DPDP Act · Capital Markets

DPDP Act Compliance for Stock Brokers and Capital Markets

Data principal rights that respect SEBI's record-keeping regime

Brokers and depository participants must honour DPDP consent and rights obligations while preserving KYC files, order trails, and call recordings for five-plus years under SEBI regulations. TruePrivacy reconciles both regulators from one evidence base.

What DPDP Act requires of stock brokerage

Consent beyond the trading relationship

Trading-necessary processing differs from marketing, referral, and analytics uses — the latter need itemised DPDP consent.

Erasure vs SEBI retention

KYC, order logs, contract notes, and recordings are mandated records; profiles and marketing data are not — split responses are the compliant path.

Recipient disclosure in access requests

Exchanges, depositories, KRAs, CKYC, and clearing members must be disclosed with the data shared with each.

Grievance-first enforcement

Clients must exhaust your grievance mechanism before the Data Protection Board — its quality decides where disputes end.

Breach clocks in triplicate

DPDP intimations and the 72-hour Board report run alongside CERT-In's 6-hour rule and SEBI's cyber framework.

Likely SDF designation

Discount brokers with tens of millions of clients are strong candidates for Significant Data Fiduciary designation — India-based DPO, data audits, and periodic DPIAs.

How TruePrivacy helps

01

SEBI retention matrix

Record classes mapped to their SEBI/SCRR provisions with clock triggers — one evidence base for the SEBI inspector and the DPDP auditor.

02

Split-response DSRs

Automatic partition of erasure requests against retention holds, with legal-basis-specific client responses and expiry-scheduled deletion.

03

Recording governance

Order recordings quarantined, purpose-logged, enumerated in access responses, and produced instantly for disputes.

04

Market infrastructure mapping

Exchange, depository, KRA, and vendor flows inventoried for accurate Section 11 disclosures.

05

Grievance defence trail

SLA-timed grievance workflows with complete handling records, ready if a complaint reaches SCORES or the Board.

SEBI wants everything kept; DPDP wants everything erasable. TruePrivacy's split-response engine is the only answer we've seen that satisfies both — every client gets a specific response, and every record has a documented reason to exist.

Nikhil Bhandari
Compliance Head, Crestline Securities

Frequently asked questions

A client who closed their account wants everything deleted. What can we actually erase?

Marketing profiles, analytics, telemetry, and non-mandated data — immediately and verifiably. KYC, order trails, contract notes, and recordings stay under SEBI mandates for their statutory periods, then get deleted automatically. TruePrivacy generates the split response naming each category, basis, and horizon.

Are call recordings of orders personal data?

Yes — a voice recording of an identifiable person is personal data under the DPDP Act, even though it exists as immutable regulatory evidence. TruePrivacy classifies recordings as a distinct high-sensitivity class: retained under mandate, quarantined, access-logged, and disclosed in access responses.

Must we tell clients their data went to KRAs and exchanges?

Section 11 access requests require the identities of fiduciaries and processors with whom data was shared and a description of what each received. TruePrivacy's inventory models these recipients so disclosures generate automatically and stay consistent.

How do we handle a cyber incident touching client data?

One incident record drives every clock: CERT-In within 6 hours, DPDP intimations to clients and the Board without delay, the detailed Board report within 72 hours, and SEBI notification per its cyber framework — all from a shared, consistent fact base.

Get DPDP Act-ready

Book a 30-minute demo and see how TruePrivacy handles DPDP Act compliance for stock brokerage.

Free 14-day trial · No credit card required · Setup in minutes