Legal Register
Part VI — Sector Playbooks & Integrated Implementation Cases
Part VI — Sector Playbooks & Integrated Implementation Cases
Chapter 31 · 2,689 words
13 min read

Chapter 31 — Banking, NBFCs, Fintech and Insurance Sector Playbook

1. Reconciliation, not another checklist

Financial-services teams are accustomed to overlapping obligations. The useful question is not whether a bank already has a privacy policy, but which entity, activity, record and recipient each obligation actually covers. A lending consent, a Key Facts Statement (KFS), a recovery-agent disclosure and a security incident report may concern the same customer without being interchangeable documents. The playbook preserves that distinction all the way to execution.

The DPDP timing baseline matters. On the retained schedule, core private-sector obligations and rights commence eighteen months after the Gazette issue dated 13 November 2025; these chapters use 13 May 2027 as the source-based scheduled date, not as an observed future legal event (COMM:19,49–59).[2] The Rules separately defer rr3,5–16,22–23; the corrigendum corrects the publication wording, rather than accelerating those duties (RULES:1005–1010; CORR:25–38).[3][4] The cases below assume that schedule remains unchanged. Existing sector obligations must not be postponed until DPDP starts.

Read each sector row as an applicability decision. A company selling insurance is not thereby the insurer underwriting it; a fintech label does not identify a licence; an NBFC is not automatically a securities intermediary. Section 38 adds compatible law and gives DPDP precedence to the extent of conflict, whereas s16(2) specifically preserves higher protection or restrictions on overseas transfer. It is not a general instruction to select whichever sector rule sounds stricter (ACT:515–522,887–892).[1]

Financial records can be consequential and difficult to replace. That supports proportionate safeguards and voluntary readiness, not an assertion that this sector is uniquely sensitive or certain to receive SDF designation. Section 10 requires Government notification; volume and sensitivity are assessment factors, not a self-executing designation test (ACT:404–438).[1] CASE-001’s fictional Company, ENT-001, remains not_designated. Its independent insurer ENT-002 has its own role and obligations. The fixed identities come from research/legal/DOSSIER_CONTRACT.md; none denotes a real regulated business.

2. Select the operative instrument before the control

The retained May 2025 Digital Lending Directions provide a useful historical cross-sector anchor: paragraph 3 names commercial banks, specified cooperative banks, NBFCs including HFCs and All-India Financial Institutions; paragraph 2 has separate commencement provisions (RBI-DL:153–161).[5] However, the Company’s NBFC case uses the later Reserve Bank of India (Non-Banking Financial Companies – Credit Facilities) Directions, 2025, as retained at this review. Its Chapter III supplies the operative lending rows used here; its repeal/saving provisions prevent treating an earlier general circular as the sole current authority (RBI-NBFC:255–335,614–623).[6] For this bounded teaching overlay, ENT-001 is additionally stipulated to be a customer-facing NBFC-ICC, not an excluded Type I NBFC; its prudential layer remains unspecified. Paragraph 3 includes NBFC-ICCs and distinguishes partial/excluded classes (RBI-NBFC:167–190).[6] This is a practical source-version lesson: carry forward the obligation only after comparing the successor’s wording, applicability and exceptions. Do not copy a paragraph number between instruments.

out/sector/SECTOR_OVERRIDES.xlsx and its accompanying CSV contain provision, applicability, source, owner, control, evidence category and limitations. “Mapped” means a bounded source-backed row, not complete entity compliance. The workbook includes banking, NBFC, insurance and securities distinctions rather than claiming every rule governs every financial firm. The source manifest retains retrieval dates and hashes; source keys and physical newline ranges are defined in out/remediation/Q06/source-index.json.

For implementation, give the compliance owner the actual licence and activity facts. Give engineering the approved row version, not a PDF title. Where the row is conditional, the system must not turn “not yet checked” into “not applicable.” This is an author-recommended release discipline. The retained instruments do not prescribe the workbook schema.

