The DPDP Compliance Checklist Every Company Needs Before May 2027
The DPDP Rules were notified in November 2025. Enforcement begins May 13, 2027. For banks, NBFCs, insurance companies, and fintech firms, this is not a policy exercise — it is a data infrastructure audit. Here is what you actually need to have in place.
Why Businesses Face Greater Exposure Under DPDP
And why the compliance work is harder than most CDOs currently expect.
The Digital Personal Data Protection Act 2023, operationalised by the DPDP Rules notified on November 13, 2025, applies to every organisation that processes the digital personal data of individuals in India. But it lands differently on financial institutions than on any other sector.
Banks, NBFCs, insurance companies, payment aggregators, and fintech firms process more sensitive personal data, across more systems, shared with more third parties, than almost any other class of organisation. A mid-market NBFC with ₹8,000 crore in AUM may be processing KYC records, credit bureau data, transaction histories, loan applications, insurance claims, and payment flows — spread across a core banking system, a CRM, a loan origination system, a credit bureau integration, and a data warehouse that nobody has fully documented.
The DPDP compliance challenge for BFSI is not primarily legal — it is architectural. The Act requires you to know exactly what personal data you hold, where it came from, who has accessed it, and how long you intend to keep it. If your data is ungoverned, unlineaged, and siloed across five systems, you cannot satisfy that requirement — regardless of how well-written your privacy policy is.
"DPDP compliance for a mid-market BFSI company is, at its core, a data governance audit. The organisations that pass it are the ones that governed their data before the auditor arrived."
BFSI organisations also face a dual-compliance burden unique to their sector: DPDP obligations must be satisfied simultaneously with existing RBI Master Directions on cybersecurity, digital lending, and payment security. Where the two frameworks touch the same control, the stricter requirement applies.
What Non-Compliance Actually Costs
The DPDP Act does not impose criminal sanctions. It imposes financial penalties — and they are material.
The Data Protection Board will determine penalty quantum based on: nature and severity of breach, sensitivity of data affected, number of individuals impacted, repeat offences, financial gain avoided, and mitigation efforts taken. For a mid-market BFSI firm, a single breach notification failure could represent a material proportion of annual operating profit.
The Compliance Timeline — Where You Are Now
The Data Infrastructure Gap Most CDOs Are Underestimating
DPDP compliance is not a legal exercise. It is a data governance exercise.
The checklist above reads straightforwardly. The implementation challenge is that most mid-market BFSI companies cannot satisfy these obligations with their current data infrastructure — not because of policy gaps, but because their data is ungoverned, unlineaged, and distributed across systems that have never been connected.
| DPDP Obligation | Infrastructure required | Typical mid-market gap |
|---|---|---|
| Personal data inventory | Automated discovery and cataloguing across all structured and unstructured sources | No catalog — manual spreadsheet only |
| Consent-to-use lineage | End-to-end traceable lineage from consent record to every downstream system | No lineage — data provenance unknown |
| Subject Access Request | Automated query across all systems for a given individual within 90 days | Manual process — not scalable |
| Automated erasure | Purpose-based retention with cascade deletion to all processors | No automated retention enforcement |
| Breach scope identification | Identify all affected individuals and systems within hours of a breach | Partial — individual system logs, no unified view |
| Annual DPIA evidence (SDF) | Documented data flows and processing purposes — automatically maintainable | No governed data flow documentation |
| Access control audit trail | 1-year audit log of all personal data access, unified and queryable | Partial — exists in some systems, not unified |
SCIKIQ's Connect-Curate-Control-Consume platform addresses the data infrastructure requirements that underpin DPDP compliance natively. Full data lineage, role-based access controls, audit trails, data catalog with ownership and classification, and automated retention policies are included in the core platform — not sold as separate modules. A mid-market NBFC deploying SCIKIQ connects to core banking, CRM, LOS, and third-party systems non-invasively — no migration, no source system modification — and builds governed lineage automatically from the first connection. The same governed data layer that satisfies DPDP audits also enables AI activation on clean, trustworthy data.
The RBI Dual-Compliance Layer
Mid-market banks and NBFCs must satisfy DPDP alongside existing RBI frameworks. Where the two touch the same control, the stricter requirement applies.
| Control Area | RBI Requirement | DPDP Requirement | Approach |
|---|---|---|---|
| Breach notification | Notify RBI within 2–6 hours of cyber incident | Notify DPB within 72 hours | RBI is stricter — but both must be satisfied |
| Audit logging | Per RBI Cybersecurity Framework | Minimum 1 year retention | Aligned — implement once for both |
| Encryption | AES-256 mandated for sensitive data | Reasonable safeguards specified | RBI more prescriptive — satisfies both |
| Vendor oversight | RBI outsourcing guidelines | DPAs with all processors | Additive — DPAs complement RBI guidelines |
| Data classification | RBI requires classification policy | Personal data must be classified | Aligned — one exercise covers both |
| Consent management | Not specifically addressed | Granular, purpose-specific consent | DPDP adds new requirement — build fresh |
BFSI DPDP Readiness Self-Assessment
Honest answers to these questions determine how much work remains before May 2027.
| Question | If Yes | If No / Partial |
|---|---|---|
| Do you have a current, complete inventory of all personal data across all systems? | Foundation in place | First priority — nothing else is possible without it |
| Can you trace any customer data record from source through every transformation? | Lineage capability exists | Consent-to-use lineage unachievable — critical gap |
| Can you respond to a Subject Access Request across all systems within 90 days? | SAR workflow manageable | Manual works at low volume — fails at customer scale |
| Do all third-party processors have signed DPAs with 24-hour breach notification? | Vendor compliance covered | Start immediately — 100+ vendors takes months |
| Do you have automated erasure cascading deletion to all processors? | Retention compliance achievable | Manual erasure at customer scale is not compliant |
| Have you assessed whether you will be designated a Significant Data Fiduciary? | SDF programme can begin | Assume SDF — do not wait for formal designation |
| Is your breach response playbook tested with automated notification workflows? | 72-hour window is manageable | 72 hours is not enough time to build the process after a breach |
"The organisations that sail through a DPDP audit in 2027 are the ones governing their data in 2026. The audit doesn't create the requirement — it reveals whether the infrastructure was ever there."
DPDP compliance starts with data you can see, trace, and govern.
SCIKIQ connects to your core banking, CRM, and third-party systems non-invasively and builds governed lineage from day one — the infrastructure DPDP compliance actually requires.
Talk to us → sales@scikiq.comSuccess!
Thank you for subscribing!