At a glance
A Company Secretary handles some of the most identity-dense data in the corporate system — director DIN (Director Identification Number), PAN and Aadhaar for Ministry of Corporate Affairs (MCA) filings, Significant Beneficial Owner (SBO) declarations, and the register of members. The DPDP Act applies on top of, not instead of, the Companies Act filing duties that already require collecting much of this — the gap isn’t usually whether the data can be collected, but how securely it’s stored and how long it’s kept once the filing is served.
Educational resource only. This explains how India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to Company Secretaries and CS practices; it is not formal legal advice.
The situation
A CS practice’s work is defined by statutory filings — incorporation, annual returns, SBO declarations, charge registrations — each of which requires collecting real personal data about directors, shareholders and beneficial owners. That data has always been handled as “compliance paperwork.” The DPDP Act asks the same practice to also treat it as personal data with its own separate duties, on top of the Companies Act obligations that made the collection necessary in the first place.
Does DPDP apply to a CS practice?
Yes — a solo practising Company Secretary or a larger secretarial firm is a Data Fiduciary the moment it decides why and how a client’s (or a client’s directors’ and shareholders’) personal data is used. There’s no exemption for a solo practice or a small firm; the same baseline duties — notice, a lawful basis, security, breach reporting, rights fulfilment — apply regardless of practice size.
The personal data a CS practice handles
- Director identity data — DIN, PAN, Aadhaar, address proof, collected for incorporation and ongoing MCA filings.
- Significant Beneficial Owner (SBO) data — for anyone holding 10% or more of a company’s shares or voting rights, directly or indirectly: name, father’s name, date of birth, nationality, PAN, passport number, address and email, declared via Form BEN-1 and filed by the company via Form BEN-2.
- Register of members — shareholder names and holdings, maintained as a statutory record under the Companies Act.
- Employee and payroll data, where the CS practice also handles a client’s broader secretarial and compliance function.
The obligation that actually bites: MCA filing duties as a DPDP basis
The Companies Act filing requirement is itself a lawful basis under the DPDP Act (Section 7, legal obligation) for collecting the data a specific filing needs — the gap isn’t usually the collection, it’s what happens after. Filing Form BEN-2, DIN applications or the annual return requires the underlying personal data; that statutory requirement is a recognised legal-obligation ground under the Act, so a CS practice doesn’t need to separately negotiate consent (Section 6) with a director or SBO purely to make a mandatory filing. Where the Act still bites is on everything the legal-obligation ground doesn’t cover: security of the data once collected, retention beyond what the filing needs, and any secondary use (marketing, a broader database of director contacts) that goes beyond the specific statutory purpose.
Common mistakes CS practices make
- Treating “it’s for an MCA filing” as a blanket licence — collecting more director/SBO detail than the specific form requires, or holding it indefinitely past the filing.
- PAN, Aadhaar and passport numbers sitting in shared spreadsheets with no access control, often maintained as a running master list across many clients.
- No written retention schedule for filing-related personal data once a company is wound up or the engagement ends.
- Digital signatures and MCA portal credentials shared over chat apps — a security gap distinct from the underlying personal-data question but often bundled with it.
- SBO declarations collected once and never refreshed, even as beneficial ownership changes.
Collecting director and shareholder data compliantly
A controlled intake channel for onboarding a new client’s director and shareholder data, plus a retention schedule tied to the engagement, covers most of the exposure. Route KYC and SBO documentation through one access-controlled channel rather than scattered email threads, limit access to the assigned team per client, and set a written retention period — informed by the Companies Act’s own record-keeping requirements alongside the DPDP Act’s purpose-and-erasure principle — for data held past an active engagement. The channel-and-consent mechanics are common ground across professional practices, detailed in the dedicated guide below.
What happens to director and SBO data when a company winds up
A struck-off or dissolved company stops filing, but the CS practice that handled its secretarial work doesn’t automatically stop owing a duty over the director and SBO data it collected during the engagement. Where a CS practice was engaged for a company that’s since been struck off (under Section 248 of the Companies Act) or formally wound up, the underlying MCA filings and statutory registers become historical records rather than active ones — but any copies the practice itself retained (director KYC, SBO declarations, register extracts) still carry the DPDP Act’s ordinary retention-and-purpose duty. The legal-obligation basis that justified collecting the data (an active filing requirement) no longer applies once the company is dissolved and no further filing is due; what typically remains is a narrower, time-bound reason to hold it — professional-liability risk if the CS’s own filings are later questioned, similar to the negligence-exposure logic law firms apply to closed matters. Once that narrower reason has also run its course, the practice should be deleting the former client’s director and SBO data, not retaining it indefinitely on the basis that the company once existed.
FAQ
Does a CS practice need to keep director and SBO data after a client company is struck off or dissolved?
Not indefinitely — the active filing basis ends with the company. A time-bound hold for professional-liability reasons is defensible, similar to how law firms treat closed-matter files, but it should have a defined endpoint, not become a permanent archive.
Is a solo Company Secretary in practice a Data Fiduciary under the DPDP Act?
Yes — deciding why and how client, director or shareholder data is used makes any CS practice a Data Fiduciary, regardless of size.
Does making an MCA filing require separate consent from directors or SBOs?
No — the statutory filing requirement is itself a recognised legal-obligation basis under the DPDP Act for the data that specific filing needs, without a separate consent negotiation for the filing itself.
What counts as a Significant Beneficial Owner under the DPDP Act?
Anyone holding, directly or indirectly, 10% or more of a company’s shares or voting rights — their personal data (name, DOB, nationality, PAN, passport, address) is collected via Form BEN-1 and filed by the company via Form BEN-2.
How long should a CS practice keep director and shareholder data after an engagement ends?
There’s no single DPDP-specific figure — set a written retention schedule that accounts for the Companies Act’s own record-keeping expectations, then delete what’s left over once neither the engagement nor a specific statutory requirement still needs it.