For the fictional NBFC’s digital lending, paragraph 9(1) requires a KFS under the referenced responsible-business-conduct directions. Paragraph 13 requires need-based collection with prior explicit borrower consent and an audit trail, purpose disclosure at each interface stage, borrower choices, and explicit consent before third-party sharing except where a statutory or regulatory requirement requires it (RBI-NBFC:276–310).[6] DPDP s6 separately defines the consent standard and, in s6(10), the fiduciary’s proof obligation when consent is questioned in a proceeding (ACT:206–218,264–268).[1] Presenting a KFS cannot prove the affirmative processing grant; a grant cannot substitute for the KFS. Link their references to the loan application but retain each object’s identity.

The source is also more concrete than a generic privacy checkbox. Paragraph 13(1) excludes access to listed mobile resources such as contact lists and call logs; its limited one-time access route concerns facilities necessary for onboarding/KYC and explicit consent. A customer clicking “allow everything” does not erase that boundary (RBI-NBFC:306–310).[6] The proposed control denies a contact-list upload even when a broad consent token is supplied. Consent is one necessary decision input, not a permission to violate another rule.

An LSP is described by RBI as acting on the lender’s behalf for specified lending functions. The NBFC must define roles and obligations contractually, perform enhanced due diligence and periodic review, and remains responsible for the LSP’s acts and omissions (RBI-NBFC:232–233,257–264).[6] Under DPDP, fiduciary/processor status still turns on actual purpose and means and acting on behalf; s8(2) requires a valid contract for its specified processor engagement, rather than making every supplier a processor by definition (ACT:65–81,330–337).[1]

Consider two activities by one supplier. Collections under the Company’s instructions is an assumed processor activity. Building the supplier’s own cross-client credit product is independent purpose-setting and needs a separate fiduciary analysis. Passing the original consent hash to that product does not authorise it. In the populated decision pack, independent reuse is stopped. The contract does not convert it into collection work merely by calling both activities “analytics.”

4. A collections reconciliation that can be inspected

The old claim about circular “RBI/2025/12,” a universal processor-level collection trail and a universal seven-year RBI window is withdrawn as unsupported. No claim is made that every similarly named instrument is nonexistent. The replacement uses the retained NBFC provisions and distinguishes proposed evidence from their literal requirements.

ActivitySource-backed obligationRecommended evidence and boundary
OriginationKFS and specified digital documents; prior explicit data consentSeparate KFS reference, notice version, borrower action and application identity; no combined “compliance certificate”
Recovery assignmentCommunicate recovery-agent particulars before contact, including a change of agentDispatch/receipt state linked to the assigned agent; missing delivery is investigated, not narrated as success
LSP operationAgreement, due diligence, review and retained NBFC responsibilityActivity-specific role record and access scope; supplier reuse remains denied
StorageMinimal permitted LSP borrower information; disclosed storage/use/destruction policySeparate lender archive from LSP operational view; no blanket copy of the full credit file

The first two rows derive from paragraphs 9 and 13; the latter rows from paragraphs 6 and 14 (RBI-NBFC:257–264,276–288,306–315).[6] The table is not a delivered contract-generation engine. Its completed specimen records are in out/sector/Q06_DECISIONS.json; any production automation still needs implementation, adversarial testing and operational ownership.

A settled loan illustrates why “take the longer period” is inadequate. The retention owner must first identify the record class and source of each minimum, the triggering event, a compatible disposal rule and any hold. The Act’s banking illustration is not itself a current KYC retention schedule for every NBFC. This chapter does not substitute a new unsourced number for the removed seven-year claim (ACT:351–368).[1]

In the post-commencement teaching case, r8(3)‘s minimum one-year processing/data/log retention and r6(1)(e)‘s security-purpose retention must be considered separately, alongside applicable sector law (RULES:1101–1106,1153–1166).[3] Restriction from marketing is not physical erasure. Nor should an LSP receive or retain impermissible full borrower files merely because the lender has a retention duty. Counsel and architecture owners must reconcile where each required archive belongs. An unresolved archive-location conflict prevents approving that proposed supplier storage, not all incident containment or borrower assistance.

