PAN copies in Downloads, risk-profile sheets in Excel, cheque photographs in WhatsApp Business — that is client data an ARN holder or small RIA already holds, and DPDPA treats you as the Data Fiduciary for it.
TL;DR
- An ARN holder or RIA is a Data Fiduciary in their own right. The AMC and RTA hold the folio; you hold the CRM, the KYC PDFs, the prospect sheet and the WhatsApp Business media folder — and you answer for those.
- Section 7(a) covers servicing the transaction the investor came to you for. It does not cover NFO forwards, insurance or PMS pitches, festival broadcasts, or handing your book to another distributor. Those need Section 6 consent, and Section 6(10) puts the burden of proof on you.
- Breach reporting runs on four cumulative lanes, not one: CERT-In (commonly 6 hours for specified cyber incidents), Rule 7(1) intimation to affected Data Principals without delay, Rule 7(2)(a) initial intimation to the Data Protection Board without delay, and Rule 7(2)(b) a detailed Board report within 72 hours.
- Rule 13 audits, DPIAs and a mandatory DPO apply only to Significant Data Fiduciaries notified under Section 10. Every practice, however small, still needs a published Section 8(9) contact and Section 8(10) grievance route.
- The Act commenced by G.S.R. 843(E) dated 13 November 2025, the Rules by G.S.R. 846(E), and the substantive fiduciary duties bite on 13 May 2027. The Schedule ceiling for failure of reasonable security safeguards is ₹250 crore (Section 8(5)); failure to intimate a breach is assessed separately, commonly cited at ₹200 crore (Section 8(6)).
What personal data does a DPDPA mutual fund distributor already hold?
More than the folio, and in more places than one. A typical ARN holder or small RIA practice holds PAN copies and address proofs in a Downloads folder, risk-profile sheets in Excel, goal-planning notes naming a client’s spouse and children, cheque photographs sent over WhatsApp, and a prospect list from a society event three years ago. Under DPDPA 2023 there is no “sensitive personal data” tier — a PAN, a bank proof, a risk score and a mobile number all sit under one legal standard.
| Data category | Where it usually sits | Lawful ground | Keep or erase |
|---|---|---|---|
| KYC / PAN / address proof | Email attachments, Downloads, CRM uploads, duplicate scans on the phone | Section 7(a) for the transaction the investor approached you for; Section 6 consent for anything beyond it | Keep the copy PMLA and distributor record-keeping require, for the period that law requires; delete duplicates and phone copies |
| Risk-profile and income slab | Suitability sheets, onboarding forms, portfolio tracker | Section 7(a) for servicing and suitability; Section 6 consent for cross-sell use | Keep while the advisory relationship runs; erase on withdrawal unless another law requires retention |
| Nominee / joint-holder / spouse-child “family planning” data | Application forms, goal sheets, CRM free-text notes | Section 6 consent — these are separate Data Principals with their own access and correction rights | Keep the minimum the folio needs; erase family goal notes once the purpose is served |
| Minor folios | Folio records, guardian-signed forms, minor’s DOB and school details | Section 9 — verifiable parental or guardian consent; no tracking, behavioural monitoring or targeted ads directed at children | Keep as the folio requires; rebuild the basis directly with the investor at 18 |
| Prospect / dead-lead lists | Google Sheets, event lists, contacts shared by a sub-broker | No Section 7(a) cover — a stranger did not voluntarily approach you | Erase once the lead is cold or has said no |
| WhatsApp media (cheque photos, PAN scans) | WhatsApp Business media folder, phone gallery, auto-backup to cloud | Same ground as the underlying KYC; the extra copy is rarely necessary at all | Erase after the transaction; switch off media auto-save and cloud backup for the business number |
| Staff / ops assistant data | Payroll file, ID proofs, attendance sheet | Section 7(i) — employment processing | Keep per employment and tax law; do not stretch Section 7(i) to client data |
Does DPDPA apply to a one-person ARN holder or RIA?
