United States / Guides / Is offshore bookkeeping legal? Yes — here is the actual rule set

United States · guide

Is offshore bookkeeping legal? Yes — here is the actual rule set

Updated 2026-08-14 · 10-min read · 4 primary sources

The short answer

Yes, offshore bookkeeping is legal. No U.S. law restricts where the person recording transactions, reconciling accounts, or preparing financial statements is physically located — bookkeeping is not a licensed activity anywhere in the country, and location is not a licensing variable. What is regulated is narrower and specific: under Internal Revenue Code section 7216 and its regulations, a tax return preparer must get the taxpayer's written consent before disclosing tax return information to a preparer located outside the United States, and a Social Security number generally has to be redacted before that disclosure unless the preparer uses an IRS-defined data protection safeguard. That rule applies to tax return preparation, not to bookkeeping in general. Beyond it, an offshore engagement is governed by the same data-security and privacy law that governs any provider — the FTC Safeguards Rule for firms handling taxpayer data, state breach-notification statutes, and whatever confidentiality terms the engagement contract sets.

Key facts — verified dates on each

Consent required before offshore disclosure of tax return informationWritten, signed, dated taxpayer consent naming the recipient, the specific information, and the purpose — obtained before disclosure and not as a condition of service · 2026-08-14
Social Security number offshore disclosureMust be redacted or masked before disclosure to a preparer located outside the United States by default; consent alone is not enough — an IRS-defined data protection safeguard is also required to send it unredacted, and a separate no-consent exception covers retransmitting it to the same foreign preparer who originally supplied it · 2026-08-14
IRC 7216 misdemeanor penalty for unauthorized disclosure or useFine of up to $1,000 and up to one year imprisonment, plus prosecution costs; up to $100,000 for disclosures covered by the related civil penalty provision, section 6713 · 2026-08-14
California breach-notification timing (representative state example)Notice to affected residents within 30 calendar days of discovering the breach, once unencrypted personal information is acquired, or reasonably believed acquired, by an unauthorized person (deadline set by SB 446, effective January 1, 2026) · 2026-08-14

What is actually restricted, and what is not

No federal or state statute conditions bookkeeping work on the location of the person doing it. Recording transactions, reconciling bank and credit card accounts, running payroll, closing the books monthly, and preparing financial statements are unlicensed activities that any person or firm can perform from any jurisdiction — the question "is it legal" has a flat yes for the bookkeeping function itself, independent of geography.

The one rule that turns on cross-border disclosure specifically is narrower than "offshore bookkeeping" as a category: it governs a tax return preparer sending tax return information to a preparer located outside the United States, under Internal Revenue Code section 7216. That is a return-preparation rule, not a bookkeeping rule — it applies when information is disclosed in connection with preparing a return, not to the ordinary bookkeeping data (a general ledger, a bank reconciliation, an AP aging report) that never becomes part of a tax filing.

IRC section 7216: consent for offshore disclosure of tax return information

Section 7216 makes it a misdemeanor for a tax return preparer to knowingly or recklessly disclose, or use for a purpose other than preparing the return, information a taxpayer furnished for return preparation — without the taxpayer's consent. The implementing regulation, Treasury regulation section 301.7216-3, sets out exactly what that consent has to say: the name of the recipient, the specific information covered, the purpose of the disclosure, and the taxpayer's signature and date. Consent obtained by making it a condition of service does not count, and a consent form cannot be requested after the return is already prepared.

Disclosure to a preparer located outside the United States carries one further restriction on top of the general consent rule: under 26 CFR section 301.7216-3(b)(4), a U.S.-based preparer's default obligation is to redact or mask the taxpayer's Social Security number before that tax return information leaves the country. There are two narrow exceptions. First, a U.S. preparer may obtain the taxpayer's consent to send an unredacted SSN abroad, but only if the disclosure is made through an "adequate data protection safeguard" as defined by the IRS in published guidance — consent by itself is not enough. Second, no fresh consent is needed to retransmit an SSN back to the same foreign preparer who originally supplied it to the U.S. preparer. Outside those two cases, the SSN has to be masked before disclosure.

