India's financial institutions already answer to RBI, SEBI, IRDAI and CERT-In. The DPDPA adds a fifth master — one that thinks in terms of consent and erasure, not prudence and retention. This visual deep dive maps the obligations, the overlaps, and the collisions for banks, NBFCs, insurers and fintechs.
The DPDPA does not replace a single sectoral rule. Section 38 makes it additional to existing law — and where the two genuinely conflict, the DPDPA prevails to the extent of the conflict. In practice, most conflicts dissolve because retention or disclosure mandated by another law is itself a lawful ground under the Act. The working principle: where both regimes touch the same control, the stricter standard governs.
FIG. 1 — The BFSI regulatory stack after the DPDPA
The DPDP Rules, 2025 were notified on 13 November 2025 with phased implementation. Consent architecture and vendor repapering in a bank realistically take 12–18 months — which makes the final deadline a present-day obligation, not a future one.
FIG. 2 — Phased implementation of the DPDP Rules, 2025 (watch for the proposed compression of the SDF window floated by MeitY in early 2026)
KYC, AML reporting and tax compliance run on the “legitimate use” of complying with law — no fresh consent needed, but only within what the law actually mandates. Section 17 adds exemptions for enforcing claims, fraud investigation, and — crucially for lenders — tracing the finances of loan defaulters. Everything else, from cross-selling to alternative-data underwriting, needs specific, unbundled, withdrawable consent.
FIG. 3 — Lawful basis decision flow for a financial institution
“An Account Aggregator licence from RBI is not a Consent Manager registration from the Data Protection Board. Entities wanting both roles must satisfy both regulators.”
Seven controls, four regulators, one rule of thumb: sectoral frameworks are usually stricter on security and incident clocks; the DPDPA is stricter on consent and individual rights. The “Which bar is higher?” column tells you where the genuinely new work sits.
| Theme | DPDPA / DPDP Rules | RBI | SEBI | IRDAI | Which bar is higher? |
|---|---|---|---|---|---|
| Consent | Free, specific, unbundled, withdrawable (S.6) | Digital lending: explicit, need-based; AA framework | Largely consent-light (legal mandates) | Proposal-form consent, health data norms | DPDPA Rebuild flows to S.6 standard |
| Retention & erasure | Erase when purpose served, unless law requires (S.8(7), S.12) | KYC/PMLA: 5 yrs post-relationship | Trade & KYC record retention | Long-duration policy/claim records, held in India | BOTH Retain the mandated, erase the rest |
| Localisation | Blacklist model; stricter sectoral rules preserved (S.16) | Payment data India-only (2018); lending data in India | CSCRF storage expectations | Insurance records in India | SECTORAL Continues to bind in full |
| Breach reporting | Notify Board + affected individuals; detailed report within 72 hrs | 2–6 hour incident reporting | CSCRF incident reporting | Cyber guideline reporting | SECTORAL on speed; DPDPA adds notifying customers |
| Security standards | “Reasonable safeguards” + Rule minimums (encryption, access, logs) | IT Governance MDs; cyber framework | CSCRF controls | Info & Cyber Security Guidelines 2023 | SECTORAL usually exceeds DPDPA minimums |
| Grievance | Fiduciary mechanism with timelines → Data Protection Board | Internal ombudsman; RBI-IOS | SCORES | Bima Bharosa / ombudsman | PARALLEL Route privacy grievances without breaking sectoral clocks |
| Audit & governance | SDFs: India DPO, independent audit, DPIA | IS/system audits, board IT governance | Systems audits | Statutory & IS audits | CONSOLIDATE One calendar, extended scopes |
TABLE 1 — DPDPA vs. RBI / SEBI / IRDAI across seven compliance themes
The same incident at a multi-licensed financial group can trigger reporting to four bodies on four different timelines. Build one internal trigger that fans out to every regulator, with the tightest clock — RBI's — as the binding constraint. Log fidelity matters: if your SIEM cannot reconstruct the intruder's path, you cannot file a defensible 72-hour report.
FIG. 4 — The breach fan-out: rewrite playbooks as multi-regulator workflows, not single-regulator checklists
DPDPA exposure sits on top of RBI, SEBI and IRDAI enforcement, not instead of it. The Schedule's ceilings apply per instance, and a single serious incident can breach multiple heads at once — a safeguards failure plus a notification failure alone stacks to \u20B9450 crore of statutory headroom before any sectoral regulator has even opened a file.
FIG. 5 — Maximum penalties under the Schedule, per instance of contravention
| Order | Move | Why it's on the critical path |
|---|---|---|
| 1 | Data inventory mapped to lawful basis | The statutory-mandate vs. consent classification decides what survives an erasure request and which flows need rebuilding. |
| 2 | Repaper the processor ecosystem | Contract cycles with core banking vendors, TPAs, LSPs and bureaus take quarters, not weeks. Start earliest. |
| 3 | Consent layer, not core surgery | Build notice-and-consent as a layer between channels and core systems rather than re-engineering legacy platforms. |
| 4 | Unified breach playbook | One trigger, four regulators, tightest clock binding. Test it in a tabletop before it tests you. |
| 5 | Rights & grievance workflows | Must interoperate with existing ombudsman channels without breaking either regime's timelines. |
| 6 | SDF readiness in parallel | DPO recruitment, DPIA methodology and audit-partner selection shouldn't wait for the notification to land. |
TABLE 2 — Six moves, sequenced by BFSI's real critical path: the vendor web and the legacy core
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Regulatory positions under the DPDPA, the DPDP Rules, 2025 and sectoral frameworks continue to evolve, and obligations vary by entity type, licence and notification status. Consult qualified legal counsel for advice on your specific circumstances.