EU edition
Where your data goes, and what covers it under GDPR.
The European Commission has not issued an adequacy decision for Pakistan, so every transfer runs on its own legal basis, stated here rather than buried in a policy.
Finbryn treats client financial data under the EU General Data Protection Regulation. Because the European Commission has issued no adequacy decision for Pakistan, transfers to our accounting team there run on Standard Contractual Clauses, backed by a transfer impact assessment of Pakistani law completed before any transfer begins, exactly as GDPR Clause 14 requires.
How access and transfers are handled
Standard Contractual Clauses
Data moving to our Pakistan-based team is covered by Standard Contractual Clauses rather than an adequacy finding, since none exists for Pakistan.
Transfer impact assessment
Before data starts moving, we complete a transfer impact assessment of the destination country's laws, the step GDPR Clause 14 requires alongside the SCCs themselves.
Least-privilege access
Team members reach only the client systems and files their role requires, on a written device policy rather than personal machines.
What non-compliance costs
The most serious GDPR breaches carry fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher. We build our own controls with that ceiling in mind, not as a marketing line.
Security
Controls and their current status
- In place6
- In progress7
- Planned3
Multi-factor authentication on client systems
Every team member connecting to a client's accounting software, bank feed, or shared storage does so behind multi-factor authentication. Single-factor password access to client systems is not permitted under our internal access policy, regardless of role or tenure.
Evidence: policy document
In placeLeast-privilege access control
Team members are granted access only to the specific client files and systems their engagement requires, not blanket access across the client base. Access is reviewed when an engagement ends or a role changes, and removed promptly rather than left open.
Evidence: policy document
In placeNo local storage of client files
Client accounting data is worked on inside the client's own software (QuickBooks Online, Xero, or similar) or an approved shared workspace, not downloaded and saved to an individual team member's laptop or personal device. This limits how many places a client's financial data can end up.
Evidence: policy document
In placeSigned non-disclosure agreement for every staff member
Every team member with any access to client financial information signs a non-disclosure agreement before their first day on an engagement, covering client data specifically, not just general company confidentiality. This is a condition of employment, not an optional add-on for larger accounts.
Evidence: policy document
In placeFull-disk encryption on team devices
Laptops used to access client accounting systems run full-disk encryption, so a lost or stolen device does not expose readable client data. This is a baseline device requirement before any team member is granted client system access, not a later hardening step.
Evidence: policy document
In placeDocumented onboarding and offboarding for client access
Every engagement follows a written checklist for granting access when a team member joins a client's books and revoking it when they leave the engagement or the company. This removes the common failure mode where a departed team member's access to a client's accounting software is simply forgotten.
Evidence: policy document
In placeWritten information security program (WISP)
A written information security program aligned to IRS Publication 4557, covering administrative, technical, and physical safeguards for taxpayer and client financial data, is being drafted ahead of handling any US tax preparation data. A summary will be published once it is adopted, and no US tax data will be processed before it is in place.
In progressData processing agreement templates with SCCs and IDTA
Standard Contractual Clauses for EU client data and a UK International Data Transfer Agreement, each paired with a transfer risk assessment, are being finalized with counsel to cover the cross-border transfer of client financial data from the UK and EU. These will be signed as part of onboarding for clients in those regions.
In progressSection 7216 consent workflow for US tax data
A written-consent workflow meeting the format required by Revenue Procedure 2013-14 is being built so that every US client explicitly consents, before any tax return information is disclosed, to that information being used and processed by our team. No US taxpayer data will be shared ahead of a signed consent.
In progressErrors and omissions insurance
A professional errors and omissions policy covering the firm's advisory and preparation-support work is in the process of being placed. We will not claim coverage is in force, or name a policy, until it is confirmed bound and the certificate is on file.
In progressCyber liability insurance
A cyber liability policy covering data breach response for client financial data is in the process of being placed alongside our errors and omissions coverage. As with that policy, we will not claim coverage exists until it is confirmed bound.
In progressThird-party software vendor review
A documented review of the security posture of every software vendor in our stack, QuickBooks Online, Xero, and connected apps, is being formalized into a standing checklist run before any new tool is adopted for client work, rather than left to individual judgment.
In progressWritten incident response plan
A documented, tested procedure for detecting, containing, and notifying clients of a security incident involving their data is being drafted alongside the written information security program. It will define notification timelines and responsibilities before it is relied on rather than after an incident occurs.
In progressSOC 2 Type I examination
We intend to engage an independent auditor for a SOC 2 Type I examination once the underlying controls above (WISP, incident response, vendor review, access management) are fully in place and operating, since a Type I report only has value once there is something real for the auditor to examine. No SOC 2 report exists today, and we will not use that language about ourselves until one is issued.
PlannedISO 27001 certification
ISO 27001 certification is a longer-term goal, particularly for UK and Australian clients where it carries more procurement weight, and would follow after SOC 2 readiness work is complete. No certification exists today and none is implied by any control listed above until it is actually issued.
PlannedIndependent penetration test
An independent, third-party penetration test of client-facing systems and internal tooling is planned as part of SOC 2 readiness work, to validate the access and encryption controls above rather than take them on faith. No test has been performed as of today, and none is claimed.
Planned
Questions
Questions EU clients ask about data handling
Is Pakistan covered by a GDPR adequacy decision?
No. The European Commission has not issued one, which is exactly why the transfer runs on Standard Contractual Clauses plus a transfer impact assessment rather than adequacy.
Does Finbryn hold a SOC 2 report or ISO 27001 certification?
No, not yet. We will not claim either until a real, completed report or certificate exists.
Who signs the data processing agreement?
Northlane Solutions Inc. as the contracting entity, with the SCCs annexed and a transfer impact assessment completed before your data moves.
What happens to my data if I stop being a client?
Access is removed and data handling follows the retention terms in your engagement letter and our data processing agreement.
Do you use subprocessors, and are they listed anywhere?
Any subprocessor that touches client data is bound by the same contractual safeguards as our own team, and the list is available on request as part of your data processing agreement. We do not add a new subprocessor to an active account without telling you first.
Is our data encrypted in transit and at rest?
Yes, data moves and sits encrypted using industry-standard protocols across the systems we control, and access is limited to the named pod working your account. The specifics are set out in the data processing agreement your account starts under.
Next step
Need this for your own compliance file?
Book a call and we will walk through the SCCs and transfer impact assessment in as much detail as your review needs.