Legal Framework of the DPDP Act, 2023
Page Contents
Legal framework: Digital Personal Data Protection Act 2023
The Digital Personal Data Protection (DPDP) Act, 2023 is India’s primary law governing the collection, storage, use, sharing, and protection of digital personal data. It establishes rights for individuals and obligations for organizations that process personal data. Legal framework, implementation timeline, key stakeholders, penalties, and legitimate uses under the Digital Personal Data Protection (DPDP) Act, 2023.
Digital Personal Data Protection (DPDP) Act, 2023.
- Statutory Penalty Alert: This section highlights the consequences of non-compliance with the DPDP Act.
- Maximum Fine: “Up to ₹250 Crore per instance”. This means that if a Data Fiduciary fails to meet its obligations, the Data Protection Board can impose significant financial penalties. Examples: Failure to implement security safeguards., Failure to report a personal data breach., Failure to protect children’s data and Ignoring Data Principal rights requests. For large organizations, each separate violation can attract a separate penalty.
- Adjudication: The DPDP Act establishes a Data Protection Board (DPB) as the adjudicating authority.
- Functions of DPB: The Board can Receive complaints, Investigate breaches, Conduct digital inquiries, Impose penalties and Direct corrective measures. Unlike traditional court proceedings, the DPDP framework emphasizes digital processes and electronic submissions.
- Fiduciary Liability: “Direct accountability” Under DPDP, the primary responsibility lies on the Data Fiduciary. Who is a Data Fiduciary? : Any person, company, LLP, partnership, government department, or organization that determines: Why personal data is collected, How personal data is processed. Examples Employer processing employee data, Bank processing customer information, Hospital managing patient records and Insolvency Professional managing stakeholder records. Even if a third-party vendor processes the data, the Data Fiduciary remains accountable.
- Appeals: TDSAT within 60 days If a party is aggrieved by an order of the Data Protection Board, it can appeal to TDSAT (Telecom Disputes Settlement and Appellate Tribunal). Time Limit is Appeal within 60 days from receipt of the Board’s order.
- Adjudicating Authority: Data Protection Board (DPB) : The Board is responsible for Hearing complaints, investigating non-compliance, Conducting inquiries, Imposing monetary penalties, It functions as the central enforcement authority under DPDP.
- Implementation Timeline : The slide presents a phased implementation approach.
Phase 1: 14 November 2025
- Key Activities: DPB Becomes Operational: The Data Protection Board starts functioning. This allows Complaint handling, breach investigations, and adjudication proceedings.
- RTI Exemption: Reference is made to RTI Section 8(1)(j): This relates to personal information exemptions under the Right to Information framework and the interplay between privacy protection and disclosure obligations.
Phase 2: 14 November 2026
- Consent Manager Registration: Consent Managers are entities that help Data Principals Give consent, Withdraw consent and Manage permissions Example: A centralized platform where a citizen can manage permissions given to multiple organizations.
- Net Worth Requirement: ₹2 Crore Net Worth Norms and Entities seeking registration as Consent Managers may need to satisfy prescribed financial requirements.
Phase 3: 14 May 2027 :
This phase introduces full-scale compliance obligations.
- Substantive Data Fiduciary Obligations: Organizations must fully comply with Notice requirements, Consent management, Security safeguards, Breach reporting and Rights handling.
- Standalone Notices in 22 Languages: Privacy notices may need to be available in multiple Indian languages to improve accessibility. Example Hindi, English, Tamil, Telugu, Bengali, Marathi, Gujarati and Punjabi etc.
- AES-256 Safeguards: AES-256 refers to a strong encryption standard. For the Purpose to Protect Customer data, Employee data, Financial information and Sensitive personal information. Example: Encrypting employee payroll databases.
- One-Year Log Retention: Organizations should maintain logs showing User access, System activities and Security events. Bais Purpose is Audit trail, Investigations and Regulatory compliance
- 72-Hour Breach Reporting: If a data breach occurs, the organization must notify the regulatory authority within the prescribed timeframe.Examples Ransomware attack, Unauthorized access, Data leakage and Lost databases. Organizations therefore require an Incident Response Plan.
- Three-Year Inactive Data Erasure: Organizations should not retain personal data indefinitely. When data becomes inactive and retention is no longer necessary Erase, Delete and Anonymize. This reflects the principle of data minimization.
- Verifiable Parental Consent: For individuals below 18 years: Organizations must obtain verifiable parental consent before processing the child’s personal data. Examples: Educational platforms, Gaming applications, social media services and Online learning portals.
- IT Act Section 43A Repeal: Historically, privacy obligations in India were linked to Section 43A of the Information Technology Act, 2000. The DPDP framework gradually becomes the primary privacy legislation.
Statutory Legal Roles

The DPDP Act creates three important roles.
Data Principal: Definition The individual to whom personal data relates: Examples: Customer, Employee, Vendor (individual), Student, and Citizen
For minors: Parents or lawful guardians exercise rights on their behalf. Rights of Data Principal: Right to information, Right to access data, Right to correction, Right to update, right to erasure, Right to grievance redressal
- Data Fiduciary: Definition: The entity deciding the purpose of processing and means of processing. Examples: Company, bank, insurance company, educational institution, and government agency. Responsibilities: Obtain consent when required, Provide notices, protect personal data, report breaches, and respond to rights requests. This role bears primary liability under the Act.
- Data Processor: Definition: A third-party processing personal data on behalf of the Data Fiduciary. Examples: Payroll service provider, cloud hosting company, data analytics vendor, and HR software provider. Processors act only according to instructions from the Data Fiduciary.
CA Firm Dual Role:
An interesting professional example. As a data fiduciary, a CA firm becomes a Data Fiduciary when Filing tax returns, collecting client documents, and determining processing purposes.
As a Data Processor: A CA firm acts as a processor when outsourced payroll processing, bookkeeping services, and back-office functions are done and acts under the client’s instructions.
Section 7: Legitimate Uses
One of the most important concepts under DPDP is that certain processing activities do not require consent.
-
- Employment and Payroll (Section 7) : Consent is generally not required for Employment Purposes Examples: Salary processing, attendance management, PF administration, ESI administration, tax deduction (TDS), and background verification. An employee’s consent is not needed every month to process salary.
- Statutory Compliance (Section 7) : Consent is not required where processing is necessary to comply with legal obligations. Examples: Income tax reporting, GST compliance, MCA filings, court orders, regulatory reporting, IBC proceedings
- Medical Emergencies (Section 7) : Personal data may be processed without consent during Medical emergencies, epidemics, disaster response, or life-saving situations. Example: A hospital sharing critical patient information with emergency responders.
- Voluntary Provision of Data (Section 7) : If a person voluntarily provides information for a specific purpose, separate consent may not be necessary for fulfilling that request. Example: A customer sends an email requesting a quote for services, product information, and complaint resolution. The organization may use that information to answer the request.
Key takeaway: Essentially explains that DPDP compliance revolves around four pillars:
- Understand your legal role (data principal, fiduciary, or processor).
- Know when consent is required and when it is not.
- Implement safeguards and governance controls.
- Avoid severe penalties by maintaining continuous compliance and breach readiness.
DPDP Act Explained for Chartered Accountants:

Here we explain how the Digital Personal Data Protection (DPDP) Act, 2023 applies specifically to Chartered Accountants (CAs), CA Firms, Tax Consultants, Auditors, and Professional Service Firms. The main message is that a CA firm can act either as a data fiduciary or a data processor, depending on the nature of the engagement.
Core Statutory Roles (Section 2) :
The DPDP Act defines several key stakeholders.
