Infosek
INFOSEK

DPDP for Stock Brokers and SEBI-Regulated Entities

If you have already done CSCRF work, a large share of Rule 6 is behind you. The parts that are genuinely new are consent, retention and rights handling.

DPDP for Stock Brokers and SEBI-Regulated Entities

What you already have

An intermediary that has done CSCRF work will typically already have access control, logging and monitoring, incident response and continuity measures. That maps well onto Rule 6(1)(b), (c), (d) and (g).

Confirm one detail: Rule 6(1)(e) requires logs and personal data to be retained for one year specifically to support detection and investigation. Check your retention meets that, because CSCRF-driven retention is set for different reasons.

Client data is the hard part

A broker holds KYC records, trading history, bank details and communications. Much of it is retained under SEBI requirements, which Rule 8 accommodates where retention is necessary for compliance with a law in force.

The discipline is writing down, per data set, which requirement justifies the period. Retention that cannot be tied to a law or a live purpose is retention you have to defend.

Reporting stacks up

A single incident can require intimation to affected clients and the Data Protection Board under Rule 7, a CERT-In report, and a report to SEBI. Different formats, different recipients, different clocks, all starting close to the moment of awareness.

Intermediaries have the strongest starting position of any sector on Rule 6, and the weakest on Rule 14. Nobody has built a client rights request process, because until now nothing required one.

Infosek Team

Priorities

Common questions

Does DPDP apply to SEBI-regulated intermediaries?

Yes. DPDP applies to the processing of digital personal data irrespective of sector regulation. SEBI obligations, including the Cyber Security and Cyber Resilience Framework, continue to apply alongside it.

Does CSCRF compliance cover DPDP requirements?

Partly. CSCRF work covers much of what Rule 6 requires on access control, logging and monitoring. It does not cover consent and notice under Rule 3, erasure under Rule 8, or Data Principal rights under Rule 14, which have no CSCRF equivalent.

Already doing CSCRF work?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment