an identified contact and a short procedure are useful before any incident occurs.
Your preparation checklist
- Describe the engagements and data used.
- Check necessity and the applicable basis.
- Classify roles for each processing operation.
- Adapt the data processing agreement if required.
- Limit and review access.
- Review parties involved and transfers.
- Prepare retention and return of data.
- Designate contacts in the event of an incident.
Frequently asked questions
Is a fiduciary service provider always a processor?
The classification depends on the processing actually carried out. Services performed on behalf of the client must be distinguished from the firm's own purposes.
Does the GDPR require everything to be deleted when the client leaves?
No. What happens to the data must take account of statutory retention obligations, the roles of the parties and the applicable contractual framework.
Do all errors result in the same notification?
The facts and the risk must be analysed and documented. Notification to the authority and informing individuals are subject to separate conditions.
Useful terms in this guide
Questions to ask the professional
- Which processing operations do we each carry out and in what role?
- Who has access to the data and from where?
- How are the return of data and alerting handled in the event of an incident?
To specify the engagement to be entrusted, also consult our accounting page.
And for your situation?
Prepare the list of engagements, tools and documents exchanged. Search our directory for a professional to clarify the organisation of the file with your team and, where necessary, with your data protection adviser.
Sources and verification
References consulted on 20 September 2026. Official procedures specify the applicable conditions and exceptions.
- CNPD — RGPD, définitions des acteurs
- CNPD — RGPD, principes et licéité
- CNPD — RGPD, contrat, sécurité et incidents
- CNPD — RGPD, transferts internationaux
- Guichet.lu — utilisateurs et rôles d’un espace professionnel
This guide explains a general process. The applicable rules depend on your situation; it does not constitute personalised advice. Report a correction.
Your next step
A specific need deserves the right contact
Accounting, taxation, company formation or payroll: prepare your questions, then search the directory for the professional who can review your situation. Check their assignments and status before entrusting them with your file.