InfraVeritas360DPDPiq

DPDP Insights › Banking, financial services and insurance › Branch / business head

Banking, financial services and insurance

DPDP for the Branch / business head in BFSI

As a branch or business head, your team meets customers face to face and holds their papers.

Open this seat in the interactive tool

What is different here

Requests, complaints and wrong sends happen at your desk first. You also see pressure to cross-sell, which is where consent matters most.

The first four things to sort out

  1. Check that branch forms carry the current notice.
  2. Make sure cross-sell leads come with consent.
  3. Lock away paper files and KYC copies at day end.
  4. Know whom to call when a customer asks what you hold.

A worked example: A relationship manager wants to share leads on chat

  1. MondayThe branch head notices a lead list on a WhatsApp group.
  2. MondayThe list is deleted and the DPO is told.
  3. Week 1The CRM's lead-sharing feature is switched on for the branch.
  4. AfterThe branch checks every lead for consent.

Evidence kept: Report; CRM change; Consent check.

Give people a better tool and the chat groups go quiet.

What others in the sector usually do. Branch heads in some banks review a short privacy checklist each month along with cash and audit checks.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Scheduled commercial bankCross-selling insurance and mutual funds on account terms; Business correspondent devices and paper forms in villages; Old core banking archives with no deletion path
Co-operative bank (urban or rural)Vendor-run core banking with admin access from the vendor's office; Member and share registers kept on open shelves; Directors and staff who are also members and relatives of borrowers
NBFC and digital lenderApps asking for contacts, photos and call logs; Collection agents sharing borrower details with family or employers; Leads bought from aggregators with no consent record
Insurance company (life, general or health)Medical reports passed to TPAs and hospitals by email; Agent and broker access to policyholder data; Claims data kept long after the claim is closed
Broking, depository and wealthAuthorised persons with client lists on personal phones; Research-tip calls to people who never consented; Client KYC copies shared over email with partners
Payments and fintechCard numbers in logs and support tickets; Merchant onboarding documents in shared drives; Fraud models that use data beyond what users were told

9 guides for the Branch / business head, in full

Can we cross-sell insurance, cards or mutual funds to existing customers?

Short answer: Only with separate, specific consent

Only with specific consent for that purpose. Account opening terms do not count as consent to receive offers or to have data shared with a partner insurer or fund house. Service messages about the customer's own account are different and do not need marketing consent.

From your seat: Branch / business head. Branch targets often push cross-selling. Check that each lead has consent.
What the law says

Section 6 needs specific consent for each purpose. Section 5 needs a notice that names the purpose. Section 6 · Section 5 · Rule 3 · Section 8(1)–(2)

Steps
  1. Separate service messages from offers in your systems.
  2. Ask consent for offers and partner sharing separately, by channel.
  3. Record consent by purpose and partner.
  4. Check the record before each campaign.
  5. Pass withdrawals to partners the same day.
Evidence to keep
  • Consent records by purpose and partner
  • Campaign approval with consent check
  • Withdrawal logs
Common mistakes
  • Using account terms as consent
  • Partners calling from their own lists
  • Withdrawal not reaching partners
Related questions

How long must we keep KYC and transaction records, and what happens after?

Short answer: At least five years after the relationship ends; then erase

Under PMLA and RBI's KYC Master Direction, keep identity records for at least five years after the relationship ends, and transaction records for at least five years from the transaction. During that time, keep them only for that legal purpose. After it, erase or anonymise unless another law requires more.

What the law says

Section 8(7) allows retention where a law requires it. PMLA and RBI's KYC rules are such laws. Section 8(7) · Rule 8 · Section 7

Steps
  1. List KYC and transaction record types.
  2. Set the start date: end of relationship or date of transaction.
  3. Restrict access to closed-account records.
  4. Erase or anonymise after the period.
  5. Explain this in erasure replies.
Evidence to keep
  • Retention schedule
  • Access restrictions on closed accounts
  • Deletion logs
Common mistakes
  • Keeping everything for ever
  • Deleting before the legal period
  • Using closed-account data for marketing
Related questions

What can collection agents do with borrower data?

Short answer: Only what is needed, under your contract and RBI conduct rules

Collection agents act for you, so you are responsible for what they do. They should get only the data needed to contact the borrower, use it only for collection, and never share the debt with family, friends or employers. RBI's rules on recovery conduct, including calling hours, apply alongside DPDP.

What the law says

Section 8(1) and 8(2) make you responsible for processors. Section 8(5) needs safeguards. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 6

Steps
  1. Share only name, contact details and the amount due.
  2. Put data terms and conduct rules in every agency contract.
  3. Record calls and review a sample.
  4. Ban use of the borrower's phone contacts.
  5. Take back or delete data when the account closes.
Evidence to keep
  • Agency contracts
  • Call review records
  • Data return certificates
Common mistakes
  • Sending full loan files to agencies
  • Agents calling relatives
  • No deletion after the account closes
Related questions

Staff share personal data on WhatsApp and personal email. What do we do?

Short answer: Yes, this is a common breach; give staff a safer option

Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.

From your seat: Branch / business head. Your teams share data in the middle of real work. Make the approved way faster than the risky way.
In BFSI

Relationship managers share lead lists and statements on chat. Give them a CRM route.

