Retention conflicts
RBI record-keeping says keep it; the Act says delete once the purpose is served. Purpose-level retention lets both be true for different fields.
You already answer to the RBI. The DPDP Act adds a second axis — purpose limitation and erasure — to data you were told to retain. Reconciling the two is the whole job.
RBI record-keeping says keep it; the Act says delete once the purpose is served. Purpose-level retention lets both be true for different fields.
Identity documents leak into ticketing, analytics and vendor systems. Discovery finds the copies before an auditor does.
Notices must be itemised without adding friction to a flow you have spent years optimising.
Your BC network, KYC vendors and collection agencies are all processors you remain liable for.
Itemised notice inside the KYC flow, capturing purpose-level consent without adding a screen.
Borrowers and payers raise access and erasure requests themselves, verified against data you already hold.
Payment-data incidents triaged and classified the moment they are logged, with blast radius from the map.
One record of processing, exported in the shape each regulator asks for.
Capture, version and honour every consent
Know what personal data you hold, and why
Your processors are your liability
Delete on schedule, and prove it
Multi-product lending and payments stacks usually cross 1,00,000 data principals and need discovery, DPIA and SSO from day one.
42 questions covering every operative section of the Act. No account needed — tell us where to send it.
Most vendors open a deck. We open the product, map one of your real data flows, and tell you honestly how far you are from compliant.
What the 30 minutes looks like
If we are not the right fit, we will say so on the call rather than three follow-ups later.