Industry · MFDs
DPDPA Compliance for MFDs in India
Mutual fund distributors hold PAN, bank mandates, KYC documents, folio numbers and complete transaction histories — often for hundreds of families, in Excel sheets and WhatsApp threads. Under the DPDP Act 2023 an ARN holder is a Data Fiduciary regardless of size. There is no AUM threshold. The compliance date is 13 May 2027, with AMFI and SEBI obligations running alongside.
Last reviewed: 30 July 2026
What DPDPA compliance risks do MFDs face?
The sharp edges are the ones nobody set up. Legacy books built over fifteen years, where Section 5(2) requires fresh notice to clients whose consent predates the Act. Nominee and joint-holder details — PAN, date of birth, address — collected from the investor, never from those people. AMCs and RTAs are fiduciaries in their own right, not your processors; your CRM and reporting vendor is. Plus client statements screenshotted into WhatsApp groups, and old prospect lists mined for insurance cross-sell.
What should MFDs prepare first for DPDPA compliance?
- Send Section 5(2) notice across the legacy client book — one clean start, not optional.
- Itemise Section 6 consent at onboarding; separate mutual funds from insurance / PMS / AIF cross-sell.
- Put a written processor contract on CRM, reporting tools, and cloud storage — not click-through alone.
- Encrypt the laptop, enable 2FA on CRM and email, stop KYC scans living in Downloads and WhatsApp.
- Map what you must retain under PMLA/AMFI vs what you can erase (old prospects, exited-client media).
Frequently asked questions
I'm a one-person ARN holder with 200 clients. Does DPDPA actually apply to me?
Yes. The Act draws no line by turnover, AUM or headcount — if you determine the purpose and means of processing personal data, you are a Data Fiduciary, and a solo distributor working from a laptop is squarely inside it. What differs is scale of effort, not scope of duty. Your baseline obligations are: a clear notice at collection, a lawful ground for each purpose, purpose limitation, accuracy, reasonable security safeguards, erasure once the purpose ends, breach notification, and a published grievance channel with a named contact and a response timeline. On the lawful ground, Section 6 consent is your default — itemised by purpose, plain language, in English or any Eighth Schedule language, and as easy to withdraw as to give. Section 7(a) gives you some room where a client voluntarily hands over data for a specified purpose and hasn't indicated otherwise, but it is tied tightly to that purpose. It does not stretch to cross-selling insurance, PMS or AIFs, to broadcast marketing, or to passing a client's details to another distributor or an NBFC partner. Those need separate consent. Note also that DPDPA has no "sensitive personal data" tier — PAN, bank details and a phone number sit under one legal standard.
My clients' data sits with the AMC, the RTA and the transaction platform. Who is liable for what?
Split it into three buckets. The AMC and the RTA are Data Fiduciaries in their own right for the folio — they hold the investment relationship, have their own lawful ground and their own retention duties, and they are not your processors. You do not carry their liability, and they do not carry yours. Your own bucket is everything in your practice: the CRM, the reporting and portfolio-tracking software, the goal-planning tool, the WhatsApp business account, the Google Sheet of prospects, the KYC scans in your Downloads folder. There, your software vendor and cloud host are Data Processors — they may process client data only under a valid written contract specifying purpose, security obligations, sub-processing limits and deletion on exit. Most MFD tech is signed up on a click-through plan with no such contract, which is a straightforward gap to close. Liability for a processor's failure stays with you and cannot be contracted away. The third bucket is people you bring in: sub-distributors under your ARN, referral partners, your operations assistant, a part-time telecaller. Their access is your processing.
I have fifteen years of client data and dormant folios. What do I owe on legacy lists, and what can I delete?
Two separate questions. On notice: Section 5(2) requires that where consent was obtained before the Act commenced, you give those Data Principals the required notice as soon as reasonably practicable — so a one-time notice exercise across your existing book is unavoidable, not optional, and it is the cleanest single task to start with. On erasure: the duty to erase on withdrawal or once the purpose is served is qualified by the retention exception where a law requires you to keep the record, so your PMLA and AMFI-mandated KYC and transaction records stay put for their prescribed period even if a client asks you to delete everything. What you cannot justify keeping is the rest — rejected prospects from 2016, exited clients' scanned cheques, WhatsApp media folders full of statements, spouse and child details captured "for planning" and never used. Two further points specific to your book: minor folios trigger Section 9, meaning verifiable parental or guardian consent and no behavioural tracking or targeted advertising directed at that child, with the consent shifting to the investor at 18; and nominee and joint-holder data you collected from the primary investor belongs to those individuals, who have their own access and correction rights over it.
My laptop is stolen, or my CRM account is compromised. What do I report, and do I need audits and a DPO?
Two clocks start at detection and both must be met; they are cumulative, not alternatives. CERT-In requires reporting of covered cyber incidents within 6 hours. Separately under DPDPA, you must intimate every affected client without delay (Rule 7(1)), give the Board an initial description without delay (Rule 7(2)(a)), and file detailed particulars within 72 hours (Rule 7(2)(b)) — and "I'm a small distributor" is not an exemption from either. Failure to maintain reasonable security safeguards attracts up to ₹250 crore under Section 8(5), and failure to give the required breach intimation is assessed separately at up to ₹200 crore under Section 8(6), with the Board deciding actual quantum on the facts, including the scale of the operation. An unencrypted laptop with client KYC on it is the single most common failure mode here, and full-disk encryption plus two-factor authentication on your CRM and email closes most of it. On the heavier obligations: annual DPIAs, independent data audits, algorithmic due diligence and an India-based Data Protection Officer bind Significant Data Fiduciaries only, and SDF status is conferred by Central Government notification — it is not triggered automatically by client count or AUM. No MFD practice becomes an SDF by growing. You still owe the baseline duties in full.
Thirty minutes on your client book — not a compliance lecture
We walk your actual setup: where client KYC and bank details are stored, what your CRM or reporting vendor's contract says, which purposes your onboarding form covers, what happens when a client asks you to delete their data, and how you'd handle a lost laptop. You leave with a written gap list sized for a distributor practice, not a bank — whether or not you work with us.
Book a demo call
Free Gap Analysis
Bring your client onboarding form and the name of your CRM. No deck.
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.