DPDP Act Compliance
for Chartered Accountant Firms
Your practice holds PAN, Aadhaar, bank statements, and payroll records for hundreds of people. Under the Digital Personal Data Protection Act, 2023 that makes your firm a Data Fiduciary. This page sets out the provisions that apply, what they mean in a practice, and the parts QwikCA handles for you.
General information, reviewed August 2026 — not legal advice. The DPDP Rules are being brought into force in phases and the position changes; confirm the current requirements with your legal advisor before acting.
Rated by CA firms on
A CA firm is a Data Fiduciary — there is no small-practice exemption
The Act applies to the processing of digital personal data within India, and to processing outside India where it relates to offering goods or services to people in India. Personal data is any data about an identifiable individual — which describes almost everything in a practice: PAN and Aadhaar copies, bank statements, Form 16s, salary registers, client contact lists, and your own staff records.
Three roles matter. The Data Principal is the individual the data is about. The Data Fiduciary decides why and how it is processed — that is your firm, for its client and staff records. The Data Processor processes on the Fiduciary's instructions under a contract — that is your practice management software, cloud storage, and payroll bureau.
The complication for practices is that you are often both. For your own client records you are a Data Fiduciary. When you run payroll or maintain books strictly on a corporate client's instructions, you act as that client's Data Processor and they will expect a contract from you under Section 8(2). Map each engagement before you write a single policy.
Note for practices: the obligation with the largest penalty attached is reasonable security safeguards under Section 8(5). It bites whether or not anything has gone wrong. Shared logins, client documents on personal WhatsApp, and unencrypted drives are the everyday exposures in an Indian practice.
The DPDP Provisions That Apply to a Practice
Section references are to the Digital Personal Data Protection Act, 2023. The right-hand column is our plain reading of what each provision means inside a CA firm — not a substitute for advice on your own facts.
| Section | Obligation | What it means in your firm |
|---|---|---|
| S. 4 & 7 | Lawful basis for processing | Process personal data only on consent or a listed legitimate use. Client engagements, statutory filings, and employee records usually rest on legitimate use or a legal obligation — marketing does not. |
| S. 5 | Notice to the Data Principal | Give an itemised notice of what personal data you collect, the purpose, how the individual can exercise their rights, and how to complain to the Board. It must be available in English and the languages listed in the Eighth Schedule. |
| S. 6 | Consent and withdrawal | Where you rely on consent it must be free, specific, informed, unconditional, and unambiguous, limited to the data actually needed — and withdrawable as easily as it was given. |
| S. 8(2) | Engaging processors under contract | Any processor you use — practice management software, cloud storage, payroll bureau, tally hosting, virtual assistants — must be engaged under a valid contract. Keep a register of them. |
| S. 8(5) | Reasonable security safeguards | Encryption, access control, logging, and backups are the baseline. This is the obligation that carries the heaviest penalty, and it applies whether or not a breach ever happens. |
| S. 8(6) | Personal data breach reporting | Report a personal data breach to the Data Protection Board and to every affected individual, in the form and time the Rules prescribe. Have the escalation path written down before you need it. |
| S. 8(7) | Erasure and retention limits | Erase personal data once consent is withdrawn or the purpose is served — unless a law requires you to retain it. Write a retention schedule per record type with the statute that justifies it. |
| S. 8(9) | Grievance redressal & contact point | Publish the contact details of the person who answers questions about your processing, and run an effective grievance mechanism for Data Principals. |
| S. 9 | Children's data | Verifiable parental consent is required before processing a child's personal data, and tracking or behavioural advertising directed at children is prohibited. Relevant if you onboard minors as clients or hold data on clients' children. |
| S. 10 | Significant Data Fiduciary duties | If notified as a Significant Data Fiduciary, you additionally need an India-based Data Protection Officer, an independent data auditor, periodic audits, and Data Protection Impact Assessments. |
| S. 11–14 | Rights of the Data Principal | Individuals can seek access to a summary of their data and who it was shared with, correction, completion, updating, and erasure, grievance redressal, and can nominate someone to exercise their rights. |
| S. 16 | Cross-border transfer | Transfer outside India is permitted except to territories restricted by notification. Know where each vendor you use actually stores and processes your client data. |
What a Breach Costs
Penalties are imposed by the Data Protection Board of India after inquiry, having regard to the nature, gravity, and duration of the breach and the steps taken to mitigate it. The figures below are statutory ceilings, not standard fines.
