Enforcement Deadline: 13 May 2027

The DPDP Compliance Checklist Every Company Needs Before May 2027

The DPDP Rules were notified in November 2025. Enforcement begins May 13, 2027. For banks, NBFCs, insurance companies, and fintech firms, this is not a policy exercise — it is a data infrastructure audit. Here is what you actually need to have in place.

₹250Cr
Maximum penalty
per violation
72hrs
Breach notification
to Data Protection Board
5
Obligation buckets
all BFSI firms must satisfy
11mo
Remaining until
full enforcement
Key Dates
Nov 13, 2025 — DPDP Rules notified. Data Protection Board established.
Nov 13, 2026 — Consent Manager Framework operational.
May 13, 2027 — Full enforcement. All obligations active.

Why Businesses Face Greater Exposure Under DPDP

And why the compliance work is harder than most CDOs currently expect.

The Digital Personal Data Protection Act 2023, operationalised by the DPDP Rules notified on November 13, 2025, applies to every organisation that processes the digital personal data of individuals in India. But it lands differently on financial institutions than on any other sector.

Banks, NBFCs, insurance companies, payment aggregators, and fintech firms process more sensitive personal data, across more systems, shared with more third parties, than almost any other class of organisation. A mid-market NBFC with ₹8,000 crore in AUM may be processing KYC records, credit bureau data, transaction histories, loan applications, insurance claims, and payment flows — spread across a core banking system, a CRM, a loan origination system, a credit bureau integration, and a data warehouse that nobody has fully documented.

The DPDP compliance challenge for BFSI is not primarily legal — it is architectural. The Act requires you to know exactly what personal data you hold, where it came from, who has accessed it, and how long you intend to keep it. If your data is ungoverned, unlineaged, and siloed across five systems, you cannot satisfy that requirement — regardless of how well-written your privacy policy is.

₹250Cr
Max penalty for security safeguard failure
72hrs
Window to notify Data Protection Board of breach
90days
To respond to Subject Access Requests
9–12mo
Typical enterprise DPDP programme duration

"DPDP compliance for a mid-market BFSI company is, at its core, a data governance audit. The organisations that pass it are the ones that governed their data before the auditor arrived."

BFSI organisations also face a dual-compliance burden unique to their sector: DPDP obligations must be satisfied simultaneously with existing RBI Master Directions on cybersecurity, digital lending, and payment security. Where the two frameworks touch the same control, the stricter requirement applies.


What Non-Compliance Actually Costs

The DPDP Act does not impose criminal sanctions. It imposes financial penalties — and they are material.

₹250 Crore
~USD 30 million
Failure to implement reasonable security safeguards to prevent personal data breach
Section 8(5)
₹200 Crore
~USD 24 million
Failure to notify the Data Protection Board or Data Principals of a personal data breach
Section 8(6)
₹200 Crore
~USD 24 million
Non-compliance with special provisions for children's data processing
Section 9
₹150 Crore
~USD 18 million
Failure to fulfil additional Significant Data Fiduciary (SDF) obligations
Section 10

The Data Protection Board will determine penalty quantum based on: nature and severity of breach, sensitivity of data affected, number of individuals impacted, repeat offences, financial gain avoided, and mitigation efforts taken. For a mid-market BFSI firm, a single breach notification failure could represent a material proportion of annual operating profit.


The Compliance Timeline — Where You Are Now

Aug 2023
Complete
DPDP Act receives Presidential assent
Act notified. Framework established. 18-month compliance window begins after Rules notification.
Nov 13, 2025
Complete
DPDP Rules 2025 notified. Data Protection Board established.
Phase I effective immediately. Gap assessments must begin now. Typical programme is 9–12 months.
Nov 13, 2026
5 months away
Consent Manager Framework becomes operational
Consent management systems must be production-ready. Organisations may register as Consent Managers.
Dec 2026
Prudent target
Internal audit-readiness target
Starting now means reaching full audit-readiness before enforcement — with buffer for remediation.
May 13, 2027
Hard deadline
Full enforcement — all obligations active
Data Protection Board begins adjudication. All five obligation buckets enforceable. Penalties apply.

