Mumbai is India's financial centre, so most DPDP programmes here begin inside an organisation that is already heavily regulated. The work is less about building governance from nothing and more about reconciling a new statute with RBI, IRDAI or SEBI rules that were written for different purposes and occasionally point the other way.
The recurring conflict is retention against erasure. KYC and transaction records carry statutory retention periods, so a data principal's erasure request cannot simply be honoured — but you must be able to explain, per record, which basis applies and for how long. Organisations that cannot do that end up refusing requests without being able to justify the refusal.
The second is lawful basis. A great deal of financial processing rests on legal obligation rather than consent. Labelling it as consent-based creates a withdrawal right you then cannot honour.
ProtectComply is built by Exuverse, whose team sits in Noida. We work with organisations across India — remotely for most of a programme, in person when discovery or a workshop genuinely needs it.
It sits alongside them. DPDP adds consent, purpose limitation and data principal rights; RBI and IRDAI obligations on retention and localisation continue to apply. Where they appear to conflict — erasure against KYC retention — the answer is a per-record basis you can evidence, not a choice between regulators.
No. Erasure does not override a statutory retention obligation. What you must be able to show is which records are retained, under which basis, and for how long.
Jupinder Bedi — Jupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →