RISKFORTIS
Enforcement092d 01h 44m

Case study

Eleven unmapped processors found, and a breach clock the team could actually meet.

Industry
Lending · NBFC
Location
Western India · 34 branches
Company size
800 employees
Engagement
Gap assessment → implementation

Client anonymised at their request. Sector, scale, regulatory stack and findings are as delivered. Regulatory stack: DPDP Act 2023 & Rules 2025 · CERT-In Directions 2022 · RBI Digital Lending Guidelines · RBI Master Direction on IT Governance · TRAI TCCCPR.

04
Consultants deployed
11
Weeks to deliver
1.4M
Data principals covered

Challenges

What the assessment actually found.

  1. 01

    Eleven vendors were processing borrower personal data with no data processing agreement and no breach notification clause.

  2. 02

    The KYC vendor's retention setting kept Aadhaar and PAN images indefinitely, three years past any purpose the lender could state.

  3. 03

    Consent was captured once at onboarding as a single bundled tick, with no withdrawal path and no retained artefact.

  4. 04

    The incident response plan named no owner for regulatory filing, and nobody in the room knew the CERT-In window was six hours.

  5. 05

    Two collections agencies held delinquency lists on agent-owned devices, outside any access control the lender operated.

  6. 06

    RBI record-keeping mandates and DPDP erasure rights had never been reconciled, so every deletion request stalled in legal.

Solutions

What we built, one for one.

Each item below closes the finding with the matching number above.

  1. 01

    All eleven vendors repapered onto one processor agreement with a four-hour internal breach notification obligation.

  2. 02

    Field-level retention schedule written against RBI mandates, with the KYC vendor's purge configured and evidenced.

  3. 03

    Purpose-separated consent capture with a withdrawal route in the app, and every artefact stored with its notice version.

  4. 04

    Rule 7 and CERT-In runbook with named owners and deputies, both clocks on one page, tested in a timed drill in week ten.

  5. 05

    Collections moved to a managed portal with per-agent access, no local export, and a monthly access review the lender runs.

  6. 06

    A written reconciliation of RBI retention against DPDP erasure, field by field, so support answers without escalating.

Outcomes

What changed, measured at handover.

  1. 01

    Processor coverage went from 0 of 11 under a DPDP-compliant agreement to 11 of 11.

  2. 02

    The first purge cycle deleted 2.6M KYC document images the lender had no basis to hold.

  3. 03

    A data principal correction request that previously had no route now closes in a median 6 days, inside the window.

  4. 04

    In the week-ten drill the team filed a CERT-In report at 04h 12m against the 6h window. The first attempt, in week two, had reached hour nine without filing.

  5. 05

    Borrower data on agent-owned devices went to zero, replaced by 340 named portal accounts under monthly review.

  6. 06

    Erasure requests stopped escalating to legal — support now answers from the reconciliation table, and the board pack reports it quarterly.

Services used

01

DPDP Gap Assessment

Three weeks. Produced the eleven-processor finding and the costed roadmap the board approved.

See the scope

02

DPDP Compliance Implementation

Eight weeks. Notices, consent, rights workflow, retention, processor pack and the evidence behind them.

See the scope

03

Fortis Drills

Two timed drills, week two and week ten, which is where the four-hour filing came from.

See how a drill runs

Eleven processors nobody had mapped. How many do you have?

Talk to DPDP experts

Free consultation · 45 min · scope and fee in writing within two working days.