- Data Principal [Section 2(j)]: A Data Principal is the individual whose personal data is being processed. Examples like client, employee, director, shareholder, debtor, creditor, and vendor. Special Cases for Children Below 18 Years and Persons with Disabilities. Their lawful guardians exercise rights on their behalf.
Rights of Data Principal: They can know what data is collected, request access, seek correction, update information, request deletion (where legally permitted), and file grievances. Example for CA Practice: A client provides PAN, Aadhaar, bank account details, and income details. The client becomes the data principal.
- Data Fiduciary [Section 2(i)]: A Data Fiduciary is the entity deciding Why data is collected and how it is processed. Important Principle: “Primary statutory liability cannot be outsourced.” This means even if a CA firm uses cloud storage, Payroll software, tax filing platforms, and outsourced IT vendors, the responsibility remains with the data fiduciary. Example: A CA firm decides which client documents to collect How long records will be retained and which software will store data. The CA firm acts as a data fiduciary.
- Data Processor [Section 2(k)]: A Data Processor processes personal data on behalf of a Data Fiduciary. They do not decide purpose or means; they merely follow instructions. Examples: payroll service providers, cloud storage providers, software vendors, and bookkeeping BPOs
-
- Requirement: Processing must occur under a formal:
- Data Processing Agreement (DPA) : The DPA should define the scope of processing, security requirements, confidentiality obligations, and deletion requirements
-
- Consent Manager [Section 2(g)]: A Consent Manager is a registered entity that helps individuals Give consent, track consent, withdraw consent, and review permissions through a common dashboard. Example: Similar to a privacy management portal where a person can see which organizations have access to their data, which permissions are active, and how to revoke them.
- Significant Data Fiduciary (SDF) [Section 10] : The Government may classify some organizations as Significant Data Fiduciaries.
Factors Considered: Volume of data processed, sensitivity of data, risk to citizens, and impact on national interests.
Additional Obligations:
-
-
-
- Appointment of DPO: (Data Protection Officer) Must Be based in India and the Handle compliance matters.
- Independent Audits: Annual privacy audits become mandatory.
- DPIA Data Protection Impact Assessment to evaluate privacy risks.
-
-
- CA Firm Dual Role Matrix: This is one of the most important concepts for CA professionals. A CA firm may play two different legal roles.
Indian CA Firm as Data Fiduciary:
This applies when the CA firm independently decides how personal data will be processed.
-
- Direct Tax & Advisory: The firm collects PAN, Aadhaar, Form 26AS, AIS/TIS, and bank statements. The firm determines the information required, processing methods, and storage mechanisms. Therefore, CA Firm = Data Fiduciary
- Statutory Audit: During audit The CA firm collects employee data, vendor information, director records, and financial documentation. The audit approach, testing procedures, and working papers are determined by ICAI standards. Therefore, CA Firm = Data Fiduciary
- Internal Firm HR and Payroll: The firm processes employee records, Form 16, PF information, ESI information, and salary details. The firm decides the purpose. Therefore, CA Firm = Data Fiduciary
CA Firm as Data Processor:
This occurs when the firm merely acts on client instructions.
-
- Outsourced Client Payroll: Example: A company outsources payroll processing. The CA firm calculates salary, computes TDS, and generates payroll reports. The client decides why data is processed. Hence: Client = Data Fiduciary and CA Firm = Data Processor
- Outsourced Ledger Management: The client instructs Maintain sales ledger and Prepare customer accounts. CA firm processes customer information according to client SOPs. Hence, Data Processor. Practical Example: Suppose a company hires your CA firm.
- Tax Planning Assignment: You determine required documents, tax strategy, and processing activities, which Result: Data Fiduciary
- Payroll Processing Assignment: Client determines employee list, salary structure, and HR policies. You merely process. Result: Data Processor
Section 7 Legitimate Uses (Consent Exemptions):
The DPDP Act allows certain processing without consent.
-
- Employment & Payroll: Consent is not required for salary processing, PF deductions, ESI deductions, bonus calculation, and TDS deductions. Example: An employer does not need to obtain fresh employee consent every month to process payroll.
