Skip to content

Securities

Sector regulation

Apply the CSCRF category and implementation schedule for the exact SEBI regulated entity (RE). The 20 August 2024 framework, subsequent circulars and 11 June 2025 FAQ must be read together.

Investor KYC, PAN-linked identifiers, bank/demat, holdings/orders/trades, nominee, risk profile, research/advisory, complaints, call recordings, device/fraud and employee data flow through KRA, CKYC, exchange/depository, OMS/RMS, back office, fund accounting, RTA, broker apps, surveillance, CRM, SCORES and cloud/security providers.

TopicDPDP operationsSEBI/CERT-In overlay
entityFiduciary/Processor per purposeRE category and registration
safeguardsAct s8 / Rule 6 readinessCSCRF governance and maturity controls
incidentPrincipal/Board notices from 2027CSCRF/SEBI and CERT-In clocks now
retentionpurpose end subject to lawbooks, orders, calls, audit/surveillance sources
vendors/cloudprocessor instructionCSCRF/cloud, audit and regulator access
rightsaccess/correction/erasuremarket integrity, third-party and preservation exceptions

Store SEBI registration, RE category, market infrastructure dependencies, service criticality, CSCRF circular/FAQ versions, SOC route, cyber-audit cadence and regulator contacts. Inventory OMS/RMS, order/trade logs, KYC/KRA, RTA/depository, grievance, telephony and analytics. Use record- class retention rather than “SEBI data: eight years” shorthand.

An investor correction enters with a client/folio/demat reference. The case verifies identity through the existing account, splits KYC-source correction from broker/fund copies, preserves trade records, sends approved updates to authoritative systems, obtains acknowledgements and securely delivers a completion/partial result. Connector failure creates reconciliation, not a false close.

Classify CSCRF and CERT-In triggers immediately while assessing personal-data breach impact. Store exchange/depository dependencies and regulator-specific formats. A DDoS with no personal-data compromise can still be a cyber reporting event; a misdirected investor file can be a DPDP breach without the same infrastructure impact.

Approved RE profile, CSCRF control map, asset inventory, VAPT/audit artefact references, incident test decisions, regulator receipts, processor/cloud assessments, rights fulfilment, retention authority and deletion/hold results.

  • Which later SEBI implementation circulars alter dates for this RE class?
  • Which records require preservation for inspection, surveillance, investor dispute or AML?
  • Which group/outsourced entity determines purpose for RTA, KRA, research and distribution flows?
  • How do foreign portfolio investor and overseas support flows affect scope and transfer controls?