Legal Register
Visual Infographic
I-20 Sector Overlays ๐Ÿ‘ค BFSI Legal Counsel, Compliance Officers & FinTech Architects

Sector Conflict Map (BFSI & FinTech)

Managing Overlaps: DPDP vs RBI KYC/Retention Mandates, PMLA, and CERT-In Directions

Financial sector enterprises do not operate under DPDP in a regulatory vacuum; they must harmonize DPDP rules with preexisting sector regulations from the Reserve Bank of India (RBI), SEBI, IRDAI, and the Prevention of Money Laundering Act (PMLA 2002). The golden rule is 'Map, don't flatten': DPDP Section 8(7) erasure duties yield to statutory retention mandates under PMLA (10-year KYC/transaction retention), while DPDP notice and security standards apply concurrently.

Statutory Source: Ch. 5, Ch. 31
Archetype: sector conflict
I-20 DiagramArchetype: SECTOR CONFLICT

Sector Conflict Map (BFSI & FinTech)

Statutory Conflict Harmonization (Map, Don't Flatten)

KYC & Transaction Retention

DPDP Rule: s.8(7) Erase data upon purpose completion or consent withdrawal
Sector Rule: PMLA s.12 & RBI Master Direction: Retain KYC and records for 5โ€“10 years
โš–๏ธ Harmonization Rule: PMLA retention takes statutory precedence under s.17(1)(b) / s.7(d). Quarantine data in cold compliance vault.

Data Localization

DPDP Rule: s.16(1) Cross-border transfers permitted to all non-blacklisted countries
Sector Rule: RBI 2018 Payment Data Localization: Unconditional storage in India only
โš–๏ธ Harmonization Rule: Strict sector rule applies. Payment system data must remain exclusively stored on Indian servers.

Breach Reporting

DPDP Rule: s.8(6) & r.7 Notify Board and Principals immediately / 72h
Sector Rule: CERT-In 6-hour report + RBI 2-6 hour cyber incident reporting
โš–๏ธ Harmonization Rule: Dual notifications mandatory. Report to CERT-In/RBI within 6h; notify DPBI/Principals under Rule 7.

๐Ÿ’ก Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

โœฆ Where sector laws explicitly mandate data retention, DPDP Section 8(7) erasure is overridden.
โœฆ Quarantined compliance data cannot be used for commercial or analytical purposes.
โœฆ Payment data localization mandates from RBI remain fully binding despite general DPDP transfer rules.

๐Ÿ“œ Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Section 7(b)Section 8(7)Section 17(1)(b)RBI DirectionsPMLA Section 12

๐Ÿ—๏ธ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) โ†’

โš™๏ธ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix โ†’

๐Ÿ› ๏ธ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Tag financial datasets with statutory retention codes (e.g. RET-PMLA-10Y).
  2. Configure automated data quarantine routing for closed lending and deposit accounts.
  3. Align breach incident response playbooks with both RBI and DPDP reporting trees.

Enterprise Traps & Failure Modes

  • โš ๏ธ Blindly deleting core banking records upon customer consent withdrawal, violating PMLA.
  • โš ๏ธ Exporting Indian payment card transactions to global cloud analytics platforms.

๐Ÿ“ Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

๐Ÿ“„ BFSI Sector Regulatory Harmonization Matrix (/sectors/bfsi-fintech/)
๐Ÿ“„ PMLA Retention Override Register
๐Ÿ“„ Payment Data Residency Audit Certificate