InfraVeritas360DPDPiq

DPDP Insights › Banking, financial services and insurance › Marketing department

Banking, financial services and insurance

DPDP for the Marketing department in BFSI

Marketing in BFSI is where consent is tested most.

Open this seat in the interactive tool

What is different here

You hold identity, money and sometimes health data, and you already answer to RBI, SEBI or IRDAI. DPDP does not replace that supervision. It adds one new thing: each customer can now ask you directly what you hold, who you shared it with, and complain if the answer is poor.

The first four things to sort out

  1. Use only lists with consent records.
  2. Separate service messages from offers.
  3. Respect TRAI preference rules for calls and SMS.
  4. Check partner and agency contracts.

A worked example: An agency offers a list of salaried professionals

  1. Day 1Marketing asks for consent proof.
  2. Day 2The agency cannot provide it.
  3. Day 3The list is declined.
  4. AfterOnly consent-backed lists are used.

Evidence kept: Request; Reply; Decision.

No consent proof, no campaign.

What others in the sector usually do. Banks are running consent-only campaigns and tracking stop requests closely.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Scheduled commercial bankCross-selling insurance and mutual funds on account terms; Business correspondent devices and paper forms in villages; Old core banking archives with no deletion path
Co-operative bank (urban or rural)Vendor-run core banking with admin access from the vendor's office; Member and share registers kept on open shelves; Directors and staff who are also members and relatives of borrowers
NBFC and digital lenderApps asking for contacts, photos and call logs; Collection agents sharing borrower details with family or employers; Leads bought from aggregators with no consent record
Insurance company (life, general or health)Medical reports passed to TPAs and hospitals by email; Agent and broker access to policyholder data; Claims data kept long after the claim is closed
Broking, depository and wealthAuthorised persons with client lists on personal phones; Research-tip calls to people who never consented; Client KYC copies shared over email with partners
Payments and fintechCard numbers in logs and support tickets; Merchant onboarding documents in shared drives; Fraud models that use data beyond what users were told

8 guides for the Marketing department, in full

Can we cross-sell insurance, cards or mutual funds to existing customers?

Short answer: Only with separate, specific consent

Only with specific consent for that purpose. Account opening terms do not count as consent to receive offers or to have data shared with a partner insurer or fund house. Service messages about the customer's own account are different and do not need marketing consent.

From your seat: Marketing department. No campaign leaves without a consent check.
What the law says

Section 6 needs specific consent for each purpose. Section 5 needs a notice that names the purpose. Section 6 · Section 5 · Rule 3 · Section 8(1)–(2)

Steps
  1. Separate service messages from offers in your systems.
  2. Ask consent for offers and partner sharing separately, by channel.
  3. Record consent by purpose and partner.
  4. Check the record before each campaign.
  5. Pass withdrawals to partners the same day.
Evidence to keep
  • Consent records by purpose and partner
  • Campaign approval with consent check
  • Withdrawal logs
Common mistakes
  • Using account terms as consent
  • Partners calling from their own lists
  • Withdrawal not reaching partners
Related questions

What can our lending or banking app collect from a phone?

Short answer: Need-based only, with explicit consent

Only what you need, with explicit consent. RBI's Digital Lending Directions already bar access to contacts, files, media and call logs, and allow one-time access to camera, microphone or location for onboarding or KYC. DPDP adds a notice, the right to withdraw and the right to know what was collected.

What the law says

Section 6 needs consent limited to what is necessary. RBI's Digital Lending Directions, 2025 set specific limits. Section 6 · Section 5 · Rule 3 · Section 8(5) · Rule 6

Steps
  1. List every permission the app asks for.
  2. Remove permissions not needed.
  3. Ask camera and location only at the KYC step.
  4. Show the notice in the app before sign-up.
  5. Check partner apps the same way.
Evidence to keep
  • Permission list with reasons
  • App store listing
  • Partner app review
Common mistakes
  • Contacts permission for 'reference checks'
  • Third-party analytics SDKs collecting device data
  • Partner apps not reviewed
Related questions

Can we send offers to past customers and leads?

Short answer: Only with separate consent and an easy way to stop

Marketing needs consent that is separate and specific, unless the person clearly expects it from the relationship. Bought or scraped lead lists are risky because you cannot show consent. Every message should carry an easy way to stop.

From your seat: Marketing department. Every campaign list needs a consent source. If you cannot say where the consent came from, do not use the list.
In BFSI

Telemarketing must follow TRAI's preference rules as well as DPDP consent.

What the law says

Section 6 sets the consent standard. Section 5 needs a notice. Section 9 bars targeted advertising at children. Section 6 · Section 5 · Rule 3 · Section 9 · Rules 10, 12

Steps
  1. Separate service messages from marketing messages.
  2. Ask marketing consent separately, with a clear action.
  3. Stop using bought lists unless the seller can show consent for you.
  4. Add an easy stop option to every message.
  5. Respect the telecom preference rules for calls and SMS.
Evidence to keep
  • Marketing consent records
  • Lead source records
  • Stop requests and their handling
Common mistakes
  • Treating account sign-up as marketing consent
  • Agency lists with no consent proof
  • A stop option that does not work
Related questions

Someone withdraws consent. What has to stop, and how fast?

Short answer: Stop that use quickly, across every system and vendor

Withdrawal must be as easy as giving consent. Once someone withdraws, you and every vendor working for you must stop that use within a reasonable time. What was done before withdrawal stays lawful, and data that a law requires you to keep is kept.

From your seat: Marketing department. Make the stop option work across every channel and agency within a day.
In BFSI

A customer taps 'stop offers' in the app. The dialler, SMS tool and partner insurer must all stop within a day.

What the law says

Section 6(4) to 6(6) give the right to withdraw at any time, with the same ease, and require processors to stop as well. Section 8(7) then asks for erasure unless a law requires retention. Section 6 · Section 8(7) · Rule 8 · Section 8(1)–(2)

Steps
  1. Give one simple way to withdraw on every channel where consent is taken.
  2. Record the withdrawal against the person and the purpose.
  3. Push the change to every system and vendor that uses that purpose.
  4. Confirm to the person, in writing, what has stopped and what is kept by law.
  5. Check a sample every month to see that the change actually reached every list.
Evidence to keep
  • Withdrawal log with time stamps
  • Proof that downstream systems and vendors updated
  • Confirmation sent to the person
Common mistakes
  • Withdrawal by email only, while consent was one tap in an app
  • Stopping in the main system but not in vendor lists
  • Deleting records a law requires you to keep
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Marketing department. Landing pages, contest forms and event sign-ups each need a short notice.
In BFSI

A bank's account opening form, its mobile app sign-up and its loan application each need their own short notice, separate from the terms and conditions.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your customers actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: Marketing department. Switch off targeting for under-18 audiences and avoid tracking them.
In BFSI

Minor savings accounts and student loans involve children's data. Parent consent and no targeted offers apply.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Marketing department. Agencies, ad platforms and event partners receive data. Their contracts need data terms.
In BFSI

Collection agencies, BCs, DSAs, KYC vendors, card processors and the core banking vendor all need data schedules aligned with RBI outsourcing rules.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for banking, financial services and insurance.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
Prevention of Money-laundering Act, 2002 and RBI KYC Master Direction, 2016Keep transaction records for at least five years from the transaction, and identity records for at least five years after the relationship ends.These periods override an erasure request. Explain the retention to the customer and stop every other use.RBI KYC Master Direction
RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023In force from 1 April 2024 for commercial banks, larger NBFCs, credit information companies and all-India financial institutions. Requires IT governance under the board, audit trails, logging and incident reporting to CERT-In and RBI.Most of the DPDP security duty is already here. Map controls once and use the evidence for both.RBI
RBI Master Direction on Outsourcing of IT Services, 2023The regulated entity stays responsible for outsourced IT, with contracts, audit rights and exit plans.Line up DPDP processor contracts with this direction, so one schedule meets both.RBI
RBI direction on storage of payment system data, 2018All data relating to payment systems must be stored only in India.This is stricter than DPDP Section 16, and it continues to apply.RBI
RBI rules on card storage and tokenisation (from 1 October 2022)Only card issuers and card networks may store actual card data. Others use tokens, created with the cardholder's explicit consent.Check logs, call recordings and support tickets for card numbers.RBI
RBI (Digital Lending) Directions, 2025Collect only need-based data with prior explicit consent and an audit trail. Apps should not access contacts, files, media or call logs; one-time access to camera, microphone or location is allowed for onboarding or KYC with consent.Your app permissions and lending partner contracts are where DPDP and RBI meet.RBI
IRDAI Information and Cyber Security Guidelines, 2023Report cyber incidents to CERT-In within six hours, and to IRDAI within 24 hours of the CERT-In report.One incident plan should run the CERT-In, IRDAI and Data Protection Board steps together.IRDAI
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), 2024Security, logging and incident-reporting duties for SEBI-regulated entities. Stock brokers and depository participants report cyber incidents within six hours.Use CSCRF evidence for DPDP security, then add notices, consent and rights.SEBI
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to Indian time sources.Applies to every BFSI entity in addition to the regulator's own clock.CERT-In
Credit Information Companies (Regulation) Act, 2005Governs what credit information is shared with credit bureaus and how errors are corrected.Credit bureau sharing has its own law; DPDP rights requests about bureau data should point to that process too.Act
RBI Integrated Ombudsman Scheme, 2021Customers can escalate unresolved complaints to the RBI Ombudsman.Privacy complaints may reach both the Ombudsman and the Data Protection Board. One complaint log helps.RBI
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.