DPDP Rules, 2025 are now in effect. See where your business stands, in 3–5 minutes.Find out — free →
Where your data travels · CA Firms

One client. Many systems. One firm's responsibility.

Follow a single client's documents as they move through email, WhatsApp, Tally, cloud drives, tax software, government portals and a decade of archives - and count every place they end up, and where you lose control of them.

10 stages
  1. 1

    Client onboarding & engagement control breaks

    +7 places · 7 so far

    A new client is signed. Basic identity, contact and engagement details are captured - often over email or WhatsApp before any secure system exists.

    Where control breaks: PAN, Aadhaar and bank statements arrive over WhatsApp · Client files on personal laptops · Shared drive access that outlives the staff

    Moving hereIdentity data (new at this stage)Contact data (new at this stage)Bank & financial statements (new at this stage)

    DPDPATell the client what you collect and why, at or before collection, and record the engagement's purpose.

  2. 2

    KYC collection

    +2 places · 9 so far

    PAN, Aadhaar, and for companies the MCA and board documents are collected to establish identity for filings and portal access.

    Moving hereCorporate & MCA records (new at this stage)Identity dataBank & financial statements

    DPDPACollect only the identity documents the filing actually needs; Aadhaar is high-impact and often over-collected.

  3. 3

    Document collection control breaks

    +1 place · 10 so far

    Bank statements, Form 16, salary sheets, invoices and investment proofs arrive - by email, WhatsApp, a shared drive or a portal - and copies scatter immediately.

    Where control breaks: Outsourced data entry with no written contract

    Moving hereTax documents (new at this stage)Investment & loan documents (new at this stage)Medical & insurance data (new at this stage)Identity dataBank & financial statements

    DPDPAPrefer one controlled intake channel; every extra copy is a place a deletion request must later reach.

  4. 4

    Accounting & bookkeeping

    +2 places · 12 so far

    Transactions are entered into Tally or Busy. For business clients this pulls in employee payroll - salary, bank and PF data for people who are not your clients.

    Moving herePayroll & salary data (new at this stage)GST & indirect-tax data (new at this stage)Bank & financial statements

    DPDPAPayroll data belongs to the client's employees; you are handling it on the client's instructions, so agree the terms in writing.

  5. 5

    Tax preparation & computation

    +2 places · 14 so far

    Returns and computations are prepared in Winman or ClearTax. Working papers, drafts and the computed tax position are created and copied to laptops.

    Moving hereComputed tax position· inferred (new at this stage)Identity dataBank & financial statementsTax documentsGST & indirect-tax data

    DPDPAThe computed position is derived personal data about the client - protect it like the source documents.

  6. 6

    GST / TDS compliance control breaks

    +3 places · 17 so far

    GST returns and TDS statements are prepared and uploaded to the GST portal and TRACES, using credentials the firm holds on the client's behalf.

    Where control breaks: Client portal passwords in a shared sheet

    Moving herePortal credentials (new at this stage)Identity dataPayroll & salary dataGST & indirect-tax data

    DPDPAPortal credentials held for a client are a serious custody responsibility - store them like the data they unlock.

  7. 7

    ITR filing control breaks

    +2 places · 19 so far

    Returns are filed on the Income Tax portal, e-verified with the client's DSC or OTP. The firm often holds the DSC token physically.

    Where control breaks: The firm holds the client's digital signature

    Moving hereDigital Signature Certificate (new at this stage)Identity dataTax documentsPortal credentialsComputed tax position· inferred

    DPDPAA DSC is signing authority, not just data - holding it means you can act legally as the client, so control it tightly.

  8. 8

    Client review & sign-off

    +2 places · 21 so far

    Drafts and filed returns are sent back to the client for confirmation - usually as email or WhatsApp attachments, creating another copy outside the firm.

    Moving hereBank & financial statementsTax documentsComputed tax position· inferred

    DPDPAShare the minimum needed for sign-off, over a channel you can later account for.

  9. 9

    Government submission

    Filings reach the Income Tax department, GSTN and MCA. Documents may also go to banks or statutory auditors who receive them without a processing contract.

    Moving hereBank & financial statementsPayroll & salary dataCorporate & MCA records

    DPDPAStatutory disclosures are lawful, but a bank or auditor receiving data without a contract needs minimisation and a protected channel.

  10. 10

    Archive, retention & deletion control breaks

    +1 place · 22 so far

    Everything is retained - and then kept. A decade of ITRs, Form 16s and bank statements accumulates in folders and inboxes that are never cleared, and next year the cycle starts again.

    Where control breaks: A decade of client folders, never deleted

    Moving hereIdentity dataBank & financial statementsTax documentsPayroll & salary data

    DPDPAKeep records only as long as the law or the engagement needs; set a deletion schedule, because the default here is 'forever'.

In this reference model, one client's data ends up in 22 distinct places across 10 stages, with 7 places where control breaks.

Top risk hotspots - where control usually breaks

The seven places recruitment agencies most often lose track of candidate data. Each links to the matching check in the readiness assessment.

  1. Hotspot 1 Critical risk

    Clients' DSC USB tokens and PINs are kept at the firm so returns can be e-signed and filed without chasing the client each time.

    Why this matters

    A DSC is signing authority, not just a document - whoever holds the token and PIN can legally sign and file as the client, so its custody deserves the same care as the signature itself.

    Fix: Keep tokens in named custody with a signing log, store the PIN separately, and return or destroy tokens when the engagement ends.

    Check this in the assessment
  2. Hotspot 2 Critical risk

    Income Tax, GST and TRACES logins for hundreds of clients sit in one spreadsheet so any staff member can file for anyone.

    Why this matters

    A single file unlocks government portals for every client at once; if it leaks, so does the ability to log in as each of them.

    Fix: Move credentials into a proper password manager with per-user access and logging, and stop keeping portal logins in a shared file.

    Check this in the assessment
  3. Hotspot 3 High risk

    Clients send their most sensitive documents to staff personal phones, where they auto-download and back up to personal cloud accounts.

    Why this matters

    The firm cannot find, protect or delete these copies - an erasure request cannot reach a staff member's personal phone backup.

    Fix: Move document intake to a secure portal or an official channel, and stop accepting IDs and statements over personal chat.

    Check this in the assessment
  4. Hotspot 4 High risk

    Documents are downloaded onto unmanaged laptops to work on, and simply stay there after the return is filed.

    Why this matters

    There is no wipe when an article assistant leaves and no record of what they took - the firm's most sensitive data walks out with the device.

    Fix: Work from managed devices or the drive, disable local downloads where you can, and collect or wipe devices on exit.

    Check this in the assessment
  5. Hotspot 5 High risk

    A single drive holds every client's documents, and access granted to article assistants and staff is rarely reviewed when they leave.

    Why this matters

    Ex-staff and old trainees can retain access to every client's financial documents long after they have gone.

    Fix: Review and revoke drive access quarterly, remove leavers immediately, and scope folders so access can be limited per client.

    Check this in the assessment
  6. Hotspot 6 High risk

    ITRs, Form 16s and bank statements are kept year on year, in drives, folders and inboxes, with no deletion schedule.

    Why this matters

    The firm does not have a deletion problem, it has an accumulation one - ten years of the most sensitive documents multiplies the damage of any breach.

    Fix: Set a retention schedule tied to the statutory period and securely delete client data once the engagement and the law no longer require it.

    Check this in the assessment
  7. Hotspot 7 High risk

    Bulk data entry and document processing is handed to a freelancer or agency, often on trust with nothing in writing.

    Why this matters

    A processor handling client financial documents without a contract leaves the firm liable, with no agreed controls, deletion duties or breach obligations.

    Fix: Put a data-processing agreement in place before sharing anything, and limit the vendor's access to only what the task needs.

    Check this in the assessment

How to read this journey

The places add up

Each stage shows the new places the data reaches - inboxes, WhatsApp, Tally, drives, laptops, portals, backups. Every place is counted once, so the running counter always matches the systems listed above it.

When it leaves you

A violet left edge and a tag mark systems outside your firm - the client business, cloud vendors, government portals, banks and auditors. Once data lands there your control is indirect: it runs through your contract and instructions, not your admin panel. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and an in-house one high risk.

Where control breaks

Red flags mark the hotspots - the places CA firms most often lose control of client data, from the DSC token to a decade of undeleted folders. Tap any system to see what it holds and how to fix it.

Now check whether your controls hold up

The map shows where client data travels in a typical firm. The 3-minute readiness scan checks whether your firm has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.

Educational reference model - not legal advice, and not a scan of your actual systems.