{"id":33135,"date":"2026-09-14T00:17:20","date_gmt":"2026-09-13T18:47:20","guid":{"rendered":"https:\/\/carajput.com\/blog\/?p=33135"},"modified":"2026-09-14T00:53:20","modified_gmt":"2026-09-13T19:23:20","slug":"legal-framework-of-the-dpdp-act-2023","status":"publish","type":"post","link":"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/","title":{"rendered":"Legal Framework of the DPDP Act, 2023"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_58 counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<p class=\"ez-toc-title\">Page Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6aa711fd68e24\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #000000;color:#000000\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #000000;color:#000000\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6aa711fd68e24\"  aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Legal_framework_Digital_Personal_Data_Protection_Act_2023\" title=\"Legal framework: Digital Personal Data Protection Act 2023\">Legal framework: Digital Personal Data Protection Act 2023<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Digital_Personal_Data_Protection_DPDP_Act_2023\" title=\"Digital Personal Data Protection (DPDP) Act, 2023.\">Digital Personal Data Protection (DPDP) Act, 2023.<\/a><ul class='ez-toc-list-level-3'><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Phase_1_14_November_2025\" title=\"Phase 1: 14 November 2025\">Phase 1: 14 November 2025<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Phase_2_14_November_2026\" title=\"Phase 2: 14 November 2026\">Phase 2: 14 November 2026<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Phase_3_14_May_2027\" title=\"Phase 3: 14 May 2027 : \">Phase 3: 14 May 2027 : <\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Statutory_Legal_Roles\" title=\" Statutory Legal Roles\"> Statutory Legal Roles<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#CA_Firm_Dual_Role\" title=\"CA Firm Dual Role: \">CA Firm Dual Role: <\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Section_7_Legitimate_Uses\" title=\" Section 7: Legitimate Uses\"> Section 7: Legitimate Uses<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Key_takeaway_Essentially_explains_that_DPDP_compliance_revolves_around_four_pillars\" title=\"Key takeaway: Essentially explains that DPDP compliance revolves around four pillars:\">Key takeaway: Essentially explains that DPDP compliance revolves around four pillars:<\/a><ul class='ez-toc-list-level-3'><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Core_Statutory_Roles_Section_2\" title=\" Core Statutory Roles (Section 2) :\"> Core Statutory Roles (Section 2) :<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Indian_CA_Firm_as_Data_Fiduciary\" title=\"Indian CA Firm as Data Fiduciary: \">Indian CA Firm as Data Fiduciary: <\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#CA_Firm_as_Data_Processor\" title=\" CA Firm as Data Processor:\"> CA Firm as Data Processor:<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Section_7_Legitimate_Uses_Consent_Exemptions\" title=\" Section 7 Legitimate Uses (Consent Exemptions): \"> Section 7 Legitimate Uses (Consent Exemptions): <\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#CA_Practice_Compliance_Action_Plan\" title=\" CA Practice Compliance Action Plan\"> CA Practice Compliance Action Plan<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/carajput.com\/blog\/legal-framework-of-the-dpdp-act-2023\/#Key_Learning_for_Chartered_Accountants_and_Insolvency_Professionals\" title=\"Key Learning for Chartered Accountants and Insolvency Professionals\">Key Learning for Chartered Accountants and Insolvency Professionals<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-33132\" src=\"https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-10-at-1.41.32-AM.jpeg\" alt=\"India's Digital Personal Data Protection (DPDP) Act, 2023\" width=\"1536\" height=\"1024\" srcset=\"https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-10-at-1.41.32-AM.jpeg 1536w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-10-at-1.41.32-AM-300x200.jpeg 300w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-10-at-1.41.32-AM-1024x683.jpeg 1024w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-10-at-1.41.32-AM-768x512.jpeg 768w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-10-at-1.41.32-AM-800x533.jpeg 800w\" sizes=\"(max-width: 1536px) 100vw, 1536px\" \/><\/h2>\n<h2><span class=\"ez-toc-section\" id=\"Legal_framework_Digital_Personal_Data_Protection_Act_2023\"><\/span><span style=\"color: #000080;\">Legal framework: Digital Personal Data Protection Act 2023<\/span><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The Digital Personal Data Protection (DPDP) Act, 2023 is India&#8217;s primary law governing the collection, storage, use, sharing, and protection of digital personal data. It establishes rights for individuals and obligations for organizations that process personal data. Legal framework, implementation timeline, key stakeholders, penalties, and legitimate uses under the Digital Personal Data Protection (DPDP) Act, 2023.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Digital_Personal_Data_Protection_DPDP_Act_2023\"><\/span><span style=\"color: #000080;\">Digital Personal Data Protection (DPDP) Act, 2023.