An accounting firm handles hundreds of documents every month containing clients' personal and tax data: payslips, invoices, IDs, tax forms. The uncomfortable question is how they come in. If the answer is WhatsApp, loose email or an uncontrolled shared folder, your firm has a GDPR problem, and a professional-image one too, that a client portal solves at the root.
This guide explains what the rules actually require when you handle third-party documents, why informal channels don't comply, and how a secure portal brings order to your firm right as your clients start to digitalise their invoicing.
Why WhatsApp and email are a GDPR problem
When a client sends you a payslip over WhatsApp or attaches a balance sheet to an email, that data travels and is stored outside your control. The General Data Protection Regulation (GDPR) requires you, as controller or processor, to guarantee the integrity and confidentiality of that data (Article 5.1.f) and to apply security measures appropriate to the risk (Article 32).
Conventional, unencrypted email transmits information in plain text across several servers: a channel vulnerable to interception. WhatsApp stores documents on personal devices, with no per-client access control, no record of who uploaded what, and copies in personal backups you don't manage. Spain's data-protection authority, the AEPD, has sanctioned the sending of sensitive documentation by email without adequate measures, precisely for breaching Article 32.
On top of this sits the duty of professional secrecy of the tax and labour advisor: not just good practice, but an obligation.
The day you lose a phone with client documents on it, the GDPR gives you 72 hours to notify the breach to the authority (Article 33). With a portal, the data lives on the server, not in your pocket.
What the rules actually require (no jargon)
You don't need to be a lawyer to grasp the essentials:
- Confidentiality and integrity (GDPR Art. 5.1.f): only the right people get access, and documents are neither altered nor lost.
- Security measures appropriate to the risk (GDPR Art. 32): encryption, access control and activity logging. The more sensitive the data, the stricter the measure.
- 72-hour breach notification (GDPR Art. 33): if there's a leak, you must report it, so it pays to minimise the chances of one.
- Duty of secrecy and compliance with Organic Law 3/2018 (LOPDGDD), Spain's adaptation of the GDPR.
The key isn't just to comply, but to be able to prove it. With WhatsApp that's nearly impossible; with a portal, it's all on the record.
WhatsApp and email versus a client portal
| Criterion | WhatsApp / email | Client portal |
|---|---|---|
| Encryption in transit and at rest | Partial or not guaranteed | Yes |
| Each client sees only their own files | No | Yes, with permissions |
| Traceability (who uploaded what and when) | No | Audit log |
| Meeting and proving GDPR Art. 32 | Very hard | Built for it |
| If a phone is lost | Breach risk | Data on the server, not the device |
| Image in front of the client | Informal | Professional |
What a client portal for accounting firms is
It's a private, secure space, branded as your firm, where each client logs in with their own account to upload or view their documents. It replaces "just send me that on WhatsApp" with an ordered, encrypted, logged flow. For you, it stops being a chaotic inbox and becomes a system.
How it works, step by step
- The client uploads their documents to the portal, not over WhatsApp or loose email.
- Secure portal with permissions: each client sees only their own files, logged and GDPR-compliant.
- AI classifies and sorts: invoices, payslips and delivery notes are left ready to review.
- Ready in your software: synced with A3, Sage, Holded or the ERP you already use.
It's exactly the flow I build on the web design for accounting firms page: website + portal + automation, applied to the specific case of a firm.
What your firm gains
- Less time chasing documents and fewer transcription errors.
- Demonstrable GDPR compliance, with real traceability.
- A modern image that sets you apart from the firm next door.
- Scalability: more clients no longer means more chaos in your inbox.
Need something more advanced?
Professional Package from €1,490. E-commerce, CMS, advanced SEO.
See Professional PackageWhy now: Verifactu and e-invoicing
The tax calendar is pushing your clients towards digital, and that's an opportunity for your firm. Verifactu will be mandatory for companies before 1 January 2027 and for the rest of those obliged before 1 July 2027, under Royal Decree-law 15/2025. And the B2B electronic invoice from the Crea y Crece Law arrives in phases between 2027 and 2028 (Royal Decree 238/2026).
In plain terms: over the next two years, almost all of your clients will change how they issue and receive invoices. A firm that already receives and processes documents through a portal, rather than over WhatsApp, reaches that transition with its homework done. For the detail on deadlines and penalties, I broke it down in the Verifactu guide for SMEs.
How to take the step
You don't have to blow up the way you work overnight. You start with a professional website and a secure portal, connect it to your software, and add automation where it hurts most. The goal isn't technology for its own sake: it's that you stop chasing documents and can prove you comply.
Need something more advanced?
Professional Package from €1,490. E-commerce, CMS, advanced SEO.
See Professional PackageSources
- Regulation (EU) 2016/679 (GDPR): Articles 5, 32 and 33.
- Organic Law 3/2018 (LOPDGDD).
- Spanish Data Protection Agency (AEPD): guidance on encryption and security of processing.
- Tax Agency: Verifactu deadlines.



