Chartered accountants: how to protect client ITR, PAN and Aadhaar files on your laptop
A CA's laptop is a vault of other people's lives: ITR acknowledgements, Form 16s, PAN and Aadhaar copies, bank statements, GST returns, balance sheets. Clients trust you to keep them confidential, and from May 2027 India's data-protection rules expect you to secure them properly. Here's how to do that on an ordinary office PC or laptop, without changing how you work.
Why this matters for a CA practice
- Professional duty: confidentiality is one of the fundamental principles of the ICAI Code of Ethics. Client information must not be disclosed without proper and specific authority.
- The DPDP Act, 2023: a practice that processes clients' digital personal data is a data fiduciary. Rule 6 of the DPDP Rules, 2025 (notified 13 November 2025) lists security measures including "encryption, obfuscation, masking or the use of virtual tokens", access controls, access logs, and backups. Rule 6 takes effect 18 months after notification, around 13 May 2027.
- Penalties: failing to take reasonable security safeguards can attract a penalty of up to ₹250 crore under the Act's Schedule, after an inquiry by the Data Protection Board.
- Everyday risks: a stolen laptop, an article clerk's pen drive, a shared office PC, a repair shop, or a phishing attack.
Set it up in 15 minutes
- Download Clavis Encrypt and install it (Windows 10 or 11; no administrator rights or internet needed).
- Create a vault with a strong password, and store the one-time recovery key somewhere safe, for example printed and kept in the office safe.
- Encrypt existing client folders. With Clavis Pro, right-click a folder → Clavis → Encrypt to do the whole folder at once. Clavis Free encrypts files one at a time.
- Make a dedicated folder for client downloads (ITR-V, Form 26AS, AIS, GST returns), save portal downloads there, and add it as a watch folder (Pro). Every new file is encrypted automatically once it finishes saving.
- Open a file when you need it: double-click the
.encfile. With Pro's Open, you edit it in Excel or Word and it's re-locked when you're done; the temporary working copy is cleaned up. - Use separate vaults (Pro) for different partners or client groups, each with its own password.
Good practice for the whole office
- Never email unprotected PAN or Aadhaar copies. See how to encrypt files before emailing.
- Use masked Aadhaar (only the last four digits visible) whenever the full number isn't needed.
- Encrypt before the cloud. If you keep client files in Google Drive or OneDrive, store only encrypted copies there (Clavis Premium can encrypt files straight into your cloud folder). See encrypting before the cloud.
- Keep backups encrypted too, and delete files you no longer need to keep.
- Turn on full-disk encryption (BitLocker or Device encryption) as a second layer for lost laptops.
Options compared
| Method | Protects a stolen laptop | Protects files sent or copied | Works offline | Cost |
|---|---|---|---|---|
| Windows password only | No | No | Yes | Free |
| BitLocker / Device encryption | Yes (when off) | No | Yes | Free (edition-dependent) |
| Password-protected ZIP / 7-Zip | Yes | Yes | Yes | Free, but manual for every file |
| Clavis Encrypt | Yes | Yes | Yes | Free for files; Pro is a one-time $19 for folders and automation |
Many practices use two layers: full-disk encryption for the laptop, plus file encryption for client documents, so they stay protected when copied, emailed or backed up.
Questions
How should a chartered accountant store client PAN and Aadhaar copies?
Keep them encrypted on your PC rather than in ordinary folders, use masked Aadhaar where the full number isn't needed, never send unprotected copies by email or WhatsApp, and delete copies you no longer need. A file-encryption app such as Clavis Encrypt seals each file with AES-256-GCM and works offline.
Does the DPDP Act apply to a CA firm?
Yes, if the firm processes clients' digital personal data, it acts as a data fiduciary under the DPDP Act, 2023. Rule 6 of the DPDP Rules, 2025 sets minimum security safeguards, including encryption, access controls, logs and backups; it takes effect around 13 May 2027.
Is encryption mandatory under the DPDP Rules?
Rule 6 lists "encryption, obfuscation, masking or the use of virtual tokens" as ways to secure personal data, so encryption is one of the named options rather than the only one. For files on laptops and PCs, encryption is the most practical of them.
Will encrypted files still open in Excel, Word or a PDF reader?
Yes. Open the encrypted file in Clavis and it opens in its usual program. With Clavis Pro's Open, your changes are saved back into the encrypted file when you're done and the temporary working copy is cleaned up.
Do client files leave my computer with Clavis Encrypt?
No. Encryption happens on your PC. There's no account or cloud service, and the app goes online only to download signed updates.
Sources
- DPDP Rules, 2025 — Rule 6, reasonable security safeguards (text)
- Exchange4media — DPDP penalties can reach ₹250 crore
- ICAI Code of Ethics — fundamental principles including confidentiality (WIRC material)
- Clavis Encrypt — security design
This guide explains general practice, not legal advice. Laws and rules change; check the current text or ask a lawyer for your situation.