AMLEGALS — Strategic Lawyering

DPDPA for Banks and BFSI: Where Retention Meets Erasure

DPDPA for Banks and BFSI: Where Retention Meets Erasure

‘The regulator told us to keep it’ covers the KYC file. It does not cover the marketing list built from it.

The scene

A customer closed her account in 2016. Her KYC file was kept, as the law requires. So was her transaction history, her call recordings, a pre-approved loan offer, and her details in three cross-sell campaigns. Only one of those had a statute behind it.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

RBI compliance means DPDPA compliance.

Sectoral rules govern specific data; DPDPA governs all personal data and adds rights sectoral rules do not.

Map where sectoral law is stricter, and where DPDPA reaches further.

We retain for PMLA, so we retain everything.

Retention must serve a purpose; the legal hold covers records the law names.

Separate legally-held records from everything that merely stayed.

Our DSAs and agents are independent.

Data flowing to sourcing agents and collection partners is processing on your behalf.

Contract and audit every hand the data passes through.

Three reporting clocks

A single incident may require reporting to CERT-In, to the RBI and, under DPDPA, to the Board and each affected customer. Each has its own format and timeline. Resilience means one playbook that satisfies all three.

The full Banking & BFSI briefing 3 deep dives

Deep dive 01 →

One incident. Three clocks start at once.

The breach is one event. The reporting is three exams, sat at the same time.

Deep dive 02 →

The law says keep. The Act asks: keep what, exactly?

‘Required by law’ is a reason for one file. It is not a reason for the building.

Deep dive 03 →

Your DSA's phone is inside your perimeter.

The bank signs the licence. The agent holds the phone. The customer holds you responsible.

Monday morning

01 Split the retention register into 'law requires' and 'we chose'.

02 List every third party that receives customer data, including agents.

03 Rehearse one incident against all three reporting clocks.

Questions, answered plainly

Does DPDPA override RBI data retention requirements? +

No. Section 8(7) requires erasure when the purpose is served unless retention is necessary for compliance with law. Records a law such as PMLA requires to be kept may be retained for that period and purpose.

Do banks need consent for cross-selling under DPDPA? +

Using data collected for account opening to market other products is a new purpose. Unless a legitimate use applies, it generally requires specific consent.

Sector · Fintech & NBFC Your onboarding takes ninety seconds. Your liability lasts years. Read →

Sector · Healthcare & Pharma The Act has no 'sensitive' category. Your patients do. Read →

Sector · EdTech A child's data is not a cookie. Stop treating it like one. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).