The penalty for a knowing or reckless violation is a fine of up to $1,000 and up to a year in prison, plus prosecution costs, under 26 U.S.C. section 7216(a) — and it escalates to a fine of up to $100,000 for the more serious disclosures covered by the related civil penalty provision, section 6713.

  • Applies to: a tax return preparer disclosing tax return information to a preparer located outside the United States
  • Requires: written, dated, signed taxpayer consent naming the recipient, the information, and the purpose, obtained before disclosure
  • Default rule: the taxpayer's Social Security number must be redacted before disclosure abroad — with a narrow exception where consent covers an IRS-defined data protection safeguard, and another for retransmitting to the same foreign preparer who originally supplied it
  • Does not apply to: bookkeeping data that is never furnished in connection with preparing a tax return

What governs bookkeeping data that is not tax return information

Once a transaction record, bank statement, or payroll file is outside the specific context of preparing a tax return, section 7216 has nothing to say about it — but that does not mean the data is unregulated. A firm handling taxpayer or client financial data for compensation, including a bookkeeping or tax-adjacent practice, falls within the Federal Trade Commission's Safeguards Rule, which the IRS restates for tax professionals in Publication 4557: a written information security plan covering access controls, encryption, employee training, and vendor oversight, regardless of where the work is performed or by whom.

Separately, most states have their own breach-notification statutes that apply once personal information — Social Security numbers, financial account numbers, and similar identifiers — is involved, regardless of whether the data ever touched a tax return. California's statute is a representative example: a business that owns or licenses computerized personal information on a California resident must, as of the deadline set by a 2025 amendment (SB 446) that took effect January 1, 2026, notify that resident within 30 calendar days of discovering the breach, once an unauthorized party has acquired, or is reasonably believed to have acquired, unencrypted personal information. A firm working with an offshore provider does not get an exception from these statutes by virtue of where the provider sits — the obligation runs to whoever owns or controls the data, and a vendor relationship does not transfer it away.

Contractual confidentiality sits underneath both of the above: an engagement agreement or data-processing addendum with an offshore bookkeeping provider is what actually specifies retention, breach notice timelines, subcontracting limits, and what happens to data at the end of the relationship — none of which any statute fills in by default.

The diligence questions that actually matter

Because the legal floor is relatively low — bookkeeping location is unrestricted, and only tax-return-specific offshore disclosure triggers a consent rule — the practical protection in an offshore engagement comes from operational diligence, not from a license check. A short, specific set of questions does more work than "are you legal":

  • Access controls: who inside the provider can see which client's data, and is that access role-based and logged, not shared-login
  • Credential custody: does anyone at the provider hold live online banking credentials, or does the engagement use read-only bank feeds and accountant-level access that stops short of moving money
  • SOC reports: has the provider had a SOC 1 or SOC 2 examination performed by an independent auditor, and can the report (or a bridge letter) actually be produced on request — "we take security seriously" is not evidence, a report is
  • Data residency and encryption: where is data stored at rest and in transit, and is it encrypted in both states
  • Subcontracting: does the provider use its own subcontractors or a distributed workforce, and does the contract require disclosure and consent before adding one
  • Offboarding: what happens to a client's data and access on termination, and is that written into the agreement rather than assumed

Where CapEasy sits in this rule set

CapEasy is an India-based provider serving U.S. businesses, and holds this page to the same standard it describes rather than treating the rules above as a general-knowledge disclaimer. CapEasy's work is bookkeeping — recording transactions, reconciling accounts, and preparing financial statements — which is the unrestricted activity described above, not tax return preparation. It does not act as a tax return preparer disclosing tax return information under section 7216, does not request or hold client Social Security numbers as part of the bookkeeping engagement, and does not hold live banking credentials that can move money; bank connections used for reconciliation are read-only. Where a client also needs a federal return prepared or filed, that work is a named preparer's responsibility under the PTIN and Circular 230 rules described in CapEasy's companion guide on non-CPA bookkeeping, not something this page or this engagement extends into.

The figures, and when we checked them

These numbers change by year or by notification. Each one shows the date we last verified it against the source — if that date looks old, check the source before relying on it.

