All articles
ComplianceEpisode 2 of 5· 14 min read
DPDP Rules 2025 for Fintech, BFSI & NBFC

DPDP Rules 2025 Episode 2: Continuous Data Governance for BFSI

Why your regulator already requires continuous governance, and how to run five regimes as one programme.

AS
Ankita Sharma
Talk to an expert
4
Regimes
Already requiring continuous ops
70%
Overlap
Same controls, four labels
6h
Tightest clock
CERT-In from detection
1
Control library
Evidence once, map many

In Episode 1 we mapped DPDP against RBI, SEBI, PMLA and CERT-In, and set the rule: DPDP layers on top, and where regimes touch the same control, the stricter one binds.

Continuous governance is not a philosophy for BFSI. RBI mandates continuous auditing. SEBI mandates continuous monitoring and a measurable maturity score. CERT-In mandates 180 days of logs in India. DPDP extends the same evidentiary discipline to personal data. This is the baseline your supervisor already expects.

Why manual compliance collapses in regulated finance

Every company outgrows spreadsheets. Financial entities outgrow them faster, for structural reasons.

Unsynchronised audit cadences

IS Audit, CSCRF cyber audit, VAPT, Board reviews, and now DPDP DPIA if you are an SDF. A sprint model means you are permanently sprinting.

Evidence fragmented by design

Consent in product DB, retention with eng, deletion in logs, vendors in procurement, access in a spreadsheet. Nobody owns the join.

Environment outruns docs

New LSP, co-lender, offshore analytics, new app permission. Static docs do not track this. Your regulator assumes they do.

The failure mode is not missing controls. It is unprovable controls. SEBI asked you to prove security on a schedule examiners can read. DPDP does the same for personal data.

What your regulators already mandate

Four regulators already told you to run continuously. The work is unifying mandates that overlap by about 70%, not inventing a new model.

In force 1 Apr 2024Banks, SFBs, payments banks, NBFCs Top/Upper/Middle, CICs, AIFIs
  • Board and committee IT governance
  • Continuous auditing
  • Risk-based IS Audit policy (ACB)
  • Periodic VA/PT
  • Vendor concentration and SPOF risk
  • Cyber incident root-cause analysis

A mid-sized NBFC with a broking arm is being told to do the same thing four times. Continuous governance is how you stop.

Collect evidence once. Map it many times.

SEBI's 28 August 2025 CSCRF clarifications added Equivalence: where similar controls are already mandated by another regulator, that compliance can count under CSCRF. Exclusivity narrows CSCRF to systems used exclusively for SEBI-regulated activities. The control is the unit of compliance, not the framework.

1
Control library
Framework-agnostic
2
Evidence once
From source systems
3
Map many ways
RBI · SEBI · DPDP · CERT-In · ISO

Design one control library, one evidence pipeline, many framework mappings. Contradictory policies across regimes are themselves an enforcement exposure.

Data discovery in a real BFSI estate

Classify each dataset on four axes: category and sensitivity, purpose, system location and owner, processor involvement.

Core banking / LOS / LMSOften no purpose segmentation
KYC repositoriese-KYC, DigiLocker, CKYC
Account Aggregator pullsFIP / FIU flows
Credit bureau exchangesAlso CIC Act 2005
Fraud & underwriting modelsDevice and alt data
Collections stackDialler, CRM, references
LSP / DLA layerApp you may not own
Warehouses, support, backupsQuiet copies
Legacy core trap

Cores predate consent granularity. Realistic answer: a consent management layer between customer apps and the core, enforcing purpose at the boundary the core cannot.

Purpose drift

Fraud data later feeding collections breaches RBI conduct and DPDP purpose limitation. Purpose mapping catches drift before a regulator does.

Wire rights into RBI machinery. Do not rebuild it.

You already run nodal officers, Internal Ombudsman, and RBI CMS. Integrate DPDP into that stack: dual categorisation at intake, stricter timeline (DPDP caps at 90 days), and automated fulfilment with evidence.

Rights fulfilment path
Request
Identity verify
Dual classify
Route owners
Automate action
Evidence artefact
Respond in SLA

Nomination has no GDPR analogue. It needs a real product surface. Easy to forget, trivially auditable.

Retention orchestration (preview of Episode 3)

Field-level reconciliation, not a policy paragraph. Legal obligation lets you refuse erasure for regulated fields only if you erase non-essential fields, document the basis, and prove both.

