Subscribe to the Bombay Chartered Accountant Journal Subscribe Now!

A Compressed File – An Uncompressed Risk

A client emails a scanned copy of his Aadhaar card to your office for uploading on the GST registration portal. The file size is 3 MB, while the portal accepts uploads only up to 1 MB. The intern handling the registration opens a free online PDF-compression website, uploads the Aadhaar scan, downloads the compressed version and completes the filing. The registration is successful. The client is satisfied. No one in the office gives the compression website another thought.

Yet this simple and commonplace act illustrates one of the most overlooked data protection risks in professional practice.

Across Chartered Accountants’ offices, personal identity documents such as Aadhaar cards, PAN cards, passport copies and bank statements are routinely compressed, merged, converted, translated or subjected to OCR using freely available online tools. The convenience is undeniable. The legal implications, however, deserve closer attention.

The High Cost of free online tools

The Digital Personal Data Protection Act, 2023 (“DPDP Act”) introduces a statutory framework governing the processing of digital personal data. The principal compliance requirements including notices, consent management, security safeguards, breach reporting and data principal rights become operative from 13 May 2027.

Consider the Aadhaar example. Once the document is uploaded to an external website, the firm relinquishes direct control over how that file is processed, stored or deleted. Many online utilities process documents on servers outside the firm’s infrastructure, under terms that users seldom read and whose retention practices may vary. A complete identity document, in the wrong hands, is a master key: it is good enough to open a mule bank account, procure a duplicate SIM card through fraudulent e-KYC, apply for an unsecured loan in the client’s name, or register a shell entity. Even where a service claims to delete uploaded files after a specified period, the firm has entrusted sensitive personal data to a third party over whom it exercises no contractual control.

The DPDP Act applies to personal data processed in digital form, or to physical data that is subsequently digitised. Accordingly, while a physical photocopy of an identity document lying in a paper file may fall outside its scope, the moment that document is scanned, emailed, uploaded or electronically processed, the statutory framework becomes relevant.

For most professional engagements, a Chartered Accountant processes personal data on behalf of the client and becomes a Data Processor under the Act. At the same time, where the firm independently determines the manner or means of processing—for instance, deciding to use a particular software platform or online utility—it may also assume obligations associated with a Data Fiduciary under the Act. The precise legal characterisation will depend upon the facts of each engagement, but in either case the responsibility to handle personal data with appropriate care remains.

In the illustration above, several provisions of the DPDP framework could become relevant. The processing continues to serve the authorised purpose of GST registration. However, the firm’s decision to route the Aadhaar through an unapproved public website raises broader compliance questions. Was the client adequately informed that an external service provider might process the document and did he consent to that arrangement explicitly/implicitly? Has the firm exercised reasonable due diligence before entrusting personal data to that provider? Is there an appropriate contractual arrangement with the website governing confidentiality, security safeguards, retention and deletion of the data? The DPDP framework places the responsibility for these decisions squarely on the organisation processing the personal data. Convenience cannot substitute governance.

The DPDP Act prescribes substantial monetary penalties ranging upto Rs.250 crores for failure to put in place reasonable security safeguards to prevent a personal security breach. Many other contraventions also attract high penalties. These represent statutory maximums, and any penalty would necessarily depend upon the facts, the nature of the contravention, mitigating circumstances and the assessment of the Data Protection Board.

Fortunately, the solution to this specific risk is neither expensive nor complicated.

Every firm should adopt a simple written policy prohibiting the upload of client documents to public or unapproved online utilities for compression, conversion, OCR or similar processing. Where such functionality is required, firms should use licensed desktop software or approved applications operating within their own controlled environment. Equally important is a basic due diligence process before introducing any technology that handles client data, together with periodic sensitisation of staff who routinely process documents. This will necessarily require incurring of additional costs, but failure to do so may result in far higher financial penalties.

The most significant data protection risks seldom arise from sophisticated cyberattacks. More often, they emerge from ordinary shortcuts taken in busy offices by well-intentioned people. A seemingly harmless decision to compress a PDF using a free website may appear inconsequential, but it can expose sensitive personal information to risks that neither the client nor the professional intended.

Show More

Thank You!

With Best Regards,

CA Sunil Gabhawalla
Editor