Sector-specific DPDP guides

These are the verticals the Manatoko DPDP work focuses on: banking, healthcare, higher education, K-12, and quick-commerce. Each faces a different exposure profile based on data types, volume, regulatory classification, and how much the business depends on personal data.

Banking

Very High risk

Banks carry the heaviest recurring identity burden in India. The RBI Master Direction on Know Your Customer (KYC), implementing the Prevention of Money Laundering Act (PMLA), requires identity records kept for five years after a relationship ends, with periodic re-KYC, which pulls against DPDP data minimisation and the right to erasure. Large and cooperative banks are near-certain Significant Data Fiduciaries.

Sector-specific obligations

  • KYC retention under the PMLA collides with DPDP erasure rights, so the two duties have to be reconciled rather than chosen between.
  • The Central KYC Records Registry (CKYCR) counts as one more centralised processor every institution answers for under Section 8(1).
  • Section 8(1) makes the bank absolutely liable for its processors, with no contractual escape by indemnity.
  • Significant Data Fiduciary status is almost certain for large banks: a mandatory DPIA, an independent audit, and a Data Protection Officer.
  • A verifiable credential lets a customer prove identity once and carry the proof, so compliance rises while re-verification falls.

See your own number

Run the five-dimension assessment for your organisation.

Calculate your exposure