For most of the last decade, “archival” sat quietly in the IT budget, somewhere between backup and offsite tape storage, a cost center nobody asked questions about until an auditor did. That era ended in 2026. Three regulatory forces – the Reserve Bank of India, the Securities and Exchange Board of India, and the Digital Personal Data Protection (DPDP) Act, have converged on the same category of infrastructure decision, and the penalties attached now reach the balance sheet, not just the server room. For India’s banks, NBFCs, fintechs, and increasingly its media companies, how long data is kept, where it lives, and how fast it can be produced has become a question the board asks the CFO, not one the CFO delegates to IT.
The Three-Front Regulatory Squeeze
The pressure isn’t coming from one direction, it’s coming from three regulators with different, sometimes conflicting, mandates.
RBI requires banks and NBFCs to retain KYC and identity documentation for a minimum of five years from the end of the customer relationship, and in many cases up to ten years under the Prevention of Money Laundering Act rules governing NBFCs specifically. Loan files must survive seven to ten years after account closure meaning a 20-year mortgage can carry a 27-year retention obligation on a single file. Board and committee minutes must be preserved for the lifetime of the institution.
SEBI has moved in the same direction. Broker books, records and KYC documentation, previously governed by a five-year window under the 1992 regulations, now carry an eight-year minimum under SEBI’s 2026 regulatory update – a direct extension aimed at intermediaries, trading platforms and the fast-growing wealthtech segment of India’s FinTech industry.
DPDP, meanwhile, pulls in a different direction entirely. The Act’s default posture is deletion: Section 8(5) requires data fiduciaries to erase personal data once its stated purpose is served or consent is withdrawn unless another law requires longer retention. But the DPDP Rules, 2025, notified in November 2025, added a twist few compliance teams saw coming: Rule 8(3) now mandates that every data fiduciary retain personal data, associated traffic data, and processing logs for a minimum of one year from the date of processing regardless of whether the user has withdrawn consent or deleted their account. For large e-commerce, gaming and social media intermediaries, the Third Schedule adds further erasure timelines layered on top.
The result: the same customer record can simultaneously be subject to a “keep it for ten years” instruction from RBI and a “delete it once the purpose ends” instruction from DPDP reconciled only by DPDP’s own legal-obligation carve-out, which most organizations haven’t yet documented properly.
The Stakes: What Non-Compliance Actually Costs
This isn’t a theoretical compliance exercise. The DPDP Act’s penalty schedule, published by the Ministry of Electronics and IT, sets a ceiling of ₹250 crore per instance for failing to maintain reasonable security safeguards over personal data, and up to ₹200 crore for failing to notify a breach to the Data Protection Board and affected individuals. Crucially, these are fixed-rupee ceilings, not a percentage of turnover and they apply per qualifying instance, meaning a single incident that breaches multiple obligations at once can compound quickly.
On the RBI side, the cost of non-compliance is less a fixed fine and more an operational failure at the worst possible moment: an active file must be producible within 15-30 minutes of an auditor’s request, and even archived records are expected within 48-72 hours. A record that technically exists but can’t be retrieved on schedule is, from an inspection standpoint, indistinguishable from a record that was never kept at all.
BFSI and FinTech: Reconciling “Keep Everything” with “Delete on Request”
The practical fix compliance and infrastructure teams are converging on is a tiered retention schedule mapping each data category to its governing regulation rather than applying one blanket policy. Financial transaction data, KYC records and loan documentation get retained for the RBI-mandated period (five to ten years) under the DPDP’s own legal-obligation exception. Marketing consent, behavioral analytics and other non-regulatory personal data follow DPDP’s purpose-limitation principle and get deleted once their purpose ends. Processing logs get retained for the one-year DPDP floor at minimum, often longer to support RBI audit trails.
This only works if the underlying storage layer can actually enforce it, different retention clocks, immutability where required, and provable deletion where required, all within infrastructure that itself resides in India.
Media: The Archival Blind Spot Nobody’s Naming Yet
BFSI’s retention rules get the regulatory headlines, but media and broadcast companies carry a quieter version of the same problem. DPDP applies to any organization processing the personal data of Indian users which includes subscriber data, viewer analytics, and OTT account information that media companies hold at scale. Layered on top is a separate, non-regulatory but equally pressing archival need: broadcast masters, licensed content libraries and uplinked feeds that carry both commercial IP value and potential evidentiary weight in disputes often sitting on storage media that was never designed to last a decade, let alone survive a DPDP-grade audit trail.
What Board-Ready Archival Actually Requires
Across BFSI, FinTech and Media, the converging checklist looks the same: data residency within India to satisfy RBI, SEBI and DPDP simultaneously; encryption keys controlled by the enterprise, not the vendor; tiered, rule-mapped retention schedules rather than a single policy; immutable, tamper-evident storage for audit trails; and retrieval SLAs measured in minutes and hours, not days. This is precisely the layer GatiCloud’s long-term archival storage is built for grounded in the SCOPE framework of Sovereignty, Cost-Efficiency, Open Source, Performance and Ease-of-Use, giving regulated Indian enterprises archival infrastructure that’s audit-ready by design, not retrofitted under deadline pressure.
Frequently Asked Questions
Is 10-year retention now mandatory for all BFSI records in India?
It varies by record type: KYC/identity records typically require a minimum of 5 years post-relationship, loan files 7-10 years post-closure, and certain NBFC transaction records up to 10 years under PMLA.
Does DPDP override RBI or SEBI retention requirements?
No. Section 8(5) of the DPDP Act explicitly allows longer retention when required by another law, so RBI and SEBI’s sector-specific mandates take precedence over DPDP’s general purpose-limitation principle for those specific record categories.
What’s the maximum penalty under DPDP for an archival or security failure?
Up to ₹250 crore per instance for failing to implement reasonable security safeguards, applied by the Data Protection Board of India.
Does DPDP’s one-year retention rule apply to media and OTT companies?
Yes, DPDP Rule 8(3) applies to every data fiduciary processing personal data, which includes media and OTT platforms holding subscriber and viewer information, regardless of sector.
Key Takeaway
Long-term archival in India has quietly become a board-level infrastructure decision not because storage got harder, but because three regulators now expect the same data to be retained, protected, deleted and produced on entirely different clocks. Whether you are a bank preparing for an RBI inspection, a broker aligning with SEBI’s 2026 record rules, or a media company processing subscriber data under DPDP, the archival layer is where all three requirements have to be reconciled at once. GatiCloud’s archival infrastructure is built for exactly this convergence, India-resident, audit-ready, and engineered to make retrieval a formality rather than a fire drill.
Sources cited: RBI, Consentos, Myriad Storage Systems, TCSA, PwC India, ThePrint, ICSI, PIB (Government of India), MeitY.