<\/span><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ol>\n<li><strong><span style=\"color: #000080;\"> Statutory Penalty Alert:<\/span> <\/strong>This section highlights the consequences of non-compliance with the DPDP Act.<\/li>\n<\/ol>\n<ul>\n<li><span style=\"color: #000080;\"><strong>Maximum Fine:<\/strong> <\/span>&#8220;Up to \u20b9250 Crore per instance&#8221;. This means that if a Data Fiduciary fails to meet its obligations, the Data Protection Board can impose significant financial penalties. Examples: Failure to implement security safeguards., Failure to report a personal data breach., Failure to protect children&#8217;s data and Ignoring Data Principal rights requests. For large organizations, each separate violation can attract a separate penalty.<\/li>\n<li><span style=\"color: #000080;\"><strong>Adjudication:<\/strong><\/span> The DPDP Act establishes a Data Protection Board (DPB) as the adjudicating authority.<\/li>\n<li><strong><span style=\"color: #000080;\">Functions of DPB:<\/span><\/strong> The Board can Receive complaints, Investigate breaches, Conduct digital inquiries, Impose penalties and Direct corrective measures. Unlike traditional court proceedings, the DPDP framework emphasizes digital processes and electronic submissions.<\/li>\n<li><span style=\"color: #000080;\"><strong>Fiduciary Liability:<\/strong> <\/span>&#8220;Direct accountability&#8221; Under DPDP, the primary responsibility lies on the Data Fiduciary. Who is a Data Fiduciary? : Any person, company, LLP, partnership, government department, or organization that determines: Why personal data is collected, How personal data is processed. Examples Employer processing employee data, Bank processing customer information, Hospital managing patient records and Insolvency Professional managing stakeholder records. Even if a third-party vendor processes the data, the Data Fiduciary remains accountable.<\/li>\n<li><strong><span style=\"color: #000080;\">Appeals:<\/span><\/strong> TDSAT within 60 days If a party is aggrieved by an order of the Data Protection Board, it can appeal to TDSAT (Telecom Disputes Settlement and Appellate Tribunal). Time Limit is Appeal within 60 days from receipt of the Board&#8217;s order.<\/li>\n<li><span style=\"color: #000080;\"><strong>Adjudicating Authority:<\/strong> <\/span>Data Protection Board (DPB) : The Board is responsible for Hearing complaints, investigating non-compliance, Conducting inquiries, Imposing monetary penalties, It functions as the central enforcement authority under DPDP.<\/li>\n<li><span style=\"color: #000080;\"><strong> Implementation Timeline : <\/strong><\/span>The slide presents a phased implementation approach.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Phase_1_14_November_2025\"><\/span><span style=\"color: #000080;\"><strong>Phase 1: 14 November 2025<\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>Key Activities: DPB Becomes Operational: The Data Protection Board starts functioning. This allows Complaint handling, breach investigations, and adjudication proceedings.<\/li>\n<li>RTI Exemption: Reference is made to RTI Section 8(1)(j): This relates to personal information exemptions under the Right to Information framework and the interplay between privacy protection and disclosure obligations.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Phase_2_14_November_2026\"><\/span><span style=\"color: #000080;\"><strong>Phase 2: 14 November 2026<\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>Consent Manager Registration: Consent Managers are entities that help Data Principals Give consent, Withdraw consent and Manage permissions Example: A centralized platform where a citizen can manage permissions given to multiple organizations.<\/li>\n<li>Net Worth Requirement: \u20b92 Crore Net Worth Norms and Entities seeking registration as Consent Managers may need to satisfy prescribed financial requirements.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Phase_3_14_May_2027\"><\/span><span style=\"color: #000080;\"><strong>Phase 3: 14 May 2027 : <\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This phase introduces full-scale compliance obligations.<\/p>\n<ul>\n<li>Substantive Data Fiduciary Obligations: Organizations must fully comply with Notice requirements, Consent management, Security safeguards, Breach reporting and Rights handling.<\/li>\n<li>Standalone Notices in 22 Languages: Privacy notices may need to be available in multiple Indian languages to improve accessibility. Example Hindi, English, Tamil, Telugu, Bengali, Marathi, Gujarati and Punjabi etc.<\/li>\n<li>AES-256 Safeguards: AES-256 refers to a strong encryption standard. For the Purpose to Protect Customer data, Employee data, Financial information and Sensitive personal information. Example: Encrypting employee payroll databases.<\/li>\n<li>One-Year Log Retention: Organizations should maintain logs showing User access, System activities and Security events. Bais Purpose is Audit trail, Investigations and Regulatory compliance<\/li>\n<li>72-Hour Breach Reporting: If a data breach occurs, the organization must notify the regulatory authority within the prescribed timeframe.Examples Ransomware attack, Unauthorized access, Data leakage and Lost databases. Organizations therefore require an Incident Response Plan.