The Data Protection Board exists and takes grievances digitally. A client, employee or any data principal can already complain about your firm’s handling of their personal data — the regulator is operational even though the duty-side provisions phase in later.
Consent Manager registration opens, and the enforcement and penalty framework begins. From this date the exposure is real money: up to ₹250 crore for failing reasonable security safeguards, ₹200 crore for breach-notification and children-data failures, ₹50 crore for other violations.
Notice, consent, data-principal rights, retention limits and grievance redressal all bind. Every engagement letter, employee file and website form your firm runs must be compliant by this date — no grace period is expected.
Payroll registers, director PANs and addresses, customer/vendor ledgers with individual names — audit files are dense with third-party personal data. Processing for a legal obligation (statutory audit) sits on the legitimate-use footing, but security, retention and breach duties apply in full.
The firm is a plain-vanilla employer data fiduciary: employee and article records, salary data, biometric attendance, references — all in scope, all needing notice, purpose limits and security.
Website forms, seminar registrations, WhatsApp groups: this is consent territory, not legitimate use. Itemised notices and withdrawal mechanics apply — the classic first gap in a firm’s DPDP posture.
Every SaaS your firm routes client data through — audit tools, e-sign, cloud storage, AI services — is your data processor. The Act keeps the fiduciary (you) responsible; contracts must bind processors to your obligations, and where the tool trains on data or hosts abroad, that is your compliance question, not the vendor’s.
Timelines verified 18 July 2026 against the Rules notification (13 November 2025) and MeitY/PIB releases — confirm current status on meity.gov.in before advising a client on a deadline.
CORAA processes client books in India with engagement-scoped access — see the trust page or start free: your first audit is on us.
Yes — the firm determines the purpose and means of processing for its clients’ personal data, its employees’ data and its marketing lists, which is the definition of a data fiduciary. For client engagements the firm may also act as a processor in some flows, but the audit file the firm controls makes it a fiduciary for most practical purposes.
Generally no — processing necessary for compliance with law (the statutory audit, tax filings) rests on the legitimate-use provisions rather than consent. But legitimate use does not waive the other duties: reasonable security safeguards, breach notification, retention discipline and processor contracts still apply to that data in full.
They stack, not conflict: SQC 1 requires audit files be retained at least seven years, and DPDP permits retention as long as a legal purpose subsists — the statutory retention IS the purpose. The discipline DPDP adds is the other end: once retention periods lapse, personal data should be erased rather than accumulating indefinitely, and your retention policy should say so.
Notify the Data Protection Board and affected data principals of a personal data breach — with the Rules prescribing 72-hour timelines to the Board for detailed reporting. For a firm this means an incident-response plan that covers the audit-tool stack and cloud storage, not just the office server; breach-notification failure carries exposure up to ₹200 crore.
Most are not — SDF designation is by government notification based on volume and sensitivity, aimed at large platforms. But large firms processing bulk payroll or running outsourced accounting at scale should watch the notifications: SDF status brings annual data-protection impact assessments, independent audits and a DPO.
Six things, roughly in order: map what personal data the firm holds and where (the data inventory); fix the consent surfaces (website forms, marketing lists) with itemised notices; paper the processors (DPAs with every tool and cloud vendor, India-hosting where possible); write the retention-and-erasure policy against the 7-year file rule; stand up the 72-hour breach playbook; and train the team — the articled assistant forwarding a ledger over personal WhatsApp is the breach vector the plan must reach.