CA Firms and Client Data: Hosting Obligations Under DPDP and ICAI Guidance

A 2026 control checklist for CA firms moving confidential client records, working papers, Tally or practice systems to hosted infrastructure.

Last reviewed: 5 August 2026. CA firms routinely hold tax records, bank statements, payroll data, audit working papers, identity documents and confidential commercial information. Moving those files or accounting applications to a hosted server changes the control environment; it does not transfer professional responsibility to the hosting company.

Practical position: ICAI confidentiality and due-care duties, DPDP responsibilities and client contracts must be translated into one hosting control set: approved purpose, named users, documented provider roles, secure storage and transfer, tested recovery, incident escalation and defensible deletion.

This supporting article applies the procurement framework in DPDP-Ready Hosting to professional accounting practices. It is operational information, not legal or professional-conduct advice.

What ICAI’s current Code of Ethics requires

ICAI announced that the revised Code of Ethics, 13th edition applies from 1 April 2026, subject to the exception stated in the announcement. In Volume II, subsection 114 requires chartered accountants to respect confidentiality and take reasonable steps to ensure that personnel and people providing advice or assistance also comply.

The Code expressly connects confidentiality with the collection, use, transfer, storage or retention, dissemination and lawful destruction of information. That wording makes hosting governance directly relevant. A firm cannot focus only on whether an employee intentionally emailed a file; it must also consider cloud administrators, backups, remote sessions, residual copies and disposal.

The Code does not turn a particular cloud brand, certification or country into an automatic safe harbour. The professional question is whether the firm has identified the risks and taken proportionate, documented action to protect client information throughout its lifecycle.

ICAI cloud guidance points to shared responsibility and vendor review

ICAI’s publication list includes the Guide to Cloud Computing for Accountants. The guide discusses confidentiality risks in cloud environments and identifies controls such as encryption, access management, backup review, incident procedures, service-level terms, administrator access and review of provider assurance reports.

The guide’s audit-oriented checklists are useful for procurement even when the firm is buying a simple VPS. They encourage the user organisation to examine who has access, whether sensitive data is encrypted, how terminated users are removed, whether incidents are handled through defined procedures and what the service agreement says about protection and termination.

ICAI principle or guide themeHosting implicationEvidence to retain
ConfidentialityPrevent unauthorised access during storage, transfer, support and disposalAccess matrix, encryption design, approved sharing method
Professional competence and due careSelect and supervise technology appropriate to the engagementRisk assessment, provider review, staff training and periodic control review
Personnel and third partiesExtend confidentiality controls to staff, contractors and advisersNamed accounts, NDAs/contract terms, onboarding and offboarding records
Cloud-provider assuranceDo not rely solely on sales claimsCurrent audit/certification scope, SLA, architecture and remediation records
Continuity and backupEnsure client work can be recovered without uncontrolled duplicationBackup schedule, restore test, RPO/RTO and expiry rules
TerminationProtect and remove data when a service or engagement endsExport, revocation, deletion and backup-expiry confirmation

How DPDP roles can arise in a CA practice

The DPDP Act applies to digital personal data within its scope. A CA firm may determine purposes and means for its own employee, prospect, billing, compliance and practice-management records. For client data, the role can depend on the engagement and the processing purpose; the firm should not assume one label covers audit, tax, payroll, outsourced accounting and advisory work identically.

The notified DPDP Rules, 2025 use a phased implementation model. Preparation should include data inventories, notices or engagement disclosures where applicable, processor terms, reasonable security safeguards, breach workflows and support for data-principal requests. A server order is only one component.

Where a hosting provider processes application data for the firm, the contract should state the instructions, permitted locations, subprocessors, access restrictions, security measures, incident notification, assistance, deletion and audit evidence. The provider may separately act for its own billing, identity-verification, security and abuse-management records; those activities need their own privacy explanation.

Classify client data before choosing the hosting design

Data setTypical sensitivityHosting control priority
Income-tax and GST recordsIdentity, financial and transaction informationStrict user segregation, encryption, secure sharing and retention schedule
Payroll and HR recordsEmployee identifiers, salary and bank detailsRole-based access, limited exports and prompt offboarding
Audit working papersConfidential evidence and professional judgmentsEngagement-level separation, version control and protected archives
Bank statements and payment filesFinancial account and transaction dataSecure transfer, restricted download and monitored administration
Corporate transaction or due-diligence filesHighly confidential commercial informationDedicated workspace, named access, watermarking where useful and short retention
Client credentials and portal tokensAuthentication secrets with high misuse impactPassword vault, MFA, no plaintext ticket sharing and rotation at exit

A small firm does not need an elaborate classification taxonomy to begin. Public, internal, confidential and highly confidential can be enough, provided each level drives concrete storage, sharing, access and deletion rules.

