DPDP Act 2023 for professional-services firms: a practical checklist
Updated 3 September 2026
The Digital Personal Data Protection Act 2023 applies to any firm that processes digital personal data — which includes almost every CA, CS, legal and advisory practice. As a Data Fiduciary deciding the purpose and means of processing client and employee personal data, a firm carries the following core obligations.
Checklist
- Notice. Give data principals a clear notice — what personal data is collected, the purpose, how to withdraw consent and how to complain to the Data Protection Board.
- Lawful basis. Process on consent or a recognised legitimate use. Consent must be free, specific, informed and revocable, and requests should be no broader than the purpose.
- Purpose limitation. Use the data only for the purpose it was collected for; delete it when the purpose is served and retention is no longer required or legally mandated.
- Accuracy. Keep data used for decisions or disclosures complete and accurate.
- Security safeguards. Implement reasonable technical and organisational measures to prevent a personal-data breach.
- Breach response. Notify the Board and affected principals of a personal-data breach as prescribed.
- Processor contracts. Engage data processors (including software vendors) only under a valid contract.
- Principal rights. Be able to service access, correction, erasure and grievance-redressal requests, and appoint a contact for them.
- Children’s data. Obtain verifiable parental consent where a principal is a minor.
Where AI tooling fits
Sending client personal data to a third-party AI service makes that provider a processor in your chain, to be covered by contract and reflected in your notice. Keeping processing on infrastructure you control shortens that chain and simplifies the security-safeguards and processor-contract items.
How Yogin AI helps
Yogin AI is built to keep client data on self-hosted infrastructure rather than routing it to a third-party model API — see how data is handled. This guide is a general checklist, not legal advice on your firm’s DPDP compliance; confirm your position with counsel.