10 October 2026 · DPDP Act · CA & Professional Firms
DPDP Act for CA and Professional Firms: Your Client Files Are Personal Data
By CA Ratan Singh Tanwar · Chartered Accountant, Bhilwara
Chartered Accountants, company secretaries, lawyers and consultants advise clients on compliance every day. Under the DPDP Act, professional firms themselves are Data Fiduciaries, and often hold more personal data than they realise.
Think of a typical CA office: PAN and Aadhaar copies, bank statements, Form 16s, salary registers of client employees, GST portal credentials, partner and director KYC, and years of ITR acknowledgements, spread across desktops, email, pen drives, cloud folders and WhatsApp.
Where professional firms are exposed
- Client documents on WhatsApp and personal email: Convenient, but they remain on staff phones long after the work is done.
- Portal credentials: Income tax, GST and MCA passwords stored in spreadsheets or shared by message.
- Articles and staff turnover: Articled assistants and staff change frequently; access is rarely revoked on the same day.
- Unlimited retention: Old client files kept indefinitely because storage is cheap.
- Public AI tools: Uploading client financials into public chatbots for quick summaries.
A simple compliance framework for firms
- Maintain a client data register: what you collect, for which engagement and where it is stored.
- Add a privacy clause to engagement letters explaining how client data will be used, shared and retained.
- Move client documents to a firm-controlled storage with folder-level access.
- Use a password manager for portal credentials instead of spreadsheets.
- Sign confidentiality and data protection undertakings with staff and articles; revoke access on exit.
- Define retention periods aligned with professional and statutory record-keeping requirements, then delete securely.
- Set a clear policy on what may and may not be entered into AI tools.
Key takeaway: Clients will increasingly ask their CA, “How do you protect my data?” Firms that can answer with a documented process will stand out as trusted advisors, not just service providers.
Making your firm DPDP-ready?
Practical privacy policies, engagement letter clauses and staff training for professional firms.