Failure to take reasonable security safeguards
S. 8(5)
Up to ₹250 crore
Failure to notify a personal data breach
S. 8(6)
Up to ₹200 crore
Breach of children's-data obligations
S. 9
Up to ₹200 crore
Breach of Significant Data Fiduciary obligations
S. 10
Up to ₹150 crore
Any other breach of the Act or Rules
Schedule
Up to ₹50 crore
Breach of duties by a Data Principal
S. 15
Up to ₹10,000
The Commencement Timeline
August 2023
The Digital Personal Data Protection Act, 2023 receives assent — but is not brought into force.
January 2025
Draft DPDP Rules published for public consultation.
November 2025
The DPDP Rules are notified with a phased commencement — a limited set of provisions takes effect on notification.
+12 months
Consent Manager registration and related obligations come into force.
+18 months
The operational core — notice, security safeguards, breach reporting, children's data, Significant Data Fiduciary duties, and Data Principal rights — comes into force.
Commencement dates can be varied by notification and the phasing has moved before. Treat the runway as time to prepare, not as a reason to wait — mapping data and cleaning up access takes a practice months, not weeks.
An 8-Step DPDP Checklist for CA Firms
Work through these in order. The first two are paperwork you cannot skip; the rest get easier once your client data lives in one system instead of eleven.
Map the personal data you hold
List every place client and staff personal data sits — practice software, email, WhatsApp, desktop folders, external drives, the CA's laptop. You cannot protect what you have not located.
Fix a lawful basis per purpose
Engagement delivery, statutory filing, employee records, and marketing are separate purposes with separate bases. Write down which is which.
Publish a DPDP notice
An itemised notice at onboarding covering data collected, purpose, rights, and how to complain to the Board — in English and the Eighth Schedule languages your clients use.
Write a retention schedule
Per record type: how long you keep it and under which statute. Then actually delete what falls outside it, including old backups and WhatsApp media.
Tighten technical safeguards
Encryption at rest and in transit, per-user logins with no shared passwords, role-based access, MFA, audit logs, and tested backups.
Paper your processors
Every vendor touching personal data needs a contract that covers security, sub-processing, breach notice, and deletion. Keep the register current.
Write the breach runbook
Who is called, who assesses, who notifies the Board and affected individuals, and by when. Rehearse it once — a breach is the wrong time to invent a process.
Train the team, name a contact
Articles and staff cause most incidents. Train them on handling, forwarding, and disposal, and publish a named contact point for data questions and grievances.
Where QwikCA Carries the Load
Software cannot make a firm compliant — policies, notices, and staff behaviour do most of the work. What it can do is remove the exposures that come from client data living in personal inboxes and chat threads.
Encrypted document vault
Supports S. 8(5)
Client documents are stored encrypted at rest and moved over TLS, in one controlled repository instead of personal WhatsApp media folders and mailbox attachments.
Role-based access control
Supports S. 8(5)
Staff see only the clients and tasks assigned to them. Access is per user, not a shared login, so responsibility for every action is attributable.
Audit trail of activity
Supports S. 8(5), 8(6)
Who accessed, uploaded, or changed what, and when — the record you need to investigate an incident and to demonstrate that safeguards were operating.
Data hosted and processed in India
Supports S. 16
QwikCA does not offer services outside India, and client data is primarily stored and processed in India — one less cross-border question to answer in a vendor assessment.
Client portal for document collection
Supports S. 8(5), 8(7)
Clients upload PAN, bank statements, and KYC documents into their own portal rather than emailing them to five staff, which is what turns one document into ten uncontrolled copies.
One record per client
Supports S. 11–12
When a client asks what you hold, or asks for a correction, the answer sits in one place instead of being reconstructed from inboxes.
Controlled deletion
Supports S. 8(7)
Documents and client records can be removed when your retention schedule says so, and firm accounts can be deleted on request.
Templated, tracked communications
Supports S. 5, 6
Reminders go out from approved templates with delivery tracking, so what was sent to which client is a record rather than someone's personal chat history.
QwikCA as Your Data Processor
When your firm stores client data in QwikCA, your firm stays the Data Fiduciary towards those clients and QwikCA processes the data on your instructions as a Data Processor. That is the relationship Section 8(2) expects you to put in writing.
- We process your data to deliver the service — we do not sell it or use it to market to your clients.
- Data is primarily stored and processed in India; QwikCA does not offer the service outside India.
- Documents are encrypted at rest and in transit, with per-user access and activity logging.
- You can export and delete your firm data; account deletion is available on request.
