Accountant Office Data Recovery: Accounting Software, e-Ledger and Taxpayer Data
Data recovery for SMMM and YMM (certified public accountant) offices. Logo, Mikro, Netsis, ETA, Zirve, Vega, Luca accounting software. 10-year retention of e-Ledger (e-Defter), e-Invoice, e-Archive, e-Waybill under the Tax Procedure Law (VUK). SGK e-Bildirge, KVKK data controllership. Disk failure and ransomware during the busy season. 3-2-1 backup plus offline plus cloud.
Accountant Office Data Recovery: Accounting Software, e-Ledger and Taxpayer Data
When a certified public accountant's office drive fails, what is lost is not a handful of files. Hundreds of taxpayers' accounting records spread across years, e-Ledger (e-Defter) certificates whose legal retention period is 10 years, e-Invoice archives, SGK declarations, income and corporate tax returns, trial balances, balance sheets, and income statement printouts all disappear at once. Moreover, because a significant part of this data is "customer data" for an SMMM or YMM office, it gives rise to data controller status under KVKK. In other words, a single disk failure can turn into a commercial, legal, and even criminal crisis all at the same time.
At DSET we have seen a marked increase in recent years in data recovery requests from certified public accountant offices. In this article we will explain the typical digital assets of accounting offices, the loss scenarios they commonly face, the retention obligation within the GİB and VUK framework, the KVKK obligation, and how to set up a correct backup strategy.
Typical Digital Assets in an SMMM or YMM Office
Although physical paperwork is still important in certified public accountant offices, the heart of the operation is the accounting software's database file. Products in widespread use in Turkey include Logo (Tiger, Go, Netsis), Mikro, ETA, Zirve, Vega, Luca, Datasoft, and Orka. The vast majority of these programs use MSSQL, Sybase, or a similar relational database. Database files are stored with extensions such as MDF, LDF, NDF, FDB, and DBF, and they can become inconsistent if copied without a proper backup.
In addition, the following digital assets are present in the office:
- e-Ledger (e-Defter) packages: Journal and general ledger XML files, certificate files approved by GİB, and signature envelopes. The GİB e-Ledger portal tracks these certificates against legal deadlines such as "the end of the third month following the relevant month." For the official guide, see GİB e-Defter.
- e-Invoice and e-Archive: The UBL-TR XML format of incoming and outgoing invoices, display PDFs, and envelope information. For details, the GİB e-Belge portal is the basic reference.
- e-Waybill and e-Producer receipt: Electronic documents that have become mandatory for many taxpayers regardless of sector.
- Tax return archives: VAT, withholding, provisional tax, corporate, income, and stamp tax returns, and BDP or GİB online tax office printouts.
- SGK declarations: Monthly premium and service documents, employment entry and exit declarations, and MUHSGK combined declaration files. For the official channel, the SGK e-Bildirge system can be consulted.
- Payroll and personnel data: Identity, IBAN, and salary information belonging to the personnel of taxpayer firms. This item falls directly into the "not special category but high risk" data category from a KVKK standpoint.
- Customer correspondence: Outlook PST/OST files, Excel trial balances in shared folders, and Word records.
A mid-sized SMMM office has between 60 and 300 taxpayers. Considering that at least 5 years of active data and 10 years of archive must be kept for each taxpayer, the total data on the office drives easily reaches the terabyte level.
Retention Obligation Within the VUK Framework: 5 Years or 10 Years?
Many office owners think, "I keep things for 5 years." This is incomplete information. According to Article 253 of the Tax Procedure Law (VUK), there is an obligation to preserve books and documents for 5 years starting from the calendar year following the year to which they relate. However, the Turkish Commercial Code imposes a 10-year retention period for the same documents. For e-Ledger certificates, GİB practice operates on a 10-year basis. So in real life, a certified public accountant office must be structured according to a 10-year data retention plan.
If a ledger or certificate is lost, a discretionary assessment ground may arise under VUK Article 30. For the taxpayer, this can translate into additional tax and penalties. For the certified public accountant, professional liability (Law No. 3568 and the TÜRMOB disciplinary regulation) comes into play. The TÜRMOB ethics and disciplinary directives define the secure retention of customer data as a professional obligation.
In short: data loss is not just an IT matter, it directly touches the financial and legal liability of the professional.
From a KVKK Standpoint, the Certified Public Accountant Is a Data Controller
A certified public accountant office processes the personal data of thousands of natural persons through the payrolls, personnel files, and invoice contents it manages on behalf of its clients. According to KVKK interpretations, SMMM and YMM offices, as a rule, carry data controller status in this processing activity. VERBİS registration, the obligation to inform, data security measures, and data breach notification (72 hours) are direct consequences of this status.
