6 mins

Mutual Fund Nominee DPDP Consent vs SEBI Nomination Rules

Determine how AMCs must separate SEBI financial nominations from DPDP Section 14 data rights nominations when processing investor data through RTAs like CAMS and KFintech.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Direct Answer for Mutual Fund Operations

Mutual fund nominee data collected by CAMS or KFintech on behalf of Asset Management Companies requires precise categorization under the Digital Personal Data Protection Act, 2023. SEBI mandates financial nominations for mutual fund folios, making the collection of the nominee's details a regulatory requirement. Under Section 14 of the DPDP Act, the investor also holds the right to nominate an individual to exercise their data rights in the event of death or incapacity. The AMC must maintain an audit trail differentiating the SEBI financial nominee from the DPDP data rights nominee, even if the investor designates the same person for both roles.

Deadline and Fiduciary Accountability

Exactly 229 days remain until the DPDP hard compliance deadline of 13 May 2027. Chief Compliance Officers at AMCs face a strict timeline to align legacy RTA integrations with the new data protection framework. The AMC acts as the Data Fiduciary, holding ultimate accountability for compliance and penalty exposure. CAMS and KFintech operate as Data Processors executing transactions and managing folio data. Relying entirely on the processor's internal compliance is legally insufficient. The AMC board expects a central dashboard that proves the RTA collects and manages consent according to the specific parameters set by the fiduciary.

What to Keep vs What to Build for Nomination Workflows

AMCs must decide what to keep and what to build regarding governance versus runtime enforcement. Keep the existing SEBI-compliant financial nomination workflows hosted by the RTAs. Build a centralized governance layer that captures the DPDP Section 14 data rights nomination and links it to the investor's core identity. This requires a control owner within the AMC to update processor contracts. The updated contracts must enforce the generation of verifiable audit trails and itemised notices as prescribed by the Digital Personal Data Protection Rules, 2025. You do not need to rebuild the RTA transaction engine, but you do need an independent system to log the consent and nomination states.

Processing the Nominee's Personal Data

Processing the nominee's personal data demands a clear legal basis. Section 4 states that a person may process personal data only in accordance with the Act and for a lawful purpose. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Collecting a nominee's name, PAN, and contact details to fulfill a SEBI mandate often falls under compliance with existing laws. The AMC must document this specific processing purpose in its Record of Processing Activities to satisfy board-level scrutiny and future regulatory audits. Any secondary use of the nominee's contact data, such as marketing new fund offers to them, requires explicit, itemised consent.

Handling Incapacity Under Section 14

Section 14 defines incapacity as the inability to exercise the rights of the Data Principal under the Act due to unsoundness of mind or infirmity of body. The AMC compliance team must establish a clear protocol for verifying this incapacity before allowing the Section 14 nominee to access data rights. RTAs process millions of folios, meaning the AMC needs an automated way to log the incapacity trigger and shift consent management authority to the nominee. This evidence trail protects the AMC if an investor's legal heirs dispute the data access granted to the nominee. Manual tracking via email or physical forms scales poorly and fails audit requirements.

Itemised Notices in the Investor Onboarding Journey

The DPDP Rules, 2025 introduce specific requirements for itemised notices presented before or at the time of collecting personal data. When a new investor opens a mutual fund folio through an RTA interface, the digital journey must present a clear notice detailing the personal data collected and the purpose for processing. This notice must distinguish between data collected for SEBI compliance and data collected for optional marketing. The AMC Chief Compliance Officer needs proof that this itemised notice appeared in English and all applicable regional languages during the onboarding flow. The compliance platform must store a snapshot of this notice version mapped to the user's consent action.

Acceptance Tests for RTA Oversight

Procurement teams evaluating DPDP compliance platforms for RTA oversight should run specific acceptance tests. 1. Can the system ingest consent artefacts from KFintech or CAMS APIs and link them to the central RoPA of the AMC. 2. Does the platform generate a regulator-ready evidence pack when an investor updates their Section 14 nomination. 3. Can the tool track processor compliance and data processing agreements without requiring a multi-year transformation of existing GRC tools. Passing these tests proves the solution can handle real mutual fund operational workflows rather than generic privacy concepts.

Common Mistake: Treating Withdrawal as Global Delete

A frequent mistake in mutual fund operations is treating a consent withdrawal request as a global delete command. Purpose-level consent tracking is necessary. Withdrawal of consent for marketing communications stops promotional emails but does not mean deleting KYC records, SEBI financial nomination details, or historical transaction logs. The RTA must halt the specified promotional processing while retaining the data required for regulatory compliance and anti-money laundering defense. An AMC failing to map purposes correctly risks deleting legally mandated records or continuing unauthorized marketing, both of which trigger regulatory penalties.

Managing Processor Breach Intimation Obligations

The DPDP Rules, 2025 specify exact obligations for managing third-party processors. AMCs bear the penalty exposure, which can reach 250 crore rupees for severe violations. The compliance team must implement strict oversight mechanisms over all RTAs handling folio data. This oversight includes validating the breach intimation workflows of the processor. If CAMS or KFintech experiences a data breach, the rules require intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours. The AMC needs a system to receive processor alerts and trigger the compliant DPBI notifications within that narrow window.

Enforcing Data Retention and Erasure Schedules

Updating the data processing agreement with RTAs involves more than a standard legal addendum. The contract must mandate that the processor returns or erases personal data upon the completion of the processing purpose, unless retention is necessary for compliance with other laws. Since SEBI rules require long-term retention of transaction data, the AMC must precisely define these retention periods in the processor agreement. The control owner must track whether the RTA executes these retention schedules correctly. The AMC remains liable for any data hoarded beyond the defined lawful purpose, making automated retention tracking a necessary capability.

Next Steps for AMC Compliance

Prepare your AMC for the 13 May 2027 deadline by automating consent records and processor oversight. Discover how our platform generates auditor-ready evidence trails for RTA integrations at https://www.complydp.com/audit-preview and schedule a technical walkthrough with our specialists.

Sources

Frequently asked questions

Does DPDP Act Section 14 replace SEBI mutual fund nominations?

No. The SEBI financial nomination determines who inherits the mutual fund assets. The DPDP Act Section 14 nomination determines who can exercise the investor's data rights in the event of death or incapacity. An AMC must maintain records for both.

How should AMCs handle consent for a nominee's personal data?

Collecting a nominee's basic details to fulfill a SEBI mandate generally falls under compliance with existing law, a legitimate use under Section 7. However, the AMC cannot use the nominee's contact data for secondary purposes, like marketing, without obtaining explicit consent from the nominee.

When is the DPDP Act deadline for asset management companies?

The hard compliance deadline for the DPDP Act is 13 May 2027. By this date, AMCs must have verifiable systems in place for consent management, itemised notices, and processor oversight across all platforms, including CAMS and KFintech.

What happens if an RTA suffers a data breach?

The AMC is the Data Fiduciary and holds the primary regulatory liability. Under the DPDP Rules 2025, a breach requires intimation to affected Data Principals without delay and a detailed report to the Data Protection Board within 72 hours of the fiduciary becoming aware of the breach.

Can an investor withdraw consent for their mutual fund folio?

An investor can withdraw consent for processing activities based on consent, such as marketing. However, this withdrawal does not force the AMC or RTA to delete data required for regulatory compliance, anti-money laundering checks, or legal defense.