Skip to content
Back to Blog
AI Security

What the DPDP Act means for CA firms in India

A practical look at what the Digital Personal Data Protection Act actually requires of a mid-sized CA firm, and by when.

Sarthhak Kaluuchaa · ·
dpdp act compliance ca firms data protection

Walk into any CA firm with 30 to 100 people and you’ll find PAN numbers, Aadhaar-linked KYC documents, bank statements, payroll records, and full financial histories for dozens of client companies. Most of it sits in shared drives, email attachments, and accounting software logins that nobody has audited in years. Few businesses this size hold this much personal data on this many third parties.

That’s what makes the Digital Personal Data Protection Act relevant to your firm specifically, not just to tech companies. The Act treats anyone who collects and processes personal data as a Data Fiduciary, with obligations to secure it, respond to requests about it, and report when it’s exposed. For a CA firm, the personal data in question is your clients’ data, and your clients’ employees’ data if you run their payroll.

What the Act actually asks of a firm like yours

Strip away the legal language and the core asks are practical. You need to know what personal data you hold, where it lives, and who can access it. You need a way to fix or delete a person’s data if they ask, under Section 12 of the Act. You need a process to handle complaints, under Section 13.

The part that changes daily practice is breach notification. If personal data you hold is compromised, you’re required to notify the Data Protection Board within 72 hours. Most firms don’t currently have anyone whose job is to notice a breach, let alone report one inside three days. That’s the gap worth closing first.

The penalties attached to this are not symbolic. Failure to maintain reasonable security safeguards carries a penalty of up to ₹250 crore under Section 8(5). Failure to notify a breach carries a separate penalty of up to ₹200 crore under Section 8(6). These are ceiling figures set for large-scale violations, not a prediction of what a 50-person firm would face. But they signal that the law is not a soft-touch compliance exercise.

The two dates that matter

Consent Manager registration opens on 13 November 2026. This affects platforms that manage consent on behalf of multiple businesses, not most CA firms directly, but it marks the point where the regulatory machinery starts operating in practice rather than on paper.

Full enforcement begins on 13 May 2027. That is the date your firm’s practices need to hold up, not the date to start building them. Ten months is enough time to do this properly if you start now, and not much time if you wait until early 2027.

Where AI tools fit into this

A live, everyday version of this risk is already inside most firms. When a staff member pastes a client’s P&L into ChatGPT to draft commentary, or summarises a client’s Aadhaar-linked KYC file in an AI tool to save time, that data leaves the firm’s environment and lands on a third-party server you have no visibility into. Under the Act, that’s a question of whether you maintained reasonable security safeguards over data you’re responsible for.

This isn’t a new problem created by the DPDP Act. It sits on top of the confidentiality obligations CA firms already carry as professionals. The Act just adds a specific enforcement mechanism and a clock to a duty that was already there.

A realistic 90-day starting point

Start with an inventory. List every place client personal data lives: accounting software, shared drives, email, WhatsApp, AI tools, outsourced bookkeeping vendors. Most firms are surprised by how long this list turns out to be once someone actually writes it down.

Next, map access. Who can open which client’s file, and does that access still make sense given who’s on that engagement today. Tighten it where it’s obviously too broad, which is usually most places.

Then write the breach playbook before you need it. One page is enough: who gets called first, who decides if it’s reportable, who drafts the notification. A 72-hour clock is not the moment to design a process from scratch.

Finally, brief your staff. Not a policy document nobody reads, but a short, direct conversation about what data should never go into a public AI tool and what the firm expects instead. Most compliance gaps at firms this size come from good intentions and no clear boundary, not from bad actors.

This is general information about the DPDP Act, not legal advice. Talk to counsel about how it applies to your specific engagements and client base.


A StackGuard audit maps exactly this exposure for your firm: where client personal data lives, who can reach it, and how your current AI tool usage measures up. It takes five to ten business days and produces a written report built for partners, not IT managers.

Ready to build systems that scale?

Book a free 30-minute strategy call and we'll map your highest-ROI automation opportunities.