A CA in Mysuru is filing GST for a diagnostic lab. Halfway through, the owner asks: "There's this new data law. Do we have to do something about it?"
That question is coming to a lot of CA offices. The DPDP Act's main obligations apply from May 2027, and there's no general exemption for small businesses. The lab, the training centre, the trading company with 2,000 customers on a WhatsApp list: they all have duties. And most of them don't have a compliance person. They have a CA.
This post covers what a DPDPA engagement involves, where CAs fit, how to scope it, and what to watch for under ICAI's rules.
Why will your SME clients ask you about DPDPA?
Because you're already the person they trust with compliance. GST, TDS, ROC filings, audits: you've spent years turning regulations into routines for them. DPDPA looks like more of the same, and in practice it mostly is.
The deadline is fixed. Most obligations under the DPDP Rules come into force in May 2027, 18 months after the Rules were notified. If your clients haven't started, the realistic window to get them ready is now. Our guide to what the DPDP Act needs from a business by May 2027 covers the full list, and it's written so you can share it with clients directly.
What does a DPDPA engagement for an SME involve?
Less law than people expect, and more process. A typical engagement looks like this:
| Stage | What you do | What the client ends up with |
|---|---|---|
| Assess | Walk through how the business collects and uses personal data | A gap list ranked by risk |
| Map | Record each processing activity: what data, why, where it's stored, who it's shared with | A record of processing activities (RoPA) |
| Notices and consent | Check notices against what's actually collected, and fix consent flows | Notices that match reality |
| Security | Review access, backups, log retention and encryption for sensitive data | A short list of controls, with owners |
| Vendors | List everyone who processes data for the client and check their contracts | A vendor register with contract gaps marked |
| Breach and requests | Set up who does what in a breach, and how access or erasure requests get answered | A breach plan and a request process |
| Ongoing | Review once a year, or when the business changes | Records that stay current |
If you've done internal audits or process documentation, most of this will feel familiar. It's controls work with a different subject.
Start with your own firm. A CA who asks a client for a data map should be able to show one for their own practice.
Where do CAs fit, and where do you need a lawyer?
Draw the line clearly with clients from day one. It protects them and it protects you.
CAs are a natural fit for:
- Mapping data flows and maintaining the RoPA
- Reviewing controls and setting up a compliance calendar
- Building a vendor register and tracking which contracts need updating
- Running the annual review
Bring in a lawyer for:
- Grey-area questions, such as whether a particular use counts as a legitimate use under the Act
- Drafting or negotiating contracts with data processors
- Any complaint, notice or inquiry from the Data Protection Board
Many CA firms already work alongside a law firm on other matters. A standing arrangement for DPDPA questions makes the service complete without stretching your scope.
How should you scope and price the work?
Scope it by the size of the data footprint, not by the client's turnover. A small diagnostic lab can have more sensitive processing than a much larger trading firm. The things that drive effort are:
- How many separate processing activities the client has (billing, HR, marketing, patient or student records, and so on)
- How many systems and vendors hold personal data
- Whether the client handles health data, financial data or children's data
- Whether they act as a processor for their own customers
A structure that works well is a fixed fee for the initial setup, then an annual retainer for reviews, updates and handling the occasional request or incident. Fixed fees are easier for SMEs to approve, and the retainer keeps the records from going stale.
What should your firm sort out first?
Your own compliance. Your firm holds client PAN details, bank statements, payroll files and employee records. For your own staff and client contacts, you're a Data Fiduciary. When you process a client's payroll or customer data on their behalf, you're usually their Data Processor.
Before you advise anyone, check:
- How client documents reach you. Email attachments and WhatsApp forwards are hard to secure and hard to delete.
- Who in the firm can access which client files
- Whether your engagement letters cover data processing
- How long you keep client data after an engagement ends, and why
A firm that has done this for itself gives much better advice, and has a ready answer when a client asks "do you follow this yourselves?"
Can you tell clients about this new service?
Carefully. ICAI's code of ethics still restricts CAs from soliciting work and advertising their services, with allowances for neutral, factual websites and factual write-ups within the Council's guidelines. As of the latest commentary we've seen, that position hasn't changed.
In practice, that leaves plenty of room:
- Answer clients who ask, which many will
- Share factual guides, like this one, during existing engagements
- Run an information session for existing clients on what the Act requires
- List the service on your website in neutral, factual terms
Avoid mass promotional emails, testimonials and claims of being better than other firms. Check ICAI's current guidelines before you change how you communicate. This is a flag, not legal advice.
Where does DPDPOne fit?
DPDPOne does the structured groundwork, so your time goes on judgement and client conversations rather than building templates. Each client gets its own readiness assessment, RoPA, policies generated from its own records, and processes for breaches and rights requests.
Firms can manage several client organisations from one account. On the Professional Plus plan, everything runs under your firm's brand and domain, and you set your own fees. There's no revenue share. The partner programme page has the details, and current plans are on the pricing section.
See how CA firms run DPDPA engagements on DPDPOne, under their own brand.
The short version
Your SME clients will need DPDPA groundwork before May 2027, and many will come to you first. The work is process and controls, which CAs already do well. Get your own firm in order, draw a clear line where a lawyer is needed, and keep your client communication factual.
