DPDP compliance for accounting and tax firms

DPDP compliance for accounting and tax firms
Accounting

DPDP compliance for accounting and tax firms

CA firms and tax advisors handle sensitive client financial data with a duty of confidentiality. Here is how the DPDP Act adds a data protection layer to that relationship.

Quick Answer: Accounting and tax firms are Data Fiduciaries under the DPDP Act for the personal and financial data of their clients — income, tax returns, bank statements, asset details, family information for estate planning, and sensitive corporate financial information about individuals. Client financial data is sensitive personal data. CA firms that use cloud accounting tools, outsource data entry, or share client data with co-professionals must have Data Processing Agreements in place. The existing professional duty of confidentiality under the CA Act is reinforced but not replaced by DPDP — firms need explicit privacy notices and consent frameworks as well. Enforcement begins May 2027.

What client data do accounting and tax firms process under DPDP?

CA firms process: individual income and tax data (ITR, TDS certificates, Form 26AS), bank statements and financial account details, investment portfolio information, property ownership records, salary and bonus details, business profit and loss accounts, GST filing data, personal details of family members for estate planning, and sometimes sensitive business information about corporate promoters. This financial data is among the most sensitive personal data category — its misuse or disclosure can cause severe financial harm.

Does the CA Act's duty of confidentiality cover DPDP compliance?

The duty of confidentiality under the Chartered Accountants Act and ICAI's Code of Ethics imposes a professional obligation to protect client information. DPDP adds a statutory data protection layer that goes beyond professional ethics: clients have legal rights to access, correct, and erase their data; firms must issue a formal privacy notice; and breaches must be reported to the Data Protection Board. These are legal obligations distinct from the professional confidentiality duty — both must be satisfied.

What cloud accounting tools are in scope for DPDP?

Most accounting firms use cloud tools: Tally Prime, Zoho Books, QuickBooks Online, SAP, or similar. These vendors process client financial data on the firm's behalf as Data Processors. CA firms must have Data Processing Agreements with each tool provider covering: what data is processed, that it is not used for the vendor's own analytics or AI training without consent, that it is stored in India or an approved country, and that breaches are notified promptly. Many standard SaaS agreements do not meet these requirements.

How does DPDP apply to outsourced data entry and accounting BPO?

Many smaller CA firms and larger practices outsource data entry, bank reconciliation, and GST filing to accounting BPOs. These BPOs access client financial data on the firm's behalf — they are Data Processors and need DPAs. The DPA must prohibit the BPO from using client data for any purpose beyond the assigned task, require deletion of client data from BPO systems on task completion, and mandate breach notification. Due diligence on the BPO's security practices is the CA firm's responsibility.

What privacy notice must a CA firm issue to clients?

Before collecting client financial data, firms should provide a privacy notice covering: what data is collected and why; which tools and BPO partners process it; whether data is transferred outside India; how long it is retained (aligned to statutory tax record retention periods — typically 8 years); and how clients can access, correct, or request erasure. This can be part of the firm's engagement letter or a separate privacy disclosure document. Issue it at onboarding and update it when your tools or processes change.

How long must CA firms retain client financial data?

Tax records must be retained for the period specified by the Income Tax Act (typically 8 years from the end of the relevant year), GST records for 72 months, and company audit records per the Companies Act. These statutory retention obligations override DPDP erasure requests for those specific records. However, data beyond the statutory period — old drafts, communication threads, working papers no longer needed — should be deleted on schedule. Build a retention schedule that maps each document type to its applicable statutory period.

Frequently asked questions

As a CA firm, are we liable if our cloud accounting vendor has a breach?

You are the Data Fiduciary for client data. If your cloud accounting vendor (Data Processor) has a breach involving client data, the notification obligation runs to you as Fiduciary — you must notify the Data Protection Board and affected clients. The vendor should notify you promptly under your DPA, triggering your response plan. Liability for the breach may flow to the vendor under your DPA, but the regulatory obligation to notify is yours. This is why breach notification clauses in vendor DPAs are non-negotiable.

Can we share client data with another CA firm for a referral?

Sharing client personal financial data with another CA firm — whether for a referral, a peer review, or a joint engagement — requires the client's explicit consent for that specific sharing. You cannot share client data on the basis of your general engagement terms unless those terms specifically disclose referral data sharing. Get written consent from the client before sharing any personal financial data with a third-party professional.

Does DPDP apply to data collected from clients before the Act's enforcement date?

The DPDP Act's obligations apply from the enforcement date (expected May 2027). Pre-existing client data held at that date comes within scope — you need a lawful basis for continuing to process it. For most active client engagements, the ongoing contractual relationship (ongoing tax advisory) provides a lawful basis. For former clients whose data you retain beyond the statutory period, you need to either obtain retrospective consent or delete the data.

Get your CA firm DPDP-ready

Niti Bharat's DPDP Service Kit for CA Firms covers client privacy notices, cloud tool DPAs, BPO data sharing, retention schedules, and breach response — everything a CA practice needs for DPDP compliance.

Get the CA Firm DPDP Kit
Previous Post Next Post

Get Free DPDP Checklist