Principle 9 is about the relationship with consumers: complaints, product recalls, cyber-security and data privacy, and product information. With the Digital Personal Data Protection Act 2023 now in force, its data-breach and privacy disclosures have moved from routine to closely watched.
Key takeaways
- 01Principle 9 covers consumer complaints, product recalls, cyber-security and data-privacy policy, and data breaches.
- 02It is split between customer service (complaints, recalls) and Legal or IT-security (privacy policy, breaches).
- 03The data-breach disclosure (P9-E7) is under growing scrutiny under the DPDP Act 2023.
- 04P9-E2 asks what share of turnover carries environmental, safe-usage and disposal information on the product.
What Principle 9 asks
| Disclosure | What it asks | ICAI page |
|---|---|---|
| P9-E1 | Mechanisms to receive and respond to consumer complaints and feedback | 150 |
| P9-E2 | Share of turnover carrying environmental, safe-usage and disposal information | 151 |
| P9-E3 | Consumer complaints by type: data privacy, advertising, cyber-security, quality | 151 |
| P9-E4 | Instances of product recalls on account of safety issues | 152 |
| P9-E5 | Whether a cyber-security and data-privacy policy exists, with a web link | 152 |
| P9-E7 | Data breaches: number, share involving personal information, and impact | 153 |
The Leadership indicators cover the channels where product information can be accessed (P9-L1), consumer education on safe usage (P9-L2), and any consumer-satisfaction survey (P9-L4).
Who owns the data
Principle 9 is split between Customer service and Legal/IT
How to answer the data-breach disclosure (P9-E7)
P9-E7 asks for three things: the number of data-breach instances in the year, the percentage that involved personally identifiable customer information, and the impact of those breaches. Draw it from the information-security incident register, and reconcile it with your breach-notification records. Under the Digital Personal Data Protection Act 2023 this disclosure is read closely, so a nil return should be one you can stand behind, not a default.
Best practice for Principle 9
- Build data-privacy controls for the Digital Personal Data Protection Act 2023 and comply with the Consumer Protection Act 2019, including transparent labelling.
- Operate a customer grievance-redressal system and disclose resolution rates.
- Certify information security to ISO/IEC 27001 and adopt privacy-by-design.
- Run a product-safety and stewardship management system and track customer-satisfaction metrics.
Map Principle 9 alongside the other eight
Try Saaksh free
BRSR gap analysis in under 60 seconds. No login, no data leaves your browser.
Stay ahead of the regulation
SEBI, BRSR, CBAM and CCTS moves that matter, plus the newest guides, in your inbox. No spam.



