Your Tally ledgers are full of personal data. Here's what India's DPDP Act asks of every business running Tally — and how EasyDP makes it seamless.
Yes. The DPDP Act covers personal data in digital form — and even paper records once they're typed into software (Section 3). Every customer master you create in Tally is exactly that. If you maintain ledgers with customer names, phone numbers, addresses, or GSTINs, your business is a Data Fiduciary under the Act, whatever its size.
| No. | Record | Personal data held |
|---|---|---|
| 01 | Ledger / customer masters | Names, billing & shipping addresses, phone, email, GSTIN |
| 02 | Sales vouchers & invoices | Who bought what, when, for how much — per person |
| 03 | Outstanding & follow-up reports | Contact details used for payment reminders |
| 04 | Payroll module | Employee names, PAN, bank accounts, salaries — staff data counts too |
| 05 | Tally add-ons (TDL) | Third-party extensions that read your data are processors |
| 06 | Backups & sync services | Cloud backup and remote-access tools hold copies of it all |
Give notice and collect consent for ledger data
A plain-language notice and valid consent for each purpose (Sections 5–6, Rule 3). Billing and marketing are different purposes — a ledger contact is not a marketing list.
Answer customer data requests on your published timelines
Customers can ask what your ledgers hold, demand corrections, or request erasure (Sections 11–13). The Rules don't fix one deadline — you publish your response time and meet it (Rule 14). Many businesses commit to 30 days.
Put data-protection terms in processor contracts
Your CA, TDL add-on vendors, and backup services process customer data on your behalf — you stay responsible (Section 8(2)).
Report breaches on the legal clock
A leaked ledger means informing affected customers and the Data Protection Board without delay, with the detailed Board report within 72 hours (Rule 7).
Keep records that prove compliance
Security and access logs for at least one year (Rule 6); consent records for as long as you rely on them — the burden of proof is yours (Section 6).
Both — for different data. GST law requires you to keep your books and invoices for roughly six years; DPDP requires erasing personal data once its purpose ends (Section 8(7)). The Act resolves the clash itself: data another law requires you to keep is exempt from erasure for as long as that law applies. In practice: the invoice stays, but reusing that customer's ledger contact for marketing after they've withdrawn consent doesn't. When a customer asks for deletion, erase what no law requires, and tell them what stayed and under which law.
Yes. Ledger masters hold names, addresses, phone numbers, emails, and GSTINs — digital personal data under Section 3 of the DPDP Act. The moment a customer's details are entered in Tally, the Act's duties apply to your business, whatever its size.
Upload a ledger export, and EasyDP handles consent, requests, and records. Join early access free.