Back to Interaction with Other Laws

SEBI and IRDAI Regulations

How securities and insurance sector regulations interact with the DPDPA - cybersecurity frameworks, data handling, and dual compliance.

7 min read

SEBI Cybersecurity Framework

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) applies to stock exchanges, depositories, mutual funds, brokers, and other market intermediaries. It prescribes requirements for data classification, access controls, encryption, incident response, and business continuity. A crucial 2025 update introduced the 'Principle of Equivalence': if a Regulated Entity (e.g., a Bank acting as a Broker) complies with a stricter primary regulator's (RBI) cyber framework, SEBI deems it compliant with CSCRF to avoid duplication. The DPDPA, however, has no such equivalence - entities must still meet the DPDPA's specific privacy-centric safeguards under Rule 6 and breach notification under R.7. The financial services sector guide provides additional compliance context.

IRDAI Information Security Guidelines

IRDAI's Information and Cyber Security Guidelines apply to insurance companies and intermediaries. They cover data protection, access management, network security, and incident reporting. Insurance entities process sensitive personal data including health information, financial details, and family data. The DPDPA's consent requirements and children's data provisions (R.9-12) add additional obligations beyond IRDAI's framework.

Dual Compliance Requirements

Regulated entities in both sectors face dual compliance obligations. Key areas of overlap include: (a) incident reporting - SEBI/IRDAI/CERT-In require reporting within 6 hours of becoming aware of a cybersecurity incident, while DPDPA Rule 7 requires a detailed report to the Board within 72 hours. A single breach therefore triggers a dual-clock obligation: reporting at 72 hours satisfies the DPDPA but constitutes a regulatory violation under SEBI/IRDAI; (b) data retention - sectoral requirements may mandate longer retention than DPDPA's R.8; (c) security measures - both frameworks prescribe security standards; and (d) cross-border transfers - sectoral restrictions may apply beyond DPDPA. The principle of applying the stricter standard at each overlap point applies.

Practical Steps for Compliance

Securities and insurance entities should: (a) map all regulatory requirements in a compliance matrix; (b) identify overlap points between sectoral and DPDPA requirements; (c) implement the stricter standard at each overlap; (d) establish unified incident response procedures covering all regulators; and (e) designate compliance officers familiar with both frameworks.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.