Analyse the interplay between sectoral regulators (RBI, SEBI) and horizontal data protection law (DPDP Act, 2023) in India's data governance architecture.

Q. Analyse the interplay between sectoral regulators (RBI, SEBI) and horizontal data protection law (DPDP Act, 2023) in India's data governance architecture. (15 marks, 250-350 words)

India's data governance architecture rests on two layers: a horizontal statute, the Digital Personal Data Protection Act, 2023, which creates uniform consent-based obligations for all data fiduciaries [2], and vertical sectoral regulation by RBI and SEBI, which treats data as a prudential and systemic risk concern. Analysing their interplay requires separating their distinct logics before seeing how they combine.

Distinct mandates - DPDP Act protects the individual data principal — consent, notice, erasure, grievance redress — enforced by the Data Protection Board; Rules notified in November 2025 phase in fiduciary duties [3]. - Sectoral regulators protect market and institutional integrity. RBI's draft "Guidance on Regulatory Expectations for Data Governance" (July 2026) mandates a board-approved Data Governance Framework, roles of Data Owner/Steward/Custodian, and a Single Source of Truth across regulated entities including NBFCs, ARCs and CICs [1]. - SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), 2024 similarly imposes uniform data-security and resilience standards on its regulated entities [4].

Points of convergence - Sectoral norms operationalise the statute: RBI explicitly frames its guidance as aiding DPDP compliance, converting broad statutory duties into auditable controls [1]. - Both embed board-level accountability, continuing the trajectory of RBI's IT Governance Master Direction (2023) [5]. - Proportionality — scaling obligations to an entity's size and complexity — keeps small cooperative banks and RRBs within reach of compliance [1].

Points of friction - Regulatory overlap: an entity answers both the Data Protection Board and its sectoral supervisor, risking duplicated audits and compliance cost. - Doctrinal tension: DPDP's data-minimisation and erasure rights sit uneasily with prudential record-retention and KYC mandates. - Sectoral instruments issued as draft guidance create interim uncertainty for entities already preparing for DPDP timelines [1].

The architecture is therefore best read as complementary rather than competing — the statute sets the floor of individual rights, sectoral regulators build supervisory depth above it. Harmonised timelines, a common taxonomy, and formal RBI–SEBI–Data Protection Board coordination would convert overlap into layered assurance, advancing both financial stability and the informational privacy affirmed in K.S. Puttaswamy.

(~330 words)

Sources: 1. RBI Press Release — "RBI issues draft 'Guidance on Regulatory Expectations for Data Governance'" (15 July 2026) — DGF mandate, Data Owner/Steward/Custodian roles, Single Source of Truth, applicability to NBFCs/ARCs/CICs, proportionality, draft status, DPDP alignment 2. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitY — horizontal consent-based obligations on data fiduciaries 3. PIB — "Digital Personal Data Protection (DPDP) Rules, 2025" — Rules notified November 2025, phased fiduciary obligations 4. SEBI Circular — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024) — uniform data-security and resilience standards in securities markets 5. RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (7 November 2023) — board-level accountability for IT and data risk