- Statutory Mandates: Consent is not required when processing is necessary to comply with law. For Examples
-
- Income Tax Act: TDS filings, ITR filings
- Companies Act: Annual Return and Financial Statements
- GST Law: GST returns, E-way compliance
- Insolvency & Bankruptcy Code: CIRP disclosures, claim processing, and Committee of Creditors records, As an RP or Liquidator, much data processing falls under statutory obligations.
- Voluntary Provision: If a person voluntarily provides information for a specific purpose: Consent may not be separately required. Example: A prospective client emails: “Please review my tax position.” The firm can use the information to perform that requested service.
- Medical Emergencies: Processing without consent is permitted where necessary for medical emergencies, epidemics, and life-threatening situations
- State Subsidies and Licenses: Government authorities may process personal data for welfare schemes, subsidies, licenses, and certificates without seeking separate consent.
-
CA Practice Compliance Action Plan
CA firms, what practical steps should be taken?
-
- Unbundled Consent Architecture: In this case, advises avoiding broad and vague consent and instead providing specific notices. Example: Separate notices for Tax filing, audit services, payroll processing, and marketing communications. This improves transparency.
-
- Mandatory DPA Execution: Execute Data Processing Agreements with cloud vendors, Payroll software vendors, document storage providers, and accounting software providers. This is objective To clearly define responsibilities, data security measures, and liability allocation
- Statutory Retention Harmonization: One major challenge for CAs is record retention.
-
-
- DPDP Principle: Delete personal data when no longer necessary.
- Other Laws Require Retention: Examples: Income Tax records: often retained for several years, company act records, audit working papers, and GST documents. A documented retention schedule must reconcile these requirements.
-
-
- Engagement Letter Update: The company needed to update engagement letters. Include:
-
-
- Role Clarification: Specify whether the firm acts as Data Fiduciary and Data Processor
- Cloud Hosting Disclosure: Specify where data is stored and which third parties are involved
- Liability Clauses: Clearly define risk allocation, indemnities, and limitation of liability
-
-
- Security Safeguards:
-
-
- AES-256 Encryption: Protect databases containing PAN, Aadhaar, bank details, and tax information.
- One-Year Access Logs: Maintain records showing who accessed data, when access occurred, and what changes were made. This supports investigations, audit trails, and regulatory compliance
-
Insolvency Professionals (IRP/RP/Liquidator) and DPDP Act
Relevance for Insolvency Professionals (IRP/RP/Liquidator) : As an IRP, RP, or Liquidator, you routinely process Employees’ personal data, creditors’ contact details, directors’ KYC documents, shareholder information, financial records, email addresses, and phone numbers.
Under DPDP: You may rely on legitimate uses for statutory disclosures under IBC, information sharing with regulators. Claim verification and employee salary processing during CIRP, However, you must still protect personal data, limit unauthorized access, retain records securely, respond to grievances, and report data breaches when required.
Key Learning for Chartered Accountants and Insolvency Professionals
For professionals such as CAs, Insolvency Professionals (IPs), Resolution Professionals (RPs), and Liquidators, the most important takeaway is:
- Understand Your Role: For every engagement, identify whether you are a data fiduciary or a data processor
- Use Section 7 Exemptions Properly: Many professional activities such as payroll processing, Tax compliance, statutory filings, and IBC-related disclosures may be carried out under legitimate use provisions without obtaining fresh consent.
- Strengthen Documentation: Maintain privacy notices, engagement letters, Data Processing Agreements (DPA), retention schedules, and incident response procedures
- Improve Data Security: Implement encryption, role-based access controls, secure backups, access logs, and vendor oversight. In short, this chapter translates the DPDP Act into a practical compliance roadmap for CA firms and professional practices, showing when a firm is legally responsible for data and what controls must be implemented to avoid regulatory and reputational risks.

