Compliance in Indian financial distribution has always scaled with registration. SEBI’s rules reach the entities it registers. AMFI’s code reaches ARN holders through the empanelment contract the fund house signs with them. SEBI’s cyber resilience framework is addressed to its regulated entities - the fund house, the registrar, the broker - and an ARN holder is not on that list.

The Digital Personal Data Protection Act does not work that way. It attaches to a function rather than a registration, and the function is holding other people’s personal data for a purpose you chose. That describes every mutual fund distributor in the country, including one working alone from a laptop with forty families on it.

The Rules that operationalise the Act are dated 13 November 2025. Rule 4, which registers Consent Managers, commences one year after publication, in November 2026. Rules 3 and 5 to 16 - notice, security safeguards, breach intimation, retention, children’s data, data principal rights - commence eighteen months after publication, in May 2027, along with the substantive sections of the Act itself. That is the date worth marking, and most of the work it implies is retrospective.

The Act Never Asks How Big You Are

Neither the Act nor the Rules contains the words turnover, revenue, MSME, threshold, small or micro. Not as a carve-out, not as a lighter tier, not anywhere. The obligations are keyed to what you do with data, and to nothing else.

Section 2(s) defines “person” to include an individual. Section 2(i) defines a Data Fiduciary as any person who, alone or with others, determines the purpose and means of processing personal data. A proprietor with an ARN, a client list and a phone determines both. There is no second condition to fail.

The one place the Act acknowledges size is section 17(3), which lets the Central Government notify certain fiduciaries, “including startups,” as exempt from a handful of provisions. Two things about that. It is a power the government may exercise, not a relief already granted. And the Explanation defines a startup as a private limited company, a partnership firm or an LLP recognised as such - an individual proprietor is outside the definition before the discretion is even reached.

Even if it were exercised, the relief covers section 5, sub-sections (3) and (7) of section 8, and sections 10 and 11. It does not touch consent under section 6, security safeguards under section 8(5), breach intimation under section 8(6), or children’s data under section 9 - which is to say it does not touch anything carrying the larger penalties.

The Distributor Is Not the Fund House’s Processor

The comfortable reading is that the AMC and the registrar are the fiduciaries, and the distributor merely passes data along on their behalf - a processor, covered by somebody else’s compliance budget.

The test is control. A processor acts on instruction and exercises no meaningful autonomy over purpose or means. A distributor decides which clients to prospect, what to ask them, what to record about their families and incomes, which platform to onboard them through, what to keep in a CRM and for how long, and when to call them. None of that is instructed by the fund house.

So the relationship is not fiduciary-and-processor. It is two fiduciaries sharing data, each answerable for its own end. Section 8(1) closes the escape route explicitly: a Data Fiduciary is responsible for compliance “irrespective of any agreement to the contrary.” The empanelment agreement cannot move this, no matter what it says.

The processors in the picture are the distributor’s own vendors - the CRM, the bulk-messaging tool, the email service, the spreadsheet in somebody’s cloud drive. Section 8(2) permits engaging them only under a valid contract, and Rule 6(1)(f) requires that contract to carry security terms. Most of those relationships today run on a monthly subscription and nothing else.

Servicing Rides on One Clause. Prospecting Doesn’t.

Not everything needs consent. Section 7(a) permits processing for the specified purpose for which the Data Principal voluntarily provided her data and has not objected to its use. The Act illustrates the clause with an intermediary: X messages Y, a real estate broker, asking for help finding rented accommodation and shares her data for that purpose. Y may process it to identify and inform her of what is available.

The same illustration sets the boundary. When X tells Y she no longer needs his help, Y must stop. The clause covers the purpose the client walked in with, for as long as she wants it pursued, and nothing else.

Which means the servicing half of a distribution practice largely rides on section 7(a), and the growth half does not. A purchased lead list, a scheme pitch to somebody who never approached you, the insurance or bond or PMS conversation the client did not ask for, the data passed to a group company - these need consent under section 6: free, specific, informed, unconditional, unambiguous, and limited to what is necessary for the stated purpose.

Rule 3 then specifies what the notice accompanying that request must look like. It has to stand on its own, readable independently of anything else the fiduciary has put in front of the client. It has to give an itemised description of the personal data and the specific purposes. And it has to provide the means to withdraw consent, with the ease of withdrawal comparable to the ease with which it was given. Sections 5(3) and 6(3) add that the client must be able to read it in English or any language in the Eighth Schedule - a practical matter for a regional book, not a formality.

Section 6(10) is the sentence to design around. Where consent is the basis of processing and a question arises, the fiduciary is obliged to prove both that notice was given and that consent was given. A remembered conversation is not evidence. A tick-box with no stored record of what was shown is not evidence either.

A Minor’s Folio Has No Carve-Out

Section 9(1) requires verifiable consent of the parent or lawful guardian before processing any personal data of a child, and the Act sets the age at eighteen. Rule 10 requires due diligence that the person identifying herself as the parent is an adult, by reference to identity and age details already held or voluntarily provided. Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children.

Rule 12 and the Fourth Schedule exempt specified classes from sub-sections (1) and (3) of section 9. The list is clinical establishments, mental health establishments, healthcare and allied healthcare professionals, educational institutions, creches and child day care centres, and transport providers engaged by them. There is no financial services entry. A minor’s folio - opened by a parent, held for a decade, funded by a SIP - sits inside section 9 with nothing to lean on.

Two further edges. The Schedule to the Act puts breaches of section 9 in the second-highest penalty band, up to ₹200 crore. And the child eventually turns eighteen, at which point she is the Data Principal in her own right and the guardian’s consent is no longer the basis for anything.

A related problem sits in every financial plan: the spouse’s income, the parents’ medical history, the sibling’s stake in an inherited property. Those are adults, each a Data Principal, and the client cannot consent on their behalf.

The Breach Clock Has No Materiality Threshold

Section 2(u) defines a personal data breach to include accidental disclosure, sharing or loss of access - not merely a hack. A lost phone with the client book on it qualifies. So does a spreadsheet mailed to the wrong address.

Rule 7 then runs two clocks. Each affected Data Principal must be told, without delay, five specific things: the nature, extent and timing of the breach, the consequences relevant to her, what the fiduciary is doing about it, what she can do to protect herself, and the business contact of a person who can answer her questions. The Board must be told without delay, and given detailed findings within seventy-two hours.

There is no minimum number of affected clients and no materiality filter. One client’s data exposed is a reportable breach.

Behind that sits section 8(5) and Rule 6, which set out the minimum security safeguards: encryption, obfuscation, masking or tokenisation; access controls; logs and monitoring sufficient to detect unauthorised access; backups for continued processing; retention of those logs for one year; and security terms in processor contracts. Failure here carries the highest penalty in the Schedule, up to ₹250 crore.

That ceiling is not a forecast for a one-person practice. Section 33(2) requires the Board to weigh the nature and gravity of the breach and the likely impact of the penalty on the person before setting an amount. But proportionality in the penalty is not the same thing as exemption from the duty, and only one of those is written into the Act.

Most of This Was Already in AMFI’s Code

The AMFI Master Circular for Mutual Fund Distributors, issued in January 2026 and consolidating AMFI’s guidelines to 31 December 2025, already requires a distributor to maintain confidentiality of all investor information, not to share or publish it without the investor’s prior written consent, not to disclose it to third parties except as law requires, and not to share data with group companies for cross-marketing. It requires adherence to contractual data privacy terms with the AMC so that data is used only for the purpose for which it was obtained and purged as soon as it is no longer required. It asks for cyber security measures around electronic data in collection, transmission and storage. It asks for records of investor consent and dissent.

Read alongside the Act, that list is nearly a summary of it. Which is the point worth taking away: for a distributor already following the code, DPDP is not a new set of principles. It is the same principles relocated.

What moves is who the duty is owed to, and who enforces it. Confidentiality under the AMFI code is a contractual obligation running to the fund house, policed by empanelment and the ARN. The same conduct under DPDP is a statutory duty owed to the investor, who can demand a summary of her data and the identities of everyone it was shared with under section 11, require correction or erasure under section 12, and complain to a Board - after first exhausting a grievance mechanism the fiduciary must publish and answer within a period not exceeding ninety days under Rule 14(3).

Section 11(1)(b) deserves its own sentence. The investor is entitled to be told the identities of every other fiduciary and processor with whom her data has been shared. Answering that honestly means being able to name the fund houses, the registrar, the transaction platform, the national distributor if there is one, the CRM, and the messaging tool. Most practices have never assembled that list.

What This Means for Distributors

Start with the map, not the policy document. Where does client data actually sit - which platform, which CRM, which laptop, which WhatsApp history, whose personal Google Drive? The Act applies to digital data and to non-digital data digitised subsequently, so the paper form in a filing cabinet is outside it and the photograph of that form on a phone is inside. A practice that cannot list its own data locations cannot answer a section 11 request, meet a seventy-two hour clock, or prove consent.

Separate the two bases deliberately. Decide what is being processed because the client came to you for it, and what is being processed because you want to sell something else. The second needs its own consent, its own notice, and a stored record of both.

Treat client WhatsApp groups as what they are. Adding forty clients to a common group discloses every member’s mobile number to every other member. Whether that is a breach or processing without a basis depends on whether anyone agreed to it, and the remedy in both cases is the same - a broadcast list, or actual consent.

Write down the retention rule for each category of data, and name the law you are relying on. Section 8(7) requires erasure when consent is withdrawn or the purpose is no longer served, unless retention is necessary for compliance with a law in force. KYC and transaction records sit behind that proviso. The running notes on a client’s health, job change and family disagreements do not obviously sit anywhere, and they are the most valuable thing in the file.

Publish a contact point. Rule 9 requires the business contact information of a person who can answer questions about processing to be prominently published and repeated in every response to a rights request. For most practices that person is the principal, and a named individual on the website is the whole requirement.

One last provision, easy to miss and oddly close to this practice’s usual subject matter. Section 14 gives every Data Principal the right to nominate an individual to exercise her data rights on her death or incapacity. India spent a decade teaching investors that a nominee is not an heir. There is now a second nomination, over a different asset, with its own rules.

The deadline is May 2027, and the temptation will be to treat it as a form-filling exercise for new clients from that date. Section 5(2) is the reason that fails: where consent was given before commencement, the fiduciary must give the client a notice of what data it holds and why, as soon as is reasonably practicable. The work is the existing book, not the next one.

Back to Writing