<\/li>\n<li>Three-Year Inactive Data Erasure: Organizations should not retain personal data indefinitely. When data becomes inactive and retention is no longer necessary Erase, Delete and Anonymize. This reflects the principle of data minimization.<\/li>\n<li>Verifiable Parental Consent: For individuals below 18 years: Organizations must obtain verifiable parental consent before processing the child&#8217;s personal data. Examples: Educational platforms, Gaming applications, social media services and Online learning portals.<\/li>\n<li>IT Act Section 43A Repeal: Historically, privacy obligations in India were linked to Section 43A of the Information Technology Act, 2000. The DPDP framework gradually becomes the primary privacy legislation.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Statutory_Legal_Roles\"><\/span><span style=\"color: #000080;\"><strong> Statutory Legal Roles<\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-33141\" src=\"https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-11-at-4.29.02-PM.jpeg\" alt=\"DPDP compliance \" width=\"1024\" height=\"1280\" srcset=\"https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-11-at-4.29.02-PM.jpeg 1024w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-11-at-4.29.02-PM-240x300.jpeg 240w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-11-at-4.29.02-PM-819x1024.jpeg 819w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-11-at-4.29.02-PM-768x960.jpeg 768w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-11-at-4.29.02-PM-800x1000.jpeg 800w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p style=\"padding-left: 40px;\">The DPDP Act creates three important roles.<\/p>\n<p style=\"padding-left: 40px;\">Data Principal: Definition The individual to whom personal data relates: Examples: Customer, Employee, Vendor (individual), Student, and Citizen<\/p>\n<p style=\"padding-left: 40px;\">For minors: Parents or lawful guardians exercise rights on their behalf. Rights of Data Principal: Right to information, Right to access data, Right to correction, Right to update, right to erasure, Right to grievance redressal<\/p>\n<ul>\n<li>Data Fiduciary: Definition: The entity deciding the purpose of processing and means of processing. Examples: Company, bank, insurance company, educational institution, and government agency. Responsibilities: Obtain consent when required, Provide notices, protect personal data, report breaches, and respond to rights requests. This role bears primary liability under the Act.<\/li>\n<li>Data Processor: Definition: A third-party processing personal data on behalf of the Data Fiduciary. Examples: Payroll service provider, cloud hosting company, data analytics vendor, and HR software provider. Processors act only according to instructions from the Data Fiduciary.<\/li>\n<li style=\"list-style-type: none;\"><\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"CA_Firm_Dual_Role\"><\/span><span style=\"color: #000080;\">CA Firm Dual Role: <\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"padding-left: 40px;\">An interesting professional example. As a data fiduciary, a CA firm becomes a Data Fiduciary when Filing tax returns, collecting client documents, and determining processing purposes.<\/p>\n<p style=\"padding-left: 40px;\">As a Data Processor: A CA firm acts as a processor when outsourced payroll processing, bookkeeping services, and back-office functions are done and acts under the client&#8217;s instructions.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Section_7_Legitimate_Uses\"><\/span><span style=\"color: #000080;\"><strong> Section 7: Legitimate Uses<\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"padding-left: 40px;\">One of the most important concepts under DPDP is that certain processing activities do not require consent.<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><span style=\"color: #000080;\"><strong> Employment and Payroll (Section 7) : <\/strong><\/span>Consent is generally not required for Employment Purposes Examples: Salary processing, attendance management, PF administration, ESI administration, tax deduction (TDS), and background verification. An employee&#8217;s consent is not needed every month to process salary.<\/li>\n<li><strong><span style=\"color: #000080;\"> Statutory Compliance (Section 7) :<\/span> <\/strong>Consent is not required where processing is necessary to comply with legal obligations. Examples: Income tax reporting, GST compliance, MCA filings, court orders, regulatory reporting, IBC proceedings<\/li>\n<li><strong><span style=\"color: #000080;\"> Medical Emergencies (Section 7)<\/span> : <\/strong>Personal data may be processed without consent during Medical emergencies, epidemics, disaster response, or life-saving situations. Example: A hospital sharing critical patient information with emergency responders.<\/li>\n<li><span style=\"color: #000080;\"><strong> Voluntary Provision of Data (Section 7) : <\/strong>I<\/span>f a person voluntarily provides information for a specific purpose, separate consent may not be necessary for fulfilling that request. Example: A customer sends an email requesting a quote for services, product information, and complaint resolution. The organization may use that information to answer the request.