VDA SPs must comply with both FIU-IND cybersecurity requirements and DPDPA obligations. Key intersection points: (a) security safeguards -
R.6 requirements for encryption, masking, and access controls align with FIU-IND audit criteria; (b) the Rule 6 logging mandate, which specifically requires technical measures to retain logs for one year for security detection; (c) breach notification - both frameworks require incident reporting; (d) data retention - transaction monitoring records must be balanced against R.8 retention limits; and (e) KYC data - processing falls under
legitimate use (Section 7) for legal compliance.
As reporting entities under the Prevention of Money-Laundering Act (PMLA), 2002, VDA SPs are also independently required by section 12 of the PMLA to maintain records of transactions and client identification, and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 require these records to be retained for a minimum of five years. This PMLA retention obligation applies alongside, and may exceed, DPDPA retention limits.
The stricter standard applies at each overlap point.