DPDP NavigatorAct 2023 · Rules 2025
All guides
Legal Intelligence

How Sector Regulators (RBI, IRDAI, TRAI) Interact With the DPDP Act

23 Jul 20269 min read

The DPDP Act does not operate in a vacuum. Existing sectoral rules on data localisation, KYC, and customer information continue alongside it, sometimes overlapping and sometimes diverging.

Layered regulation, not replacement

The DPDP Act is a horizontal, general-purpose data protection law, and it does not repeal or displace the sector-specific data-related requirements that regulators like the Reserve Bank of India (RBI), the Insurance Regulatory and Development Authority of India (IRDAI), and the Telecom Regulatory Authority of India (TRAI) had already established before the Act's passage. Organisations operating in regulated sectors should expect to comply with both the DPDP Act's general obligations and their sector regulator's pre-existing data-related directions, rather than treating the DPDP Act as a full substitute for either.

This layered structure is common internationally, general data protection law sitting alongside sector-specific rules, but it does raise a genuine practical question of how the two layers interact where they address overlapping ground, such as security safeguards or breach reporting, an area where further clarity from regulators over time would be useful.

RBI and data localisation

RBI's data localisation expectations for payment system data, requiring certain payment-related data to be stored only in India, predate the DPDP Act and continue to apply alongside it. Because the DPDP Act's own cross-border transfer regime under Section 16 is comparatively permissive by default, RBI's sector-specific localisation requirement is likely to remain the more restrictive and operative constraint for payment system operators, regardless of how the DPDP Act's own restricted-country list develops.

Banks, payment aggregators, and other RBI-regulated entities should therefore continue to treat their existing RBI compliance obligations as a separate, ongoing workstream rather than assuming DPDP compliance automatically satisfies them.

IRDAI and insurer data practices

IRDAI has its own body of guidance concerning insurers' handling of policyholder data, including expectations around outsourcing arrangements and data security, that likewise operates independently of the DPDP Act. Insurers processing health-related information in the course of underwriting or claims, for instance, need to satisfy both IRDAI's sector expectations and the DPDP Act's general obligations, bearing in mind that the DPDP Act does not create a separate sensitive-data tier the way some other frameworks do, so health data is not automatically subject to a higher DPDP-specific bar even though it may be commercially and ethically treated with extra care.

TRAI and telecom customer information

TRAI's regulatory framework for telecom operators includes its own long-standing rules on subscriber information, privacy, and unsolicited communication, which continue to apply to telecom licensees independently of the DPDP Act. Telecom operators, already among the more heavily regulated sectors for customer data handling in India, are also a plausible category for Significant Data Fiduciary designation under Section 10 given the scale of personal data they process, which would add a further compliance layer on top of both TRAI's rules and the DPDP Act's general baseline.

Where to go next

For sector-specific compliance mapping, the Obligation Finder can help separate DPDP-specific obligations from pre-existing sectoral ones so the two are not conflated in an internal compliance program.