Stay abreast with the latest developments in the professional domain along with in-depth analysis through the monthly BCA Journal. Get access to an engaging library of researched publications from the BCAS stable.
Learn MoreExplore past issues of BCA Journal & indulge in a treasure trove of high-quality professional content across format of print, videos & learning events from the BCAS stable.
Learn MoreMonthly mouth-piece of BCAS, the BCA Journal is a leading publication that has been in continuous circulation for more than 55 years. Over the years the BCAJ has become synonymous with high-quality & authentic content across fields of finance, accounting, tax & regulatory matters. The BCAJ has wide circulation across India & commands huge respect amongst the Chartered Accountants` community.
Learn MoreFor queries, collaborations, and insights to forge, Drop a line, share thoughts, inquiries galore, At BCAJ, your messages, we eagerly explore.
Learn MoreAs part of our AI initiative, this audio summary presents the key points of the BCAJ in just 15 minutes. This well-rounded discussion serves as an ice-breaker, encouraging you to explore the full article or feature in detail from the journal.
Learn More
A client emails a scanned copy of his Aadhaar card to your office for uploading on the GST registration portal. The file size is 3 MB, while the portal accepts uploads only up to 1 MB. The intern handling the registration opens a free online PDF-compression website, uploads the Aadhaar scan, downloads the compressed version and completes the filing. The registration is successful. The client is satisfied. No one in the office gives the compression website another thought.
Yet this simple and commonplace act illustrates one of the most overlooked data protection risks in professional practice.
Across Chartered Accountants’ offices, personal identity documents such as Aadhaar cards, PAN cards, passport copies and bank statements are routinely compressed, merged, converted, translated or subjected to OCR using freely available online tools. The convenience is undeniable. The legal implications, however, deserve closer attention.

The Digital Personal Data Protection Act, 2023 (“DPDP Act”) introduces a statutory framework governing the processing of digital personal data. The principal compliance requirements including notices, consent management, security safeguards, breach reporting and data principal rights become operative from 13 May 2027.
Consider the Aadhaar example. Once the document is uploaded to an external website, the firm relinquishes direct control over how that file is processed, stored or deleted. Many online utilities process documents on servers outside the firm’s infrastructure, under terms that users seldom read and whose retention practices may vary. A complete identity document, in the wrong hands, is a master key: it is good enough to open a mule bank account, procure a duplicate SIM card through fraudulent e-KYC, apply for an unsecured loan in the client’s name, or register a shell entity. Even where a service claims to delete uploaded files after a specified period, the firm has entrusted sensitive personal data to a third party over whom it exercises no contractual control.
The DPDP Act applies to personal data processed in digital form, or to physical data that is subsequently digitised. Accordingly, while a physical photocopy of an identity document lying in a paper file may fall outside its scope, the moment that document is scanned, emailed, uploaded or electronically processed, the statutory framework becomes relevant.
For most professional engagements, a Chartered Accountant processes personal data on behalf of the client and becomes a Data Processor under the Act. At the same time, where the firm independently determines the manner or means of processing—for instance, deciding to use a particular software platform or online utility—it may also assume obligations associated with a Data Fiduciary under the Act. The precise legal characterisation will depend upon the facts of each engagement, but in either case the responsibility to handle personal data with appropriate care remains.
In the illustration above, several provisions of the DPDP framework could become relevant. The processing continues to serve the authorised purpose of GST registration. However, the firm’s decision to route the Aadhaar through an unapproved public website raises broader compliance questions. Was the client adequately informed that an external service provider might process the document and did he consent to that arrangement explicitly/implicitly? Has the firm exercised reasonable due diligence before entrusting personal data to that provider? Is there an appropriate contractual arrangement with the website governing confidentiality, security safeguards, retention and deletion of the data? The DPDP framework places the responsibility for these decisions squarely on the organisation processing the personal data. Convenience cannot substitute governance.
The DPDP Act prescribes substantial monetary penalties ranging upto Rs.250 crores for failure to put in place reasonable security safeguards to prevent a personal security breach. Many other contraventions also attract high penalties. These represent statutory maximums, and any penalty would necessarily depend upon the facts, the nature of the contravention, mitigating circumstances and the assessment of the Data Protection Board.
Fortunately, the solution to this specific risk is neither expensive nor complicated.
Every firm should adopt a simple written policy prohibiting the upload of client documents to public or unapproved online utilities for compression, conversion, OCR or similar processing. Where such functionality is required, firms should use licensed desktop software or approved applications operating within their own controlled environment. Equally important is a basic due diligence process before introducing any technology that handles client data, together with periodic sensitisation of staff who routinely process documents. This will necessarily require incurring of additional costs, but failure to do so may result in far higher financial penalties.
The most significant data protection risks seldom arise from sophisticated cyberattacks. More often, they emerge from ordinary shortcuts taken in busy offices by well-intentioned people. A seemingly harmless decision to compress a PDF using a free website may appear inconsequential, but it can expose sensitive personal information to risks that neither the client nor the professional intended.
Thank You!
With Best Regards,
CA Sunil Gabhawalla
Editor
You might also like to read