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h2><span class=\"ez-toc-section\" id=\"Key_takeaway_Essentially_explains_that_DPDP_compliance_revolves_around_four_pillars\"><\/span><span style=\"color: #000080;\"><strong>Key takeaway: E<\/strong>ssentially explains that <strong>DPDP compliance revolves around four pillars<\/strong>:<\/span><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li>Understand your legal role (data principal, fiduciary, or processor).<\/li>\n<li>Know when consent is required and when it is not.<\/li>\n<li>Implement safeguards and governance controls.<\/li>\n<li>Avoid severe penalties by maintaining continuous compliance and breach readiness.<\/li>\n<\/ul>\n<p><span style=\"color: #000080;\"><strong>DPDP Act Explained for Chartered Accountants:<\/strong><\/span><\/p>\n<p><strong><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-33133\" src=\"https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-13-at-4.43.11-PM.jpeg\" alt=\"Digital Personal Data Protection (DPDP) Act, 2023\" width=\"1236\" height=\"1600\" srcset=\"https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-13-at-4.43.11-PM.jpeg 1236w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-13-at-4.43.11-PM-232x300.jpeg 232w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-13-at-4.43.11-PM-791x1024.jpeg 791w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-13-at-4.43.11-PM-768x994.jpeg 768w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-13-at-4.43.11-PM-1187x1536.jpeg 1187w, https:\/\/carajput.com\/blog\/wp-content\/uploads\/2026\/09\/WhatsApp-Image-2026-09-13-at-4.43.11-PM-800x1036.jpeg 800w\" sizes=\"(max-width: 1236px) 100vw, 1236px\" \/><\/strong><\/p>\n<p>Here we explain how the Digital Personal Data Protection (DPDP) Act, 2023 applies specifically to Chartered Accountants (CAs), CA Firms, Tax Consultants, Auditors, and Professional Service Firms. The main message is that a CA firm can act either as a data fiduciary or a data processor, depending on the nature of the engagement.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Core_Statutory_Roles_Section_2\"><\/span><span style=\"color: #000080;\"><strong> Core Statutory Roles (Section 2) :<\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"padding-left: 40px;\">The DPDP Act defines several key stakeholders.<\/p>\n<ul>\n<li>Data Principal [Section 2(j)]: A Data Principal is the individual whose personal data is being processed. Examples like client, employee, director, shareholder, debtor, creditor, and vendor. Special Cases for Children Below 18 Years and Persons with Disabilities. Their lawful guardians exercise rights on their behalf.<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\">Rights of Data Principal: They can know what data is collected, request access, seek correction, update information, request deletion (where legally permitted), and file grievances. Example for CA Practice: A client provides PAN, Aadhaar, bank account details, and income details. The client becomes the data principal.<\/p>\n<ul>\n<li>Data Fiduciary [Section 2(i)]: A Data Fiduciary is the entity deciding Why data is collected and how it is processed. Important Principle: &#8220;Primary statutory liability cannot be outsourced.&#8221; This means even if a CA firm uses cloud storage, Payroll software, tax filing platforms, and outsourced IT vendors, the responsibility remains with the data fiduciary. Example: A CA firm decides which client documents to collect How long records will be retained and which software will store data. The CA firm acts as a data fiduciary.<\/li>\n<li>Data Processor [Section 2(k)]: A Data Processor processes personal data on behalf of a Data Fiduciary. They do not decide purpose or means; they merely follow instructions. Examples: payroll service providers, cloud storage providers, software vendors, and bookkeeping BPOs<\/li>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Requirement: Processing must occur under a formal:<\/li>\n<li>Data Processing Agreement (DPA) : The DPA should define the scope of processing, security requirements, confidentiality obligations, and deletion requirements<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Consent Manager [Section 2(g)]: A Consent Manager is a registered entity that helps individuals Give consent, track consent, withdraw consent, and review permissions through a common dashboard. Example: Similar to a privacy management portal where a person can see which organizations have access to their data, which permissions are active, and how to revoke them.<\/li>\n<li>Significant Data Fiduciary (SDF) [Section 10] : The Government may classify some organizations as Significant Data Fiduciaries.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p style=\"padding-left: 120px;\">Factors Considered: Volume of data processed, sensitivity of data, risk to citizens, and impact on national interests.<\/p>\n<p style=\"padding-left: 120px;\">Additional Obligations:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Appointment of DPO: (Data Protection Officer) Must Be based in India and the Handle compliance matters.<\/li>\n<li>Independent Audits: Annual privacy audits become mandatory.