Talk to a Partner →
Legal

Data Protection Policy

This page is maintained by GSSK & Co. to describe how we protect the personal and confidential information entrusted to us.

Last updated: 2026

1. Purpose and scope

This Data Protection Policy sets out the principles and practices that GSSK & Co. follows to safeguard personal and confidential information against unauthorised access, misuse, disclosure, alteration, or loss. It applies to all partners, directors, employees, contractors, interns, and third-party service providers who handle personal or confidential information in the course of our business.

We are committed to handling personal information responsibly and in compliance with applicable laws, regulations, and professional standards, including those issued by the Institute of Chartered Accountants of India (ICAI).

2. Data protection principles

We process personal data in accordance with the following principles:

  • Lawfulness, fairness, and transparency: We process personal data lawfully, fairly, and in a transparent manner;
  • Purpose limitation: We collect personal data for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes;
  • Data minimisation: We limit the collection of personal data to what is adequate, relevant, and necessary;
  • Accuracy: We take reasonable steps to ensure that personal data is accurate and kept up to date;
  • Storage limitation: We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law; and
  • Integrity and confidentiality: We protect personal data using appropriate technical and organisational measures.

3. Lawful basis for processing

We process personal data only where we have a valid legal basis to do so, such as:

  • The consent of the data subject;
  • The performance of a contract or professional engagement;
  • Compliance with a legal or regulatory obligation;
  • Protection of vital interests; or
  • Legitimate interests pursued by our firm, where such interests are not overridden by the rights and freedoms of the data subject.

4. Security measures

We implement a range of technical and organisational security measures to protect personal and confidential information, including:

  • Access controls and user authentication mechanisms;
  • Encryption of data in transit and at rest, where appropriate;
  • Secure communication channels and email practices;
  • Regular data backups and disaster recovery arrangements;
  • Physical security measures at our office premises;
  • Up-to-date antivirus, firewall, and endpoint protection; and
  • Regular review and testing of our security controls.

We recognise that no security system is impenetrable, and we continually assess and improve our safeguards to address evolving risks.

5. Roles and responsibilities

All personnel who handle personal or confidential information are responsible for doing so in accordance with this policy and applicable law. Management is responsible for:

  • Overseeing compliance with this policy and applicable data protection laws;
  • Ensuring adequate resources are allocated to data protection;
  • Reviewing and approving this policy on a periodic basis; and
  • Addressing data protection concerns, complaints, and breaches promptly.

6. Data subject rights

We respect the rights of individuals whose personal data we process. Depending on applicable law, these rights may include:

  • The right to access personal data we hold about them;
  • The right to request correction of inaccurate or incomplete data;
  • The right to request erasure or restriction of processing;
  • The right to object to processing, including direct marketing;
  • The right to data portability, where applicable; and
  • The right to lodge a complaint with a supervisory authority.

We will respond to data subject requests in a timely manner and in accordance with applicable law.

7. Sharing and disclosure

We do not sell personal data. We may share personal or confidential information only where necessary and with appropriate safeguards, including:

  • Internally with personnel who have a legitimate need to know;
  • With trusted service providers under contractual confidentiality and security obligations;
  • With regulatory, tax, or law enforcement authorities where required by law; and
  • With the consent of the data subject or as otherwise permitted by law.

8. Data retention

We retain personal and client data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal, regulatory, and professional record-keeping obligations, and to defend or pursue legal claims. Retention periods are determined based on the nature of the information and applicable requirements.

9. Data breach response

In the event of a suspected or actual data breach, we will:

  • Investigate the incident promptly to determine its nature and scope;
  • Take immediate steps to contain the breach and mitigate harm;
  • Assess the risk to affected individuals and our operations;
  • Notify affected individuals and relevant authorities as required by law; and
  • Review and strengthen controls to prevent recurrence.

10. Training and awareness

We provide training and guidance to our personnel on data protection obligations and secure information handling practices. We promote a culture of confidentiality and accountability across the firm.

11. Policy review

This policy is reviewed regularly and updated as necessary to reflect changes in law, regulation, technology, business practices, and risk. The latest version is available to all personnel and is published on our Website.

12. Contact us

For data protection enquiries, requests, or concerns, please contact us at:

GSSK & Co.
E-595, 2nd Floor, Daani Plaza,
Near Ramphal Crossing, Dwarka,
Sector - 7, Block E, Palam Extension,
Palam, New Delhi, Delhi 110077