Answer in one line: BFSI entities must separate mandated / legitimate-use processing (KYC, AML, collections where applicable) from consent-based cross-sell and analytics, keep a purpose-and-retention register, and erase only when law allows — while cascading DSRs to KYC SaaS, cloud, and BPA vendors under Section 8(2).

Built from the BFSI industry map in the DPDP Handbook for compliance, risk, and digital product teams.


Why BFSI cannot reuse a generic CMP playbook

Retail banking and lending already collect high-sensitivity identifiers. Regulated retention often overrides a customer erase request. Marketing teams that treat KYC phone numbers as an ESP list create dual-use risk the Board will not ignore.


Figure 1 — BFSI purpose streams

Figure 1. Bank / NBFC / insurer — purpose streams, basis classes, and retention register
flowchart TD
  HUB([Bank / NBFC / insurer / broker]) --> P1[KYC / AML / CKYC]
  HUB --> P2[Account / policy / loan]
  HUB --> P3[Payments / cards]
  HUB --> P4[Cross-sell / analytics]
  HUB --> P5[Collections / recovery]
  HUB --> P6[Employees / agents]
  HUB --> P7[Vendors: KYC SaaS / cloud / BPA]
  P1 --> B1[Sec 7 or mandated retention]
  P2 --> B2[Sec 6 consent for that product]
  P3 --> B2
  P4 --> B3[Fresh specific consent]
  P5 --> B1
  P6 --> B4[Employment notice + basis]
  P7 --> B5[DPA + Sec 8-2 chain]
  B1 --> REG[(Purpose + retention register)]
  B2 --> REG
  B3 --> REG
  B4 --> REG
  B5 --> REG
  REG --> CORE[Core / CRM / collections / vendors]
  CORE --> Q{Purpose ends or DSR?}
  Q -->|Law requires keep| KEEP([Retain that record class only])
  Q -->|Erase allowed| ER([Erase + notify processors])
  class HUB,P1,P2,P3,P4,P5,P6,P7,B1,B2,B3,B4,B5,CORE act;
  class Q dec;
  class REG start;
  class KEEP,ER ok;
  classDef start fill:#DBEAFE,stroke:#2563eb,color:#0f172a;
  classDef act fill:#EFF6FF,stroke:#3B82F6,color:#1e3a8a;
  classDef dec fill:#FEF3C7,stroke:#D97706,color:#78350f;
  classDef ok fill:#D1FAE5,stroke:#059669,color:#064e3b;
  classDef stop fill:#FEE2E2,stroke:#DC2626,color:#7f1d1d;
  classDef note fill:#F1F5F9,stroke:#64748B,color:#334155;

Purpose classes that must stay separate

StreamTypical basisRetention note
KYC / AML / CKYCSec 7 / mandatedKeep for statutory period
Account / policy / loan servicingConsent or contract-aligned purposeLifecycle of relationship + law
Cross-sell / analyticsFresh specific Sec 6 consentShorter; honour withdrawal
CollectionsOften Sec 7 / mandated pathDo not mix with marketing lists
Employees / agents / vendorsEmployment notice or DPARole-based access + exit erase

Figure 2 — Lawful basis and retention gate

Figure 2. BFSI processing gate — Sec 7 vs Sec 6, then retain or erase
flowchart TD
  A([Processing decision]) --> B{Purpose lawful and specific?}
  B -->|No| X([Stop - do not collect])
  B -->|Yes| C{Sec 7 legitimate use or mandated?}
  C -->|Yes| D[Record basis + retention class]
  C -->|No| E{Valid Sec 6 consent?}
  E -->|No| F[Serve notice + capture consent]
  F --> E
  E -->|Yes| D
  D --> G[Process only what is necessary]
  G --> H{Purpose done or withdrawn?}
  H -->|Law requires keep| K([Retain that class only])
  H -->|Erase allowed| I([Erase under Sec 8-7 + notify processors])
  H -->|Still needed| G
  class A,D,F,G act;
  class B,C,E,H dec;
  class K,I ok;
  class X stop;
  classDef start fill:#DBEAFE,stroke:#2563eb,color:#0f172a;
  classDef act fill:#EFF6FF,stroke:#3B82F6,color:#1e3a8a;
  classDef dec fill:#FEF3C7,stroke:#D97706,color:#78350f;
  classDef ok fill:#D1FAE5,stroke:#059669,color:#064e3b;
  classDef stop fill:#FEE2E2,stroke:#DC2626,color:#7f1d1d;
  classDef note fill:#F1F5F9,stroke:#64748B,color:#334155;

BFSI operating checklist

  1. Tag every CRM segment with purpose code and basis.
  2. Block marketing automation from KYC-only fields without fresh consent.
  3. Publish DSR SLAs that explain when erasure is refused for legal retention.
  4. Inventory processors: KYC SaaS, cloud core, BPA, collections partners — DPAs + breach SLAs.
  5. Tabletop a breach that touches cards or KYC images.

FAQ

Can customers force banks to delete KYC data under DPDP?

Not when another law requires retention. Document the legal hold class, refuse erase for that class only, and still fulfil access/correction where applicable.

Is cross-sell covered by account opening consent?

Usually no. Cross-sell and behavioural analytics need fresh, specific Section 6 consent — not a bundled onboarding tick.

What about insurance TPAs and brokers?

They sit in the vendor chain. Fiduciaries remain accountable; contracts must flow purpose limits, security, and breach notice duties.

Where do we get the full diagrams?

In the free DPDP Handbook, plus sector consulting via Complynz.

Related reading

Informational only — not legal advice. Deadline context: organisations should treat 13 May 2027 as the practical compliance horizon under the notified Rules timeline.