DPDP Act Compliance for Stock Brokers and Capital Markets
Data principal rights that respect SEBI's record-keeping regime
Brokers and depository participants must honour DPDP consent and rights obligations while preserving KYC files, order trails, and call recordings for five-plus years under SEBI regulations. TruePrivacy reconciles both regulators from one evidence base.
What DPDP Act requires of stock brokerage
Consent beyond the trading relationship
Trading-necessary processing differs from marketing, referral, and analytics uses — the latter need itemised DPDP consent.
Erasure vs SEBI retention
KYC, order logs, contract notes, and recordings are mandated records; profiles and marketing data are not — split responses are the compliant path.
Recipient disclosure in access requests
Exchanges, depositories, KRAs, CKYC, and clearing members must be disclosed with the data shared with each.
Grievance-first enforcement
Clients must exhaust your grievance mechanism before the Data Protection Board — its quality decides where disputes end.
Breach clocks in triplicate
DPDP intimations and the 72-hour Board report run alongside CERT-In's 6-hour rule and SEBI's cyber framework.
Likely SDF designation
Discount brokers with tens of millions of clients are strong candidates for Significant Data Fiduciary designation — India-based DPO, data audits, and periodic DPIAs.
How TruePrivacy helps
SEBI retention matrix
Record classes mapped to their SEBI/SCRR provisions with clock triggers — one evidence base for the SEBI inspector and the DPDP auditor.
Split-response DSRs
Automatic partition of erasure requests against retention holds, with legal-basis-specific client responses and expiry-scheduled deletion.
Recording governance
Order recordings quarantined, purpose-logged, enumerated in access responses, and produced instantly for disputes.
Market infrastructure mapping
Exchange, depository, KRA, and vendor flows inventoried for accurate Section 11 disclosures.
Grievance defence trail
SLA-timed grievance workflows with complete handling records, ready if a complaint reaches SCORES or the Board.
“SEBI wants everything kept; DPDP wants everything erasable. TruePrivacy's split-response engine is the only answer we've seen that satisfies both — every client gets a specific response, and every record has a documented reason to exist.”
Frequently asked questions
A client who closed their account wants everything deleted. What can we actually erase?
Marketing profiles, analytics, telemetry, and non-mandated data — immediately and verifiably. KYC, order trails, contract notes, and recordings stay under SEBI mandates for their statutory periods, then get deleted automatically. TruePrivacy generates the split response naming each category, basis, and horizon.
Are call recordings of orders personal data?
Yes — a voice recording of an identifiable person is personal data under the DPDP Act, even though it exists as immutable regulatory evidence. TruePrivacy classifies recordings as a distinct high-sensitivity class: retained under mandate, quarantined, access-logged, and disclosed in access responses.
Must we tell clients their data went to KRAs and exchanges?
Section 11 access requests require the identities of fiduciaries and processors with whom data was shared and a description of what each received. TruePrivacy's inventory models these recipients so disclosures generate automatically and stay consistent.
How do we handle a cyber incident touching client data?
One incident record drives every clock: CERT-In within 6 hours, DPDP intimations to clients and the Board without delay, the detailed Board report within 72 hours, and SEBI notification per its cyber framework — all from a shared, consistent fact base.
Get DPDP Act-ready
Book a 30-minute demo and see how TruePrivacy handles DPDP Act compliance for stock brokerage.
Free 14-day trial · No credit card required · Setup in minutes