Customer data in accounting tools should be limited to what is needed for invoicing, payment management and other justified purposes. Review the provider arrangement, user access and retention, especially when integrations copy information into additional services.
Do not place sensitive case notes in invoice descriptions merely because the software allows free text. Keep marketing use separate from accounting necessity and assess it on its own basis.
Collect the details needed for the transaction
Identify the information required to invoice the customer, deliver the agreed service and manage payment. A business customer may need a company name, billing address and accounts contact, while an individual customer's record should remain proportionate to the transaction. Avoid adding identity documents or detailed personal circumstances simply because the accounting tool has an attachment field. More data does not automatically make the invoice record more useful.
ICO's data-protection principles cover lawful and transparent use, purpose limitation, minimisation, accuracy, retention and security. Apply those principles to the actual accounting workflow, including information copied to connected tools. The fact that customer data is needed for invoicing does not establish that every later marketing or unrelated use is justified. Assess the additional purpose separately and explain relevant processing appropriately. [1]
Keep invoice descriptions informative but restrained
Describe the goods or services clearly enough to support the commercial and tax record. For sensitive professional work, avoid placing confidential case details in a description that will appear on emails, bank-payment references or reports visible to wider finance staff. Use a controlled matter or order reference where it provides the necessary traceability, with detailed records held in the appropriate restricted system.
Review standard invoice templates and automated messages for unnecessary personal fields. A template copied from another business may request a date of birth or personal address that serves no purpose in the current transaction. Remove fields that are not needed, while retaining information required by the applicable invoice rules. The aim is a sufficient accounting record with a clear purpose for each personal detail collected.
Control customer access and internal permissions
Give staff the access needed for invoicing, credit control or reporting without assuming everyone needs the full customer database. Review bulk exports and administrator functions separately from routine invoice entry. For customer portals, check that each user can see only the records they are entitled to access. A correct invoice sent through an incorrectly configured portal can still expose another customer's information.
Use a verified process for changes to billing contacts or delivery addresses where the change affects confidentiality or payment. Do not redirect a customer's invoices based solely on an unexpected email without considering the risk and appropriate verification. Retain a proportionate record of the authorised change. This supports both accurate records and a clear explanation if the customer later disputes who received a document.
Understand what integrations copy
List the systems receiving customer details, such as payment processors, CRM tools, reporting dashboards and email services. Identify the purpose and fields transferred to each. An integration enabled for payment reconciliation may also synchronise optional contact fields unless configured otherwise. Check the actual settings and provider arrangements rather than assuming that only invoice totals leave the accounting application.
When a connection is no longer required, remove its access through the supported process and review retained copies under the relevant arrangements. Keep a record of the provider and processing purpose so later data requests or incidents can be assessed accurately. The business should be able to explain where a customer's accounting information travels without reconstructing years of software subscriptions from bank payments.
Retain and respond using a clear process
Keep accounting records for the applicable justified periods and distinguish them from unnecessary working copies or outdated contact lists. A customer request to erase information requires assessment of the relevant obligations and rights; it should not trigger automatic deletion of records the business must retain. Equally, the existence of tax records does not justify keeping every unrelated note indefinitely.
Use User permissions in cloud accounting for user-permission controls and Cloud bookkeeping setup to discuss customer-data handling within accounting administration. Describe the information, systems and purpose involved without attaching the full customer export. Where the question concerns a data-subject request, breach or disputed legal basis, identify the need for appropriate data-protection advice alongside the operational accounting review.
Periodically check whether customer contacts are still current and whether dormant accounts contain unnecessary sensitive notes. Correct inaccurate details through a traceable process and apply the retention schedule. A manageable review of actual fields and access is more useful than a broad privacy statement that does not reflect what the accounting system stores or shares.
Illustrative scenario
A professional-services firm changes invoice wording to a neutral service description and stores confidential working papers in the appropriate restricted system. Finance retains enough detail to explain the charge without unnecessary disclosure.
Preparation checklist
- Map customer data fields
- Review integrations
- Limit sensitive descriptions
- Set access and retention rules
Frequently asked questions
Does invoicing necessity justify using customer details for marketing?
Not automatically. Assess the separate purpose and applicable rules, including the relevant transparency and marketing requirements.
Should sensitive case details appear in invoice descriptions?
Use only the detail needed for the accounting and commercial purpose. Keep sensitive substantive records in an appropriately restricted system and use a suitable reference where possible.
Can a customer deletion request be handled by removing every invoice?
Not automatically. Assess the request alongside applicable record obligations and rights, retaining what is justified and responding through the proper process.
Why review accounting integrations for customer data?
They may copy more fields than expected or retain access after their original purpose ends. Identify the information, purpose and permissions for each connection.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction