Banking, financial services and insurance
DPDP compliance for banks, NBFCs, fintechs and insurers
Financial firms hold the most sensitive identifiers there are, under sector rules that already demand a lot. The DPDP Act adds its own duties on top, and the largest firms may be notified as Significant Data Fiduciaries.
The data you hold
- Aadhaar and PAN from KYC
- Bank account and card numbers
- UPI IDs
- Income and credit history
- Nominee details
What the Act asks of you
- Safeguards that match the data
- Identifiers and financial data cause the most harm when leaked. The Rules set minimum safeguards, including encryption, access control, monitoring and one year of logs.
- Section 8(5), Rule 6
- Keep what the law requires, erase the rest
- Sector rules may require records to be kept for years. The Act allows that, but data kept for no legal reason must be erased once its purpose ends.
- Section 8(7)
- Report breaches to the Board too
- A personal data breach has to be reported to the Data Protection Board and to each affected person, with a detailed report within 72 hours, alongside whatever your sector regulator requires.
- Section 8(6), Rule 7
- Significant Data Fiduciary duties
- If notified as a Significant Data Fiduciary because of volume or sensitivity, a firm needs a Data Protection Officer based in India, and a DPIA and an independent audit every year.
- Section 10, Rule 13
How GRC Flow handles it
Discovery checks Aadhaar with its checksum, and finds PAN, UPI IDs and card numbers (Luhn check).
See how it worksThe breach register runs the 72-hour clock; the DPIA register tracks reviews and residual risk.
See how it worksThe risk register scores each gap by likelihood and impact, with an owner and a due date.
See how it works