InfraVeritas360DPDPiq

DPDP Insights › Banking, financial services and insurance › Practical examples

Banking, financial services and insurance

Practical examples for BFSI

Five documents most organisations in this sector need before 13 May 2027.

Examples to adapt, not legal advice. Replace the text in square brackets with your own details.

EXAMPLE · NOT LEGAL ADVICE

Notice wording: Savings account opening (branch or app)

We collect your name, address, date of birth, PAN, Aadhaar or other ID, photograph, mobile number, email and income details to open and run your account, to meet KYC and anti-money-laundering laws, and to protect you against fraud. We share them with the regulator, tax authorities and credit bureaus where the law requires.

We will send you offers for insurance, cards or investments, or share your details with our partners for their offers, only if you tick the separate box below. You can withdraw that consent any time in the app, at a branch or by calling us.

You can ask what we hold about you, ask us to correct it, or complain to our Grievance Officer at [contact]. If you are not satisfied, you may approach the Data Protection Board of India.

EXAMPLE

Request and complaint log

RefDate inCustomer IDTypeSystems searchedOwnerReply dueStatus
PR-014203-11-2026verifiedWho received my dataCBS, cards, CRM, partner logDPO teamwithin published periodReplied day 9
PR-014304-11-2026verifiedStop offersConsent store, diallerService desksame dayClosed day 1
PR-014405-11-2026pendingDelete closed accountCBS archiveDPO teamwithin published periodKYC kept under PMLA; reply sent
EXAMPLE · NOT LEGAL ADVICE

Retention schedule

RecordKeep forWhy
Identity and KYC recordsAt least 5 years after the relationship endsPMLA and RBI KYC Master Direction
Transaction recordsAt least 5 years from the transactionPMLA
Marketing consent recordsAs long as consent is used, plus a short bufferProof of consent
Call recordingsFixed period set by policy and regulator guidanceComplaints and quality
Unsuccessful applicationsShort period, then erasePurpose over
Access and activity logsAt least 1 year; ICT logs 180 days in IndiaDPDP Rules; CERT-In
EXAMPLE · NOT LEGAL ADVICE

Vendor data clause

The Agency shall process Customer Personal Data only to contact the borrower about the amount due under this Agreement and for no other purpose. It shall not disclose the debt to any person other than the borrower, shall not use the borrower's phone contacts, shall follow the Bank's conduct code including calling hours, and shall keep reasonable security safeguards. It shall inform the Bank of any personal data breach within [6] hours of becoming aware. On closure of the account, or on termination, it shall return or delete all Customer Personal Data within 15 days and confirm in writing.

EXAMPLE · NOT LEGAL ADVICE

Breach notice to affected people

Dear customer, on [date] we found that a partner's system exposed your name, account number and balance for about [hours]. Your password, PIN and card details were not affected. We closed the access at once and have informed CERT-In, [regulator] and the Data Protection Board. You do not need to change your PIN, but please be careful of calls asking for OTPs; we will never ask for them. For questions, contact our Grievance Officer at [contact].

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.