- Security incidents affecting your data are escalated to your firm so you can meet your own reporting duties.
- A data processing agreement is available on request for your vendor file.
One honest caveat: the DPDP Act does not create a certification or a licence for software. Any vendor claiming a "DPDP certified" product is describing something that does not exist. Ask instead for their security measures, hosting location, sub-processor list, and breach process — and a contract that commits to them.
DPDP Act for CA Firms — FAQs
Does the DPDP Act apply to CA firms?
Yes. The Digital Personal Data Protection Act, 2023 applies to any person who processes digital personal data in India. A CA firm holds PAN, Aadhaar, bank statements, salary records, and KYC documents belonging to identifiable individuals — clients, their employees, and its own staff — so the firm is a Data Fiduciary in respect of that data and carries the obligations in Sections 5 to 10 of the Act. There is no small-firm exemption: a sole proprietor CA is covered on the same terms as a large firm.
Is a CA firm a Data Fiduciary or a Data Processor under the DPDP Act?
It depends on the engagement. Where the firm decides why and how personal data is processed — its own client records, staff records, and marketing lists — it is a Data Fiduciary. Where it processes personal data purely on a corporate client's instructions, for example running payroll on the client's behalf, it acts as a Data Processor for that client and must be engaged under a valid contract as required by Section 8(2). Many firms are both, on different engagements, and should map each engagement separately.
When do the DPDP obligations actually start applying?
The Act received assent in August 2023 but was not brought into force immediately. The Digital Personal Data Protection Rules were notified in November 2025 with a phased commencement — a limited set of provisions took effect on notification, Consent Manager registration obligations roughly 12 months later, and the bulk of operational obligations (notice, security safeguards, breach reporting, children's data, Significant Data Fiduciary duties) roughly 18 months later, in 2027. Commencement dates can be varied by notification, so confirm the current position with your legal advisor before relying on any timeline.
What are the penalties for a data breach under the DPDP Act?
The Schedule to the Act sets penalties of up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to report a personal data breach, up to ₹200 crore for breaching the children's-data obligations, up to ₹150 crore for a Significant Data Fiduciary's additional obligations, and up to ₹50 crore for any other breach. Penalties are imposed by the Data Protection Board of India after an inquiry, having regard to the nature, gravity, and duration of the breach and any mitigation taken.
Can a client ask a CA firm to erase their data under the DPDP Act?
A Data Principal can withdraw consent and request erasure under Sections 6(6) and 12. But the erasure obligation does not override retention that is required by law. Working papers, audit files, books of account, and records a firm must keep under the Income-tax Act, the Companies Act, GST law, or ICAI requirements can be retained for the period the law prescribes. The practical answer is a written retention schedule that states, for each record type, the legal basis and the retention period — and deletion of everything outside it.
Do we need consent to send WhatsApp and email reminders to clients?
Communications that are necessary to deliver the service the client engaged you for generally sit within the engagement. Promotional messaging is different and should run on consent that is free, specific, informed, and as easy to withdraw as it was to give, with an opt-out on every message. Keep a record of when and how each contact consented, and separate your service reminders from your marketing list.
Does QwikCA make our firm DPDP compliant?
No software can. Compliance is a mix of your policies, your retention schedule, your consent notices, and your staff practices — plus the tooling underneath. What QwikCA provides is the technical layer: encrypted document storage, role-based access so staff only see their own clients, audit logs of who accessed what, an India-hosted client portal instead of documents scattered across personal WhatsApp and email, and controlled deletion. Anyone selling you a DPDP certification for software is selling something the Act does not create.
Is QwikCA a Data Processor for our firm, and is a data processing agreement available?
Yes. When your firm stores client data in QwikCA, QwikCA processes that data on your instructions as a Data Processor, and your firm remains the Data Fiduciary towards your clients. A data processing agreement covering scope of processing, security measures, sub-processors, breach notification, and deletion on termination is available on request — write to [email protected].
Related Resources
Security
Encryption, access control, audit logging, and infrastructure practices behind QwikCA.
Privacy Policy
What personal data QwikCA collects, how it is used, shared, retained, and deleted.
CA Practice Management Software
The full platform — task board, client records, documents, billing, and staff management.
Enterprise
For larger firms with multi-branch teams, tighter access controls, and vendor reviews.
Get client data out of personal inboxes
Encrypted documents, per-user access, and a full activity trail — the technical safeguards the DPDP Act expects, in one place. Start free for a month, no credit card required.