For CA & Law Firms

How CA firms can offer DPDPA compliance to their SME/MSME clients

Mahadev Thukaram·9 October 2026·5 min read

Short answer

CA firms are well placed to help SME/MSME clients with the DPDP Act. Most of the work is process: mapping personal data, fixing notices, setting up security, breach and request handling, and keeping records current. Scope it by processing activities, bring in a lawyer for legal interpretation, sort out your own firm first, and keep client communication factual.

Key takeaways

  • →Most SME clients will need DPDPA groundwork before May 2027, and many will ask their CA first.
  • →A DPDPA engagement is mostly structured process work: data mapping, notices, security, vendor contracts, breach and rights processes.
  • →CAs fit the process and controls side. Legal interpretation and contract drafting still need a lawyer.
  • →Your firm holds atleast client PAN, bank and payroll data, so get your own DPDPA house in order first.
  • →ICAI rules still restrict advertising and solicitation, so keep client communication factual.
Contents

A CA in Mysuru is filing GST for a diagnostic lab. Halfway through, the owner asks: "There's this new data law. Do we have to do something about it?"

That question is coming to a lot of CA offices. The DPDP Act's main obligations apply from May 2027, and there's no general exemption for small businesses. The lab, the training centre, the trading company with 2,000 customers on a WhatsApp list: they all have duties. And most of them don't have a compliance person. They have a CA.

This post covers what a DPDPA engagement involves, where CAs fit, how to scope it, and what to watch for under ICAI's rules.

Why will your SME clients ask you about DPDPA?

Because you're already the person they trust with compliance. GST, TDS, ROC filings, audits: you've spent years turning regulations into routines for them. DPDPA looks like more of the same, and in practice it mostly is.

The deadline is fixed. Most obligations under the DPDP Rules come into force in May 2027, 18 months after the Rules were notified. If your clients haven't started, the realistic window to get them ready is now. Our guide to what the DPDP Act needs from a business by May 2027 covers the full list, and it's written so you can share it with clients directly.

What does a DPDPA engagement for an SME involve?

Less law than people expect, and more process. A typical engagement looks like this:

Stage What you do What the client ends up with
Assess Walk through how the business collects and uses personal data A gap list ranked by risk
Map Record each processing activity: what data, why, where it's stored, who it's shared with A record of processing activities (RoPA)
Notices and consent Check notices against what's actually collected, and fix consent flows Notices that match reality
Security Review access, backups, log retention and encryption for sensitive data A short list of controls, with owners
Vendors List everyone who processes data for the client and check their contracts A vendor register with contract gaps marked
Breach and requests Set up who does what in a breach, and how access or erasure requests get answered A breach plan and a request process
Ongoing Review once a year, or when the business changes Records that stay current

If you've done internal audits or process documentation, most of this will feel familiar. It's controls work with a different subject.

Start with your own firm. A CA who asks a client for a data map should be able to show one for their own practice.

Where do CAs fit, and where do you need a lawyer?

Draw the line clearly with clients from day one. It protects them and it protects you.

CAs are a natural fit for:

  • Mapping data flows and maintaining the RoPA
  • Reviewing controls and setting up a compliance calendar
  • Building a vendor register and tracking which contracts need updating
  • Running the annual review

Bring in a lawyer for:

  • Grey-area questions, such as whether a particular use counts as a legitimate use under the Act
  • Drafting or negotiating contracts with data processors
  • Any complaint, notice or inquiry from the Data Protection Board

Many CA firms already work alongside a law firm on other matters. A standing arrangement for DPDPA questions makes the service complete without stretching your scope.

How should you scope and price the work?

Scope it by the size of the data footprint, not by the client's turnover. A small diagnostic lab can have more sensitive processing than a much larger trading firm. The things that drive effort are:

  • How many separate processing activities the client has (billing, HR, marketing, patient or student records, and so on)
  • How many systems and vendors hold personal data
  • Whether the client handles health data, financial data or children's data
  • Whether they act as a processor for their own customers

A structure that works well is a fixed fee for the initial setup, then an annual retainer for reviews, updates and handling the occasional request or incident. Fixed fees are easier for SMEs to approve, and the retainer keeps the records from going stale.

What should your firm sort out first?

Your own compliance. Your firm holds client PAN details, bank statements, payroll files and employee records. For your own staff and client contacts, you're a Data Fiduciary. When you process a client's payroll or customer data on their behalf, you're usually their Data Processor.

Before you advise anyone, check:

  • How client documents reach you. Email attachments and WhatsApp forwards are hard to secure and hard to delete.
  • Who in the firm can access which client files
  • Whether your engagement letters cover data processing
  • How long you keep client data after an engagement ends, and why

A firm that has done this for itself gives much better advice, and has a ready answer when a client asks "do you follow this yourselves?"

Can you tell clients about this new service?

Carefully. ICAI's code of ethics still restricts CAs from soliciting work and advertising their services, with allowances for neutral, factual websites and factual write-ups within the Council's guidelines. As of the latest commentary we've seen, that position hasn't changed.

In practice, that leaves plenty of room:

  • Answer clients who ask, which many will
  • Share factual guides, like this one, during existing engagements
  • Run an information session for existing clients on what the Act requires
  • List the service on your website in neutral, factual terms

Avoid mass promotional emails, testimonials and claims of being better than other firms. Check ICAI's current guidelines before you change how you communicate. This is a flag, not legal advice.

Where does DPDPOne fit?

DPDPOne does the structured groundwork, so your time goes on judgement and client conversations rather than building templates. Each client gets its own readiness assessment, RoPA, policies generated from its own records, and processes for breaches and rights requests.

Firms can manage several client organisations from one account. On the Professional Plus plan, everything runs under your firm's brand and domain, and you set your own fees. There's no revenue share. The partner programme page has the details, and current plans are on the pricing section.

See how CA firms run DPDPA engagements on DPDPOne, under their own brand.

The short version

Your SME clients will need DPDPA groundwork before May 2027, and many will come to you first. The work is process and controls, which CAs already do well. Get your own firm in order, draw a clear line where a lawyer is needed, and keep your client communication factual.

Frequently asked questions

Do CAs need a special licence or certification to advise on DPDPA?

The DPDP Act doesn't need or create a licence for DPDPA advisory work. Significant Data Fiduciaries must appoint an independent data auditor, which is a separate and more formal role. For most SME/MSME work, what matters is method and documentation.

Is my CA firm itself covered by the DPDP Act?

Yes. You hold personal data of clients, their employees and your own staff. For your own staff and client contacts you're a Data Fiduciary. When you process client payroll or customer data on a client's behalf, you're usually their Data Processor.

Can I deliver DPDPA work under my own firm's name?

Yes. You can run the engagement with your own templates, or use a platform that supports white-label delivery so reports, notices and dashboards carry your firm's branding.

When should I bring in a lawyer?

When a question needs legal interpretation, such as whether a use counts as a legitimate use, when a contract needs drafting, or when a client faces a complaint or a Board inquiry.

Sources

Last reviewed on 9 October 2026 by Mahadev Thukaram

Mahadev Thukaram
Mahadev Thukaram

Founder, DPDPOne

Founder of DPDPOne. 25+ years in information security and IT service management, now building DPDP Act compliance software for Indian businesses and the CAs and lawyers who advise them.

50+ years in information security and IT service management · Security operations and GRC: SIEM/SOAR, NIST CSF 2.0, ITIL 4 · Active in the DPDP Act practitioner community (FDPPI sessions, industry panels) · Author - Advanced Malware Analysis · CISM, CDPO, GDPR CEP, ISO27001 Lead Auditor, ISO22301 Lead Auditor, ITIL Expert, Auhorized trainer for Forcepoint DLP & Netskope

Ready to check your DPDP readiness?

This article is general information about the DPDP Act, not legal advice. Check with a qualified professional before acting on it.