Yes, and this is the most common misreading in the distributor community. The Act has no turnover, AUM or headcount threshold. Whoever determines the purpose and means of processing personal data is a Data Fiduciary — so a single ARN holder running a laptop, a WhatsApp Business number and a spreadsheet is squarely in scope, on the same timeline as a 200-crore practice. The scaling happens in effort, not in applicability: a two-person firm needs a notice, a consent record, processor contracts and a grievance route, not a compliance department. Our 2027 readiness guide for Indian SMBs walks the same logic for other small businesses.
If the AMC and RTA already have the folio, why am I still a Data Fiduciary?
Because you are not processing their copy — you are processing yours. The AMC and the RTA are each Data Fiduciaries for the folio they hold. Their consent artefacts cover their purposes. Nothing in that chain reaches your CRM, your KYC PDFs, your Excel sheets or your broadcast list.
Everything you plug into that practice is a Data Processor under Section 8(2) and needs a written contract: MFD CRM, portfolio tracker, WhatsApp Business Solution Provider, SMS and email gateway, cloud backup, and the part-time accountant or virtual assistant who touches client files. Click-through terms that let a vendor use your client book to “improve services” are a live gap, not boilerplate. And when a processor fails, the liability stays with you.
If you want a vendor to alert you within 24 hours of an incident, put it in the contract — that is a commercial term you negotiate, never a statutory DPDPA deadline. The DPDPA for financial services view sets out how the same processor logic runs across distributor, advisory and lending stacks.
Can I use KYC and risk-profile data to cross-sell insurance, PMS or WhatsApp campaigns?
Only with consent that meets Section 6: free, specific, informed, unconditional, unambiguous, and given by clear affirmative action. In practice that means separate ticks, not one bundled box:
- (a) servicing mutual fund transactions
- (b) review calls and portfolio statements
- (c) cross-sell of insurance, PMS, AIF or NPS
- (d) WhatsApp and marketing broadcasts
- (e) sharing with a sub-broker or relationship manager
Refusing (c) or (d) must not block (a). A consent screen that withholds servicing until the investor accepts marketing is not free consent, and under Section 6(10) you carry the burden of proving otherwise.
Section 5 requires notice at collection, in plain language, in English or an Eighth Schedule language the investor chooses. For the legacy book — the 400 clients onboarded before any of this existed — Section 5(2) requires a one-time notice as soon as reasonably practicable. That is a real project, and the earlier you run it, the less it collides with 13 May 2027. Our DPDPA guide for MFDs in India covers the notice-and-consent rebuild in more depth.
None of this displaces SEBI or AMFI. DPDPA sits alongside SEBI KYC and RIA conduct requirements and PMLA record-keeping; Section 8(7) expressly accommodates retention that another law compels. An ARN in good standing is not, by itself, DPDPA compliance.
What do I report if my laptop or CRM is compromised?
Four lanes, cumulative, all of them running at once — not two clocks and not a choice:
- CERT-In — for specified cyber incidents, commonly within 6 hours of becoming aware (Directions dated 28 April 2022).
- Rule 7(1) — intimate affected Data Principals without delay, in plain language, telling them what happened and what to do.
- Rule 7(2)(a) — initial intimation to the Data Protection Board without delay.
- Rule 7(2)(b) — a detailed report to the Board within 72 hours.
The common failure mode in this segment is not a sophisticated attack. It is an unencrypted laptop with a folder of KYC PDFs, or a WhatsApp backup sitting in a personal cloud account. The Schedule ceiling for failure of reasonable security safeguards is ₹250 crore under Section 8(5); failure to intimate a breach is assessed separately, commonly cited at ₹200 crore under Section 8(6). The Board decides on facts — it is not an automatic invoice. Our NBFC breach walkthrough covers the mechanics in a lending context; for a distributor, read it as the four Rule 7 lanes plus CERT-In.
Do I need a DPO or an annual DPDPA audit as an MFD?
No. Rule 13 DPIAs, independent data protection audits, algorithmic due diligence and an India-based DPO attach only to Significant Data Fiduciaries notified by the Central Government under Section 10. Client count and AUM do not promote you into that class. Do not title anyone “DPO” if you are not an SDF — it creates an obligation you did not have.
What every practice does need: a published Section 8(9) contact, a Section 8(10) grievance mechanism, and Rule 14(1) publication of how investors make access, correction and erasure requests. Note that the Rule 14(3) 90-day figure is the outer ceiling for grievance resolution, not a service standard to apply to every rights request — a nominee asking to correct a spelling should not wait a quarter.
Who owns what in a one-to-five person practice?
| Area | Owner | Status ☐ |
|---|---|---|
| Notice and consent artefacts (new onboarding + Section 5(2) legacy notice) | Principal / ARN holder | ☐ |
| CRM, tracker, BSP and backup — Section 8(2) written processor contracts | Principal / ops assistant | ☐ |
| WhatsApp and marketing opt-out, honoured across all lists | Ops assistant | ☐ |
| PMLA and record-keeping retention vs erasure purge (dead leads, duplicate scans, WhatsApp media) | Principal | ☐ |
| Named Section 8(9) contact published on site, emailer and folio comms | Principal | ☐ |
| Saturday breach drill — who calls CERT-In, who drafts the Rule 7(1) client note | Whole team | ☐ |
Closing
Three things worth doing this quarter, in order:
- Map before you fix. One page listing every place client data lives — CRM, laptop, WhatsApp, Drive, email, the accountant’s machine. You cannot contract or erase what you have not found.
- Split the consent. Rebuild onboarding so servicing, review, cross-sell, broadcasts and sub-broker sharing are five separate affirmative choices, then run the Section 5(2) notice to the legacy book.
- Paper the processors. Written Section 8(2) contracts with the CRM, the BSP and the backup vendor, including the alert window you want commercially.
On the architecture side, what holds up under Board scrutiny is boring and structural: personal data sealed in a vault rather than scattered across folders, consent records written so they cannot be quietly edited after the fact, and an audit trail good enough to be evidence rather than a log file. If you would rather start from a list than a blank page, the DPDPA checklist for MFDs is built for a practice this size.
Book a 30-minute DPDPA discovery call
Frequently asked questions
Does DPDPA apply to a one-person ARN holder with a small book?
Yes. The Act sets no AUM, turnover or headcount threshold. If you decide why and how client data is processed — your CRM, your KYC PDFs, your WhatsApp Business number — you are a Data Fiduciary and Sections 5, 6, 8 and 9 apply to you exactly as they apply to a large distributor.
Does the AMC’s consent cover my CRM and WhatsApp?
No. The AMC and the RTA are separate Data Fiduciaries for the folio. Consent taken on their application form covers their processing, not yours. Under Section 6(10) the burden of proving valid consent for your CRM, prospect sheets and broadcast lists sits with you.
Does PMLA retention block an investor’s erasure request?
Partly. Section 8(7) lets you retain what another law requires you to keep, so client-identity and transaction records stay for the period that law requires. It does not cover dead prospect lists, duplicate KYC scans, WhatsApp media or marketing segments — those must be erased once the purpose is served or consent is withdrawn.
Do I need an annual DPDPA audit or a DPO as an MFD?
No. Rule 13 DPIA, independent audit, algorithmic due diligence and an India-based DPO apply only to Significant Data Fiduciaries notified by the Central Government under Section 10, and client count or AUM does not make you one. You still need a published Section 8(9) contact and a Section 8(10) grievance route.
Sources
- Digital Personal Data Protection Act, 2023 (MeitY) — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- DPDP Act commencement, G.S.R. 843(E), 13 November 2025 (MeitY) — https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) (MeitY) — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- PIB — DPDP Act background — https://pib.gov.in/PressReleseDetail.aspx?PRID=1947264
- CERT-In Directions under Section 70B(6) of the Information Technology Act, 2000, dated 28 April 2022 — https://www.cert-in.org.in/Directions70B.jsp — cited for the 6-hour cyber-incident reporting clock.
Privigo is not a law firm. This article is general information, not legal advice. SEBI, AMFI and PMLA obligations continue to apply alongside DPDPA and are not displaced by it. Please consult qualified Indian counsel before acting on anything here.


