India Regulatory Hub
Cross-regulator · India Deep Dive

Regulator Overlap Matrix

Auditors use this matrix to avoid duplicating compliance programmes — and to spot the genuine conflicts (data retention vs erasure, 6-hour vs 72-hour clocks, localisation vs whitelist transfers) that need a documented position.

Last verified: 2026-06-17
Compliance DimensionDPDP Act 2023RBI (MD-ITGRC)SEBI CSCRFIRDAI 2023 GuidelinesConflict?
Data RetentionRetain only as long as purpose exists; right to erasureRetain financial records 5–8 years per statute; payment data 10 yearsRetain investor records 5 years (SEBI regulations)Retain policy and claims records as per Insurance ActYES — right to erasure vs statutory retention
Breach Notification Timeline72 hours to DPB and data principals6 hours to RBI CSITE6 hours to SEBI Cybercell6 hours to IRDAIYES — run parallel workflows; CERT-In 6-hr pace governs
Consent for Data ProcessingExplicit consent required; purpose limitation; withdrawal anytimeRegulatory mandate is a lawful basis — no separate consent neededRegulatory mandate is a lawful basis — no separate consent neededIRDAI requires consent for health data specificallyPARTIAL — DPDP consent not needed where RBI/SEBI mandate exists
Third-Party / Vendor RiskData processor contracts required; processor bound by fiduciary instructionsTPRM due diligence mandatory; audit rights; annual vendor reviewTPRM obligations in CSCRF; cloud vendor risk assessmentOutsourcing guidelines mandate security requirements and audit rightsNO — broadly aligned; DPDP adds contractual obligations
Cross-Border Data TransferPermitted only to countries notified by Central Government; whitelist modelPayment data must stay in India; strong localisation stanceNo specific prohibition but cloud risk assessment appliesNo specific prohibition; outsourcing guidelines applyYES — RBI localisation stricter than DPDP's whitelist model
Grievance RedressalData principal can file complaint with DPB; DF must have grievance officerRBI Banking Ombudsman for customers; no DPDP-specific mechanismSCORES platform for investor complaints; no DPDP mechanismInsurance Ombudsman; IRDAI IGMS portalPARTIAL — separate grievance channels; DPDP channel is new and additional

Made with Emergent