InfraVeritas360DPDPiq

DPDP Insights › Banking, financial services and insurance › Customer service department

Banking, financial services and insurance

DPDP for the Customer service department in BFSI

Contact centres and service desks receive most customer requests and complaints.

Open this seat in the interactive tool

What is different here

You hold identity, money and sometimes health data, and you already answer to RBI, SEBI or IRDAI. DPDP does not replace that supervision. It adds one new thing: each customer can now ask you directly what you hold, who you shared it with, and complain if the answer is poor.

The first four things to sort out

  1. Log privacy requests and complaints the same day.
  2. Play a recording notice and pause for card details.
  3. Verify identity before sharing anything.
  4. Answer within published timelines.

A worked example: A caller asks to stop all offers

  1. CallThe agent logs a withdrawal and confirms.
  2. Day 1The flag reaches the dialler and SMS tool.
  3. Day 2A partner list is checked.
  4. AfterThe customer gets a written confirmation.

Evidence kept: Log; Flag update; Confirmation.

One call should be enough.

What others in the sector usually do. Contact centres are adding a privacy tag to the complaint system.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Scheduled commercial bankCross-selling insurance and mutual funds on account terms; Business correspondent devices and paper forms in villages; Old core banking archives with no deletion path
Co-operative bank (urban or rural)Vendor-run core banking with admin access from the vendor's office; Member and share registers kept on open shelves; Directors and staff who are also members and relatives of borrowers
NBFC and digital lenderApps asking for contacts, photos and call logs; Collection agents sharing borrower details with family or employers; Leads bought from aggregators with no consent record
Insurance company (life, general or health)Medical reports passed to TPAs and hospitals by email; Agent and broker access to policyholder data; Claims data kept long after the claim is closed
Broking, depository and wealthAuthorised persons with client lists on personal phones; Research-tip calls to people who never consented; Client KYC copies shared over email with partners
Payments and fintechCard numbers in logs and support tickets; Merchant onboarding documents in shared drives; Fraud models that use data beyond what users were told

8 guides for the Customer service department, in full

How long must we keep KYC and transaction records, and what happens after?

Short answer: At least five years after the relationship ends; then erase

Under PMLA and RBI's KYC Master Direction, keep identity records for at least five years after the relationship ends, and transaction records for at least five years from the transaction. During that time, keep them only for that legal purpose. After it, erase or anonymise unless another law requires more.

From your seat: Customer service department. Explain retention politely when customers ask to delete.
What the law says

Section 8(7) allows retention where a law requires it. PMLA and RBI's KYC rules are such laws. Section 8(7) · Rule 8 · Section 7

Steps
  1. List KYC and transaction record types.
  2. Set the start date: end of relationship or date of transaction.
  3. Restrict access to closed-account records.
  4. Erase or anonymise after the period.
  5. Explain this in erasure replies.
Evidence to keep
  • Retention schedule
  • Access restrictions on closed accounts
  • Deletion logs
Common mistakes
  • Keeping everything for ever
  • Deleting before the legal period
  • Using closed-account data for marketing
Related questions

What can collection agents do with borrower data?

Short answer: Only what is needed, under your contract and RBI conduct rules

Collection agents act for you, so you are responsible for what they do. They should get only the data needed to contact the borrower, use it only for collection, and never share the debt with family, friends or employers. RBI's rules on recovery conduct, including calling hours, apply alongside DPDP.

What the law says

Section 8(1) and 8(2) make you responsible for processors. Section 8(5) needs safeguards. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 6

Steps
  1. Share only name, contact details and the amount due.
  2. Put data terms and conduct rules in every agency contract.
  3. Record calls and review a sample.
  4. Ban use of the borrower's phone contacts.
  5. Take back or delete data when the account closes.
Evidence to keep
  • Agency contracts
  • Call review records
  • Data return certificates
Common mistakes
  • Sending full loan files to agencies
  • Agents calling relatives
  • No deletion after the account closes
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

From your seat: Customer service department. Log every request on the day it comes in and route it to the DPO's register.
In BFSI

The summary should list partner insurers, credit bureaus and collection agencies that received data.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

How do we handle a privacy complaint within 90 days?

Short answer: Reply within your published period, never beyond 90 days

Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.

From your seat: Customer service department. Tag privacy complaints and count the days.
In BFSI

A privacy complaint may also reach the RBI Ombudsman. One log, tagged for both, avoids two different answers.

What the law says

Section 8(10) requires a working grievance process. Rule 14(3) caps the reply time at 90 days. Section 13 says people must use your process before approaching the Board. Section 8(9)–(10) · Rules 9, 14 · Sections 11–14 · Rule 14 · Sections 18–26

Steps
  1. Publish one contact for privacy complaints on your website, app and notices.
  2. Log each complaint with the date, channel and a named owner.
  3. Acknowledge within a few days, and set an internal target well under 90 days.
  4. Find and fix the cause, not just the single case.
  5. Reply in writing and close the entry with the date.
Evidence to keep
  • Complaint register with dates
  • Replies sent
  • Monthly summary to management
Common mistakes
  • Mixing privacy complaints into general complaints with no tag
  • No owner, so nobody counts the days
  • Closing a complaint without fixing the cause
Related questions

What about call recordings and customer service screens?

Short answer: Yes, with notice, a retention period and masking

Call recordings, chat transcripts and agent screens hold a lot of personal data. Tell callers that calls are recorded and why, keep recordings for a set period, limit who can listen, and mask card numbers and passwords on screen and in recordings.

From your seat: Customer service department. Play the recording notice and pause recording for card details.
In BFSI

Never record card numbers or OTPs. Pause recording when customers read them out.

What the law says

Section 5 needs notice, Section 8(5) needs safeguards, and Section 8(7) needs erasure after the purpose. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. Play a short recording notice at the start of calls.
  2. Set a retention period by call type.
  3. Pause recording when card or other sensitive details are given.
  4. Limit replay rights to quality and complaint teams.
  5. Lock agent screens and stop phones on the floor if data is sensitive.
Evidence to keep
  • Recording notice script
  • Retention settings
  • Replay access list
Common mistakes
  • Recordings kept indefinitely
  • Card numbers in recordings
  • Open replay access for all supervisors
Related questions

Someone asks us to delete their data. Must we?

Short answer: Yes, unless a law requires you to keep it

You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.

From your seat: Customer service department. Explain clearly what can be deleted and what the law requires to be kept.
In BFSI

Closed-account KYC and transaction records stay for the PMLA period; offers and profiling stop at once.

What the law says

Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8

Steps
  1. Log the request and verify identity.
  2. Check the retention schedule for each record type involved.
  3. Delete what has no legal reason to stay, including copies with vendors and in test systems.
  4. Mark what must stay, with the law and the end date.
  5. Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
  • Erasure log
  • Vendor deletion confirmations
  • Reply to the person
Common mistakes
  • Refusing every erasure request 'because of backups'
  • Deleting records a law requires
  • Not telling vendors
Related questions

Someone withdraws consent. What has to stop, and how fast?

Short answer: Stop that use quickly, across every system and vendor

Withdrawal must be as easy as giving consent. Once someone withdraws, you and every vendor working for you must stop that use within a reasonable time. What was done before withdrawal stays lawful, and data that a law requires you to keep is kept.

From your seat: Customer service department. Process stop requests the same day and confirm in writing.
In BFSI

A customer taps 'stop offers' in the app. The dialler, SMS tool and partner insurer must all stop within a day.

What the law says

Section 6(4) to 6(6) give the right to withdraw at any time, with the same ease, and require processors to stop as well. Section 8(7) then asks for erasure unless a law requires retention. Section 6 · Section 8(7) · Rule 8 · Section 8(1)–(2)

Steps
  1. Give one simple way to withdraw on every channel where consent is taken.
  2. Record the withdrawal against the person and the purpose.
  3. Push the change to every system and vendor that uses that purpose.
  4. Confirm to the person, in writing, what has stopped and what is kept by law.
  5. Check a sample every month to see that the change actually reached every list.
Evidence to keep
  • Withdrawal log with time stamps
  • Proof that downstream systems and vendors updated
  • Confirmation sent to the person
Common mistakes
  • Withdrawal by email only, while consent was one tap in an app
  • Stopping in the main system but not in vendor lists
  • Deleting records a law requires you to keep
Related questions

Staff share personal data on WhatsApp and personal email. What do we do?

Short answer: Yes, this is a common breach; give staff a safer option

Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.

From your seat: Customer service department. Never send customer data from personal phones or accounts.
In BFSI

Relationship managers share lead lists and statements on chat. Give them a CRM route.

What the law says

Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Ask teams how they actually share files and photos today.
  2. Provide an approved tool for that job.
  3. Set three simple rules: approved tool, no personal accounts, report wrong sends.
  4. Teach the rules with real examples from your own work.
  5. Treat a quick report as good behaviour, not a disciplinary case.
Evidence to keep
  • Approved-tool policy
  • Training record
  • Incident reports of wrong sends
Common mistakes
  • A ban with no alternative
  • Punishing people who report
  • Ignoring group chats with vendors
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for banking, financial services and insurance.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Prevention of Money-laundering Act, 2002 and RBI KYC Master Direction, 2016Keep transaction records for at least five years from the transaction, and identity records for at least five years after the relationship ends.These periods override an erasure request. Explain the retention to the customer and stop every other use.RBI KYC Master Direction
RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023In force from 1 April 2024 for commercial banks, larger NBFCs, credit information companies and all-India financial institutions. Requires IT governance under the board, audit trails, logging and incident reporting to CERT-In and RBI.Most of the DPDP security duty is already here. Map controls once and use the evidence for both.RBI
RBI Master Direction on Outsourcing of IT Services, 2023The regulated entity stays responsible for outsourced IT, with contracts, audit rights and exit plans.Line up DPDP processor contracts with this direction, so one schedule meets both.RBI
RBI direction on storage of payment system data, 2018All data relating to payment systems must be stored only in India.This is stricter than DPDP Section 16, and it continues to apply.RBI
RBI rules on card storage and tokenisation (from 1 October 2022)Only card issuers and card networks may store actual card data. Others use tokens, created with the cardholder's explicit consent.Check logs, call recordings and support tickets for card numbers.RBI
RBI (Digital Lending) Directions, 2025Collect only need-based data with prior explicit consent and an audit trail. Apps should not access contacts, files, media or call logs; one-time access to camera, microphone or location is allowed for onboarding or KYC with consent.Your app permissions and lending partner contracts are where DPDP and RBI meet.RBI
IRDAI Information and Cyber Security Guidelines, 2023Report cyber incidents to CERT-In within six hours, and to IRDAI within 24 hours of the CERT-In report.One incident plan should run the CERT-In, IRDAI and Data Protection Board steps together.IRDAI
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), 2024Security, logging and incident-reporting duties for SEBI-regulated entities. Stock brokers and depository participants report cyber incidents within six hours.Use CSCRF evidence for DPDP security, then add notices, consent and rights.SEBI
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to Indian time sources.Applies to every BFSI entity in addition to the regulator's own clock.CERT-In
Credit Information Companies (Regulation) Act, 2005Governs what credit information is shared with credit bureaus and how errors are corrected.Credit bureau sharing has its own law; DPDP rights requests about bureau data should point to that process too.Act
RBI Integrated Ombudsman Scheme, 2021Customers can escalate unresolved complaints to the RBI Ombudsman.Privacy complaints may reach both the Ombudsman and the Data Protection Board. One complaint log helps.RBI
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.