DPDP Policy Document
Digital Personal Data Protection Policy
Mahadevan & Hari Chartered Accountants
This Policy is issued in accordance with the provisions of the Digital Personal Data Protection
Act, 2023 (“DPDP Act”). The Firm is committed to protecting the privacy of personal data
entrusted to it and to processing such data in a lawful, fair, and responsible manner.
Scope
This Policy applies to all personal data collected, stored, processed, or otherwise handled by the
Firm in the course of providing professional services, whether in digital form or in physical
form that is subsequently digitised.
Personal Data
The Firm may collect and process personal data including identity details, contact information,
statutory identifiers, financial information, and documents furnished in connection with
professional engagements. Personal data is collected only to the extent necessary for lawful and
specified purposes.
Purpose of Processing
Personal data is processed solely for rendering professional services, complying with statutory
and regulatory requirements, maintaining professional records, and fulfilling contractual and
legal obligations.
Consent and Legitimate Use
Personal data is processed based on valid consent where required under law. In certain
circumstances, personal data may be processed without explicit consent where such processing
is permitted under the DPDP Act for legitimate uses.
Data Security
The Firm implements reasonable technical and organisational safeguards to protect personal
data against unauthorised access, disclosure, alteration, loss, or misuse.
Data Sharing
Personal data is not shared with third parties except where required under applicable law or
with the consent of the Data Principal, and only with authorised service providers engaged for
professional purposes and bound by confidentiality obligations
Rights of Data Principals
Data Principals have the right to access, correct, or request deletion of their personal data and to
raise grievances relating to data processing, in accordance with the DPDP Act.
Data Retention
Personal data is retained only for such period as is necessary to fulfil the purpose for which it
was collected or as required under applicable laws and professional standards.
Policy Updates
This Policy may be updated from time to time to reflect changes in law or internal practices.
The updated Policy shall be made available on the Firm’s website.