Purpose and minimisation
Pull and expose the fields needed for the reporting purpose rather than collecting additional personal data simply because an API makes it available.
GDPR and accounting data
Accounting data from Xero and QuickBooks can include personal information. Datplan's desktop model keeps pulled provider datasets in the local reporting workflow instead of a Datplan-hosted analytics warehouse, while the organisation remains responsible for why the data is processed, who can access it, how long it is retained and where exports are later shared.
The short answer
The organisation creates another working copy that needs its own controls. Whether that copy is a spreadsheet, CSV, local database, dashboard export or BI dataset, personal information does not stop being personal information simply because it has moved into a reporting workflow.
Datplan can reduce the need to send provider datasets through another hosted reporting warehouse, but the user still decides the purpose, scope, retention, access and onward sharing of the local data.
UK data-protection principles
The ICO summarises the core UK data-protection principles as lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
Pull and expose the fields needed for the reporting purpose rather than collecting additional personal data simply because an API makes it available.
Decide how long local databases, exports, archived reporting packs and backups are genuinely needed. A reporting copy should not become an indefinite store by default.
Protect the Windows account, device, export folders and backups; document the controls and review any later cloud BI publication or file sharing as a separate processing step.
For current regulatory guidance, use the Information Commissioner's Office guidance. Data-protection guidance can change as legislation and regulatory interpretation develop.
Accounting data is mixed data
Invoices, bills, expense claims, contacts, payments and transaction narratives can contain names, email addresses, postal addresses, employee information, sole-trader details or free-text descriptions. That means a reporting dataset should be handled according to its actual contents, not assumed to be non-personal merely because it came from an accounting system.
When a report only needs totals by month, account or product, consider whether detailed personal fields need to be included in the downstream output at all.
Where data is stored
Pulled source datasets remain in the desktop reporting workflow and your chosen export locations. Datplan may process the account, billing, usage and support records needed to operate the service.
Xero, QuickBooks, HubSpot and other supported source datasets are stored in the local desktop reporting workflow and user-selected export locations.
Account, sign-in, source-access, billing, allowance, run-status and support records may be processed online where needed to operate the service. See the privacy policy for more detail.
Xero and QuickBooks reporting
Pull supported Xero accounting data into the desktop workflow, then control the resulting dashboards, local database and exports under the organisation's reporting and retention policy.
View Xero reporting →Apply the same discipline to supported QuickBooks data: select the needed reporting population, protect local outputs and review any onward sharing separately.
View QuickBooks reporting →GDPR questions
No. Storage location is only one design choice. An organisation still needs an appropriate lawful basis, purpose, access controls, retention decisions, security measures, transparency and other controls required by applicable data-protection law.
Yes. Accounting records can contain names, contact details, transaction narratives, employee or supplier information and other data relating to identifiable people. The organisation should classify and handle exported data accordingly.
Provider datasets are pulled into the Windows desktop reporting workflow rather than a Datplan-hosted analytics warehouse. Users still control and are responsible for their device, local files, exports, backups, retention and any later sharing or BI publication.
No. Datplan is reporting and data-pull software. Its privacy-first architecture can reduce some unnecessary data movements, but using Datplan does not by itself demonstrate or certify compliance.
Review Datplan's security and privacy pages, then apply your organisation's own access, retention, backup and sharing controls to local accounting data.