Think of what sits on a CA firm's systems on an ordinary Tuesday. Salary registers with the PAN and bank account of every employee of forty clients. Scanned Aadhaar cards from a GST registration. A partner's personal investments, attached to a return. A client's customer list, pulled into a working paper to test debtors.
Most of it isn't the firm's own business. All of it is personal data, and from 13 May 2027 the Digital Personal Data Protection Act, 2023 decides how it has to be held.
Three dates, one of them close
The Digital Personal Data Protection Rules, 2025 were published on 13 November 2025, G.S.R. 846(E). A notification the same day, G.S.R. 843(E), brought the Act into force in three steps:
- From 13 November 2025: the definitions and the Data Protection Board.
- One year later, 13 November 2026: the provisions on Consent Managers, section 6(9) and Rule 4.
- Eighteen months later, 13 May 2027: everything that binds a firm day to day. That means notice and consent, legitimate uses, the duties of a Data Fiduciary, the rights of the people whose data it is, and the penalties.
That is less than eight months away, and as at 19 September 2026 no notification has changed it. Section 44(2), which removes section 43A of the Information Technology Act, starts on the same day.
Where a CA firm fits
The Act has two main roles. A Data Fiduciary is anyone who "alone or in conjunction with other persons determines the purpose and means of processing of personal data". A Data Processor is anyone who processes personal data "on behalf of a Data Fiduciary". A firm, partnership or LLP is a "person" for both.
Neither the Act nor the Rules mention chartered accountants or auditors. The test is what you do with the data, not what profession you are in, and it can come out differently from one engagement to the next.
Some of it is clear on the words alone:
- Your staff and your own client relationships. The firm decides why and how it holds its employees' records and its clients' contact details, so for those it is the Data Fiduciary.
- Payroll or bookkeeping done for a client. Where a client hands over its employees' data and the firm processes it for the client, the firm's position depends on who decides the purpose and means. Section 8(1) keeps the Data Fiduciary responsible for anything a processor does on its behalf, and section 8(2) allows a processor only "under a valid contract".
- Paper counts once it is scanned. The Act applies to personal data collected in digital form, and to data "in non-digital form and digitised subsequently".
What the Act asks of a Data Fiduciary
- A notice before consent. Under section 5 and Rule 3, the notice itemises the personal data and the purpose, and tells the person how to withdraw consent, as easily as it was given, how to exercise their rights, and how to complain to the Board.
- Or a legitimate use. Section 7 allows processing without consent in listed cases. For a firm, the one used most is section 7(i), for the purposes of employment.
- Reasonable security safeguards. Rule 6(1) sets the minimum: encryption, obfuscation or masking; access control; logs, monitoring and review; backups so processing can continue after an incident; contracts with processors that cover security; and logs kept for one year.
- Breach intimation. Section 8(6) requires the firm to tell both the Board and each affected person about any personal data breach. The Act sets no size threshold. Rule 7 asks for an intimation to the Board without delay, and a detailed report within 72 hours of becoming aware of it.
- Erasure. Section 8(7) requires personal data to be erased once its purpose is served, unless a law requires it to be kept. Records that another law obliges a firm to keep fall within that exception.
- A named contact. Section 8(9) and Rule 9 ask for the business contact of a person who can answer questions about the processing, published on the website.
- Rights, answered. People can ask for a summary of their data, and have it corrected or erased, under sections 11 to 13. The Government's release on the Rules says requests are to be answered within 90 days at most.
What it costs to get it wrong
The Schedule to the Act sets maximum penalties, imposed by the Board only for a significant breach and after a hearing:
- up to ₹250 crore for failing to take reasonable security safeguards;
- up to ₹200 crore for failing to report a breach to the Board or to the people affected;
- up to ₹200 crore for breaching the obligations for children's data;
- up to ₹50 crore for any other breach of the Act or the Rules.
Section 33(2) asks the Board to weigh, among other things, the gravity and duration of the breach, what was done to mitigate it, and the likely impact of the penalty on the person paying it.
The largest penalty in the Act is not for a leak. It is for not having taken reasonable steps to prevent one.
Check your firm
Ten things the Act asks of every Data Fiduciary
Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)); commencement notification G.S.R. 843(E), both of 13 November 2025. Your ticks stay on this page.
One exemption to know about
Section 17(1)(a) switches off much of Chapter II where processing is necessary for enforcing a legal right or claim. Even then, section 8(1) (responsibility) and section 8(5) (security safeguards) still apply. Neither the Act nor the Rules exempt professionals or small firms as a class, though section 17(3) lets the Government notify exemptions for startups and other classes of Data Fiduciary.
Where this comes from
The Act is quoted from the Digital Personal Data Protection Act, 2023 as published in the Gazette, the Rules from G.S.R. 846(E) and the commencement dates from G.S.R. 843(E), both of 13 November 2025. The 90-day figure is from the Government's press release on the Rules. This page describes what the text says. It doesn't decide, for any engagement, whether a firm is a Data Fiduciary or a Data Processor, because the Act leaves that to the facts.
Questions this answers
When do the DPDP Act's obligations apply?
From 13 May 2027, eighteen months after the DPDP Rules were published on 13 November 2025. The Consent Manager provisions start on 13 November 2026.
Is a CA firm a Data Fiduciary or a Data Processor?
The Act does not name CA firms. A firm is a Data Fiduciary where it decides the purpose and means of processing, such as for its own staff, and the role can differ by engagement.
What security measures do the DPDP Rules require?
Rule 6 requires encryption, obfuscation or masking, access control, logs with monitoring, backups, security terms in processor contracts, and logs kept for one year.
How soon must a data breach be reported under DPDP?
To the Board without delay, with a detailed report within 72 hours of becoming aware of it, and to each affected person without delay.
What is the maximum penalty under the DPDP Act?
Up to ₹250 crore for failing to take reasonable security safeguards, imposed by the Board only for a significant breach.
