Stock brokers, asset managers, registered investment advisers and depository participants hold large volumes of sensitive financial and KYC data, making them high-priority Data Fiduciaries under the DPDP Act 2023. SEBI rules already mandate KYC, recordkeeping and cybersecurity; the DPDP Act adds consent, notice, Data Principal rights and breach-notification duties on top. This guide and checker map the overlap for capital-market firms.
How India's DPDP Act 2023 applies to brokers, AMCs, RIAs and depository participants — alongside SEBI rules.
Capital-market intermediaries already operate under detailed SEBI requirements for KYC, recordkeeping, and the Cybersecurity and Cyber Resilience Framework. The DPDP Act 2023 does not replace these — it layers personal-data obligations on top: lawful consent, clear notice, Data Principal rights, storage limitation, and breach notification to the Data Protection Board.
The practical work is reconciling the two. For example, SEBI sets minimum retention periods for records, while DPDP expects you not to keep personal data longer than necessary. A mapped retention schedule and a unified breach process keep you compliant with both.
A SEBI-to-DPDP mapping, a KYC consent/notice template, and a reconciled retention schedule for brokers and AMCs.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.