| Prevention of Money-laundering Act, 2002 and RBI KYC Master Direction, 2016 | Keep transaction records for at least five years from the transaction, and identity records for at least five years after the relationship ends. | These periods override an erasure request. Explain the retention to the customer and stop every other use. | RBI KYC Master Direction |
| RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023 | In force from 1 April 2024 for commercial banks, larger NBFCs, credit information companies and all-India financial institutions. Requires IT governance under the board, audit trails, logging and incident reporting to CERT-In and RBI. | Most of the DPDP security duty is already here. Map controls once and use the evidence for both. | RBI |
| RBI Master Direction on Outsourcing of IT Services, 2023 | The regulated entity stays responsible for outsourced IT, with contracts, audit rights and exit plans. | Line up DPDP processor contracts with this direction, so one schedule meets both. | RBI |
| RBI direction on storage of payment system data, 2018 | All data relating to payment systems must be stored only in India. | This is stricter than DPDP Section 16, and it continues to apply. | RBI |
| RBI rules on card storage and tokenisation (from 1 October 2022) | Only card issuers and card networks may store actual card data. Others use tokens, created with the cardholder's explicit consent. | Check logs, call recordings and support tickets for card numbers. | RBI |
| RBI (Digital Lending) Directions, 2025 | Collect only need-based data with prior explicit consent and an audit trail. Apps should not access contacts, files, media or call logs; one-time access to camera, microphone or location is allowed for onboarding or KYC with consent. | Your app permissions and lending partner contracts are where DPDP and RBI meet. | RBI |
| IRDAI Information and Cyber Security Guidelines, 2023 | Report cyber incidents to CERT-In within six hours, and to IRDAI within 24 hours of the CERT-In report. | One incident plan should run the CERT-In, IRDAI and Data Protection Board steps together. | IRDAI |
| SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), 2024 | Security, logging and incident-reporting duties for SEBI-regulated entities. Stock brokers and depository participants report cyber incidents within six hours. | Use CSCRF evidence for DPDP security, then add notices, consent and rights. | SEBI |
| CERT-In Directions, 28 April 2022 | Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to Indian time sources. | Applies to every BFSI entity in addition to the regulator's own clock. | CERT-In |
| Credit Information Companies (Regulation) Act, 2005 | Governs what credit information is shared with credit bureaus and how errors are corrected. | Credit bureau sharing has its own law; DPDP rights requests about bureau data should point to that process too. | Act |
| RBI Integrated Ombudsman Scheme, 2021 | Customers can escalate unresolved complaints to the RBI Ombudsman. | Privacy complaints may reach both the Ombudsman and the Data Protection Board. One complaint log helps. | RBI |