DPDP Insights › Banking, financial services and insurance › Practical examples
Five documents most organisations in this sector need before 13 May 2027.
Examples to adapt, not legal advice. Replace the text in square brackets with your own details.
We collect your name, address, date of birth, PAN, Aadhaar or other ID, photograph, mobile number, email and income details to open and run your account, to meet KYC and anti-money-laundering laws, and to protect you against fraud. We share them with the regulator, tax authorities and credit bureaus where the law requires.
We will send you offers for insurance, cards or investments, or share your details with our partners for their offers, only if you tick the separate box below. You can withdraw that consent any time in the app, at a branch or by calling us.
You can ask what we hold about you, ask us to correct it, or complain to our Grievance Officer at [contact]. If you are not satisfied, you may approach the Data Protection Board of India.
| Ref | Date in | Customer ID | Type | Systems searched | Owner | Reply due | Status |
|---|---|---|---|---|---|---|---|
| PR-0142 | 03-11-2026 | verified | Who received my data | CBS, cards, CRM, partner log | DPO team | within published period | Replied day 9 |
| PR-0143 | 04-11-2026 | verified | Stop offers | Consent store, dialler | Service desk | same day | Closed day 1 |
| PR-0144 | 05-11-2026 | pending | Delete closed account | CBS archive | DPO team | within published period | KYC kept under PMLA; reply sent |
| Record | Keep for | Why |
|---|---|---|
| Identity and KYC records | At least 5 years after the relationship ends | PMLA and RBI KYC Master Direction |
| Transaction records | At least 5 years from the transaction | PMLA |
| Marketing consent records | As long as consent is used, plus a short buffer | Proof of consent |
| Call recordings | Fixed period set by policy and regulator guidance | Complaints and quality |
| Unsuccessful applications | Short period, then erase | Purpose over |
| Access and activity logs | At least 1 year; ICT logs 180 days in India | DPDP Rules; CERT-In |
The Agency shall process Customer Personal Data only to contact the borrower about the amount due under this Agreement and for no other purpose. It shall not disclose the debt to any person other than the borrower, shall not use the borrower's phone contacts, shall follow the Bank's conduct code including calling hours, and shall keep reasonable security safeguards. It shall inform the Bank of any personal data breach within [6] hours of becoming aware. On closure of the account, or on termination, it shall return or delete all Customer Personal Data within 15 days and confirm in writing.
Dear customer, on [date] we found that a partner's system exposed your name, account number and balance for about [hours]. Your password, PIN and card details were not affected. We closed the access at once and have informed CERT-In, [regulator] and the Data Protection Board. You do not need to change your PIN, but please be careful of calls asking for OTPs; we will never ask for them. For questions, contact our Grievance Officer at [contact].