Banks keep everything.The law now asks why.

Regulated retention is a reason, not a blanket. Everything outside it now needs its own justification.

In one line: No. Section 8(7) requires erasure when the purpose is served unless retention is necessary for compliance with law. Records a law such as PMLA requires to be kept may be retained for that period and purpose.

The estate · Banking & BFSIHover to inspect

‘The regulator told us to keep it’ covers the KYC file. It does not cover the marketing list built from it.

The scene

A customer closed her account in 2016. Her KYC file was kept, as the law requires. So was her transaction history, her call recordings, a pre-approved loan offer, and her details in three cross-sell campaigns. Only one of those had a statute behind it.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
RBI compliance means DPDPA compliance. Sectoral rules govern specific data; DPDPA governs all personal data and adds rights sectoral rules do not. Map where sectoral law is stricter, and where DPDPA reaches further.
We retain for PMLA, so we retain everything. Retention must serve a purpose; the legal hold covers records the law names. Separate legally-held records from everything that merely stayed.
Our DSAs and agents are independent. Data flowing to sourcing agents and collection partners is processing on your behalf. Contract and audit every hand the data passes through.

Three reporting clocks

A single incident may require reporting to CERT-In, to the RBI and, under DPDPA, to the Board and each affected customer. Each has its own format and timeline. Resilience means one playbook that satisfies all three.

The full Banking & BFSI briefing

3 deep dives
Deep dive 01→

One incident. Three clocks start at once.

The breach is one event. The reporting is three exams, sat at the same time.

Deep dive 02→

The law says keep. The Act asks: keep what, exactly?

‘Required by law’ is a reason for one file. It is not a reason for the building.

Deep dive 03→

Your DSA's phone is inside your perimeter.

The bank signs the licence. The agent holds the phone. The customer holds you responsible.

Monday morning

  1. 01Split the retention register into 'law requires' and 'we chose'.
  2. 02List every third party that receives customer data, including agents.
  3. 03Rehearse one incident against all three reporting clocks.

Questions, answered plainly

Does DPDPA override RBI data retention requirements?

No. Section 8(7) requires erasure when the purpose is served unless retention is necessary for compliance with law. Records a law such as PMLA requires to be kept may be retained for that period and purpose.

Do banks need consent for cross-selling under DPDPA?

Using data collected for account opening to market other products is a new purpose. Unless a legitimate use applies, it generally requires specific consent.

Sector · Fintech & NBFCYour onboarding takes ninety seconds. Your liability lasts years.Read → Sector · Healthcare & PharmaThe Act has no 'sensitive' category. Your patients do.Read → Sector · EdTechA child's data is not a cookie. Stop treating it like one.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner