At a glanceProfessionals — chartered accountants, lawyers, brokers, consultants — collect sensitive client documents constantly, and the default channels (email, WhatsApp) are the weak link under India’s DPDP Act: no notice or consent at capture, sensitive documents scattered across inboxes, and no retention control. A secure intake — an access-controlled portal or upload that presents a notice and captures consent at the point of collection — closes those gaps. The shift that matters is treating document collection as a controlled step with consent, security and deletion built in, not a casual “just send it over.”
Educational resource only. This explains secure client document collection under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The situation
If you run a professional practice, client onboarding is document collection — PAN, Aadhaar, bank statements, agreements, financials. It usually happens over email or chat because that’s easy for the client. But those channels leave you holding a scattered, sensitive pile you’re accountable for, and they miss the notice-and-consent step the DPDP Act expects at collection. This is the single most concentrated data risk most practices carry.
Why “email me the documents” is the weak link
Email and chat move documents but skip every DPDP-specific safeguard — and then keep copies forever. When a client emails their documents, there’s no notice of purpose, no captured consent, no control over the channel, and no retention limit. Worse, each document now lives in multiple inboxes, sent folders, devices, and backups — a sprawl you can’t fully locate, let alone secure or delete. For a practice handling many clients’ identity and financial documents, that’s a large, standing exposure sitting in ordinary mailboxes.
Email vs a secure portal, compared
The difference isn’t just encryption — it’s whether notice, consent, control and deletion are built into the collection step.
| Email / chat | Secure intake (portal / controlled upload) | |
|---|---|---|
| Notice at collection | None | Presented before upload |
| Consent capture | None / assumed | Specific consent, recorded |
| Channel security | Weak; unencrypted, forwardable | Encrypted, access-controlled |
| Where copies live | Many inboxes, devices, backups | One controlled location |
| Retention control | None — lingers indefinitely | Set retention, deletable |
| Proof of what was agreed | Hard to reconstruct | Recorded at capture |
The point isn’t that email is banned — it’s that a controlled intake is built for the duties email leaves to chance.
What secure collection looks like at onboarding
A good intake makes the compliant path the easy path for the client. In practice, secure collection at onboarding means:
- The client is shown a clear notice — which documents, why, how long you’ll keep them — and gives specific consent, recorded, before uploading.
- Documents are requested to the minimum (only what the engagement needs) and masked where possible (e.g. masked Aadhaar).
- Uploads go into an encrypted, access-controlled location, not a mailbox — with access limited to who needs it.
- Retention is set — you keep documents only as long as the engagement (or a specific legal duty) requires, then delete them.
- You hold a record of the notice shown and consent given.
Building it into your practice
Make the secure route the default for every new client — not an exception for sensitive cases. A few moves get most of the benefit: give clients one consistent, controlled way to send documents instead of ad-hoc email; write the notice-and-consent step into your onboarding so it happens every time; minimise and mask what you request; and set a retention schedule so documents don’t accumulate past their purpose. Being able to show clients you handle their documents this way is increasingly a mark of a serious practice, not just a compliance nicety.
FAQ
Is it against the DPDP Act to collect client documents by email?
Email isn’t banned, but it misses notice, consent, channel security, and retention control — and scatters copies you stay accountable for. A controlled intake is a much better fit for sensitive documents.
What makes a document-collection method “secure” under DPDP?
Notice and specific consent at collection, an encrypted access-controlled channel and store, minimisation (and masking) of what’s collected, set retention, and a record of the consent.
Do I need an expensive system to do this?
Not necessarily — the essentials are one controlled channel, a notice-and-consent step, limited access, and a retention habit. The aim is fewer copies in fewer places, collected with consent.
How long should a practice keep client documents?
Only as long as the engagement or a specific legal or regulatory duty requires, then delete them — including stray copies.