DPDP Act 2023 for CAs: How to Protect Your Practice and Safely Use AI
For years, Chartered Accountants relied on the ICAI Code of Ethics to maintain client confidentiality. But with the rollout of the Digital Personal Data Protection (DPDP) Act, 2023, privacy is no longer just an ethical guideline—it is a strict law.
Because CA firms handle highly sensitive information like PANs, bank statements, and payroll, the law treats your practice as a Data Fiduciary. This means you are legally on the hook for how client data is collected, stored, and deleted. Fines for getting this wrong can reach a staggering ₹250 crore.
Here is a simple breakdown of how the DPDP Act impacts your daily practice and how to stay compliant.
1. Move Beyond Just "Consent" Under the new privacy law, you need permission to process data. But for a CA, relying only on "consent" is risky—if a client revokes it during a tax audit, you are stuck. Instead, anchor your data processing in Contractual Necessity. Make sure your Engagement Letters explicitly state what data you need and how you will use it to fulfill your professional duties.
2. Corporate Data is Personal Data
Don't fall for the myth that auditing a business means you aren't handling personal data. If your corporate audit files or tax workings contain details about directors, partners, or employee salaries, that is classified as personal data. You must protect it just like an individual’s ITR.
3. The Hidden AI Trap (And How We Solved It)
AI is a massive time-saver for financial professionals, but consumer-grade AI tools (like free versions of ChatGPT or Gemini) are a privacy nightmare. Whether you are drafting a response to a complex banking notice or outlining profit-sharing ratios for a partnership restructuring deed, pasting raw client documents into a free AI prompt is dangerous.
Free AI tools often use your inputs to train their future models. Sharing client data this way violates both the DPDP Act and ICAI guidelines, putting you directly in line for multi-crore penalties.
💡 Introducing Our Automated Document Masking Tool: To eliminate this risk, we have developed a cutting-edge automated masking tool specifically for professional firms. Before you upload any client notice, deed, or financial data to an AI platform, our tool instantly sanitizes the document—automatically scrubbing names, PANs, GSTINs, and sensitive figures. This allows your team to freely leverage the power of AI while saving your practice from crores in regulatory penalties
4. Three Quick Steps to Compliance To get your firm up to speed, start with these three operational changes:
- Update Contracts: Add specific DPDP privacy clauses to all your new Engagement Letters.
- Clean House: Stop hoarding old client files. Delete records securely once the statutory retention period (e.g., 8 years for income tax) has passed.
- Control Access: Implement strict folder permissions in your office so junior staff only see the specific client files they are actively working on.
Final Thoughts
The DPDP Act 2023 is a wake-up call for the financial sector. Ignorance of data laws—especially when it comes to adopting AI—is a risk your practice cannot afford. By upgrading your compliance workflows, using our advanced document masking tool, and expanding into privacy advisory, you can turn this new regulatory burden into your firm's competitive edge.