<\/li>\n<li>DPIA Data Protection Impact Assessment to evaluate privacy risks.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><strong><span style=\"color: #000080;\"> CA Firm Dual Role Matrix:<\/span> <\/strong>This is one of the most important concepts for CA professionals. A CA firm may play two different legal roles.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Indian_CA_Firm_as_Data_Fiduciary\"><\/span><strong><span style=\"color: #000080;\">Indian CA Firm as Data Fiduciary:<\/span> <\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"padding-left: 40px;\">This applies when the CA firm independently decides how personal data will be processed.<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Direct Tax &amp; Advisory: The firm collects PAN, Aadhaar, Form 26AS, AIS\/TIS, and bank statements. The firm determines the information required, processing methods, and storage mechanisms. Therefore, CA Firm = Data Fiduciary<\/li>\n<li>Statutory Audit: During audit The CA firm collects employee data, vendor information, director records, and financial documentation. The audit approach, testing procedures, and working papers are determined by ICAI standards. Therefore, CA Firm = Data Fiduciary<\/li>\n<li>Internal Firm HR and Payroll: The firm processes employee records, Form 16, PF information, ESI information, and salary details. The firm decides the purpose. Therefore, CA Firm = Data Fiduciary<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"CA_Firm_as_Data_Processor\"><\/span><span style=\"color: #000080;\"><strong> CA Firm as Data Processor:<\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"padding-left: 40px;\">This occurs when the firm merely acts on client instructions.<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Outsourced Client Payroll: Example: A company outsources payroll processing. The CA firm calculates salary, computes TDS, and generates payroll reports. The client decides why data is processed. Hence: Client = Data Fiduciary and CA Firm = Data Processor<\/li>\n<li>Outsourced Ledger Management: The client instructs Maintain sales ledger and Prepare customer accounts. CA firm processes customer information according to client SOPs. Hence, Data Processor. Practical Example: Suppose a company hires your CA firm.<\/li>\n<li>Tax Planning Assignment: You determine required documents, tax strategy, and processing activities, which Result: Data Fiduciary<\/li>\n<li>Payroll Processing Assignment: Client determines employee list, salary structure, and HR policies. You merely process. Result: Data Processor<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Section_7_Legitimate_Uses_Consent_Exemptions\"><\/span><span style=\"color: #000080;\"><strong> Section 7 Legitimate Uses (Consent Exemptions): <\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"padding-left: 40px;\">The DPDP Act allows certain processing without consent.<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Employment &amp; Payroll: Consent is not required for salary processing, PF deductions, ESI deductions, bonus calculation, and TDS deductions. Example: An employer does not need to obtain fresh employee consent every month to process payroll.<\/li>\n<li>Statutory Mandates: Consent is not required when processing is necessary to comply with law. For Examples\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Income Tax Act: TDS filings, ITR filings<\/li>\n<li>Companies Act: Annual Return and Financial Statements<\/li>\n<li>GST Law: GST returns, E-way compliance<\/li>\n<li>Insolvency &amp; Bankruptcy Code: CIRP disclosures, claim processing, and Committee of Creditors records, As an RP or Liquidator, much data processing falls under statutory obligations.<\/li>\n<\/ul>\n<\/li>\n<li>Voluntary Provision: If a person voluntarily provides information for a specific purpose: Consent may not be separately required. Example: A prospective client emails: &#8220;Please review my tax position.&#8221; The firm can use the information to perform that requested service.<\/li>\n<li>Medical Emergencies: Processing without consent is permitted where necessary for medical emergencies, epidemics, and life-threatening situations<\/li>\n<li>State Subsidies and Licenses: Government authorities may process personal data for welfare schemes, subsidies, licenses, and certificates without seeking separate consent.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"CA_Practice_Compliance_Action_Plan\"><\/span><span style=\"color: #000080;\"><strong> CA Practice Compliance Action Plan<\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"padding-left: 40px;\">CA firms, what practical steps should be taken?<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong><span style=\"color: #000080;\"> Unbundled Consent Architecture<\/span>:<\/strong> In this case, advises avoiding broad and vague consent and instead providing specific notices. Example: Separate notices for Tax filing, audit services, payroll processing, and marketing communications. This improves transparency.