The DPDP Act is law. Your clean-up starts with today’s files.
What the law asks of every business that holds client documents, the exact dates, and which parts Reposha handles for you.
Already law. Full duties from 13 May 2027.
Your duty of confidentiality to clients, and the reasonable-security rules under the IT Act, already apply today. The Government has also consulted on bringing some deadlines forward for larger businesses, so dates can move earlier, not later.
The date is fixed. The work grows every week you wait.
The clean-up grows every week
Each document collected on WhatsApp or email is one more copy to find, secure or erase later, on every phone and inbox it reached. Starting now stops the pile growing.
Access history starts the day you start
The law asks you to know who opened which client’s files. A log cannot be written backwards. Start today and you will have months of records when the duties apply.
Risks do not wait for a date
A lost phone, a staff member who leaves, a mail sent to the wrong person. These happen this month, not in 2027. Your clients expect care today.
| Start with your next request | Wait until spring 2027 | |
|---|---|---|
| Old files to clean up | Only what you hold today | Today’s, plus every file from the months in between |
| Access history when duties apply | Months of records, ready | Starts from zero |
| Clients used to the upload link | Before your next busy season | Learning it in the rush |
| Team habits | Settled, without pressure | Changed against a deadline |
| Cost of switching | The same plan price | The same plan price, plus the backlog |
Is your business a Data Fiduciary? Most likely, yes.
You decide why you collect your clients’ PAN, Aadhaar, bank statements and Form 16, and how you use them. That makes your business a Data Fiduciary under the Digital Personal Data Protection Act, 2023. Size does not matter. A one-person practice is covered too.
Reposha is your Data Processor. We store and process documents on your instructions, under the safeguards described below.
Maximums from the Schedule to the Act. The Data Protection Board decides the amount case by case. A breach inquiry asks simple questions: who could open the files, who did, and why were they still there?
Seven duties, and who handles each one.
| The duty | What it means for you | Reposha handles | Still with you |
|---|---|---|---|
| Protect personal data Section 8(5), Rule 6 | Encrypt files and limit who can open them. | Encryption, India storage, roles, assigned Clients, emailed login codes | Device and email security in your office |
| Keep access logs for a year Rule 6(c), 6(e) | Know who opened which client’s documents, and review it. | Every view, download, upload and delete logged. 12 months in the app, then archived. Monthly report | Read the monthly report and act on anything odd |
| Report breaches Section 8(6), Rule 7 | Tell the Board and each affected client without delay. Details within 72 hours. | Log filters by date, client and team member to find who was affected | Your breach plan and the notices themselves |
| Erase when the purpose is served Section 8(7), Rule 8 | Do not keep client data forever. | Retention setting, reminders, one-click delete, purge after 7 days, backups cleared in 35 | Deciding how long each record must legally be kept |
| Respect client rights Sections 11 to 13 | Clients can ask what you hold, ask for erasure and complain. Reply within 90 days. | Deletion requests from the client’s own link, due-date tracking, recorded decisions | Your reply, and your grievance contact |
| Give notice of purpose Section 5, Rule 3 | Tell clients what you collect and why. | Purpose shown on every upload request, with a link to your privacy notice | Writing the privacy notice |
| Contract with your processor Rule 6(f) | Your software provider must follow the same safeguards. | Data processing terms in Reposha’s Terms of Use | Keeping a copy on file |
Ten steps. Reposha covers five of them on day one.
The highlighted steps are done the moment your client documents move into Reposha. The rest are short policy tasks for your business.
- Name a person in your business who owns data protection
- List the client documents you collect, and why
- Write a short privacy notice for clients
- Stop collecting ID and bank documents on WhatsApp and personal email Reposha
- Give each staff member their own login. No shared passwords Reposha
- Limit staff to the clients they work on Reposha
- Keep access logs for at least a year and review them monthly Reposha
- Set how long you keep client files, and erase on time Reposha
- Write a one-page breach plan: who decides, who tells the Board and clients
- Ask staff to delete client files from phones and laptops
The law is a good reason to switch. Your time is a better one.
Businesses stay with Reposha for what it does every day.
No more chasing
One link per request, with reminders until it is done.
Find any file in seconds
One folder per client. Search by name, PAN or tag.
Your team, accountable
Personal logins. Staff see only their clients.
Easy for clients
No app, no password. English and Hindi.
Reposha is software, not legal advice. It covers how client documents are collected, stored, accessed, logged and erased. Your lawful purpose, privacy notice and breach plan stay with your business. Check your own position with your legal adviser. Based on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025).
Our client help page explains their rights in English and Hindi. Ready-to-send messages are in For your clients.
