DPDP Insights › Banking, financial services and insurance
You hold identity, money and sometimes health data, and you already answer to RBI, SEBI or IRDAI. DPDP does not replace that supervision. It adds one new thing: each customer can now ask you directly what you hold, who you shared it with, and complain if the answer is poor.
Open the interactive tool for this sectorNotice, request log, retention schedule, vendor clause and breach notice.
| Rule | What it says | What it means alongside DPDP | Source |
|---|---|---|---|
| Prevention of Money-laundering Act, 2002 and RBI KYC Master Direction, 2016 | Keep transaction records for at least five years from the transaction, and identity records for at least five years after the relationship ends. | These periods override an erasure request. Explain the retention to the customer and stop every other use. | RBI KYC Master Direction |
| RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023 | In force from 1 April 2024 for commercial banks, larger NBFCs, credit information companies and all-India financial institutions. Requires IT governance under the board, audit trails, logging and incident reporting to CERT-In and RBI. | Most of the DPDP security duty is already here. Map controls once and use the evidence for both. | RBI |
| RBI Master Direction on Outsourcing of IT Services, 2023 | The regulated entity stays responsible for outsourced IT, with contracts, audit rights and exit plans. | Line up DPDP processor contracts with this direction, so one schedule meets both. | RBI |
| RBI direction on storage of payment system data, 2018 | All data relating to payment systems must be stored only in India. | This is stricter than DPDP Section 16, and it continues to apply. | RBI |
| RBI rules on card storage and tokenisation (from 1 October 2022) | Only card issuers and card networks may store actual card data. Others use tokens, created with the cardholder's explicit consent. | Check logs, call recordings and support tickets for card numbers. | RBI |
| RBI (Digital Lending) Directions, 2025 | Collect only need-based data with prior explicit consent and an audit trail. Apps should not access contacts, files, media or call logs; one-time access to camera, microphone or location is allowed for onboarding or KYC with consent. | Your app permissions and lending partner contracts are where DPDP and RBI meet. | RBI |
| IRDAI Information and Cyber Security Guidelines, 2023 | Report cyber incidents to CERT-In within six hours, and to IRDAI within 24 hours of the CERT-In report. | One incident plan should run the CERT-In, IRDAI and Data Protection Board steps together. | IRDAI |
| SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), 2024 | Security, logging and incident-reporting duties for SEBI-regulated entities. Stock brokers and depository participants report cyber incidents within six hours. | Use CSCRF evidence for DPDP security, then add notices, consent and rights. | SEBI |
| CERT-In Directions, 28 April 2022 | Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to Indian time sources. | Applies to every BFSI entity in addition to the regulator's own clock. | CERT-In |
| Credit Information Companies (Regulation) Act, 2005 | Governs what credit information is shared with credit bureaus and how errors are corrected. | Credit bureau sharing has its own law; DPDP rights requests about bureau data should point to that process too. | Act |
| RBI Integrated Ombudsman Scheme, 2021 | Customers can escalate unresolved complaints to the RBI Ombudsman. | Privacy complaints may reach both the Ombudsman and the Data Protection Board. One complaint log helps. | RBI |