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><span style=\"color: #000080;\"><strong> Mandatory DPA Execution: <\/strong><\/span>Execute Data Processing Agreements with cloud vendors, Payroll software vendors, document storage providers, and accounting software providers. This is objective To clearly define responsibilities, data security measures, and liability allocation<\/li>\n<li><strong><span style=\"color: #000080;\"> Statutory Retention Harmonization:<\/span> <\/strong>One major challenge for CAs is record retention.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>DPDP Principle: Delete personal data when no longer necessary.<\/li>\n<li>Other Laws Require Retention: Examples: Income Tax records: often retained for several years, company act records, audit working papers, and GST documents. A documented retention schedule must reconcile these requirements.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong><span style=\"color: #000080;\"> Engagement Letter Update: <\/span><\/strong><span style=\"color: #000080;\">The <\/span><span style=\"color: #000080;\"><span style=\"color: #000000;\">company<\/span><\/span>\u00a0needed to update engagement letters. Include:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Role Clarification: Specify whether the firm acts as Data Fiduciary and Data Processor<\/li>\n<li>Cloud Hosting Disclosure: Specify where data is stored and which third parties are involved<\/li>\n<li>Liability Clauses: Clearly define risk allocation, indemnities, and limitation of liability<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><span style=\"color: #000080;\"><strong> Security Safeguards:<\/strong><\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>AES-256 Encryption: Protect databases containing PAN, Aadhaar, bank details, and tax information.<\/li>\n<li>One-Year Access Logs: Maintain records showing who accessed data, when access occurred, and what changes were made. This supports investigations, audit trails, and regulatory compliance<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"color: #000080;\"><strong>Insolvency Professionals (IRP\/RP\/Liquidator) and DPDP Act<\/strong><\/span><\/p>\n<p style=\"padding-left: 80px;\">Relevance for Insolvency Professionals (IRP\/RP\/Liquidator) : As an IRP, RP, or Liquidator, you routinely process Employees&#8217; personal data, creditors&#8217; contact details, directors&#8217; KYC documents, shareholder information, financial records, email addresses, and phone numbers.<\/p>\n<p style=\"padding-left: 80px;\">Under DPDP: You may rely on legitimate uses for statutory disclosures under IBC, information sharing with regulators. Claim verification and employee salary processing during CIRP, However, you must still protect personal data, limit unauthorized access, retain records securely, respond to grievances, and report data breaches when required.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Key_Learning_for_Chartered_Accountants_and_Insolvency_Professionals\"><\/span><span style=\"color: #000080;\"><strong>Key Learning for Chartered Accountants and Insolvency Professionals<\/strong><\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>For professionals such as CAs, Insolvency Professionals (IPs), Resolution Professionals (RPs), and Liquidators, the most important takeaway is:<\/p>\n<ul>\n<li>Understand Your Role: For every engagement, identify whether you are a data fiduciary or a data processor<\/li>\n<li>Use Section 7 Exemptions Properly: Many professional activities such as payroll processing, Tax compliance, statutory filings, and IBC-related disclosures may be carried out under legitimate use provisions without obtaining fresh consent.<\/li>\n<li>Strengthen Documentation: Maintain privacy notices, engagement letters, Data Processing Agreements (DPA), retention schedules, and incident response procedures<\/li>\n<li>Improve Data Security: Implement encryption, role-based access controls, secure backups, access logs, and vendor oversight. In short, this chapter translates the DPDP Act into a practical compliance roadmap for CA firms and professional practices, showing when a firm is legally responsible for data and what controls must be implemented to avoid regulatory and reputational risks.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Legal framework: Digital Personal Data Protection Act 2023 The Digital Personal Data Protection (DPDP) Act, 2023 is India&#8217;s primary law governing the collection, storage, use, sharing, and protection of digital personal data. It establishes rights for individuals and obligations for organizations that process personal data. Legal framework, implementation timeline, key stakeholders, penalties, and legitimate uses &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[115],"tags":[10562],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/posts\/33135"}],"collection":[{"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/comments?post=33135"}],"version-history":[{"count":5,"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/posts\/33135\/revisions"}],"predecessor-version":[{"id":33138,"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/posts\/33135\/revisions\/33138"}],"wp:attachment":[{"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/media?parent=33135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/categories?post=33135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/carajput.com\/blog\/wp-json\/wp\/v2\/tags?post=33135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}