When taxpayer data is leaked as a result of a ransomware attack, the office owner must notify not only its clients but also KVKK. For this reason, in data recovery processes it is necessary to document not just "get the data back" but also "how, with whom, in what environment, and under what destruction commitment the data was recovered." On this subject, our KVKK compliance framework covers an NDA, a chain of custody record, and a commitment to secure destruction after delivery to the data controller.
On the international standards side, ISO/IEC 27037 should be taken as a reference for digital evidence and data collection processes. This standard sets out the principles for identifying, collecting, acquiring, and preserving digital evidence, and forms the basic skeleton of a recovery process compliant with KVKK.
The Most Common Loss Scenarios in Certified Public Accountant Offices
The recurring patterns we have compiled from our field experience are as follows:
1. Disk Failure During the Busy Year-End Period
Late February, March, and April are periods when computers stay constantly on due to the corporate and income tax workload. In single-disk workstations, the mechanical parts of HDDs wear out under this intense write tempo. In cases that come in with the complaint "my disk froze" while closing the year-end trial balance, the SMART error counters have usually been signaling for months but went unnoticed. The first response in these cases is critical: the disk must be powered off, cloning must be done in a cleanroom, and "check disk" must never be run on the original disk.
2. Season-Opening Ransomware
At the start of the September and January seasons, when offices fill up with new staff and new taxpayers, ransomware arriving via an email attachment spreads to the accounting server. MDF files, e-Ledger folders, e-Invoice PDF archives, and Outlook PSTs are encrypted within seconds. Our approach to data recovery in ransomware attacks is shaped around the principle of not paying the ransom: shadow copies, file system remnants, raw disk scanning, and, if available, restoring from an offline backup.
3. Incorrect Rebuild of a RAID Array
The most common mistake on multi-disk NAS devices or servers is starting a rebuild with the "wrong order" for a failed disk. Especially in RAID 5 data recovery cases, when a second disk is pushed in degraded mode and crashes, the array goes completely offline. The array must be rebuilt virtually through parameter estimation (block size, parity direction, disk order).
4. The Cloud Synchronization Misconception
The claim "I use Google Drive or OneDrive, so I have a backup" is the most frequently encountered but most misleading picture. Synchronization is not a backup. A file deleted locally is also deleted from the cloud, and an encrypted file is also encrypted in the cloud. Version history rescues some cases, but it usually falls short for cases older than 30 days.
5. Personnel Movements
Cases such as intentional or accidental deletions made via the account of a departed assistant or intern, the customer's statement "I deleted the wrong taxpayer's period," and a formatted user profile recur every month.
What to Watch For When Recovering an Accounting Software Database
MSSQL files such as MDF and LDF, or Sybase, Firebird, and Pervasive databases, become inconsistent if copied while hot. The correct process is this:
- No file copy attempt is made until the SQL service on the server is stopped.
- A bit-by-bit clone is taken at the disk level (the original media is kept read-only).
- File system repair is performed on the clone, and the MFT or inode tables are analyzed.
- The database file is put through an integrity test; if there is corruption, page-level repair is attempted.
- The repaired database is opened on an isolated server with the same version of the accounting software, and verified by comparing the trial balance and the last month's journal.
Skipping these steps is the most common mistake. Every intervention along the lines of "I tried taking another backup from the program's own backup menu" irreversibly shrinks the recoverable data.
Loss of an e-Ledger Certificate: A Special Case
e-Ledger files are not just XML. The journal and general ledger XML for each month must be kept together with the certificate files approved by GİB. When a certificate is lost, the file can technically be downloaded again from the GİB system; however, if the signed original package itself has not been kept, VUK and special irregularity penalties come into play. For this reason, the e-Ledger folder is the most critical folder in the office and must have more than one offline backup copy.
A Correct Backup Strategy: The 3-2-1 Rule
The framework we apply for certified public accountant offices is based on the "3-2-1" rule:
- 3 copies: Production data plus two independent backups.
- 2 different media: At least two different media types (e.g. a RAID array plus an external drive).
- 1 offline / off-site: At least one copy kept on a physically separate location not connected to the internet.
In a practical setup we recommend the following:
- Primary server: RAID 1 or RAID 10 for the accounting software database. If RAID 5 is preferred, it should have a hot spare disk and regular SMART monitoring.
- NAS backup: A full database backup after 22:00, with an incremental backup for the e-Ledger folder, e-Invoice archive, and PST files.
- Offline backup: A copy taken to an external drive once a week and kept off-site, in a fireproof safe if possible. This copy saves lives in ransomware attacks.
- Cloud layer: A KVKK-compliant, preferably domestically hosted, end-to-end encrypted cloud backup.
- Backup drill: Once every three months, a restore-from-backup scenario should be tested on a test server. A backup that has never been opened does not count as a backup.
What to Do and Not to Do at the Moment of Response
What to do:
- The suspect system should be safely powered off immediately.
- The time of the incident, the last operation, and the last backup date should be recorded in a written note.
