DPDP Act 2023 — What Every CA Should Know About Client Data
What the DPDP Act 2023 means for client data in a CA practice: the roles, the obligations, data-principal rights, penalties and a checklist.
Why this is a CA problem, not just an IT problem
A CA practice holds some of the most sensitive personal data in the economy: PAN and Aadhaar numbers, bank statements, salary details, capital-gains records and family financial information for hundreds of clients. The Digital Personal Data Protection Act, 2023 brings all of that within a statutory framework for the first time. The Act does not care whether you think of yourself as a "tech company" — if you collect and process personal data digitally, its obligations apply to your firm directly.
The vocabulary you have to know
- Data Principal — the individual the data is about. Your client, their employees, their family members.
- Data Fiduciary — the entity that decides why and how the data is processed. In most engagements, that is your firm.
- Data Processor — a party that processes data on the fiduciary's behalf, such as a cloud software vendor or a payroll bureau.
- Consent Manager — a registered intermediary through which a data principal can give, manage and withdraw consent.
- Significant Data Fiduciary — a fiduciary handling large or sensitive volumes, on whom additional obligations (like a Data Protection Officer and audits) are imposed.
Consent and notice
The Act is built on consent. Before processing personal data you generally need the data principal's free, specific, informed and unambiguous consent, requested through a clear notice that states what data you collect and why. A handful of "legitimate uses" allow processing without fresh consent — for example, where the individual has voluntarily provided data for a specified purpose — but these are narrower than they sound and should not be your default assumption for client onboarding.
Rights you now have to honour
Data principals can ask for access to their data, correction of inaccuracies, erasure when the purpose is served, and redress through a grievance mechanism, and they can nominate someone to exercise these rights on their behalf. Your firm needs a defined channel to receive and act on these requests within a reasonable time — an unmonitored info@ inbox is not a grievance mechanism.
Your obligations as a fiduciary
You must process data only for the stated purpose, keep it only as long as that purpose requires, apply reasonable security safeguards, and ensure your processors are bound by contract to do the same. If a breach occurs, you are required to notify the Data Protection Board and the affected data principals. Non-compliance carries financial penalties that run into crores of rupees per instance — large enough that "we'll deal with it later" is not a tenable position for a practice.
A checklist you can start this week
- Map what personal data you hold, where it lives, and which third-party tools touch it.
- Add a clear data-processing notice and consent step to your client onboarding.
- Review every software vendor contract for processor obligations and data-residency terms.
- Write a short retention policy and actually delete data you no longer need.
- Define a breach-response plan and a single owner for grievance requests.
- Prefer tools that keep client financial data within India and never send identifiable amounts to third parties.
None of this requires a law degree. It requires treating client data with the same discipline you already apply to client money — which, for a chartered accountant, is familiar ground.