Retention lifecycle
1Collect
2Purpose-tag
3Store (India)
4Monitor
5Legal-hold
6Retain
7Erase
8Log evidence

Continuous detection: the clock starts whether you are watching

Your detection capability, not your policy library, determines whether you can comply. One trigger, one runbook, four channels with pre-drafted templates.

2 to 6h
RBI / SEBI
Sectoral cyber-incident report
6h
CERT-In
9-field initial cyber notice
ASAP
DPB + users
Intimation without delay
72h
DPB
Detailed breach report

Vendor, LSP and processor governance

ITGRCA requires vendor risk including concentration and SPOF. Outsourcing never diminishes your obligations. CSCRF adds SBOM for critical apps. DPDP Rule 6 makes processor contracts mandatory. Contract processors to notify you within one hour. Your six-hour clock does not wait for theirs.

Continuous vendor register fields
Data categories processed
Lawful basis and purpose
Fiduciary / Processor / joint
Storage location (India?)
Sub-processors
Breach-notification SLA to you
Audit rights
Deletion and exit obligations
SBOM and vulnerability posture
Concentration exposure

Measure with metrics regulators already ask for

Do not invent a scorecard. SEBI published the Cyber Capability Index. A maturity score you cannot evidence is worse than no score at all.

CCI / maturity with linked evidenceCSCRF; must be substantiable
Mean time to detect (MTTD)SEBI examiners ask directly
Alerts closed; SOC shift coverageProof continuous is literal
% data encrypted / tokenisedRule 6 and CSCRF Protect
Rights and grievance fulfilment timeDPDP ≤ 90-day cap
Consent coverage (versioned)Rule 3 + RBI audit trail
Retention enforcement; deletion logsRule 8 + sectoral retention
Vendor risk coverage + breach SLAsITGRCA + Rule 6
Evidence automation rateLeading indicator for everything else

The continuous governance operating model

Source systems feed a framework-agnostic control library and continuous evidence pipeline, then map out to RBI, SEBI, DPDP, CERT-In, and ISO / SOC 2.

Ownership (RACI)
FunctionBoardCISODPOEngCompliance
IT & cyber policy (ITGRCA)ARCCR
Consent artefact & ledgerICARC
Retention matrix & erasureICARR
SOC / detection & CCIARCCC
Breach fan-out (4 clocks)IRRCA
Vendor / LSP riskARCCR

If you are an SDF, the DPO's Board reporting line hard-wires privacy into governance.

The first 90 days

See it, unify it, automate it. Then use the runway to July 2026, November 2026, and May 2027 to harden, not scramble.

0%
1 Jul 2026
NBFC consent

Explicit, per-product, affirmative consent with withdrawable audit trail.

13 Nov 2026
Consent Managers

Interoperable give, review, manage, withdraw consent.

13 May 2027
Full DPDP regime

Harden on the runway. Do not scramble.

Compliance as a commercial asset

Faster partner diligence

Bank partners and co-lenders run the same questionnaires. An evidenced maturity score answers in days, not quarters.

Audit prep collapses

Evidence collected continuously is evidence you do not reconstruct under deadline.

Product ships faster

Privacy and security review becomes a gate the pipeline already satisfies.

Insurance and underwriting

Demonstrable, evidenced maturity beats attestations alone.

Next: Episode 3 on data retention and deletion, the field-level reconciliation of DPDP erasure against RBI KYC, PMLA and SEBI retention. This episode reflects DPDP Rules 2025, RBI ITGRCA Directions 2023, Digital Lending Directions 2025, SEBI CSCRF (as amended through Aug 2025), NBFC-AA / ReBIT specs, and CERT-In 2022 Directions. General information only, not legal advice.

See how Bugmetrics maps RBI + SEBI + DPDP into one control set

One control library, one evidence pipeline, many framework mappings. Consent, retention, rights, and vendor posture as live state.

Book a demo

Or explore Bugmetrics for Fintech & BFSI

Keep reading

Episode 3 · 16 min

Data retention & deletion for BFSI: the field-level problem nobody solves

Episode 1 · 12 min

DPDP Rules 2025: The Dual Compliance Playbook

Episode 4 · 18 min

Breach readiness & the four-clock incident runbook