DPDP Policy Document

Digital Personal Data Protection Policy

Mahadevan & Hari Chartered Accountants

This Policy is issued in accordance with the provisions of the Digital Personal Data Protection Act, 2023 (“DPDP Act”). The Firm is committed to protecting the privacy of personal data entrusted to it and to processing such data in a lawful, fair, and responsible manner.

Scope
This Policy applies to all personal data collected, stored, processed, or otherwise handled by the Firm in the course of providing professional services, whether in digital form or in physical form that is subsequently digitised.

Personal Data
The Firm may collect and process personal data including identity details, contact information, statutory identifiers, financial information, and documents furnished in connection with professional engagements. Personal data is collected only to the extent necessary for lawful and specified purposes.

Purpose of Processing
Personal data is processed solely for rendering professional services, complying with statutory and regulatory requirements, maintaining professional records, and fulfilling contractual and legal obligations.

Consent and Legitimate Use
Personal data is processed based on valid consent where required under law. In certain circumstances, personal data may be processed without explicit consent where such processing is permitted under the DPDP Act for legitimate uses.

Data Security
The Firm implements reasonable technical and organisational safeguards to protect personal data against unauthorised access, disclosure, alteration, loss, or misuse.

Data Sharing
Personal data is not shared with third parties except where required under applicable law or with the consent of the Data Principal, and only with authorised service providers engaged for professional purposes and bound by confidentiality obligations

Rights of Data Principals
Data Principals have the right to access, correct, or request deletion of their personal data and to raise grievances relating to data processing, in accordance with the DPDP Act.

Data Retention
Personal data is retained only for such period as is necessary to fulfil the purpose for which it was collected or as required under applicable laws and professional standards.

Policy Updates
This Policy may be updated from time to time to reflect changes in law or internal practices. The updated Policy shall be made available on the Firm’s website.

 
     
57897 Times Visited