What must an MFD do for DPDPA compliance?
- Issue an itemised Section 5 notice at onboarding — and a separate one before any insurance, PMS or AIF cross-sell. The notice must be standalone and plain-language, listing the personal data you collect (PAN, Aadhaar-masked KYC, bank proof, nominee details, income slab, family relationships), what each item is used for, how the investor exercises rights, and how to complain to the Data Protection Board. Onboarding a client for mutual fund transactions does not notify them that their income and risk-profile data will later feed a term-plan or PMS pitch. That is a new purpose and needs its own notice before you use the data for it.
- Break the consent form up — one bundled ARN onboarding form will not survive Section 6. Consent must be free, specific, informed, unconditional and unambiguous, with separate tick-boxes the investor can refuse individually: (a) executing and servicing mutual fund transactions; (b) portfolio review calls and periodic statements; (c) cross-sell of insurance, PMS, AIF, NPS or bonds; (d) WhatsApp Business broadcasts and marketing content; (e) sharing data with your sub-broker, RM or family-office partner. Refusing (c) and (d) must not block (a). Keep the consent artefact — timestamp, version of notice shown, IP or channel — because under Section 6(10) the burden of proving consent is on you, not the investor.
- Do not stretch Section 7(a) to cover broadcast marketing. Section 7(a) covers processing where the individual voluntarily provided data for a specified purpose and has not indicated they object. It covers servicing the transaction the investor actually approached you for. It does not cover pushing NFO forwards, IPO alerts, insurance renewal offers or festival greetings to a 900-contact WhatsApp broadcast list. Marketing to your book needs consent under Section 6, collected per purpose, with a working opt-out that actually removes them from the list within a defined turnaround.
- Sign written Section 8(2) contracts with every tool holding your client book. You cannot engage a processor without a valid contract. Cover: your CRM or MFD software (Wealth Elite, IFA-Planet, AssetPlus, Kuvera Pro, MintPro-type platforms), portfolio tracker or reporting tool, WhatsApp Business Solution Provider, SMS or email gateway, cloud drive and backup, accountant or VA who touches client files, and any lead-gen or landing-page vendor. Each contract needs purpose limitation, no onward sub-processing without approval, breach notification to you within 24 hours or less (a commercial term you set, not a statutory SLA), deletion or return of data on exit, and a bar on the vendor using your book for its own marketing. If your CRM's standard terms let it “improve services” using your client data, that clause needs to go.
- Send a one-time Section 5(2) notice to the legacy book. Everyone you onboarded before the Act commenced still needs to be told, as soon as reasonably practicable, what data you hold, what you use it for, how to withdraw consent, and how to raise a grievance — and you may keep processing until they withdraw. Do it as a single dated email or letter to the full book, keep the send log and bounce report, and re-notify anyone whose address bounced through your next physical touchpoint. This is the cheapest item on this list and the easiest one to prove you skipped.
- Reconcile PMLA and AMFI retention against your Section 8(7) erasure duty. Records relating to transactions and client identity carry statutory retention under PMLA and the rules made under it, and AMFI/SEBI distributor obligations sit on top of that. Section 8(7) does not force erasure where another law requires retention — but it does force erasure of everything outside those mandates once purpose is served or consent is withdrawn. Concretely, that means: dead prospects who never transacted, cold-lead spreadsheets bought or scraped years ago, WhatsApp media (PAN photos, cheque images, salary slips) sitting in your phone gallery and auto-backed-up to Google Photos, and the Downloads folder of KYC PDFs on your laptop. Set a quarterly purge date and turn WhatsApp media auto-download off.
- Treat minor folios as Section 9 data and capture verifiable parental consent properly. A child is anyone under 18. For every minor folio you service, you need verifiable consent from the parent or lawful guardian, tied to identity you can actually evidence — guardian PAN, the guardian's own KYC, the relationship proof already in the folio file — not a signature on the child's application form. You must not do tracking, behavioural monitoring or targeted advertising directed at children, so remove minor-folio contacts from broadcast lists entirely. Rebuild consent at the date of majority, when the folio changes hands and the child becomes the Data Principal.
- Write a four-lane breach SOP for the one asset that will actually break — your laptop and CRM login. The lanes run cumulatively. A stolen laptop, a compromised CRM password, a phished email account or a WhatsApp Web session left open on a shared machine is a personal data breach. CERT-In: 6 hours from noticing a reportable cyber incident. Rule 7(1): intimate affected investors without delay. Rule 7(2)(a): initial intimation to the Data Protection Board without delay. Rule 7(2)(b): detailed report to the Board within 72 hours, with description, likely consequences, mitigation taken and your contact details. As a one- or two-person outfit you are both owners — name yourself in writing, name a backup (partner, spouse in the business, your CA), and pre-write the investor intimation template today rather than at 2 a.m. Full-disk encryption, MFA on the CRM and email, and a separate work profile on the phone are the cheapest controls that make this SOP survivable.
- Publish a named grievance contact under Sections 8(9) and 8(10) — and skip the Rule 13 audit. Put a real name, email and phone on your website, email footer and onboarding pack as the person answering data-protection questions. Rule 14(1) requires publishing how an investor makes an access, correction or erasure request and any identifier you need. Rule 14(3) requires the grievance system to respond within a period not exceeding ninety days — that 90-day figure is the grievance ceiling, not the SLA for every rights request. Log every request — access, correction, erasure, consent withdrawal, nomination — with a timestamp, because an investor can only approach the Board after exhausting your route. You almost certainly will not be notified as a Significant Data Fiduciary, so Rule 13's annual independent audit, DPIA and algorithmic due-diligence duties do not apply to you. Section 8(5) reasonable security safeguards do apply, and failure there carries a penalty of up to ₹250 crore.
- Draw a one-page data map that separates your data from the AMC's. List every place client personal data sits: CRM, WhatsApp Business, phone contacts, Gmail, laptop Downloads, Google Drive, physical KYC files, the Excel you use for brokerage reconciliation. Mark who the fiduciary is for each. The folio held by the AMC and RTA is theirs — they are separate fiduciaries with their own notice, consent and breach duties. Everything in that list above is yours, and that is exactly the scope you are accountable for.
Frequently asked questions
The AMC and RTA already hold the folio and take consent. Why am I separately liable?
Because you determine the purpose and means of processing for the data sitting in your own systems. The AMC and RTA are Data Fiduciaries for the folio they maintain. You are the Data Fiduciary for your CRM database, your WhatsApp Business account, the KYC PDFs in your Downloads folder, your prospect spreadsheet and your marketing lists — none of which the AMC controls or can answer for. Their consent covers their processing, not your cross-sell campaign or your leaked laptop.
PMLA says I must retain records. Does that conflict with an investor asking me to erase their data?
No, the two coexist. Section 8(7) requires erasure on consent withdrawal or once the purpose is served, unless retention is necessary for compliance with any law in force. Transaction and client-identity records that PMLA and your AMFI/SEBI obligations require you to keep stay put, and you should tell the investor exactly that, citing the category. Everything outside those mandates must go: marketing consent data, prospect notes, WhatsApp media, old lead lists, duplicate KYC scans. Publish a retention schedule that names the statute for each retained category and a deletion date for everything else.
Do I need an annual DPDPA audit as an MFD?
Only if the Central Government notifies you as a Significant Data Fiduciary, based on volume and sensitivity of data processed, risk to Data Principal rights, and impact on public order and state security. An individual ARN holder or a small distribution firm is very unlikely to be notified, so Rule 13 audits, DPIAs and the algorithmic due-diligence obligation do not apply. Every other duty does — notice, per-purpose consent, processor contracts, breach reporting, grievance redressal and reasonable security safeguards — and 13 May 2027 is the substantive compliance deadline regardless of the size of your book.
Thirty minutes on your CRM, WhatsApp and legacy book
Book a 30-minute gap-analysis call to map your CRM, WhatsApp and legacy book against these ten items. You leave with a written gap list sized for a distributor practice, not a bank — whether or not you work with us.
Book a 30-minute gap-analysis call
Free Gap Analysis
Bring your client onboarding form and the name of your CRM. No deck.
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.