5. Underwriting: data quality is not a fairness certificate

Section 8(3) addresses completeness, accuracy and consistency of personal data likely to affect a decision about the principal or be disclosed to another fiduciary. It does not literally require a model to be “free of discrimination,” nor does it define an AUC threshold (ACT:338–342).[1] RBI-NBFC paragraph 8 requires necessary borrower economic-profile information, including age, occupation and income, kept for audit. Paragraph 7 separately regulates multi-lender offer presentation and consistent matching; those are real requirements, not a numerical model-fairness certification regime (RBI-NBFC:265–275).[6]

The former sector-defined ROC-AUC >0.78, disparity >5%, price-per-record audit tag, fairness certification code, quarterly reporting API and automatic reweight-until-compliant workflow are removed. They had no exact retained authority. CIMS reporting under paragraph 18 is real DLA reporting, with an officer certification and no RBI endorsement implied; it is not a quarterly fairness API (RBI-NBFC:325–335).[6]

Author-recommended model governance should be more demanding than ceremonial numbers. Record the intended decision, lawful input uses, input-quality failures, model version, outcome definition, validation population, selection effects, uncertainty, complaints and a human escalation route. Training and serving require separate authority decisions. Claims history does not become a permissible loan feature merely because an insurer holds it. An inference can itself be personal data; calling it a score does not remove accuracy and purpose questions.

The hypothetical underwriting specimen uses SUB-001, PUR-001 and PUR-004. A stale income field conflicts with the applicant’s updated information. The proposed response is to pause that automated decision, reconcile the source and reassess the input-dependent outcome, not automatically approve credit or claim a statutory algorithmic appeal. PUR-003 model training remains stopped for lack of an approved grant. This is a populated decision specimen, not an executed credit-model gate. The separate local fixtures compute no model-performance result and use no repayment telemetry.

If a firm chooses statistical thresholds, the validation owner must justify them for the actual population and harm. A global average can conceal a failure in a small subgroup; a label can reflect historic exclusion rather than truth. No reweighting loop proves legal fairness, and a score passing a test cannot cure unlawful inputs. Voluntary review is valuable precisely when it can reject a model that the business prefers.

6. Parallel reporting without invented universal clocks

An incident is not automatically reportable to three regulators. Apply each recipient’s actor and event trigger, commencement and current channel separately. DPDP r7, when operative, requires affected-principal and initial Board information without delay after awareness of any personal-data breach; the detailed Board update is due within seventy-two hours unless the Board allows longer on written request (RULES:1112–1139).[3] CERT-In direction (ii) applies to its listed entities and Annexure I cyber incidents, with reporting within six hours of noticing or being brought to notice. Direction (iv) separately requires ICT logs securely retained for a rolling 180 days within India (CERT:71–103,161–199).[7] Neither clock is restarted by containment. Nor is the 180-day rule permission to erase evidence that another applicable law requires for longer.

For RBI’s retained IT Governance Directions, paragraph 27(d) requires proactive CERT-In and RBI reporting as per regulatory requirements, within its entity scope; the text includes a distinct HFC recipient footnote. Do not manufacture a numerical RBI clock from that paragraph or apply its covered NBFC layers to every small lender (RBI-IT:169–183,346–351 and footnote 17).[11] The Company case does not stipulate its RBI layer. Its RBI supervisory clock/recipient row therefore requires entity-specific completion before a live drill can be accepted as complete. No simulated RBI filing is claimed here.

Securities firms have a separate example. CSCRF’s RS.CO guidelines specify CERT-In-triggered notification to SEBI and CERT-In within six hours and portal detail within twenty-four hours, with additional exchange/depository routing for brokers/participants (SEBI-CSCRF:5126–5137).[8] The 24 August 2026 circular introduces FIRE-aligned staged portal reporting; it must be read before reusing the older reporting form (SEBI-FIRE:83–162).[12] The August 2025 clarification also requires a scoped exclusivity/equivalence analysis for multi-regulator entities, not casual elimination of duplicate controls (SEBI-CLAR:94–119,159–162).[9] CASE-001 is not assumed SEBI-registered, so these are alternate-sector rows, not extra compulsory recipients for its incident.

For INC-001, the dossier distinguishes occurrence, detector alert, breach awareness, containment and specimen preparation. The sector supplement sets CERT-In noticing to the existing 09:10 alert only as an explicit hypothetical fact that the alert already identifies a reportable leak. Its deadline is calculated separately from the 09:20 DPDP awareness timestamp. A failed principal delivery remains failed. Local deadline arithmetic is not evidence that any regulator or principal received a message.

7. Insurance is a distinct decision chain

The retained IRDAI policyholder regulations apply to insurers and distribution channels with the stated reinsurance exclusion and commencement rule. Regulation 15 requires protected confidentiality and restricts sharing proposal information without explicit policyholder consent, with listed exceptions including underwriting and settling a claim; it remains subject to extant data-protection law and prohibits a default sharing clause in the proposal (IRDAI:1084–1090,1299–1310).[10] This is not a blanket DPDP ground for every insurer use. A sector exception from one consent restriction and DPDP processing authority require separate decisions.

In FLOW-006 the Company refers an adult customer to ENT-002 under separately recorded PUR-010 authority. ENT-002 determines its underwriting/claims purposes; it is not made a Company processor by receiving a referral. In the hypothetical claim-support branch, the claimant seeks help transmitting specified supporting documents. The distribution team routes only the necessary package to the identified insurer; the insurer evaluates its own applicable consent/authority and the regulation 15 exception. It does not export the entire clinical history back to the lender for credit scoring.

The claim owner lists the necessary documents and procedure, gives claim-stage information and avoids piecemeal requests, consistent with regulations 22–23 (IRDAI:1397–1414).[10] The author-designed specimen records a missing document and an unresolved claim, rather than asserting timely settlement. Claim settlement, policy cancellation, marketing withdrawal and data erasure are separate events. Removing marketing authority does not instruct the claim handler to destroy the submitted evidence; retaining claim evidence does not permit new marketing. The retention row records an unresolved product/record-specific sector period and, in the future DPDP branch, the identified Rules layer. It authorises neither indefinite retention nor automatic erasure.

This chapter does not assert a current IRDAI cyber deadline from the old 2023 framework. Search surfaced later cyber-guideline amendments, but their full authoritative chain was not established in this packet. The insurer’s cyber reporting route is expressly outside this bounded verified overlay and must be completed before production reliance. The verified IRDAI claims here are the retained policyholder regulation provisions, not a fabricated cybersecurity certificate.

8. Reader handoff and acceptance boundary

The delivered overlay and decision pack make the next conversation concrete: which record, whose purpose, which source version, which owner, and what happens when evidence is missing? Their useful output includes refused reuse, a paused credit decision, scoped claim support and an incomplete supervisory route. That is more informative than an invented all-green walkthrough.

Use the local test command in out/sector/README.md to exercise the teaching gates and clocks. Its result is only observed local test evidence. No contract engine, bias engine, regulator integration or production ledger is delivered. Independent book review remains separate.

Before applying this playbook, complete the actual entity’s licences, RBI layer, product-specific retention instruments, applicable reporting channels and subsequent amendments. Those are explicit deployment prerequisites; they do not restore any unsupported numerical requirement removed above. The next chapter applies the same purpose discipline where reuse itself is often the proposed revenue source: retail, advertising and loyalty.

Source locator key

Ranges above are physical newline lines, starting at 1; PDF form feeds do not add lines. Full source URLs follow. The retained text and hashes are indexed in out/remediation/Q06/source-index.json.

Sources

[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf — ACT [2] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — COMM [3] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — RULES [4] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — CORR [5] https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12848&Mode=0 — rbi-digital-lending [6] https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12957 — rbi-nbfc-credit [7] https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf — cert-directions [8] https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf — sebi-cscrf [9] https://www.sebi.gov.in/sebi_data/attachdocs/aug-2025/1756380695925.pdf — sebi-clarifications [10] https://financialservices.gov.in/sites/default/files/Act-Policies/2026-01/IRDAI—Protection-of—Policyholder-s-Interests—operations-and-allied-matters-of-insurers—Regulations—2024.pdf — irdai-policyholders [11] https://www.rbi.org.in/scripts/BS_ViewMasDirections.aspx?id=12562 — rbi-it [12] https://www.sebi.gov.in/sebi_data/attachdocs/aug-2026/1787569463244.pdf — sebi-fire


Contents · Reader guide and citation conventions · Artifact index