DPDP for Stock Brokers and SEBI-Regulated Entities
If you have already done CSCRF work, a large share of Rule 6 is behind you. The parts that are genuinely new are consent, retention and rights handling.
What you already have
An intermediary that has done CSCRF work will typically already have access control, logging and monitoring, incident response and continuity measures. That maps well onto Rule 6(1)(b), (c), (d) and (g).
Confirm one detail: Rule 6(1)(e) requires logs and personal data to be retained for one year specifically to support detection and investigation. Check your retention meets that, because CSCRF-driven retention is set for different reasons.
Client data is the hard part
A broker holds KYC records, trading history, bank details and communications. Much of it is retained under SEBI requirements, which Rule 8 accommodates where retention is necessary for compliance with a law in force.
The discipline is writing down, per data set, which requirement justifies the period. Retention that cannot be tied to a law or a live purpose is retention you have to defend.
Reporting stacks up
A single incident can require intimation to affected clients and the Data Protection Board under Rule 7, a CERT-In report, and a report to SEBI. Different formats, different recipients, different clocks, all starting close to the moment of awareness.
Intermediaries have the strongest starting position of any sector on Rule 6, and the weakest on Rule 14. Nobody has built a client rights request process, because until now nothing required one.
Infosek Team
Priorities
- Check log retention against the one year Rule 6(1)(e) requires.
- Build the Rule 14 rights request route and publish the means of making a request, as Rule 14(1) requires.
- Document the legal basis for each retention period rather than pointing at SEBI generally.
- Merge DPDP, CERT-In and SEBI incident reporting into one runbook with a single declaration event.
- If you also carry the accessibility mandate, sequence both together since they touch the same interfaces.
Common questions
Does DPDP apply to SEBI-regulated intermediaries?
Yes. DPDP applies to the processing of digital personal data irrespective of sector regulation. SEBI obligations, including the Cyber Security and Cyber Resilience Framework, continue to apply alongside it.
Does CSCRF compliance cover DPDP requirements?
Partly. CSCRF work covers much of what Rule 6 requires on access control, logging and monitoring. It does not cover consent and notice under Rule 3, erasure under Rule 8, or Data Principal rights under Rule 14, which have no CSCRF equivalent.
Already doing CSCRF work?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment