InfraVeritas360DPDPiq

DPDP Insights › Banking, financial services and insurance › CIO / IT head

Banking, financial services and insurance

DPDP for the CIO / IT head in BFSI

Your systems decide whether a customer request can be answered in days or in months.

Open this seat in the interactive tool

What is different here

Customer data sits in core banking, cards, loan systems, CRM, call centre tools, data warehouses and partner platforms, often with different customer IDs. Without a link between them, a single request turns into a hunt.

The first four things to sort out

  1. Link customer IDs across core systems, or at least keep a mapping.
  2. List every system and SaaS tool holding customer data, with hosting location.
  3. Build consent flags that downstream systems read before sending offers.
  4. Plan deletion and archive paths for closed accounts after the legal period.

A worked example: One customer, five customer IDs

  1. Week 1A request shows the customer has separate IDs in core banking, cards, home loans, CRM and the call centre tool.
  2. Week 3IT builds a mapping table linking IDs by verified mobile and PAN.
  3. Week 6Request searches now run across all five systems in one step.
  4. AfterConsent flags are published from one service that all channels read.

Evidence kept: ID mapping design; Search run for a test request; Consent service design.

Linking identities is the single change that makes every right workable.

What others in the sector usually do. Banks that started early built a consent and preference service that every channel reads, instead of fixing each channel separately.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Scheduled commercial bankCross-selling insurance and mutual funds on account terms; Business correspondent devices and paper forms in villages; Old core banking archives with no deletion path
Co-operative bank (urban or rural)Vendor-run core banking with admin access from the vendor's office; Member and share registers kept on open shelves; Directors and staff who are also members and relatives of borrowers
NBFC and digital lenderApps asking for contacts, photos and call logs; Collection agents sharing borrower details with family or employers; Leads bought from aggregators with no consent record
Insurance company (life, general or health)Medical reports passed to TPAs and hospitals by email; Agent and broker access to policyholder data; Claims data kept long after the claim is closed
Broking, depository and wealthAuthorised persons with client lists on personal phones; Research-tip calls to people who never consented; Client KYC copies shared over email with partners
Payments and fintechCard numbers in logs and support tickets; Merchant onboarding documents in shared drives; Fraud models that use data beyond what users were told

Control map: DPDP to NIST CSF 2.0 and ISO/IEC 27001:2022

DPDP dutyLawNIST CSF 2.0ISO/IEC 27001 Annex AEvidence
Know where personal data isSection 8(5) · Rule 6ID.AM-02, ID.AM-075.9, 5.12Inventory of systems and data types, with owner and hosting location
Only the right people get inSection 8(5) · Rule 6PR.AA-01, PR.AA-055.15, 5.16, 5.18, 8.2Role matrix, quarterly access review sign-off, leaver removal report
Strong sign-in for admins and remote usersSection 8(5) · Rule 6PR.AA-035.17, 8.5MFA enforcement report for admin, VPN and email accounts
Encrypt or mask dataSection 8(5) · Rule 6PR.DS-01, PR.DS-028.11, 8.24Encryption settings for databases, laptops, backups and transfers; masking in test copies
Keep and watch logsSection 8(5) · Rule 6PR.PS-04, DE.CM-01, DE.CM-038.15, 8.16, 8.17Log retention settings (one year; 180 days in India for CERT-In), alert rules, NTP source
Backups that restoreSection 8(5) · Rule 6PR.DS-11, RC.RP-038.13, 5.30Backup schedule, offline copy, last restore test with date and result
Separate networksSection 8(5) · Rule 6PR.IR-018.20, 8.22Network diagram showing segments, firewall rule review
Patch and fix weaknessesSection 8(5) · Rule 6ID.RA-018.8Vulnerability scan results and closure tracker
Handle incidents and tell peopleSection 8(6) · Rule 7RS.MA-01, RS.CO-02, RS.CO-035.24, 5.25, 5.26, 6.8Incident plan with the 6-hour and 72-hour steps, drill record, contact list
Learn from incidentsSection 8(6) · Rule 7DE.AE-02, ID.IM-015.27, 5.28Post-incident review and actions closed
Vendors protect data tooSection 8(1)–(2)GV.SC-05, GV.SC-075.19, 5.20, 5.22Contracts with data terms, vendor review record
Data comes back or is deleted at contract endSection 8(7) · Rule 8GV.SC-105.20, 8.10Exit clause and deletion certificate from the vendor
Cloud is set up safelySection 16 · Rule 15GV.SC-05, PR.DS-015.23Cloud region list, shared-responsibility note, configuration review
Delete when the purpose is overSection 8(7) · Rule 8PR.DS-018.10, 7.14Retention schedule, deletion log, disposal certificates for disks and paper
People know the rulesSection 8(5) · Rule 6PR.AT-016.3Training attendance and short test results by department
Legal duties are trackedSection 8(5) · Rule 6GV.OC-035.31, 5.34Register of laws and rules that apply, reviewed yearly
Roles are namedSection 8(9)–(10) · Rules 9, 14GV.RR-025.2, 5.4Named owners for each system and each duty, approved by management

Logs, backups and access checklist

9 guides for the CIO / IT head, in full

How long must we keep KYC and transaction records, and what happens after?

Short answer: At least five years after the relationship ends; then erase

Under PMLA and RBI's KYC Master Direction, keep identity records for at least five years after the relationship ends, and transaction records for at least five years from the transaction. During that time, keep them only for that legal purpose. After it, erase or anonymise unless another law requires more.

From your seat: CIO / IT head. Build an archive tier for closed accounts with restricted access.
What the law says

Section 8(7) allows retention where a law requires it. PMLA and RBI's KYC rules are such laws. Section 8(7) · Rule 8 · Section 7

Steps
  1. List KYC and transaction record types.
  2. Set the start date: end of relationship or date of transaction.
  3. Restrict access to closed-account records.
  4. Erase or anonymise after the period.
  5. Explain this in erasure replies.
Evidence to keep
  • Retention schedule
  • Access restrictions on closed accounts
  • Deletion logs
Common mistakes
  • Keeping everything for ever
  • Deleting before the legal period
  • Using closed-account data for marketing
Related questions

What can our lending or banking app collect from a phone?

Short answer: Need-based only, with explicit consent

Only what you need, with explicit consent. RBI's Digital Lending Directions already bar access to contacts, files, media and call logs, and allow one-time access to camera, microphone or location for onboarding or KYC. DPDP adds a notice, the right to withdraw and the right to know what was collected.

From your seat: CIO / IT head. Review SDKs too; they often collect more than the app.
What the law says

Section 6 needs consent limited to what is necessary. RBI's Digital Lending Directions, 2025 set specific limits. Section 6 · Section 5 · Rule 3 · Section 8(5) · Rule 6

Steps
  1. List every permission the app asks for.
  2. Remove permissions not needed.
  3. Ask camera and location only at the KYC step.
  4. Show the notice in the app before sign-up.
  5. Check partner apps the same way.
Evidence to keep
  • Permission list with reasons
  • App store listing
  • Partner app review
Common mistakes
  • Contacts permission for 'reference checks'
  • Third-party analytics SDKs collecting device data
  • Partner apps not reviewed
Related questions

Where does personal data live in our organisation?

Short answer: Start with one row per system

Usually in more places than anyone expects: core systems, email, shared drives, laptops, vendor systems, backups, test copies, spreadsheets and paper. A simple inventory, one row per system, is the base for every other duty.

From your seat: CIO / IT head. Start from your application list and cloud bills. Each system needs an owner, a hosting location and a list of the vendors that touch it.
In BFSI

Include data warehouses, CRM, call centre tools and partner platforms, not only core banking.

What the law says

Every duty in Sections 5 to 12 assumes you know where the data is. Rule 6 needs safeguards for each system, and Section 11 needs you to find the data when someone asks. Section 8(5) · Rule 6 · Sections 11–14 · Rule 14 · Section 8(7) · Rule 8

Steps
  1. List systems, then shared drives, email, spreadsheets and paper stores.
  2. For each one, note whose data, which items, purpose, owner, hosting location and vendors.
  3. Add copies: backups, test, analytics.
  4. Get each owner to confirm their rows.
  5. Update it whenever a system is bought or retired.
Evidence to keep
  • Data inventory
  • Owner confirmations
  • Change log
Common mistakes
  • A 200-column spreadsheet nobody finishes
  • Leaving out SaaS tools bought by departments
  • No owner for each row
Related questions

Can personal data be stored or accessed outside India?

Short answer: Yes, unless a sector rule says otherwise

Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.

From your seat: CIO / IT head. SaaS tools bought by departments are the usual surprise. Ask Finance for the list of software subscriptions.
In BFSI

Payment system data must be stored only in India. Check overseas support access to core systems.

What the law says

Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)

Steps
  1. List where each system is hosted and where support teams log in from.
  2. Check sector rules for localisation.
  3. Put location and access terms in cloud and vendor contracts.
  4. Keep the list current; new SaaS tools change it quietly.
  5. Tell people in your notice if data goes abroad.
Evidence to keep
  • Hosting and access-location list
  • Contract clauses
  • Sector rule check
Common mistakes
  • Forgetting email, CRM and helpdesk SaaS
  • Ignoring overseas support logins
  • Assuming 'Indian vendor' means 'data in India'
Related questions

Does deletion have to reach backups and test copies?

Short answer: Yes, through a written backup-expiry rule

Deletion should reach every copy you control. For backups, the usual practice is to let deleted records expire with the normal backup cycle, never restore them into live use, and write this down. Test and training copies should use masked data.

From your seat: CIO / IT head. Deletion is an engineering task. Decide how each system deletes, how backups expire, and how test copies are masked.
In BFSI

Core banking backups often run for years. Match backup retention to the record schedule.

What the law says

Section 8(7) asks for erasure. Rule 6 asks for backups for continuity. The two meet in a backup retention rule that is short enough and written down. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List where copies live: backups, replicas, test, analytics, laptops, vendors.
  2. Set backup retention to match the retention schedule.
  3. Write a rule: deleted records are not restored into live systems.
  4. Mask personal data in test and training copies.
  5. Get deletion confirmations from vendors.
Evidence to keep
  • Backup retention settings
  • Written backup-expiry rule
  • Masking procedure for test data
Common mistakes
  • Ten-year backups for convenience
  • Live copies in test
  • Restoring old backups and bringing deleted records back
Related questions

Who should be able to see personal data in our systems?

Short answer: Only those who need it, reviewed every quarter

Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.

From your seat: CIO / IT head. Role-based access needs application changes as well as policy. Budget for it in the next release cycle.
In BFSI

Mark staff and VIP accounts so only a small team can view them.

What the law says

Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse. Section 8(5) · Rule 6

Steps
  1. Write a role matrix for each key system.
  2. Replace shared logins with named accounts.
  3. Use multi-factor sign-in for admin and remote access.
  4. Review access every quarter with each manager.
  5. Remove access on the last working day.
Evidence to keep
  • Role matrix
  • Quarterly review sign-offs
  • Leaver removal report
Common mistakes
  • Generic logins on shared machines
  • Access that only grows
  • No review of vendor accounts
Related questions

Which logs must we keep, for how long, and where?

Short answer: At least one year; 180 days of ICT logs in India

Keep logs that show who accessed personal data and what they did, for at least one year under the DPDP Rules. CERT-In separately asks for ICT system logs to be kept for 180 days within India. Logs must be protected so nobody can quietly change them.

From your seat: CIO / IT head. Make sure applications log who viewed a record, not only system errors. That is what a request or a breach review needs.
In BFSI

Core banking, internet banking and card systems already log heavily. Check retention and that logs stay in India.

What the law says

Rule 6 lists logs and monitoring as a minimum safeguard. Rule 8(3) asks for logs to be kept for at least one year. The CERT-In Directions of 2022 ask for 180 days of ICT logs kept within India. Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. List systems holding personal data and what each logs today.
  2. Turn on access logging where it is missing.
  3. Send logs to one protected store, with at least one year of retention.
  4. Keep a copy of ICT logs in India for at least 180 days.
  5. Sync clocks and review alerts every day.
Evidence to keep
  • Log source list
  • Retention settings
  • Alert review records
Common mistakes
  • Logging only failures, not who viewed a record
  • Logs stored on the same server they describe
  • Clocks out of sync, so timelines cannot be built
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: CIO / IT head. Your architecture decisions decide which vendors see data. Prefer designs that send vendors only what they need.
In BFSI

Collection agencies, BCs, DSAs, KYC vendors, card processors and the core banking vendor all need data schedules aligned with RBI outsourcing rules.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Does ISO 27001 or NIST CSF cover our DPDP duties?

Short answer: They cover security, not the whole Act

They help a great deal with the security part. ISO/IEC 27001 and NIST CSF 2.0 are good evidence of reasonable security safeguards. They do not cover notice, consent, rights, complaints or children's data. ISO/IEC 27701 adds privacy controls, but no certificate replaces the Act.

From your seat: CIO / IT head. Keep the mapping current as systems change. A new system without logging or access control undoes the work.
In BFSI

RBI, SEBI and IRDAI frameworks plus ISO 27001 cover most of Rule 6.

What the law says

Section 8(5) and Rule 6 ask for reasonable security safeguards. A recognised standard is strong evidence of that duty, and only of that duty. Section 8(5) · Rule 6

Steps
  1. Map your current controls to Rule 6.
  2. Add the DPDP-only items: notice, consent, rights, complaints, children, retention.
  3. Use the same evidence for audits and for DPDP.
  4. Include privacy in the scope of your next internal audit.
  5. Consider ISO/IEC 27701 if clients ask for it.
Evidence to keep
  • Control map
  • Audit reports
  • Gap list for DPDP-only items
Common mistakes
  • Treating a certificate as DPDP compliance
  • Scope that leaves out the systems with the most personal data
  • No owner for the non-security duties
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for banking, financial services and insurance.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Prevention of Money-laundering Act, 2002 and RBI KYC Master Direction, 2016Keep transaction records for at least five years from the transaction, and identity records for at least five years after the relationship ends.These periods override an erasure request. Explain the retention to the customer and stop every other use.RBI KYC Master Direction
RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023In force from 1 April 2024 for commercial banks, larger NBFCs, credit information companies and all-India financial institutions. Requires IT governance under the board, audit trails, logging and incident reporting to CERT-In and RBI.Most of the DPDP security duty is already here. Map controls once and use the evidence for both.RBI
RBI Master Direction on Outsourcing of IT Services, 2023The regulated entity stays responsible for outsourced IT, with contracts, audit rights and exit plans.Line up DPDP processor contracts with this direction, so one schedule meets both.RBI
RBI direction on storage of payment system data, 2018All data relating to payment systems must be stored only in India.This is stricter than DPDP Section 16, and it continues to apply.RBI
RBI rules on card storage and tokenisation (from 1 October 2022)Only card issuers and card networks may store actual card data. Others use tokens, created with the cardholder's explicit consent.Check logs, call recordings and support tickets for card numbers.RBI
RBI (Digital Lending) Directions, 2025Collect only need-based data with prior explicit consent and an audit trail. Apps should not access contacts, files, media or call logs; one-time access to camera, microphone or location is allowed for onboarding or KYC with consent.Your app permissions and lending partner contracts are where DPDP and RBI meet.RBI
IRDAI Information and Cyber Security Guidelines, 2023Report cyber incidents to CERT-In within six hours, and to IRDAI within 24 hours of the CERT-In report.One incident plan should run the CERT-In, IRDAI and Data Protection Board steps together.IRDAI
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), 2024Security, logging and incident-reporting duties for SEBI-regulated entities. Stock brokers and depository participants report cyber incidents within six hours.Use CSCRF evidence for DPDP security, then add notices, consent and rights.SEBI
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to Indian time sources.Applies to every BFSI entity in addition to the regulator's own clock.CERT-In
Credit Information Companies (Regulation) Act, 2005Governs what credit information is shared with credit bureaus and how errors are corrected.Credit bureau sharing has its own law; DPDP rights requests about bureau data should point to that process too.Act
RBI Integrated Ombudsman Scheme, 2021Customers can escalate unresolved complaints to the RBI Ombudsman.Privacy complaints may reach both the Ombudsman and the Data Protection Board. One complaint log helps.RBI
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.