PMLA keeps a customer’s identity records for five years after the relationship ends. The DPDP Act hands that same customer a right to erasure. The Act resolves the conflict in the bank’s favour — retention required by law defeats erasure for its duration. What the Act does not supply is the workflow: which fields are held, under which instrument, until when, and the written, auditable refusal for each request. That is the banking sector’s defining DPDP problem, and it is a problem of evidence, not of law.
FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 11 PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT
Each of these is marked confirmed: two independent sources, at least one the statute or a practitioner record. The sources are linked so your counsel can read them, not take our word.
DPDP s.12 and s.8(7)(a) require erasure unless retention is required by law. PMLA 2002 s.12 requires transaction records for five years from the transaction and identity records for five years after the relationship ends; the RBI KYC Master Direction (para 46) mirrors it. The gap is classifying retention-bound fields from erasable ones, issuing a lawful partial refusal, and evidencing it per request. In its own consultation submission on the Rules, the financial-industry body ASIFMA named exactly these collisions and asked for carve-outs; none was granted.
SOURCES · PMLA s.12 (statute) · RBI KYC Master Direction (instrument) · ASIFMA submission to MeitY, 21 Mar 2025, Annex 2 (practitioner)
Confirmed · sweep of 2 Sep 2026Four regulators, separate filings, different content, different definitions of “incident” — and DPDP Rule 7 carries no materiality threshold. Industry asked for a significant-harm threshold during consultation; the final Rules kept every personal-data breach notifiable. A bank group with a broker arm files a fifth time under SEBI’s cyber framework. The clocks start before the facts exist.
SOURCES · RBI Cyber Security Framework circular, 2 Jun 2016 (instrument) · DPDP Rules 2025, Rule 7 (text) · ASIFMA submission (practitioner — the threshold request and its refusal)
Confirmed · Rule 7 in force mid-May 2027DPDP s.4–s.6 want consent per specified purpose, an itemised notice, and withdrawal as easy as the grant; s.8(7) wants erasure that reaches the record. Packaged cores carry no purpose tags and do not enforce consent at read time. Infosys Finacle’s own guidance on DPDP prescribes a centralised, API-first consent service with purpose-level tokens, revocation across every channel and deny-by-default policy checks — capabilities added around the core, not features of it.
SOURCES · Infosys Finacle, “Beyond Compliance: What DPDP 2025 Means for Banks” (the vendor’s own statement) · Protiviti report at the IBA CISO Summit 2025 (practitioner)
Confirmed for the consent-enforcement gapDPDP s.5(2) makes the entire existing book a compliance surface at once: a per-person obligation over tens of crores of relationships, many of them opened on paper through branches and business correspondents with no digital channel. Rule 3(a) also requires the notice to be understandable independently of any other information — which ASIFMA warned collides with RBI’s bundled card-onboarding disclosures. The final Rule kept the independence requirement.
SOURCES · DPDP Act s.5(2), s.5(3), s.6(3) (statute) · DPDP Rules 2025, Rule 3 (text) · ASIFMA submission on Rule 3(a) (practitioner)
Confirmed for the duty; the branch-intake half is hypothesisedThree AI research drafts gave three different KYC retention periods for the same fact. The register settled each of these from the instrument. If a vendor deck tells you otherwise, ask for the section number.
PMLA s.12 as it currently reads: transaction records five years from the transaction; identity records five years after the relationship ends. The RBI KYC Master Direction mirrors it. The ten-year figure circulating in AI-generated material most plausibly descends from PMLA’s pre-amendment text.
The RBI Digital Payment Security Controls direction (Feb 2021) requires logging capability and a retention policy. We could not locate a ten-year clause in it. The enforceable floor for payment records is PMLA’s five years. We do not quote a number the instrument does not contain.
Rule 7 puts principals on “without delay.” The 72-hour clock belongs to the detailed report to the Data Protection Board. The error appears even in reputable advisory pieces.
No notification under s.10(1) had been located as of 2 September 2026, and none can bind before s.10 and Rule 13 commence in mid-May 2027. A claim that banks “are SDFs” describes an expectation, not a fact.
The inquiry and penalty provisions (ss.28–34) commence in mid-May 2027, and the Board that would impose them had no Chairperson or Member appointed as of 1 August 2026. What is being penalised today is consent-adjacent conduct under other statutes — consumer-protection and sectoral orders. The honest framing is that the conduct is already being fined under other laws and the DPDP clock is running. The penalty schedule itself is stated plainly here, once.
RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM
Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.
Every access, correction and erasure request carries a response deadline computed when it is filed, an escalation ladder when it slips, and an outcome that is written into the audit chain. An erasure cannot be marked complete unless its execution path is configured; the destruction itself is recorded, not asserted. The refusal you write for a PMLA-held record lands in the same chain, dated and attributable, so the regulator sees a decision, not a gap.
Live: DSR orchestration · SLA tracking · grievance workflowsConsent is captured per processing purpose, never all-or-nothing; notices are versioned so a change forces re-consent and the old version stays on record; withdrawal is as easy as the grant, and a decision is honoured across every web property. The core keeps doing what it does — the consent layer sits where Finacle said it should.
Live: purpose-by-purpose consent · versioned notices · cross-domain syncNotices and consent flows are rendered in the twenty-two languages of the Eighth Schedule by a self-hosted translation model — no third-party API, nothing leaves our systems. A versioned notice is a versioned notice in every language, so the s.5(2) obligation is met with one artefact, not twenty-two divergent ones.
Live: notices & consent flows in 22 Indian languagesEvery consent, erasure, refusal and notice publication is a linked record bound to the one before it, and the chain is periodically stamped by an independent timestamp authority. A dispute is answered with a receipt that verifies in a browser, not with a database row. Anyone can check it.
Live: tamper-evident audit trail · independent anchoring · verifiable receiptsFor collision 02, an incident record tracks the notification obligation under each applicable regime and the 72-hour report countdown — it does not file for you, and it does not send SMS. We say what it does because the register found nothing sector-standard that generates all four filings from one record, and we are not going to claim we are it.