Hosting controls a CA firm should require

Identity and privileged access

  • Give every employee and contractor a named account; prohibit shared administrator logins.
  • Use MFA for email, cloud consoles, VPN, RDP, control panels and backup portals.
  • Separate ordinary work accounts from administrative accounts.
  • Approve vendor access per ticket and remove standing access when it is not necessary.
  • Review users and permissions at least when staff, clients or engagements change.

Encryption and secure movement

  • Protect data in transit with modern encrypted protocols and avoid unmanaged file-sharing links.
  • Encrypt server volumes and backups where supported, and document who controls recovery keys.
  • Sanitise or minimise diagnostic files before uploading them to support systems.
  • Use secure portals or controlled workspaces instead of sending bulk client records as ordinary email attachments.

Backup, retention and lawful destruction

  • Define retention by engagement, law, professional requirement and client contract rather than keeping every copy indefinitely.
  • Keep recovery copies logically or physically separated from production credentials.
  • Test restoration and record the result.
  • Document how deleted files age out of snapshots and backups.
  • Remove local downloads and temporary migration copies after approved validation.

CERT-In and incident readiness are separate operational layers

The CERT-In Directions of 28 April 2022 impose cyber-operational requirements on covered entities, including time synchronisation, specified incident reporting and ICT logging. CERT-In’s FAQ explains that the definition of body corporate includes companies, firms, sole proprietorships and other associations engaged in commercial or professional activities. A CA practice should obtain advice on the provisions applicable to its entity and systems rather than assuming professional firms are outside the framework.

The hosting provider must not become a six-hour bottleneck. The firm should have a 24/7 incident contact, know what evidence the provider can supply, preserve logs, identify affected clients and data, and coordinate legal, professional and contractual notices. A generic promise to “notify promptly” is not enough.

A 15-point procurement checklist for CA firms

  1. Identify the contracting, billing, network, facility and backup entities.
  2. Define whether the provider acts on the firm’s instructions for hosted client data.
  3. List every production, backup, log, monitoring and support location.
  4. Confirm whether offshore administrators or subprocessors can access client information.
  5. Require named accounts, MFA, least privilege and privileged-session controls.
  6. Define encryption in transit, at rest and for backup, including key ownership.
  7. Allocate patching responsibility for host, guest OS, applications and security agents.
  8. Set backup frequency, retention, immutability or separation, and restore testing.
  9. Require actionable incident notification with system, time, data and containment facts.
  10. Confirm log availability, time synchronisation and export speed.
  11. Include client-data export, deletion, snapshot expiry and credential revocation at termination.
  12. Review current provider assurance evidence and its exact scope.
  13. Align the arrangement with engagement letters and client-specific security clauses.
  14. Train staff on approved remote access, downloads, sharing and support escalation.
  15. Review the hosting risk assessment when services, regions or material client requirements change.

Firms hosting Tally should also use Where Is Your Tally Data Actually Stored?. For the difference between primary server location and the full data path, see Advika’s Data Residency in India guide.

Frequently asked questions

Does ICAI require every CA firm to host client data only in India?

The cited ICAI Code and cloud guide emphasise confidentiality, due care and cloud-risk controls; they do not create a blanket India-only rule for every client file. Other law, engagement terms or sector rules may be stricter.

Can a CA firm treat its hosting provider as solely responsible for client-data security?

No. The provider operates parts of the infrastructure, but the firm remains responsible for selecting the service, configuring access, supervising staff, defining retention and responding to client and legal obligations.

The answer depends on the engagement, purpose, applicable law and contract. Firms should disclose material processing arrangements where required and obtain appropriate authorisation rather than assuming a generic engagement letter covers every subprocessor.

What should a CA firm ask about backups?

Ask where backups are stored, how they are encrypted, who can restore them, how often restoration is tested, how long deleted client data remains and what happens at contract termination.

Which accounts should have administrator access?

Use named, least-privilege accounts limited to trained personnel. Shared credentials and permanent vendor access make supervision, investigation and revocation difficult.

Bottom line

For a CA firm, good hosting governance is the practical expression of confidentiality and due care. The firm should be able to show what client data it holds, why it is processed, where every relevant copy exists, who can access it, how it is protected and recovered, and how incidents and termination are handled. A provider can supply strong infrastructure; the professional practice must turn it into a controlled operating environment.