5 mins

DPDP Myth Buster: Sectoral Compliance Does Not Exempt BFSI Fiduciaries

Clarifying how the DPDP Act operates alongside RBI and IRDAI frameworks, and why financial entities need distinct consent and breach workflows.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Financial institutions often operate under a false assumption regarding their data protection duties. Compliance teams assume that strict adherence to Reserve Bank of India cybersecurity guidelines exempts them from the Digital Personal Data Protection Act, 2023. This misconception creates major gaps in legal readiness. Industry analyses from K&S Partners and eQomply show banks struggling to reconcile existing KYC frameworks with the new data protection mandates. Reports from Seqrite and DPO India point out a specific friction point. Entities must manage data under the Prevention of Money Laundering Act while facing overlapping obligations under the DPDP Act. The financial sector must implement distinct controls to satisfy both regimes.

The legislation establishes a national baseline that sectoral regulations do not override. Section 4 dictates that a person may process personal data only for a lawful purpose. Fiduciaries must base this processing on either explicit consent or specific legitimate uses. Compliance with an IRDAI or SEBI mandate qualifies as a lawful purpose, but it does not remove the procedural requirements of the DPDP Act. Banks and insurers must still generate itemised notices. They must track consent withdrawals. Financial entities cannot rely on legacy privacy policies designed solely for sectoral compliance to survive a Data Protection Board audit.

Section 17 defines specific exemptions that confuse many regulated entities. Section 17(1)(b) states that provisions of Chapter II and III do not apply to processing by any body in India entrusted by law with a regulatory or supervisory function. This clause protects the operations of the RBI, SEBI, and IRDAI directly. It exempts the regulators. It does not exempt the private banks, mutual funds, or insurers that operate under their supervision. A retail bank remains a Data Fiduciary. It bears the full weight of the legislation when processing customer records.

Financial fiduciaries do receive a narrow carve-out for specific security operations. Section 17(1)(c) permits processing personal data in the interest of prevention, detection, investigation, or prosecution of any offence. Banks rely heavily on this provision. It covers the data processing required for anti-money laundering monitoring and fraud detection under the PMLA. Financial institutions do not need to secure Data Principal consent to analyze a transaction for suspected fraud. The law allows them to process the data without notifying the individual.

This exemption has strict boundaries. Conflating fraud prevention with general commercial processing creates severe legal exposure. A bank uses customer data to run a mandatory KYC check without needing consent. That same bank cannot use the KYC dataset to market retail loans or third-party insurance products without issuing a separate notice. Cross-selling requires distinct consent under Section 4. Segregating these mixed datasets is a primary technical requirement for compliance officers. Fiduciaries must isolate data processed under statutory obligations from data processed under voluntary consent.

Insurance companies face explicit directives regarding these overlapping duties. The IRDAI issued its Information and Cyber Security Guidelines 2023 for regulated entities. These sectoral guidelines mandate that insurers comply fully with the DPDP Act. Consent.in notes that this framework forces insurance providers to harmonize their existing security architectures with the new privacy definitions. An insurer must deploy data protection controls that satisfy the IRDAI audits while generating the exact evidentiary records required by the Data Protection Board.

Breach intimation duties highlight the friction between these dual regimes. Sectoral regulators maintain tight incident reporting windows. The RBI requires banks to report cybersecurity incidents within six hours to the Indian Computer Emergency Response Team. The DPDP Rules, 2025 impose separate notification duties upon the fiduciary. A breached entity must submit a detailed report to the Data Protection Board within 72 hours. It must also notify the affected Data Principals without delay. Financial fiduciaries must build incident response workflows that trigger parallel notifications to the RBI, CERT-In, the DPB, and the affected individuals.

Compliance teams often struggle to integrate consent management within legacy core banking systems. Relying on manual spreadsheets to map RBI mandates against DPDP consent requirements leaves vast gaps in processor oversight. A credible compliance programme isolates consent records and maps third-party data flows automatically. It does this without disrupting the daily transaction processing speeds demanded by the banking sector. Board reporting demands a clear division between data processed under statutory commands and data handled through explicit consent.

Third-party vendor management requires a massive contract overhaul. Banks currently follow RBI guidelines on outsourcing financial services. These guidelines demand risk assessments and audit rights over vendors. The DPDP Act introduces strict vicarious liability under Section 8. A Data Fiduciary remains entirely responsible for any breach caused by a Data Processor. Existing RBI outsourcing contracts lack the specific statutory language required by the DPDP Act. Financial institutions must execute new data processing agreements. These contracts must bind vendors to strict deletion schedules and immediate breach reporting protocols.

Government-owned financial entities cannot assume automatic immunity. Section 17(2)(a) allows the Central Government to exempt specific state instrumentalities in the interests of sovereignty, security, or maintenance of public order. State-owned banks do not automatically fall under this umbrella for their commercial operations. A public sector lender processing retail loan applications faces the exact same notice and consent requirements as a private sector counterpart.

Compliance Checklist for BFSI

1. Map existing RBI and IRDAI data governance controls against the specific notice and consent obligations defined in the DPDP Rules, 2025.

2. Segregate databases used for Section 17 fraud prevention from datasets utilized for marketing and product development.

3. Update all vendor and collection agency agreements to include mandatory DPDP processor duties and strict liability clauses.

4. Implement an incident response protocol that satisfies the 72-hour Data Protection Board notification rule alongside sectoral reporting timelines.

5. Build an audit trail capable of proving that data processed for commercial purposes relies on verified and unwithdrawn consent.

Determine your exact regulatory exposure before the enforcement deadline. Rebuilding core banking systems is rarely required when teams correctly map data flows. Run a gap check at freescan.complydp.com to evaluate your current sectoral frameworks against the DPDP Act.

Sources

Frequently asked questions

Does RBI data localization compliance satisfy DPDP requirements?

Sectoral rules on data storage location operate independently of the Digital Personal Data Protection Act, 2023. Financial institutions must implement distinct controls for consent, itemised notices, and data principal rights under the DPDP Rules, 2025. RBI compliance does not substitute for these procedural obligations.

Can banks use Section 17 exemptions for all data processing?

Section 17 provides narrow exemptions. Processing personal data to investigate offences or enforce legal claims falls under these exemptions. General activities like cross-selling retail loans require explicit consent under Section 4. Fiduciaries must separate these processing purposes.

What are the breach notification timelines for insurers under the new rules?

Insurers must notify the Data Protection Board within 72 hours of a breach. The DPDP Rules, 2025 mandate intimating affected Data Principals without delay. These requirements operate parallel to the existing IRDAI reporting timelines.

How do we manage vendor risk under both regimes?

Existing GRC tools track vendor financial stability, but the new privacy law requires specific contractual controls. Fiduciaries must update vendor agreements to enforce data deletion and breach reporting. Section 8 holds the fiduciary strictly liable for processor failures.

Will implementing DPDP controls disrupt our core banking systems?

A properly scoped compliance programme sits alongside core banking systems rather than replacing them. Teams map data flows and centralise consent records to generate audit trails. This approach builds regulatory readiness without rebuilding legacy infrastructure.