Sector wise readiness
Professional services: the advisers with the weakest controls
- Are law and accounting firms Data Fiduciaries or Processors?
- Usually both, and it changes per engagement. Processing a client's data on their instructions makes you a Processor for that engagement. Your own staff, marketing list and prospects make you a Data Fiduciary.
- Who this affects
- Law firms, accountants, consultants and agencies.
- What to do about it
- Identify the role for each engagement, and close the gap between the sensitivity of what you hold and the strength of your controls and contracts.
An uncomfortable one for law, accounting, consulting and agency firms.
You hold some of the most sensitive data in your clients' businesses. Litigation files. Financial records. Deal documents. HR investigations.
And the auditor's observation across this sector is blunt: firms hold highly sensitive client data but often have the weakest controls and contracts. The people advising everyone else on compliance are frequently the least ready themselves.
Part of it is a genuine confusion about which role you are in, and it changes per engagement. When you process a client's data on their instructions, you are a Processor for that engagement. When you handle your own staff, your own marketing list, your own prospects, you are a Data Fiduciary. Most firms are both, at the same time, and have never written down which is which.
A sector map is a superset, not a launch checklist.
What applies from the start, whatever your size
- ✅ Notice
- ✅ Consent and easy withdrawal
- ✅ Security safeguards
- ✅ Rights handling
- ✅ Grievance mechanism
- ✅ Processor contracts
- ✅ Breach response
What professional services carries from day one
- ✅ Clarify your role per engagement. Fiduciary for your own data, Processor for client data. Decide it, write it down, and let the obligations follow.
- ✅ Engagement letters that carry the terms. Your engagement letter or DPA needs processing and breach clauses. A confidentiality clause from 2015 is not a DPA.
- ✅ Confidential record security. Encrypt and access control sensitive client files. This is where the gap usually is, not in the policy document, but in who can open the shared drive.
- ✅ Retention reconciliation. Professional record keeping duties say keep. DPDP says erase when the purpose ends. Reconcile the two and document it, file type by file type.
What may not apply
- ❌ SDF obligations. Firms are generally not Significant Data Fiduciaries, even though client data can be highly sensitive. That status comes only on Government notification.
- ❌ A mandatory Data Protection Officer, annual DPIAs and independent audits. These attach to SDF status, not to the sensitivity of your files.
The better question
The better question is not "do the compliance rules really apply to a professional firm?"
It is "if a client audited us tomorrow, would our controls survive the standard we hold them to?"
Law creates obligations. Scale and risk influence implementation. But role clarity, engagement terms and file security apply from your first client. None of them wait for scale.
If you advise clients on compliance, would your own file security pass the test?