- The office network should be isolated, and if ransomware is suspected, the other machines should also be disconnected from the network.
- A possible breach assessment under KVKK should be started.
- The data recovery specialist should be reached only through an authorized person.
What not to do:
- Trying to copy files from the damaged disk.
- Running "check disk" or similar file system repair commands.
- Attempting random decryptors on encrypted files.
- Paying the ransom (both unethical and most likely futile).
- Hiding the incident from taxpayers; the KVKK breach notification window is 72 hours.
Common Misconceptions We Encounter
During our site visits we frequently hear a few common beliefs from professionals that do not match technical reality. Correcting them openly helps offices map their own risk and prevents unnecessary disaster scenarios.
"SSDs don't fail." It is true that SSDs have no mechanical parts, but the write endurance of NAND cells is limited. Moreover, once an SSD fails, it usually goes in the form of "sudden death," without any warning, unlike a classic HDD. For this reason, even if the office server is an SSD, the obligation to have RAID or a backup does not disappear.
"I took a backup from the program's backup menu, that's enough." The internal backup feature of accounting programs usually writes the backup to the same disk or the same folder. When you lose the disk, you also lose the backup. If the backup is not on another physical medium, it is not a backup.
"If I have a cloud backup, ransomware won't affect me." Cloud services that perform real-time synchronization (Drive, OneDrive, Dropbox, etc.) send encrypted files to the cloud as is. Although version history rescues some cases, the number of versions is limited, and restoring files one by one is not practical for thousands of items. Real protection comes from a backup service with a high version count, immutable backups, and write permission held by a separate identity.
"There's a strange noise from the disk but the data opens, so there's no problem." A ticking, clicking sound, or slowdown coming from a mechanical disk is a sign of a problem at the head or platter level. Every time the disk is powered on, data loss increases geometrically. In this situation, the only thing to do is to power off the disk immediately and reach a data recovery service.
"I deleted it years ago, it won't come back." After logical deletion, data is usually removed from the file system's allocation tables but physically remains on the disk. Depending on how much has been written over it, it can be recovered even years later. For this reason, getting an expert opinion before speaking definitively about a "loss" is the right reflex.
City by City: Dense SMMM Districts and On-Site Service
We know the specific axes where certified public accountancy services are geographically concentrated in Turkey. In Ankara, the Çankaya, Kızılay, and Balgat line; this is the busiest region of our Ankara data recovery field work. In Çankaya, dozens of SMMM offices operate along the Kavaklıdere, Aşağıayrancı, Çukurambar, and Bahçelievler line, and an on-site survey to these areas can be organized the same day, often within hours. For the Mecidiyeköy, Şişli, Kadıköy, and Ataşehir lines in Istanbul, our Istanbul data recovery team is on call. In Bursa, our Bursa data recovery service is available along the Osmangazi and Nilüfer axis. In these three provinces, an on-site survey can be carried out the same day for requests from offices near the SMMM chambers.
A Practical Checklist for an Office
Once a month, can you set aside 30 minutes and answer "yes" to the following questions?
- Have I looked at my server's SMART reports in the last 30 days?
- Is my backup really on a different physical medium?
- When did my offline backup last leave the office?
- Are the original signed packages of my e-Ledger certificates kept in at least two separate places?
- When personnel leave, do I revise access permissions?
- Have I updated my KVKK information notice and VERBİS registration within the last year?
- Are the antivirus and operating system patches up to date?
- Have I tested a restore-from-backup drill in the last three months?
If you answer "no" to even two of these eight questions, we can say that your data continuity risk in your office is concrete.
Conclusion: Data Continuity for a Certified Public Accountant Office Is Not a Luxury
The data in a certified public accountant's hands is not just the commercial record of the customer, it is the digital document of the legal contract established with the state. In this area where the VUK, TTK, GİB, and KVKK frameworks intersect, data loss comes back as penalties, reputational loss, and professional liability. For this reason, the data recovery process is not just a technical operation, it is a legal and professional restoration.
As the DSET team we have a dedicated workflow for SMMM and YMM offices: a process that begins with an NDA, proceeds with an ISO/IEC 27037-compliant chain of custody, is verified by comparing the trial balance and the last month's journal, and closes with a KVKK-compliant secure destruction commitment.
Contact DSET
Thanks to our Hacettepe Teknokent center in Ankara and our location near the dense SMMM offices in Çankaya, we offer same-day on-site surveys. We are at your side with free preliminary analysis, transparent pricing, and our "no recovery, no fee" approach.
Phone and WhatsApp: +90 536 662 38 09
If you have experienced a data loss at your certified public accountancy office, the most critical step is this: do not tinker with the system, call us. The earlier and more correct the response, the higher the likelihood that taxpayer data, the e-Ledger certificate, and the payroll archive will all come back.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.