← Back to Articles

Cloud Accounting Software Updates Its Terms of Service Every 6 Months. You Click Accept Without Reading.

Six months ago, your accounting software sent an email: "Our Terms of Service have been updated. Please review and accept to continue using the platform." You tapped Accept. There were...

MENACE Votre logiciel comptable met à jour ses CGU tous les 6 mois. Vous cliquez Accepter sans lire. Chaque mise à jour = un nouveau consentement juridique. Vos données financières changent de statut sans que vous le sachiez. 2–4× mises à jour par an en moyenne 7 000 mots par mise à jour CGU type 0 s de lecture réelle en pratique "Le consentement est légalement valide. La compréhension, elle, ne l'est pas." CONDITIONS GÉNÉRALES Mise à jour — Mars 2026 § 14.3 — Utilisation des données agrégées ✓ ACCEPTER 72h pour lire Mise à jour #17 Vous, à 23h Liberté · liberte.free Souveraineté des données · Semaine 22

Cloud Accounting Software Updates Its Terms of Service Every 6 Months. You Click Accept Without Reading.

Six months ago, your accounting software sent an email: "Our Terms of Service have been updated. Please review and accept to continue using the platform."

You tapped Accept. There were approximately 6,800 words in the update. You didn't read them.

If the update included a new clause about using your financial data for product improvement or AI model training — and many accounting software updates now do — you authorized it at that moment.

---

What Happens When You Tap Accept

GDPR — the General Data Protection Regulation, the EU law governing how personal and business data can be processed — requires that consent to data processing be freely given, specific, informed, and unambiguous. This applies to the financial data in your accounting platform: your employees' payroll figures, your clients' invoice data, your revenue and expense records.

When your accounting software updates its terms of service, it is modifying the data processing agreement that governs all of that information. A business owner who clicks Accept has, in law, consented to the new terms. Whether they read them is a different question. "Informed" under GDPR doesn't require that you actually understood what you signed — it requires that you were given the opportunity to understand.

This is not a deception. Vendors send the emails. They display the banners. They log the acceptance. The process produces valid consent in law while achieving something closer to zero informed consent in practice.

---

What's in Those 7,000 Words

Terms of service updates for cloud accounting software most commonly include material changes in three areas.

Data use for product improvement and AI training: clauses giving the vendor the right to use anonymized or aggregated transaction data to train AI models, improve product features, or conduct research. Pennylane's terms of service, as of early 2026, include provisions of this type. Most major cloud accounting vendors have moved in this direction as they add AI features to their platforms — the AI needs training data, and the most valuable training data is the financial records their customers have been generating for years.

Third-party data sharing: updates may add new categories of companies the vendor shares your data with to provide services. Each new company in the chain is a new jurisdiction, a new privacy policy, and a new link between your data and an organization you've never heard of.

Jurisdiction and governing law: where disputes are resolved, which courts have authority, which country's law applies to the contract. These clauses affect your data protection rights in practice — the ability to invoke French law becomes complicated when your contract says disputes go through Irish courts and a US-headquartered resolution process.

---

The Acceptance Window Problem

72 hours is a common window for accepting updated terms. Reading 7,000 words of legal text in 72 hours is possible for a lawyer with no other commitments. For a restaurant owner managing a Saturday service, it is not.

The right to read exists. The practical ability to exercise it doesn't.

Banking regulation in France handles the equivalent situation differently. A bank changing its current account terms must give two months' advance notice, must offer the account holder the right to close the account without penalty if they don't accept the new terms, and must receive explicit acceptance before changes take effect. These protections exist because regulators recognized that "accept to continue" — when applied to a product you can't practically abandon — creates consent under pressure.

Cloud accounting software is not subject to the same banking regulation. Your financial data — which may be more sensitive than your current account balance — has fewer protections when it moves from a bank to a software platform.

---

Why This Is Your Problem, Not Just the Vendor's

French and EU law makes you — the business owner — responsible for how your employees' and clients' personal data is handled. Your accountant processes data on your behalf. Your cloud accounting software processes it on behalf of your accountant. The legal responsibility flows upward to you.

When the CNIL (the Commission Nationale de l'Informatique et des Libertés, France's data protection authority) investigates an employee complaint about payroll data handling, the investigator asks for documentation of all agreements governing how that data is processed. Your terms-of-service acceptance history is that documentation.

CNIL can fine up to 4% of annual global turnover for GDPR violations. €7.9 billion in cumulative data protection fines have been issued worldwide since 2018. Enforcement has focused largely on large enterprises. The pattern is beginning to extend to smaller businesses, particularly where AI data processing is involved — the EU AI Act, taking effect in stages from 2026, introduces documentation requirements for AI systems that process financial data.

Clicking Accept without reading is not an unusual choice — it is essentially universal among software users. It may become an expensive one.

---

The Architecture Question

Vendor data rights only matter when the vendor holds your data on their servers. If a software vendor stores your general ledger, your payroll records, and your bank transactions in their environment — as all cloud accounting platforms do — then their terms of service govern what they can do with that data. Each update potentially extends those rights.

Liberté's architecture works differently. Financial data connects to government systems directly — net-entreprises.fr for payroll and pre-hiring declarations, bank connectivity through open banking (the EU regulation that mandates free API access to your bank data) for reconciliation. Your accounting data stays where it was created. No external server holds your complete financial picture.

When AI intelligence is needed — Stralevo, available as an optional paid product on the Liberté marketplace — the data stays on infrastructure you control. Every interaction is logged. AI processing requires your explicit, revocable permission rather than a rolling terms-of-service acceptance. If a regulator asks what AI accessed your financial data and under what authorization, you can answer — because the record exists and you can read it.

No architecture eliminates the need for data governance — every business using any software should understand what that software's terms allow. What changes is the nature of the risk: from a vendor who can quietly expand their data rights via update, to direct government connections with no intermediate data holder in the chain.

---

Before the Next Accept Button

On the next terms-of-service update notification — and one will arrive — two sections are worth finding before tapping Accept.

First, find the data use clause: what can the vendor do with your financial data? Look for phrases like "product improvement," "research," "anonymized," "aggregated," and "model training." These indicate your transaction data may be used in ways beyond running your software.

Second, find the data sharing addendum: which third-party companies process your data on the vendor's behalf, and in which countries? If companies outside the EU are listed without specific data protection agreements, your data may be leaving EU jurisdiction.

Reading these two sections in a 7,000-word document takes approximately 8 minutes. Not the full document — just those two sections.

A broader question follows: whether the system holding your financial data should require you to track legal updates every six months just to stay in control. For a business owner already working seven days a week, that's eight minutes you shouldn't need to spend — and a risk you shouldn't need to carry. Liberté is designed so you don't.

Free platform. Direct government connections. Your data stays yours without requiring you to read a legal update to keep it that way.

Launching Q2 2026, France first.

← Previous Your Liasse Fiscale Has 60 Pages. Your Software Should Generate All of Them From Your Existing Data. Next → A Company That Can't Switch Accounting Software Without Losing Three Months of Productivity Is Not Free.

Ready to free your accounting data?

Join the waitlist for early access when Liberté launches in Q2 2026.

No spam, just launch updates.