If your business runs on Tally — like millions of Indian businesses — your DPDP compliance question is really a Tally question. The customer masters, sales vouchers, and payroll records inside it are exactly the "digital personal data" India's DPDP Act 2023 regulates. Here's what that means, in plain language.
Your Ledgers Are a Personal-Data Register
Open your ledger masters and look at what's there: customer names, billing and shipping addresses, phone numbers, emails, GSTINs. Your outstanding reports carry the contact details you use for payment follow-ups. If you use Tally's payroll module, add employee names, PAN, bank accounts, and salaries. All of it is personal data under Section 3 of the Act — and entering paper records into Tally is precisely the "digitisation" that brings offline data into scope.
That makes your business a Data Fiduciary: the party responsible for how that data is collected, used, protected, and eventually erased. There is no small-business exemption.
The Five Duties, Tally Edition
1. Notice and consent before the ledger entry
Creating a customer master means collecting personal data — which needs a plain-language notice and valid consent for the purposes you'll use it for (Sections 5–6; Rule 3 of the DPDP Rules 2025). Billing is one purpose; marketing is another, and needs its own opt-in. A QR code at the counter or a standard WhatsApp message covers the collection moment.
2. Data requests against your Tally records
Customers can ask what you hold on them, demand corrections, or request erasure (Sections 11–13). Your answer comes from Tally: the ledger, the vouchers, the reports. Publish how customers can ask and how fast you respond (Rule 14) — many businesses commit to 30 days — and log every request.
3. Your CA and your add-ons are processors
Whoever touches your Tally data on your behalf — your CA or accountant, Tally add-on (TDL) vendors, cloud backup and remote-access services — is a Data Processor, and Section 8(2) keeps the responsibility with you. Their contracts and engagement letters should say how customer data is handled.
4. A leaked ledger starts the breach clock
A Tally backup on a lost laptop, an exposed cloud sync, an ex-employee walking out with an export: each is a personal-data breach. The sequence is fixed by Rule 7: inform affected customers and the Data Protection Board without delay, and file the detailed report with the Board within 72 hours of becoming aware.
5. Records that prove all of it
Section 6 puts the burden of proving consent on you, and Rule 6 requires security logs kept at least a year. A disciplined business keeps consent records, request logs, and training records the way it keeps vouchers — because the Data Protection Board asks for evidence, not assurances.
GST Says Six Years, DPDP Says Delete — Both Are Right
The apparent clash between GST record-keeping (roughly six years for books and invoices) and DPDP's erasure duty resolves cleanly: Section 8(7) exempts data that another law requires you to retain, for as long as that law applies. So when a deletion request lands: the invoices stay, the marketing reuse stops, and you tell the customer which is which. This one distinction answers most Tally users' biggest DPDP worry.
Getting Compliant Without Leaving Tally
You don't need to migrate anything. The practical path: export your customer masters (Excel/CSV) and let EasyDP's Tally integration take over the compliance layer — consent notices to your whole ledger in six Indian languages, a request portal that answers against your records, re-noticing your existing base (Section 5(2)), and an audit trail your CA can verify. In early access, a direct sync through TallyPrime's built-in data gateway keeps it continuous — no manual exports.
Start where every business should: the free 2-minute checker for your specific obligations, then the 14-step interactive checklist — your Tally data map is Step 2.
References & Sources
- Ministry of Electronics & IT — The Digital Personal Data Protection Act, 2023 (Sections 3, 5, 6, 8(2), 8(7), 11–13).
- The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice), Rule 6 (security safeguards and logs), Rule 7 (breach intimation), Rule 14 (rights of Data Principals).
- Central Goods and Services Tax Act, 2017 — Section 36 (retention of accounts and records).
General information, not legal advice. Verify obligations against the notified texts for your specific business.