Home / Sectors / BFSI
BFSI · Banks, NBFCs, insurers, brokers

DPDP for BFSI

Every bank, NBFC, insurer and broker in India already lives inside a thick sectoral rulebook. DPDP does not replace any of it. DPDP adds a new India-specific data protection layer on top. Where the two collide, DPDP wins on personal data unless another Indian law demands retention.

Verified 8 Sep 2026 DPDP Act + RBI Master Directions 8 min read Rs. 250 cr cap separate from RBI action

01You already answer to RBI, SEBI or IRDAI. DPDP does not replace any of it.

DPDP is a horizontal statute. RBI, SEBI and IRDAI are vertical regulators. Where they overlap, both apply. Two rules of thumb keep you out of trouble.

First, use the Section 8(7) exception. DPDP says personal data must be erased when the purpose ends or consent is withdrawn. But it makes an exception for retention required by any Indian law. Your existing RBI KYC retention, PMLA record-keeping, SEBI intermediary records and IRDAI policyholder records all sit inside that exception. The lawyer's job is to write the retention schedule that names each sectoral basis; the operator's job is not to erase anything that basis still covers.

Second, where DPDP and a sectoral rule prescribe conflicting security or notification standards, follow the stricter one. The Board is not going to fault you for exceeding a DPDP minimum. Sector regulators can, and will, fault you for falling below theirs.

Sec. 8(7) DPDP Act. Sectoral: RBI Master Direction on KYC, PMLA 2002, SEBI (Intermediaries) Regulations, IRDAI Information and Cyber Security Guidelines.

02The one tension you actually have to write down: KYC retention vs erasure

RBI requires customer records to be retained for 5 to 8 years after account closure. DPDP Sec. 8(7) requires erasure when purpose is exhausted. Both are true at the same time.

Resolution: retain for the sectoral floor, then erase. The RBI Master Direction on KYC (2016, as amended) sets a five-year floor after the end of the business relationship. PMLA 2002 requires records for at least five years after the transaction. Companies Act 2013 keeps records for eight years. Whichever applies to you, that is your Sec. 8(7) safe harbour.

Practical: publish a retention schedule that lists each personal data category, the sectoral basis for retention, and the erasure trigger. Data Principals can ask for this under Rule 3 read with Rule 14.

RBI Master Direction on Know Your Customer (KYC), 2016. PMLA 2002. Companies Act 2013 Sec. 128. DPDP Sec. 8(7).

03Localisation you were already doing

RBI

Payment system data

RBI circular dated 6 April 2018. All payment system data must be stored only in India. Copies abroad permitted for foreign-leg processing, must return within 24 hours.

SEBI CSCRF

Trading and settlement data

SEBI Cybersecurity and Cyber Resilience Framework. Primary and DR servers for regulated entities must be located in India.

IRDAI

Insurance policyholder data

IRDAI Information and Cyber Security Guidelines. Critical policyholder data must be stored on servers located in India.

Rule 12(4)

Coming: DPDP SDF layer

If designated a Significant Data Fiduciary, the Central Government may notify additional data categories that must stay in India. Financial identifiers are the most-flagged candidate.

04Rule 6 security safeguards, BFSI-tuned

Rule 6 sets the DPDP baseline: encryption or tokenisation, access controls, one-year log retention, backups, processor contracts, and technical or organisational measures. Your sectoral baseline is already higher on most of these.

  1. Encryption

    RBI IT Framework already requires encryption at rest and in transit for core banking data. Extend the same policy to all personal data covered by Sec. 8(5). Do not treat marketing databases differently from KYC databases.

  2. Access controls

    You already run role-based access. Add a Sec. 8(4) processor-side control: every third-party access to personal data must be traceable to a Data Fiduciary approval and to a specific purpose.

  3. Log retention

    RBI requires 8 to 10 year retention for various log categories. Rule 6's one-year floor is easily met. Confirm your log store carries user-identifiable access events, not just infrastructure logs.

  4. Breach notification

    You now file to CERT-In (6 hours per 28 April 2022 Directions), to the Data Protection Board (Rule 7, without delay, comprehensive report in 72 hours), to RBI (immediate cyber incident reporting per RBI IT Framework), and potentially to SEBI or IRDAI depending on entity type. Design a single incident-response playbook that fires all four.

05The SDF designation likelihood

Large private-sector banks, consumer credit information companies, and large payment aggregators are the BFSI entities most likely to be designated Significant Data Fiduciaries first.

Section 10's six-factor test weighs volume and sensitivity of personal data, risk to Data Principals' rights, sovereignty impact, electoral democracy, State security, and public order. Large BFSI entities score high on multiple factors. Consumer credit information companies (CIBIL, Experian, Equifax, CRIF) process financial identifiers for hundreds of millions of Indians and would be an obvious first class.

Once designated, prepare: India-resident DPO, annual DPIA under Rule 12, annual independent audit, Rule 13 algorithm due diligence on any scoring or automated-decision engine.

Sec. 10 DPDP Act. Rules 12, 13 DPDP Rules 2025 (effective 14 May 2027). Industry commentary via nasscom, Vidhi Centre for Legal Policy.

06Sixty-day BFSI checklist

  1. Publish your DPO or Sec. 8(9) contact

    Every Data Fiduciary must publish. Use the Grievance Officer path already established under Rule 3(b)(iii). Same person can hold both hats if a formal DPO under Rule 12 is not yet required.

  2. Redesign your consent notice for Rule 3

    Standalone. Plain language. English plus any of 22 Eighth Schedule languages on request. Itemised data categories. Specific withdrawal link.

  3. Map your cross-border data flows

    Which customer data crosses which borders via which processor. Layer sectoral localisation on top of Sec. 16 default. Build a country-switch capability.

  4. Draft your retention schedule

    Sec. 8(7) with sectoral exceptions listed. RBI KYC 5 years, PMLA 5 years, Companies Act 8 years, tax records 8 years. Publish it.

  5. Unified breach playbook

    One incident, four notifications (CERT-In 6 hours, DPB via Rule 7, RBI IT Framework, sectoral regulator). Rehearse the timelines.

Building a BFSI-tuned DPDP stack? dcomply's BFSI Compliance Suite maps DPDP Sections 8, 9, 10, 16 to your existing RBI, IRDAI or SEBI controls, with a unified breach playbook covering all four regulators.