What the law says

Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Ask teams how they actually share files and photos today.
  2. Provide an approved tool for that job.
  3. Set three simple rules: approved tool, no personal accounts, report wrong sends.
  4. Teach the rules with real examples from your own work.
  5. Treat a quick report as good behaviour, not a disciplinary case.
Evidence to keep
  • Approved-tool policy
  • Training record
  • Incident reports of wrong sends
Common mistakes
  • A ban with no alternative
  • Punishing people who report
  • Ignoring group chats with vendors
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

From your seat: Branch / business head. People in your area hold data people may ask for. Know who logs a request and who searches.
In BFSI

The summary should list partner insurers, credit bureaus and collection agencies that received data.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: Branch / business head. Wrong sends and lost papers happen on your floor first. Make reporting quick and safe.
In BFSI

A partner API leak may need CERT-In in six hours, your regulator's report, and the DPDP messages.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Who needs DPDP training, and what should it cover?

Short answer: Everyone who handles personal data, by role

Everyone who handles personal data needs short, practical training on what to do in their own job. Front-line staff need examples from their counter or desk. Managers need to know the clocks and their own duties. Management needs to know what to ask.

From your seat: Branch / business head. Short sessions using your own daily examples work better than general training.
In BFSI

Branch staff need examples: KYC copies, walk-in requests, wrong sends.

What the law says

Section 8(4) and 8(5) ask for appropriate technical and organisational measures. Training is part of showing those measures work. Section 8(5) · Rule 6

Steps
  1. Group staff by what they handle: front line, back office, IT, managers, management.
  2. Write three to five real scenarios for each group.
  3. Keep sessions short: 20 to 30 minutes.
  4. Test with a few questions, and record attendance.
  5. Repeat every year, and at joining.
Evidence to keep
  • Training plan by group
  • Attendance and test results
  • Scenario material
Common mistakes
  • One long legal lecture for all
  • Training once and never again
  • No record of attendance
Related questions

What about CCTV, visitor registers and biometric attendance?

Short answer: Yes, with notice, limits and a deletion period

All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.

From your seat: Branch / business head. Recording on your floor needs notices and limited viewing.
In BFSI

Branch and ATM CCTV needs notices and limited retention.

What the law says

Section 5 needs notice. Section 8(5) needs safeguards. Section 8(7) needs erasure after the purpose. For staff, Section 7(i) can cover security and attendance. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8 · Section 7

Steps
  1. Put notices at CCTV points and reception, in the local language.
  2. Ask visitors only for name, phone and whom they are meeting, unless security needs more.
  3. Set a period for footage and registers, then delete.
  4. Restrict who can view footage, and log viewing.
  5. Check the vendor contracts for CCTV, guards and attendance systems.
Evidence to keep
  • Notices in place
  • Retention settings on the recorder
  • Viewing log
Common mistakes
  • Photocopying visitor IDs as routine
  • Footage kept until the disk fills
  • Biometric systems with vendor default passwords
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for banking, financial services and insurance.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Prevention of Money-laundering Act, 2002 and RBI KYC Master Direction, 2016Keep transaction records for at least five years from the transaction, and identity records for at least five years after the relationship ends.These periods override an erasure request. Explain the retention to the customer and stop every other use.RBI KYC Master Direction
RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023In force from 1 April 2024 for commercial banks, larger NBFCs, credit information companies and all-India financial institutions. Requires IT governance under the board, audit trails, logging and incident reporting to CERT-In and RBI.Most of the DPDP security duty is already here. Map controls once and use the evidence for both.RBI
RBI Master Direction on Outsourcing of IT Services, 2023The regulated entity stays responsible for outsourced IT, with contracts, audit rights and exit plans.Line up DPDP processor contracts with this direction, so one schedule meets both.RBI
RBI direction on storage of payment system data, 2018All data relating to payment systems must be stored only in India.This is stricter than DPDP Section 16, and it continues to apply.RBI
RBI rules on card storage and tokenisation (from 1 October 2022)Only card issuers and card networks may store actual card data. Others use tokens, created with the cardholder's explicit consent.Check logs, call recordings and support tickets for card numbers.RBI
RBI (Digital Lending) Directions, 2025Collect only need-based data with prior explicit consent and an audit trail. Apps should not access contacts, files, media or call logs; one-time access to camera, microphone or location is allowed for onboarding or KYC with consent.Your app permissions and lending partner contracts are where DPDP and RBI meet.RBI
IRDAI Information and Cyber Security Guidelines, 2023Report cyber incidents to CERT-In within six hours, and to IRDAI within 24 hours of the CERT-In report.One incident plan should run the CERT-In, IRDAI and Data Protection Board steps together.IRDAI
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), 2024Security, logging and incident-reporting duties for SEBI-regulated entities. Stock brokers and depository participants report cyber incidents within six hours.Use CSCRF evidence for DPDP security, then add notices, consent and rights.SEBI
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to Indian time sources.Applies to every BFSI entity in addition to the regulator's own clock.CERT-In
Credit Information Companies (Regulation) Act, 2005Governs what credit information is shared with credit bureaus and how errors are corrected.Credit bureau sharing has its own law; DPDP rights requests about bureau data should point to that process too.Act
RBI Integrated Ombudsman Scheme, 2021Customers can escalate unresolved complaints to the RBI Ombudsman.Privacy complaints may reach both the Ombudsman and the Data Protection Board. One complaint log helps.RBI
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.