InfraVeritas360DPDPiq

DPDP Insights › Banking, financial services and insurance › CEO / MD

Banking, financial services and insurance

DPDP for the CEO / MD in BFSI

Your customers trust you with their money and their identity. DPDP makes that trust something you can be asked to prove.

Open this seat in the interactive tool

What is different here

Much of the security work is already funded under regulator rules. The new spend is on notices, consent records, a request process that scales, and partner contracts. The reputational risk sits mostly with partners: agents, collection agencies and fintech partners.

The first four things to sort out

  1. Ask your CISO and DPO for one control map covering the regulator, CERT-In and DPDP.
  2. Make sure cross-selling and partner sharing run on specific consent.
  3. Review how agents, BCs and collection partners handle customer data.
  4. Agree one incident playbook that meets every clock.

A worked example: The board asks if partners are the weak spot

  1. Month 1Management lists all partners with customer data: 14 collection agencies, 3 fintech partners, 2 insurers, 1 call centre.
  2. Month 2Each gets the standard data schedule. Two agencies cannot show basic security and are given 60 days.
  3. Month 4One agency is replaced. The rest sign and send evidence.
  4. Each quarterPartner incidents and complaints are reported to the board.

Evidence kept: Partner list; Signed schedules; Board note.

Partners carry much of the risk; the contract is where you control it.

What others in the sector usually do. Most regulated entities are building on their RBI IT governance and outsourcing frameworks, then adding notices, consent records, customer requests and Board reports.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Scheduled commercial bankCross-selling insurance and mutual funds on account terms; Business correspondent devices and paper forms in villages; Old core banking archives with no deletion path
Co-operative bank (urban or rural)Vendor-run core banking with admin access from the vendor's office; Member and share registers kept on open shelves; Directors and staff who are also members and relatives of borrowers
NBFC and digital lenderApps asking for contacts, photos and call logs; Collection agents sharing borrower details with family or employers; Leads bought from aggregators with no consent record
Insurance company (life, general or health)Medical reports passed to TPAs and hospitals by email; Agent and broker access to policyholder data; Claims data kept long after the claim is closed
Broking, depository and wealthAuthorised persons with client lists on personal phones; Research-tip calls to people who never consented; Client KYC copies shared over email with partners
Payments and fintechCard numbers in logs and support tickets; Merchant onboarding documents in shared drives; Fraud models that use data beyond what users were told

What a good answer from management sounds like

Question to askA good answer sounds likeEffort and time
Can we cross-sell insurance, cards or mutual funds to existing customers?“Every campaign is checked against consent by purpose. Partners receive only consented customers, and withdrawals reach them within a day.”Medium · 8 to 12 weeks
What can collection agents do with borrower data?“Agencies get minimal data under contract, calls are reviewed, and data is returned when accounts close.”Medium · 6 to 10 weeks
One incident, many regulators: how do we meet every clock?“One playbook covers CERT-In, our regulator and the Data Protection Board. It was rehearsed this year with every filer.”Light · 3 to 6 weeks
Do we need a DPO?“We have named an accountable person with a deputy, published the contact, and that person reports to management every month.”Light · 2 to 4 weeks
How much effort and time will it take to be ready by 13 May 2027?“We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.”Programme · six to nine months
Something has gone wrong. What happens in the first 72 hours?“We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.”Medium · 4 to 8 weeks, then a yearly drill
What must a vendor contract say about personal data?“Our top vendors have data terms with a short incident-notice time, and we review them every year.”Medium · 8 to 16 weeks for the top vendors
Could we be a Significant Data Fiduciary?“We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.”Medium if you are a likely candidate
Can we send offers to past customers and leads?“Marketing runs only on separate consent. Lead lists are checked, and stop requests take effect within a day.”Light to medium · 4 to 8 weeks

9 guides for the CEO / MD, in full

Can we cross-sell insurance, cards or mutual funds to existing customers?

Short answer: Only with separate, specific consent

Only with specific consent for that purpose. Account opening terms do not count as consent to receive offers or to have data shared with a partner insurer or fund house. Service messages about the customer's own account are different and do not need marketing consent.

From your seat: CEO / MD. Back the rule even when it slows a campaign; mis-selling complaints cost more.
What the law says

Section 6 needs specific consent for each purpose. Section 5 needs a notice that names the purpose. Section 6 · Section 5 · Rule 3 · Section 8(1)–(2)

What a good answer from management sounds like: “Every campaign is checked against consent by purpose. Partners receive only consented customers, and withdrawals reach them within a day.”
Effort and time: Medium · 8 to 12 weeks.
Steps
  1. Separate service messages from offers in your systems.
  2. Ask consent for offers and partner sharing separately, by channel.
  3. Record consent by purpose and partner.
  4. Check the record before each campaign.
  5. Pass withdrawals to partners the same day.
Evidence to keep
  • Consent records by purpose and partner
  • Campaign approval with consent check
  • Withdrawal logs
Common mistakes
  • Using account terms as consent
  • Partners calling from their own lists
  • Withdrawal not reaching partners
Related questions

What can collection agents do with borrower data?

Short answer: Only what is needed, under your contract and RBI conduct rules

Collection agents act for you, so you are responsible for what they do. They should get only the data needed to contact the borrower, use it only for collection, and never share the debt with family, friends or employers. RBI's rules on recovery conduct, including calling hours, apply alongside DPDP.

From your seat: CEO / MD. Agency conduct is a reputational risk; review it yourself every quarter.
What the law says

Section 8(1) and 8(2) make you responsible for processors. Section 8(5) needs safeguards. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 6

What a good answer from management sounds like: “Agencies get minimal data under contract, calls are reviewed, and data is returned when accounts close.”
Effort and time: Medium · 6 to 10 weeks.
Steps
  1. Share only name, contact details and the amount due.
  2. Put data terms and conduct rules in every agency contract.
  3. Record calls and review a sample.
  4. Ban use of the borrower's phone contacts.
  5. Take back or delete data when the account closes.
Evidence to keep
  • Agency contracts
  • Call review records
  • Data return certificates
Common mistakes
  • Sending full loan files to agencies
  • Agents calling relatives
  • No deletion after the account closes
Related questions

One incident, many regulators: how do we meet every clock?

Short answer: Six hours for CERT-In; regulator as its rules say; DPDP without delay and 72 hours

Most BFSI incidents need a CERT-In report within six hours, a report to your regulator as its rules require (IRDAI asks within 24 hours of the CERT-In report), and DPDP messages to customers and the Data Protection Board without delay, with a detailed Board report in 72 hours. One playbook with one timeline avoids missed steps.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. CERT-In and your regulator set the others. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

What a good answer from management sounds like: “One playbook covers CERT-In, our regulator and the Data Protection Board. It was rehearsed this year with every filer.”
Effort and time: Light · 3 to 6 weeks.
Steps
  1. Put every clock on one page.
  2. Name who files each report.
  3. Keep templates ready.
  4. Rehearse with all filers present.
  5. Log the time each report went.
Evidence to keep
  • Clock page
  • Templates
  • Drill record
Common mistakes
  • Separate playbooks per regulator
  • DPO told last
  • No customer message template
Related questions

Do we need a DPO?

Short answer: Not required by law unless notified as an SDF, but name one person

Only a Significant Data Fiduciary must appoint a DPO, based in India. Every other organisation must publish the contact of a person who can answer questions about personal data. In practice, most organisations of any size name one accountable person anyway, because someone has to own requests, complaints and breaches.

From your seat: CEO / MD. The person you name needs your visible backing. Give the role a budget line and ask for a short report every month.
In BFSI

Large banks and insurers are likely candidates for SDF notification. Name a DPO now.

What the law says

Section 8(9) and Rule 9 require a published contact person for every Data Fiduciary. Section 10 requires a DPO in India for Significant Data Fiduciaries. Section 8(9)–(10) · Rules 9, 14 · Section 10 · Rule 13

What a good answer from management sounds like: “We have named an accountable person with a deputy, published the contact, and that person reports to management every month.”
Effort and time: Light · 2 to 4 weeks.
Steps
  1. Name one accountable person, with a deputy.
  2. Publish the contact on your website, app and notices.
  3. Give the role time, a budget line and a route to management.
  4. Set a short monthly report: requests, complaints, incidents, actions.
  5. Review the role if you are notified as an SDF.
Evidence to keep
  • Appointment letter
  • Published contact
  • Monthly report
Common mistakes
  • Giving the job to IT as a side task
  • A contact email nobody reads
  • No authority to make changes
Related questions

How much effort and time will it take to be ready by 13 May 2027?

Short answer: Six to nine months of steady work for most

For most organisations it is a programme of six to nine months, not a single project. The heavy parts are the data inventory, vendor contracts, access control and the request process. Notices, the contact person and training are lighter. Starting now leaves time to fix what you find.

From your seat: CEO / MD. Treat it as a nine-month programme with one owner. The cost is mostly people's time and some system changes, not a single tool.
In BFSI

Much security work is done; budget time for consent records, partner contracts and request handling.

What the law says

Most duties under the DPDP Rules start on 13 May 2027. Section 8(5) · Rule 6 · Section 8(1)–(2) · Sections 11–14 · Rule 14

What a good answer from management sounds like: “We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.”
Effort and time: Programme · six to nine months.
Steps
  1. Month 1: name the owner, set a budget line, start the inventory.
  2. Months 2 to 3: notices, consent records, contact person, request register.
  3. Months 3 to 6: vendor contracts, access control, logs, retention schedule.
  4. Months 6 to 8: breach rehearsal, training, internal review.
  5. Month 9: management review with evidence.
Evidence to keep
  • Programme plan with owners
  • Monthly status with evidence
  • Management minutes
Common mistakes
  • Leaving it to the last quarter
  • Buying a tool before knowing the gaps
  • Status colours with no evidence behind them
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: CEO / MD. You will be the public face if something goes wrong. Know who calls you, at what hour, and who speaks to customers and the media.
In BFSI

A partner API leak may need CERT-In in six hours, your regulator's report, and the DPDP messages.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

What a good answer from management sounds like: “We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.”
Effort and time: Medium · 4 to 8 weeks, then a yearly drill.
Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: CEO / MD. Ask for the top ten vendors by personal data held. If the list takes weeks to produce, that is the first gap.
In BFSI

Collection agencies, BCs, DSAs, KYC vendors, card processors and the core banking vendor all need data schedules aligned with RBI outsourcing rules.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

What a good answer from management sounds like: “Our top vendors have data terms with a short incident-notice time, and we review them every year.”
Effort and time: Medium · 8 to 16 weeks for the top vendors.
Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Could we be a Significant Data Fiduciary?

Short answer: Only by notification; none notified yet

Only the government can notify an organisation or a class of organisations as a Significant Data Fiduciary, based on the volume and sensitivity of data and the risk to people or the State. None had been notified when this page was last reviewed. Large holders of sensitive data should plan as if it could happen.

From your seat: CEO / MD. Ask management for a short note on whether you could be notified, and what it would take to be ready.
In BFSI

Large banks, insurers and payment companies hold sensitive financial data for crores of people. Plan as a likely candidate.

What the law says

Section 10 and Rule 13 set the extra duties: a DPO in India, an independent data auditor, a yearly Data Protection Impact Assessment and audit, and checks on algorithms. Rule 13(4) allows the government to restrict some data from leaving India. Section 10 · Rule 13 · Section 16 · Rule 15

What a good answer from management sounds like: “We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.”
Effort and time: Medium if you are a likely candidate.
Steps
  1. Estimate how many people's data you hold and how sensitive it is.
  2. Note any public or security role your data plays.
  3. If you are a likely candidate, run a trial impact assessment this year.
  4. Identify an auditor you could appoint.
  5. Watch MeitY notifications.
Evidence to keep
  • Volume and sensitivity note
  • Trial impact assessment
  • Board note
Common mistakes
  • Assuming 'not notified' means 'never'
  • Waiting for notification to start
  • Thinking only tech companies will be notified
Related questions

Can we send offers to past customers and leads?

Short answer: Only with separate consent and an easy way to stop

Marketing needs consent that is separate and specific, unless the person clearly expects it from the relationship. Bought or scraped lead lists are risky because you cannot show consent. Every message should carry an easy way to stop.

From your seat: CEO / MD. Growth teams feel this first. Back the rule that marketing runs only on clear consent; it protects the brand.
In BFSI

Telemarketing must follow TRAI's preference rules as well as DPDP consent.

What the law says

Section 6 sets the consent standard. Section 5 needs a notice. Section 9 bars targeted advertising at children. Section 6 · Section 5 · Rule 3 · Section 9 · Rules 10, 12

What a good answer from management sounds like: “Marketing runs only on separate consent. Lead lists are checked, and stop requests take effect within a day.”
Effort and time: Light to medium · 4 to 8 weeks.
Steps
  1. Separate service messages from marketing messages.
  2. Ask marketing consent separately, with a clear action.
  3. Stop using bought lists unless the seller can show consent for you.
  4. Add an easy stop option to every message.
  5. Respect the telecom preference rules for calls and SMS.
Evidence to keep
  • Marketing consent records
  • Lead source records
  • Stop requests and their handling
Common mistakes
  • Treating account sign-up as marketing consent
  • Agency lists with no consent proof
  • A stop option that does not work
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for banking, financial services and insurance.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Prevention of Money-laundering Act, 2002 and RBI KYC Master Direction, 2016Keep transaction records for at least five years from the transaction, and identity records for at least five years after the relationship ends.These periods override an erasure request. Explain the retention to the customer and stop every other use.RBI KYC Master Direction
RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023In force from 1 April 2024 for commercial banks, larger NBFCs, credit information companies and all-India financial institutions. Requires IT governance under the board, audit trails, logging and incident reporting to CERT-In and RBI.Most of the DPDP security duty is already here. Map controls once and use the evidence for both.RBI
RBI Master Direction on Outsourcing of IT Services, 2023The regulated entity stays responsible for outsourced IT, with contracts, audit rights and exit plans.Line up DPDP processor contracts with this direction, so one schedule meets both.RBI
RBI direction on storage of payment system data, 2018All data relating to payment systems must be stored only in India.This is stricter than DPDP Section 16, and it continues to apply.RBI
RBI rules on card storage and tokenisation (from 1 October 2022)Only card issuers and card networks may store actual card data. Others use tokens, created with the cardholder's explicit consent.Check logs, call recordings and support tickets for card numbers.RBI
RBI (Digital Lending) Directions, 2025Collect only need-based data with prior explicit consent and an audit trail. Apps should not access contacts, files, media or call logs; one-time access to camera, microphone or location is allowed for onboarding or KYC with consent.Your app permissions and lending partner contracts are where DPDP and RBI meet.RBI
IRDAI Information and Cyber Security Guidelines, 2023Report cyber incidents to CERT-In within six hours, and to IRDAI within 24 hours of the CERT-In report.One incident plan should run the CERT-In, IRDAI and Data Protection Board steps together.IRDAI
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), 2024Security, logging and incident-reporting duties for SEBI-regulated entities. Stock brokers and depository participants report cyber incidents within six hours.Use CSCRF evidence for DPDP security, then add notices, consent and rights.SEBI
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to Indian time sources.Applies to every BFSI entity in addition to the regulator's own clock.CERT-In
Credit Information Companies (Regulation) Act, 2005Governs what credit information is shared with credit bureaus and how errors are corrected.Credit bureau sharing has its own law; DPDP rights requests about bureau data should point to that process too.Act
RBI Integrated Ombudsman Scheme, 2021Customers can escalate unresolved complaints to the RBI Ombudsman.Privacy complaints may reach both the Ombudsman and the Data Protection Board. One complaint log helps.RBI
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.