🔐
Obligation Bucket 01
Consent & Lawful Basis for Processing
₹250Cr
Max exposure
Complete personal data inventory across all systems
Map every dataset containing personal data — core banking, CRM, LOS, credit bureau integrations, third-party APIs, data warehouses, and legacy systems. You cannot consent to process data you cannot locate.
Critical
Reissue privacy notices in plain language with specific purpose statements
Existing privacy policies are not valid. DPDP Rules require standalone, itemised notices specifying exactly what data is collected and the precise purpose — not a general policy document.
Critical
Implement granular consent management for each processing purpose
One blanket consent at account opening does not cover all downstream processing. Each distinct purpose requires a separate consent record — with timestamp, channel, and withdrawable mechanism.
Critical
Issue retrospective notices for data processed before DPDP Rules
Rules require retrospective notices for personal data collected before November 2025. Every customer whose data you currently hold must receive a notice meeting the new standard.
High
Establish data lineage from consent record to every downstream use
When a regulator asks "what consent authorised this use of this customer's data?", you must trace the answer automatically — from consent through every transformation and system to the output. This requires governed data lineage, not a spreadsheet.
Critical
Execute Data Processing Agreements (DPAs) with all third-party processors
Every credit bureau, collection agency, loan service provider, IT vendor, and outsourcing partner must have a DPDP-compliant DPA: 24-hour breach notification, sub-processor disclosure, audit rights, 30-day deletion on contract termination.
Critical
👤
Obligation Bucket 02
Data Principal Rights Management
₹250Cr
Max exposure
Right to Access — respond within 90 days
Customers can request a summary of all personal data you hold and a list of processors you've shared it with. Response within 90 days. Without a governed data layer querying all source systems, manual fulfilment will not scale.
High
Right to Correction and Erasure — 90-day response window
Customers can request correction of inaccurate data and erasure when processing purpose is fulfilled or consent withdrawn. Erasure must cascade to all Data Processors — requiring full processor data mapping per individual.
High
Right to Grievance Redressal — appoint and publish a Grievance Officer
A Grievance Officer must be appointed, made contactable, and published in every privacy notice. All complaints must be acknowledged and resolved within defined timelines.
High
Right to Nominate — implement nominee management for account data
Data Principals can nominate another individual to exercise their rights in the event of death or incapacity. BFSI firms must have a process intersecting with existing KYC and account operations frameworks.
Medium
Build a unified Subject Access Request workflow across all systems
The 90-day window is tight across multiple disconnected systems. Without a governed data layer that can query all source systems for a given individual, SAR fulfilment becomes a manual, error-prone, unscalable process.
Critical
🛡
Obligation Bucket 03
Reasonable Security Safeguards
₹250Cr
Max exposure
Encryption at rest and in transit for all personal data
Personal data must be encrypted across all systems and transmission channels — including legacy systems, data warehouses, backup stores, and all third-party integrations, not just production databases.
Critical
Role-based access controls with least privilege enforcement
Access to personal data must be limited to roles that require it for defined purposes. Audit access controls across all systems. Remove standing access for roles that no longer require it. Document the policy and control implementation.
Critical
Audit logging retained for minimum 1 year
Audit logs covering all access to and processing of personal data must be retained for at least 1 year, tamper-evident and searchable. In a breach investigation, these logs are the primary evidence available to the Data Protection Board.
Critical
Data minimisation — collect only what the purpose requires
Audit all data collection points across customer journeys. Data collected without a clearly defined, documented purpose must be eliminated. Over-collection is a compliance risk, not just a storage cost.
High
Implement purpose-based retention and automated erasure
Personal data must be erased when its processing purpose is fulfilled, consent withdrawn, or the individual has not engaged within the retention period. Automated erasure must cascade to all processors. Manual deletion is not compliant at scale.
Critical
Annual security due diligence for all Data Processors
Annual security audits of processors handling personal data are required. Maintain a current register of all processors and sub-processors. Obtain prior written consent before engaging new sub-processors.
High
🚨
Obligation Bucket 04
Personal Data Breach Notification
₹200Cr
Max exposure
Notify Data Protection Board within 72 hours of breach discovery
Detailed breach notification must reach the DPB within 72 hours of becoming aware. Must include affected data categories, estimated number of individuals, nature of breach, and remedial actions. This is 72 hours to notify — not to investigate.
Critical
Notify affected Data Principals without undue delay
Individuals whose data was compromised must be notified individually. For a BFSI firm with thousands of customers, this requires an automated notification workflow identifying affected individuals from breach logs.
Critical
Receive processor breach notifications within 24 hours
Data Processors must notify you within 24 hours of breach discovery — before your 72-hour DPB clock starts. Verify all DPAs include this obligation and that processors can actually meet it.
High
Establish and test a breach response playbook
72 hours does not allow time to write a response plan after a breach. A tested playbook covering detection, scoping, notification drafting, regulatory contact, and customer communication must exist before May 2027.
High
Obligation Bucket 05 — SDF Only
Significant Data Fiduciary Obligations
₹150Cr
Max exposure
Determine whether you will be designated a Significant Data Fiduciary
SDF designation is based on volume and sensitivity of personal data and risk to data principals. Most mid-market banks, NBFCs, and insurance companies should plan for SDF designation. Prepare for enhanced obligations now — do not wait for formal designation.
SDF
Appoint a Data Protection Officer (DPO) based in India
SDFs must appoint a DPO resident in India who reports to the highest management body and is contactable by the Data Protection Board and by Data Principals.
SDF
Conduct annual Data Protection Impact Assessments (DPIAs)
Annual DPIAs for high-risk processing are mandatory for SDFs — requiring documented data flows, processing purposes, risk assessments, and mitigation measures. Without a governed data layer, producing this evidence is an enormous manual exercise every year.
SDF
Engage an independent data auditor annually
SDFs must commission annual independent data audits and share significant observations and gaps with the Data Protection Board periodically.
SDF
Conduct algorithmic fairness assessments for automated decisions
Credit scoring, loan approvals, insurance underwriting, and fraud detection algorithms must be assessed and documented for fairness — including their data inputs, which must be governed and traceable.
SDF

The Data Infrastructure Gap Most CDOs Are Underestimating

DPDP compliance is not a legal exercise. It is a data governance exercise.

The checklist above reads straightforwardly. The implementation challenge is that most mid-market BFSI companies cannot satisfy these obligations with their current data infrastructure — not because of policy gaps, but because their data is ungoverned, unlineaged, and distributed across systems that have never been connected.

DPDP Obligation Infrastructure required Typical mid-market gap
Personal data inventoryAutomated discovery and cataloguing across all structured and unstructured sourcesNo catalog — manual spreadsheet only
Consent-to-use lineageEnd-to-end traceable lineage from consent record to every downstream systemNo lineage — data provenance unknown
Subject Access RequestAutomated query across all systems for a given individual within 90 daysManual process — not scalable
Automated erasurePurpose-based retention with cascade deletion to all processorsNo automated retention enforcement
Breach scope identificationIdentify all affected individuals and systems within hours of a breachPartial — individual system logs, no unified view
Annual DPIA evidence (SDF)Documented data flows and processing purposes — automatically maintainableNo governed data flow documentation
Access control audit trail1-year audit log of all personal data access, unified and queryablePartial — exists in some systems, not unified
How SCIKIQ addresses the infrastructure gap
Governed data infrastructure is DPDP compliance infrastructure

SCIKIQ's Connect-Curate-Control-Consume platform addresses the data infrastructure requirements that underpin DPDP compliance natively. Full data lineage, role-based access controls, audit trails, data catalog with ownership and classification, and automated retention policies are included in the core platform — not sold as separate modules. A mid-market NBFC deploying SCIKIQ connects to core banking, CRM, LOS, and third-party systems non-invasively — no migration, no source system modification — and builds governed lineage automatically from the first connection. The same governed data layer that satisfies DPDP audits also enables AI activation on clean, trustworthy data.


The RBI Dual-Compliance Layer

Mid-market banks and NBFCs must satisfy DPDP alongside existing RBI frameworks. Where the two touch the same control, the stricter requirement applies.

Control AreaRBI RequirementDPDP RequirementApproach
Breach notificationNotify RBI within 2–6 hours of cyber incidentNotify DPB within 72 hoursRBI is stricter — but both must be satisfied
Audit loggingPer RBI Cybersecurity FrameworkMinimum 1 year retentionAligned — implement once for both
EncryptionAES-256 mandated for sensitive dataReasonable safeguards specifiedRBI more prescriptive — satisfies both
Vendor oversightRBI outsourcing guidelinesDPAs with all processorsAdditive — DPAs complement RBI guidelines
Data classificationRBI requires classification policyPersonal data must be classifiedAligned — one exercise covers both
Consent managementNot specifically addressedGranular, purpose-specific consentDPDP adds new requirement — build fresh

BFSI DPDP Readiness Self-Assessment

Honest answers to these questions determine how much work remains before May 2027.

QuestionIf YesIf No / Partial
Do you have a current, complete inventory of all personal data across all systems?Foundation in placeFirst priority — nothing else is possible without it
Can you trace any customer data record from source through every transformation?Lineage capability existsConsent-to-use lineage unachievable — critical gap
Can you respond to a Subject Access Request across all systems within 90 days?SAR workflow manageableManual works at low volume — fails at customer scale
Do all third-party processors have signed DPAs with 24-hour breach notification?Vendor compliance coveredStart immediately — 100+ vendors takes months
Do you have automated erasure cascading deletion to all processors?Retention compliance achievableManual erasure at customer scale is not compliant
Have you assessed whether you will be designated a Significant Data Fiduciary?SDF programme can beginAssume SDF — do not wait for formal designation
Is your breach response playbook tested with automated notification workflows?72-hour window is manageable72 hours is not enough time to build the process after a breach

"The organisations that sail through a DPDP audit in 2027 are the ones governing their data in 2026. The audit doesn't create the requirement — it reveals whether the infrastructure was ever there."

Start with a governed data layer

DPDP compliance starts with data you can see, trace, and govern.

SCIKIQ connects to your core banking, CRM, and third-party systems non-invasively and builds governed lineage from day one — the infrastructure DPDP compliance actually requires.

Talk to us → sales@scikiq.com

Success!

Thank you for subscribing!