Securities
Apply the CSCRF category and implementation schedule for the exact SEBI regulated entity (RE). The 20 August 2024 framework, subsequent circulars and 11 June 2025 FAQ must be read together.
Data, systems and actors
Section titled “Data, systems and actors”Investor KYC, PAN-linked identifiers, bank/demat, holdings/orders/trades, nominee, risk profile, research/advisory, complaints, call recordings, device/fraud and employee data flow through KRA, CKYC, exchange/depository, OMS/RMS, back office, fund accounting, RTA, broker apps, surveillance, CRM, SCORES and cloud/security providers.
Control intersections
Section titled “Control intersections”| Topic | DPDP operations | SEBI/CERT-In overlay |
|---|---|---|
| entity | Fiduciary/Processor per purpose | RE category and registration |
| safeguards | Act s8 / Rule 6 readiness | CSCRF governance and maturity controls |
| incident | Principal/Board notices from 2027 | CSCRF/SEBI and CERT-In clocks now |
| retention | purpose end subject to law | books, orders, calls, audit/surveillance sources |
| vendors/cloud | processor instruction | CSCRF/cloud, audit and regulator access |
| rights | access/correction/erasure | market integrity, third-party and preservation exceptions |
Minimum configuration
Section titled “Minimum configuration”Store SEBI registration, RE category, market infrastructure dependencies, service criticality, CSCRF circular/FAQ versions, SOC route, cyber-audit cadence and regulator contacts. Inventory OMS/RMS, order/trade logs, KYC/KRA, RTA/depository, grievance, telephony and analytics. Use record- class retention rather than “SEBI data: eight years” shorthand.
Sample request path
Section titled “Sample request path”An investor correction enters with a client/folio/demat reference. The case verifies identity through the existing account, splits KYC-source correction from broker/fund copies, preserves trade records, sends approved updates to authoritative systems, obtains acknowledgements and securely delivers a completion/partial result. Connector failure creates reconciliation, not a false close.
Incident path
Section titled “Incident path”Classify CSCRF and CERT-In triggers immediately while assessing personal-data breach impact. Store exchange/depository dependencies and regulator-specific formats. A DDoS with no personal-data compromise can still be a cyber reporting event; a misdirected investor file can be a DPDP breach without the same infrastructure impact.
Evidence
Section titled “Evidence”Approved RE profile, CSCRF control map, asset inventory, VAPT/audit artefact references, incident test decisions, regulator receipts, processor/cloud assessments, rights fulfilment, retention authority and deletion/hold results.
Open counsel questions
Section titled “Open counsel questions”- Which later SEBI implementation circulars alter dates for this RE class?
- Which records require preservation for inspection, surveillance, investor dispute or AML?
- Which group/outsourced entity determines purpose for RTA, KRA, research and distribution flows?
- How do foreign portfolio investor and overseas support flows affect scope and transfer controls?