Answer in one line: BFSI entities must separate mandated / legitimate-use processing (KYC, AML, collections where applicable) from consent-based cross-sell and analytics, keep a purpose-and-retention register, and erase only when law allows — while cascading DSRs to KYC SaaS, cloud, and BPA vendors under Section 8(2).
Built from the BFSI industry map in the DPDP Handbook for compliance, risk, and digital product teams.
Why BFSI cannot reuse a generic CMP playbook
Retail banking and lending already collect high-sensitivity identifiers. Regulated retention often overrides a customer erase request. Marketing teams that treat KYC phone numbers as an ESP list create dual-use risk the Board will not ignore.
Figure 1 — BFSI purpose streams
flowchart TD
HUB([Bank / NBFC / insurer / broker]) --> P1[KYC / AML / CKYC]
HUB --> P2[Account / policy / loan]
HUB --> P3[Payments / cards]
HUB --> P4[Cross-sell / analytics]
HUB --> P5[Collections / recovery]
HUB --> P6[Employees / agents]
HUB --> P7[Vendors: KYC SaaS / cloud / BPA]
P1 --> B1[Sec 7 or mandated retention]
P2 --> B2[Sec 6 consent for that product]
P3 --> B2
P4 --> B3[Fresh specific consent]
P5 --> B1
P6 --> B4[Employment notice + basis]
P7 --> B5[DPA + Sec 8-2 chain]
B1 --> REG[(Purpose + retention register)]
B2 --> REG
B3 --> REG
B4 --> REG
B5 --> REG
REG --> CORE[Core / CRM / collections / vendors]
CORE --> Q{Purpose ends or DSR?}
Q -->|Law requires keep| KEEP([Retain that record class only])
Q -->|Erase allowed| ER([Erase + notify processors])
class HUB,P1,P2,P3,P4,P5,P6,P7,B1,B2,B3,B4,B5,CORE act;
class Q dec;
class REG start;
class KEEP,ER ok;
classDef start fill:#DBEAFE,stroke:#2563eb,color:#0f172a;
classDef act fill:#EFF6FF,stroke:#3B82F6,color:#1e3a8a;
classDef dec fill:#FEF3C7,stroke:#D97706,color:#78350f;
classDef ok fill:#D1FAE5,stroke:#059669,color:#064e3b;
classDef stop fill:#FEE2E2,stroke:#DC2626,color:#7f1d1d;
classDef note fill:#F1F5F9,stroke:#64748B,color:#334155;
Purpose classes that must stay separate
| Stream | Typical basis | Retention note |
|---|---|---|
| KYC / AML / CKYC | Sec 7 / mandated | Keep for statutory period |
| Account / policy / loan servicing | Consent or contract-aligned purpose | Lifecycle of relationship + law |
| Cross-sell / analytics | Fresh specific Sec 6 consent | Shorter; honour withdrawal |
| Collections | Often Sec 7 / mandated path | Do not mix with marketing lists |
| Employees / agents / vendors | Employment notice or DPA | Role-based access + exit erase |
Figure 2 — Lawful basis and retention gate
flowchart TD
A([Processing decision]) --> B{Purpose lawful and specific?}
B -->|No| X([Stop - do not collect])
B -->|Yes| C{Sec 7 legitimate use or mandated?}
C -->|Yes| D[Record basis + retention class]
C -->|No| E{Valid Sec 6 consent?}
E -->|No| F[Serve notice + capture consent]
F --> E
E -->|Yes| D
D --> G[Process only what is necessary]
G --> H{Purpose done or withdrawn?}
H -->|Law requires keep| K([Retain that class only])
H -->|Erase allowed| I([Erase under Sec 8-7 + notify processors])
H -->|Still needed| G
class A,D,F,G act;
class B,C,E,H dec;
class K,I ok;
class X stop;
classDef start fill:#DBEAFE,stroke:#2563eb,color:#0f172a;
classDef act fill:#EFF6FF,stroke:#3B82F6,color:#1e3a8a;
classDef dec fill:#FEF3C7,stroke:#D97706,color:#78350f;
classDef ok fill:#D1FAE5,stroke:#059669,color:#064e3b;
classDef stop fill:#FEE2E2,stroke:#DC2626,color:#7f1d1d;
classDef note fill:#F1F5F9,stroke:#64748B,color:#334155;
BFSI operating checklist
- Tag every CRM segment with purpose code and basis.
- Block marketing automation from KYC-only fields without fresh consent.
- Publish DSR SLAs that explain when erasure is refused for legal retention.
- Inventory processors: KYC SaaS, cloud core, BPA, collections partners — DPAs + breach SLAs.
- Tabletop a breach that touches cards or KYC images.
FAQ
Can customers force banks to delete KYC data under DPDP?
Not when another law requires retention. Document the legal hold class, refuse erase for that class only, and still fulfil access/correction where applicable.
Is cross-sell covered by account opening consent?
Usually no. Cross-sell and behavioural analytics need fresh, specific Section 6 consent — not a bundled onboarding tick.
What about insurance TPAs and brokers?
They sit in the vendor chain. Fiduciaries remain accountable; contracts must flow purpose limits, security, and breach notice duties.
Where do we get the full diagrams?
In the free DPDP Handbook, plus sector consulting via Complynz.
Related reading
- Free DPDP Handbook — industry maps, consent, breach, and rights diagrams
- DPDP for SaaS & product companies
- DPDP for BFSI — banks, NBFCs & insurers
- DPDP for healthcare & HealthTech
- DPDP for EdTech & schools
- DPDP for manufacturing & plants
- Consent management platform
- PII discovery tool
- DPDP consulting from INR 49,999
Informational only — not legal advice. Deadline context: organisations should treat 13 May 2027 as the practical compliance horizon under the notified Rules timeline.