In brief: Article 226-13 of the Penal Code punishes any disclosure of secret information by a professional depositary. A client’s accounting documents fall under this category. In the cloud era, this fact requires you to look at where your documents really are, who can access them, and what a leak or foreign requisition would cost your firm.
Tuesday noon. A client asks you to send last year’s tax return to their new investor. You open your Pennylane, export the document, paste it into an email, and send it. Meanwhile, the file passes through your computer, your Gmail Business inbox, Google’s servers, and the recipient’s inbox. Before even looking at the quality of the encryption, ask yourself the real question: how many third parties have just had access to a secret accounting document?

Article 226-13 leaves no room for nuance
Article 226-13 of the Penal Code has a particularity: it applies automatically as soon as you are a depositary of secret information, either by status or profession, or due to a function or mission. For a chartered accountant, this status is established by simple registration with the Order. No need to sign an NDA, no need to expressly mention the secret in the mission letter. The secret is attached to the profession.
« The disclosure of secret information by a person who is a depositary thereof, either by status or profession, or by reason of a function or temporary mission, is punishable by one year’s imprisonment and a fine of 15,000 euros. »
Article 226-13 of the Penal Code
The Code of Ethics of the Order of Chartered Accountants, in its articles 145 and following, goes even further. Professional secrecy is qualified as “absolute,” and it extends to the entire firm staff, interns, and even external service providers. The simple act of entrusting documents to an unsupervised subcontractor can constitute a breach of professional ethics.
Why the cloud is changing the rules of the game
Before 2010, the issue of accounting confidentiality was simple. Documents were on paper, in a binder, in a locked cabinet. Today, they are on a shared Drive, in Pennylane, in Tiime, in Dext, in an email, in a WeTransfer, and in the local copy of the employee who is teleworking. The scope of confidentiality has not changed. The technical perimeter to which it applies, however, has exploded.
Yet, every time a document leaves the perimeter you directly control, it enters the perimeter of a subcontractor. The GDPR regulates this relationship through contracts—Data Processing Agreements (DPA)—but these contracts do not create sovereignty; they organize it on your behalf. If the SaaS provider is American, your DPA cannot protect you against a CLOUD Act requisition. If the provider has been acquired, your DPA is renegotiated without you. If the provider has a bug that exposes your data, you are informed after everyone else.
What the tools you use are really saying
Pennylane is a French player, now valued at over two billion euros, which raised one hundred and seventy-five million euros at the start of 2026. Its jurisdiction is French. This is a real difference compared to a TaxDome or a SmartVault. However, Pennylane remains a hosted SaaS: your documents live on their servers, under their operational control, and the compliance of their security depends on their architecture. This is manageable, provided you audit the DPA and understand that you are in a subcontracting arrangement.
Dext, which belongs to the IRIS group, is British in origin — therefore post-Brexit, it is outside the European Union regarding transfer issues. Tiime is French, smaller, and focused on the independent and freelance segment. Cegid, EBP, and Sage are long-standing players but remain heavy stacks, poorly suited for small firms that want a client portal.
On the American side, TaxDome and SmartVault are references used by tens of thousands of firms in the English-speaking world. Their architecture is solid, and their ecosystem is powerful. But their jurisdiction of incorporation mechanically exposes your client documents to the CLOUD Act. For a French firm, this is not a minor detail.
Ten-year retention: what article R. 123-200 of the French Commercial Code states
In addition to accounting secrecy, there is the retention obligation. Article R. 123-200 of the Commercial Code, supplemented by Article L. 102 B of the Tax Procedure Book, mandates the retention of supporting documents for ten years from the closing of the financial year. This obligation is not a mere formality: it is regularly audited, and failure to comply exposes you to tax reassessments and penalties.
After all, ten years is longer than the average lifespan of a SaaS. It is longer than a typical buyout-rebranding cycle. If your vendor shuts down or pivots, you must be able to retrieve all documents stored in a usable and auditable format. This is true portability, not just advertised portability. It is technically feasible for most SaaS products, but the operational cost of migrating ten years of documents is rarely budgeted for.
The 2026 electronic invoicing mandate does not solve the problem, it shifts it
The transition to mandatory electronic invoicing between businesses, planned starting September 2026 for large companies and 2027 for small and medium-sized enterprises, will structure invoicing workflows around approved platforms. This is a positive development for the traceability of this specific category of documents. However, it does not cover others: bank account details, client contracts, legal statutes, proof of address, social security contribution certificates, and bank statements. All these documents will continue to be collected through other channels, and these are the ones that pose the greatest sovereignty concerns.
Criteria for a clean collection chain
Before looking at Client Vault or any other tool, here is the checklist to apply. Hosting with a French or European provider, with the publisher’s jurisdiction in France or the EU. A partitioned space per client — not a global folder accessible to the entire team. Enforceable traceability of access, uploads, validations, and deletions. Document requests should be structured rather than via free-form email. GDPR compliance regarding retention periods, the right to erasure, and portability. Independence from a single publisher: if the tool disappears, the firm recovers its data in a usable format.
This checklist allows you to evaluate Pennylane, TaxDome, SmartVault, or any other solution. Pennylane checks the box for editorial sovereignty but remains a hosted SaaS. TaxDome loses editorial sovereignty. So does SmartVault. A WordPress stack with a sovereign vault ticks all six criteria, provided you choose the right host.

What Client Vault offers for an accounting firm
Client Vault, as a WordPress plugin, creates a private space for each of your firm’s clients. When you request a tax return, bank details, or a contract, your client uploads the document to this space. Each upload is validated and timestamped. The history remains viewable and enforceable. When you transmit a document to a colleague or an auditor, you download it from your vault, send it via the channel of your choice, but keep a central record.
The benefit of WordPress architecture is that it integrates into your existing stack rather than replacing it. You keep Pennylane for accounting, you keep Dext for OCR, and you add Client Vault for the secure collection of non-flow documents. WordPress hooks allow you to connect your vault to your CRM, your messaging system, and your automation tools. It is about coexistence rather than competition.
For WordPress agencies that serve professional firms: this is exactly the type of deployment where you provide visible value. Selecting a French host, configuring an SSL certificate, integrating with Pennylane via webhooks, staff training, and annual support. A five-person firm represents a repeatable deployment that you can package.
Honest limitations
Client Vault is not accounting software. It does not replace Pennylane, Tiime, or Cegid. It is not intended to do so. It complements your stack regarding document collection and client portal functionality. It also does not handle electronic invoicing as defined by the 2026 certified platforms: for that, you will use your invoicing solution and the official platform.
Finally, digital sovereignty requires technical mediation. If you do not have a trusted WordPress agency, or if you are not comfortable maintaining a WP site, the benefit is less clear. For a firm that wants minimal technical effort and accepts SaaS dependency, a standard Pennylane setup remains simpler. The sovereign path requires commitment.
Let’s get to know each other
If you are a chartered accountant, tax specialist, or a WordPress agency serving such firms, and you are interested in the sovereignty of document collection, let’s discuss via video call. Twenty to thirty minutes to understand your situation, review your current stack, and see how to articulate a sovereign WordPress path with the tools you are already using.
Frequently asked questions
Does Article 226-13 apply to chartered accountants?
Yes. Registration with the Order automatically confers the status of a custodian of confidential information. The Order’s Code of Ethics, in its articles 145 and following, qualifies professional secrecy as absolute and extends it to all members of the firm as well as supervised external service providers.
Does storing client documents on Google Drive violate accounting secrecy?
Not automatically, but it is a high-risk area. Google Drive is a processor under GDPR: you must have a DPA in place, verify the analysis of transfers outside the EU, and ensure partitioning and traceability. In practice, an unstructured shared Drive does not provide these guarantees.
Is Pennylane compliant with Article 226-13?
Pennylane is a French player that offers a DPA and a secure architecture. This does not exempt the firm from qualifying its own processing relationship and meeting its obligations. Pennylane is compatible with a compliant approach, but compliance remains shared.
Are TaxDome or SmartVault acceptable for a French firm?
Their incorporation jurisdiction in the United States exposes them to the CLOUD Act. This requires the firm to conduct a specific impact assessment, implement additional technical measures, and maintain increased vigilance regarding DPA updates. Compliance is not impossible, but it is more complex to manage than with a French or European provider.
What is the penalty for a firm that discloses information through negligence?
Article 226-13 provides for one year of imprisonment and a fifteen-thousand-euro fine. Criminal sanctions are rare in practice, but CNIL administrative fines and disciplinary sanctions from the professional Order are more common. To this must be added the reputational cost.
How long must accounting records be kept?
Article R. 123-200 of the Commercial Code and Article L. 102 B of the Tax Procedure Code require a ten-year retention period from the close of the financial year. This duration applies to supporting documents, accounting books, and management records.
What does the GDPR say about client accounting records?
The GDPR requires security of processing (Article 32), traceability, contractual oversight of processors (Article 28), and limitation of retention periods (Article 5). For accounting records, the legal tax retention period takes precedence, but the other principles apply in full.
{ “@context”: “https://schema.org”, “@type”: “Article”, “headline”: “Art. 226-13 et secret comptable : ce que la dématérialisation change”, “author”: {“@type”: “Person”, “name”: “Dragan Stamenkovic”}, “datePublished”: “2026-05-10”, “dateModified”: “2026-05-10”, “publisher”: {“@type”: “Organization”, “name”: “Client Vault”}, “mainEntityOfPage”: “https://clientvault.pro/blog/art-226-13-secret-comptable-numerique” }{ “@context”: “https://schema.org”, “@type”: “FAQPage”, “mainEntity”: [ {“@type”: “Question”, “name”: “L’article 226-13 s’applique-t-il aux experts-comptables ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Oui. L’inscription à l’Ordre confère la qualité de dépositaire d’informations secrètes.”}}, {“@type”: “Question”, “name”: “Stocker des pièces clients sur Google Drive viole-t-il le secret comptable ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Pas mécaniquement mais c’est une zone à risque qui demande DPA, analyse de transferts et cloisonnement.”}}, {“@type”: “Question”, “name”: “Pennylane est-il conforme à l’article 226-13 ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Pennylane est français et propose un DPA. La conformité reste partagée entre éditeur et cabinet.”}}, {“@type”: “Question”, “name”: “TaxDome ou SmartVault sont-ils acceptables pour un cabinet français ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Leur juridiction américaine les expose au CLOUD Act, ce qui impose une analyse d’impact spécifique.”}}, {“@type”: “Question”, “name”: “Quelle peine encourt un cabinet qui révèle par négligence ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Un an d’emprisonnement et 15 000 euros d’amende au titre de l’article 226-13. Sanctions CNIL et ordinales également possibles.”}}, {“@type”: “Question”, “name”: “Combien de temps faut-il conserver les pièces comptables ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Dix ans à compter de la clôture de l’exercice (article R. 123-200 Code de commerce, article L. 102 B LPF).”}}, {“@type”: “Question”, “name”: “Que dit le RGPD sur les pièces comptables clients ?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Sécurité du traitement (art. 32), encadrement des sous-traitants (art. 28), limitation des durées (art. 5).”}} ] }



