GDPR taloushallinnossa: henkilötiedot, oikeusperuste ja rekisteriseloste
Taloushallinto käsittelee väistämättä henkilötietoja: asiakkaiden nimiä, osoitteita ja pankkitilinumeroita. Käymme läpi, mitä pienyrityksen taloushallinnon on otettava huomioon GDPR:n kannalta.
"Financial management inevitably processes personal data: customer names, addresses, bank account numbers, and payroll data. The EU's General Data Protection Regulation (GDPR) sets clear requirements for the processing of this data. In this article, we will go through what small business financial management needs to take into account."
"Personal data in financial management – what is it?"
"According to GDPR, personal data means all information relating to an identified or identifiable natural person. In financial management, typical personal data include:"
- "Names, addresses, and business IDs (for sole proprietorships) of customers and suppliers"
- "Bank account numbers"
- "Email addresses and phone numbers of invoice contact persons"
- "Payroll data and personal identity codes (payroll)"
- "Travel and expense report details"
Rettslig grunnlag for behandling av personopplysninger
"GDPR requires that every processing of personal data has a legal basis. In financial management, the following are generally used:"
- "Fulfilling a contract: sending invoices and receiving payments"
- "Juridisk forpliktelse: oppbevaringsplikter etter regnskapsloven, skatterapportering"
- "Legitimate interest: debt collection, credit risk assessment"
"For a small business, this practically means: you have the right to process your customer's data for invoicing and accounting without separate consent, because the processing is based on a contract and law."
"Retention periods for financial administration documents"
"GDPR requires that data not be stored longer than necessary. In financial administration, retention periods are primarily determined by the Accounting Act:"
| Asiakirjatyyppi | Säilytysaika | Peruste |
|---|---|---|
| Kirjanpitokirjat (tase, tuloslaskelma, pääkirja) | 10 vuotta tilikauden päättymisestä | Kirjanpitolaki 2:10 |
| Tositteet (laskut, kuitit) | 6 vuotta tilikauden päättymisestä | Kirjanpitolaki 2:10 |
| Palkka-aineistot | 10 vuotta | Ennakkoperintälaki, eläkelait |
| ALV-aineisto | 6 vuotta | Arvonlisäverolaki |
"When the statutory retention period ends, personal data must be deleted or anonymized."
"Mini-checklist for a small business"
- "Create a privacy statement (data protection statement) where you explain what personal data you process and why"
- "Define retention periods by document type"
- "Ensure that your financial management software (e.g. Eemel Accounting) is GDPR-compliant"
- "Restrict access to personal data only to those who need it"
- "Agree on a data processing agreement with the accounting firm and other processors"
- "Delete outdated data regularly"
"Practical example: sole proprietor and privacy statement"
"A sole proprietor kept a customer register in Excel and issued invoices as PDFs. From the GDPR perspective, the situation was problematic: no privacy statement, no data security, no monitoring of retention periods."
"Adopting Eemel Accounting solved most of the problems:"
- "Customer data is in a secure system, not an open Excel file"
- "Access restricted with user ID and password"
- "Financial management software provides a template for the privacy statement"
- "Old data can be systematically deleted"
"Try it in practice"
"Eemel Accounting is designed with GDPR requirements in mind. Personal data is secure and processing is under control."
"Try for 14 days""Frequently asked questions"
"Does a small business need a privacy statement?"
"Yes, if you process personal data (e.g., customer names and addresses for invoicing). A privacy statement must be available."
"Can accounting material be deleted based on GDPR?"
"Not before the statutory retention period expires. The Accounting Act takes precedence over GDPR here."
"Is a data processing agreement needed with the accounting firm?"
"Yes. The accounting firm processes personal data on your behalf, so GDPR requires a written agreement."
"How does GDPR affect bank connections?"
"Account transactions retrieved via bank connection contain personal data. Processing is based on agreement and law. Les mer in our PSD2 article."
"Do I need to ask the customer for consent to process invoicing data?"
"Not usually. The processing of invoicing data is based on the fulfillment of a contract, not consent."
"This article is general in nature and does not constitute legal advice."