Consent required before offshore disclosure of tax return information
Written, signed, dated taxpayer consent naming the recipient, the specific information, and the purpose — obtained before disclosure and not as a condition of service · verified 2026-08-14
Social Security number offshore disclosure
Must be redacted or masked before disclosure to a preparer located outside the United States by default; consent alone is not enough — an IRS-defined data protection safeguard is also required to send it unredacted, and a separate no-consent exception covers retransmitting it to the same foreign preparer who originally supplied it · verified 2026-08-14
IRC 7216 misdemeanor penalty for unauthorized disclosure or use
Fine of up to $1,000 and up to one year imprisonment, plus prosecution costs; up to $100,000 for disclosures covered by the related civil penalty provision, section 6713 · verified 2026-08-14
California breach-notification timing (representative state example)
Notice to affected residents within 30 calendar days of discovering the breach, once unencrypted personal information is acquired, or reasonably believed acquired, by an unauthorized person (deadline set by SB 446, effective January 1, 2026) · verified 2026-08-14

Questions on this

Is it illegal to have my bookkeeping done overseas?

No. Bookkeeping — recording transactions, reconciling accounts, and preparing financial statements — is not a licensed activity in any U.S. state, and no law restricts where the person doing it is physically located.

Does IRC section 7216 make offshore bookkeeping illegal?

No. Section 7216 governs a tax return preparer disclosing tax return information to a preparer located outside the United States, and requires the taxpayer's written consent before that specific disclosure. It does not apply to bookkeeping data that is never furnished in connection with preparing a tax return.

Can my Social Security number be sent to an offshore bookkeeper?

For tax return information specifically, the default under section 7216 is no — the SSN has to be redacted before it is disclosed to a preparer outside the U.S. Consent alone does not change that; the only way to send it unredacted is through an IRS-defined data protection safeguard, or by retransmitting it to the same foreign preparer that originally supplied it. Outside the specific tax-return-preparer context, the safer practice for any offshore engagement is the same: keep SSNs and similarly sensitive identifiers out of routine bookkeeping data where they are not needed.

Does GDPR apply to a U.S. business sending its own financial data to an offshore provider?

Generally no. GDPR governs the personal data of individuals in the European Union; a U.S. business's own financial and bookkeeping data, and its U.S. customers' data, is not brought under GDPR merely because the provider processing it is located outside the U.S. — the state and federal data-security rules described above are the ones that actually apply.

What is a SOC 2 report, and should an offshore bookkeeping provider have one?

A SOC 2 report is an independent auditor's examination of a service provider's controls over security, availability, and confidentiality of customer data. It is not a legal requirement for bookkeeping, but it is the concrete evidence — rather than a marketing claim — that a provider's access controls and security practices have actually been tested by a third party.

Who should hold the login credentials to my business bank account?

As a diligence matter rather than a legal one, the safer structure is that no outsourced bookkeeping provider holds live, transaction-capable banking credentials. Reconciliation and reporting can be done through read-only bank feeds or accountant-level access that shows transactions without the ability to move money.

Do I need a specific contract clause to make an offshore engagement legal?

No single clause makes the arrangement "legal" — the underlying work is already unrestricted. A written engagement agreement or data-processing addendum is still the practical way to fix retention periods, breach-notification timelines, subcontracting limits, and data handling on termination, none of which federal or state law specifies by default.

Does offshore bookkeeping violate my bank's terms of service?

This depends on the specific bank agreement, particularly around third-party access to online banking, and is a question for that bank directly — it is a contractual matter between the account holder and the bank, separate from the tax and privacy rules described on this page.

Can a CPA firm legally outsource bookkeeping or tax support work offshore?

Yes, for the bookkeeping and non-attest support work — the same "location is not a licensing variable" rule applies. Where the outsourced work touches tax return preparation specifically, the section 7216 consent and SSN-redaction rules described above apply to that portion of the engagement.

What data-security standard applies to a firm handling client tax and financial data, offshore staff or not?

The FTC Safeguards Rule, which the IRS restates for tax professionals in Publication 4557, requires a written information security plan covering access controls, encryption, employee training, and vendor oversight — a standard that applies based on the data being handled, not based on where the staff handling it are located.

Want this handled rather than read about?

A scoping call decides what fits. We are a consulting firm — licensed work runs through partner CPA firms. Whoever signs and files stays yours.

Book a fit call