Where your data lives, and who can touch it
Cross-border bookkeeping is a data question before it is an accounting question. Here is our arrangement, stated concretely — and the law that governs each piece of it.
The arrangement
The law that applies, market by market
Orientation, not legal advice — each framework below is public, and your counsel or accountant can confirm how it lands on your facts.
United States
Tax-return information is protected by its own federal regime: a preparer’s use and disclosure of it is governed by IRC §7216 and its consent rules — which is the partner CPA’s domain, and one reason returns run through licensed firms. State privacy and breach-notification laws apply to business data generally.
Australia
The Privacy Act’s Australian Privacy Principles govern personal information handling, and the ATO’s five-year record-keeping rules apply to the records themselves wherever the bookkeeping is done. Lodgment authority sits with TPB-registered agents, whose own obligations attach to your data too.
United Kingdom
UK GDPR governs personal data, and its international-transfer rules (the IDTA and the UK addendum) are the mechanism any offshore provider must work under. This page is information — our UK services remain under consideration.
For accounting firms
Outsourcing disclosure and client-consent obligations — including jurisdictions that require consent before records are shared outside the country — remain with your firm, and we support whatever your professional body requires: our access model, our location, and our arrangement in writing, for your engagement file.
capeasy.co is operated by CapEasy Consulting Pvt Ltd. Our delivery team works from India, on your hours, with partner CPA firms in the United States and registered agents in Australia.
Ask the awkward questions first
Security answers are only useful before you sign. Ask us who would touch your file, from where, with what access — and get it in writing.