Home All services
Start a project → Call Now

Industry compliance rules in India

Software and security built around the rules you answer to.

Some security rules come with a license or registration from a regulator such as RBI or SEBI. Others follow the card numbers and personal data you hold, whatever your sector, and customers abroad can bring their own, such as HIPAA or GDPR. We help you work out which apply, then build and secure your software to meet them.

  • Rules traced before any work is scoped
  • One team builds and secures your software
  • We reply within one working day.
  • PCI DSS v4.0.1
  • DPDP Act, 2023
  • RBI PA Directions, 2025
  • SEBI CSCRF Version 1.0
Illustration: four round platforms holding a bank with a payment card, a medical tablet with a stethoscope, a cloud of app windows and a shopping bag with a parcel, joined by glowing lines to a shield in the center

In brief

Who it's for
Banks, fintechs, clinics, software companies and online stores, and businesses in sectors with no regulator of their own, such as logistics, hotels and schools.
What gets in the way
Rules arrive by different routes: a regulator's license, the card and personal data you hold, and contracts with banks, brokers, aggregators or hospitals. You can owe several at once, and each asks for different evidence.
How we help
We trace which rules reach you and why, build and secure your software to meet them, and get you ready for the sign-offs they need.

Industries

Start with your sector, or with the data you hold.

Each sector page covers what that sector adds to the data rules, and what we build and secure for companies in it. No sector regulator? The card and personal data rules still apply.

Card and personal data, in any sector

Systems that never touch a card number can fall inside PCI DSS v4.0.1 scope by connecting to ones that do. The DPDP Act, 2023 puts its duties on the company that decides how personal data is used; its processors aren't addressed directly.

Looking for a service rather than a sector? See GRC and compliance or all our services.

License or data

Where your security rules come from.

Who licensed you and what you store matter more than your industry label.

Ask what a fintech has to comply with and you're asking two questions at once. One is about the company: RBI and SEBI write their directions for the businesses they license or register. The other is about the data: card numbers and personal records bring their own rules into any company that keeps them.

The mistake to avoid is filing a data rule under a sector. PCI DSS v4.0.1 applies to any business that stores, processes or transmits card account data. A software company whose own servers receive card numbers is in scope, though nobody would call it a payments business.

Sector rules can reach outside their sector too. RBI's Payment Aggregator Directions, 2025 require the aggregator to meet PCI DSS, and clause 9(a) makes it answerable for whether each merchant's infrastructure complies. So an online shop that RBI doesn't regulate still meets the rule when its aggregator onboards it.

Four ways a rule reaches you

  • With a license or registration. RBI's directions for banks and payment aggregators, and SEBI's CSCRF for the firms it registers.
  • With card data. PCI DSS v4.0.1, in any sector.
  • With personal data. The DPDP Act, 2023, with duties from May 2027.
  • By contract. Duties a bank, broker, aggregator or hospital passes on to you.

Which rules apply to us?

Find the line that sounds like your company.

Each line leads to the page that explains the rule and what we do about it. You may fit more than one.

Before you scope

Five checks to run before any work is scoped.

Run them in order. The answers point to the pages you need.

  1. Your license

    Check whether a regulator has licensed or registered your company in its own name.

  2. The card's path

    Trace a card number from entry and list every system of yours it touches.

  3. Personal data

    List the digital personal data you keep on customers, staff and job applicants.

  4. Your contracts

    Read contracts with banks, brokers, aggregators and hospitals for clauses that pass their duties to you.

  5. Regulator or customer

    Separate what a regulator requires from what a customer's questionnaire asks. Only the first binds you without a signature.

A spiral notebook and water bottles on a wooden meeting table

No sector regulator

Sectors without a regulator start with data rules.

If you run a restaurant, a logistics firm, a school or a property business, start with our card data and personal data pages. Those rules work the same way in a delivery app as in a bank.

Data that brings a rule into any sector

  • In-store card payments. A card tapped or swiped at a counter counts as account data under PCI DSS v4.0.1.
  • Cards kept for repeat billing. Tokenization shrinks storage scope, but card capture stays in scope.
  • Customer and staff details. Customer phone numbers, delivery addresses and staff files count once they're held in an app or a spreadsheet.
  • Records about children. Student and child records carry DPDP Act duties that adult records don't.

The DPDP Act, 2023 covers digital personal data only, so a paper register that was never digitized sits outside it.

What we don't decide for you. We don't give legal advice, so your counsel confirms whether a rule binds you. We're also neither a PCI QSA Company nor an Approved Scanning Vendor: we prepare you for those sign-offs.

FAQ

Questions about sector rules and data rules.

Who each rule binds, and when. For anything else, ask us directly.

Yes. PCI DSS v4.0.1 attaches to card account data, whatever the industry, so a hotel or a school is covered once its systems store, process or transmit that data. Size changes only how you validate: card brands set merchant levels by transaction volume, and your acquirer picks the route. The result is an Attestation of Compliance, which isn't a certificate.

The Act doesn't sort companies by industry. It binds whoever decides why and how digital personal data is processed, which it calls a Data Fiduciary, whether that's a lender or a logistics firm. Duties owed to individuals, such as notice and breach reporting, commence in May 2027 under the DPDP Rules, 2025.

Not directly. RBI writes its directions for the entities it regulates: its cybersecurity directions of 31 July 2026 cover commercial banks, with separate sets for small finance banks and payments banks. A fintech without its own RBI license isn't the addressee, though a partner bank can write the same duties into their contract.

No. It's addressed to entities SEBI regulates, and a firm comes under it through its SEBI registration. A software vendor serving brokers holds no such registration for that work, so the framework isn't addressed to it. The framework is CSCRF Version 1.0, as modified by SEBI's Technical Clarifications circular of 28 August 2025.

Data rules still reach the business. A restaurant group or an education platform comes under PCI DSS v4.0.1 once its systems handle card account data. It also comes under the DPDP Act, 2023 for the digital personal data it keeps, with duties from May 2027. Customers can add more rules by contract.

No. The DPDP Act, 2023 has no separate category for sensitive or health data, so patient records and a retailer's mailing list start from the same duties. Any health-specific obligations come from other laws layered on top of the Act.

Sources (as of September 2026)
  1. PCI Security Standards Council, PCI DSS v4.0.1.
  2. Digital Personal Data Protection Act, 2023, and DPDP Rules, 2025. Duties owed to Data Principals commence in May 2027, 18 months after the Rules were published.
  3. Reserve Bank of India, Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, for commercial banks, 31 July 2026.
  4. Reserve Bank of India, Payment Aggregator Directions, 2025, clause 9(a).
  5. SEBI, Cybersecurity and Cyber Resilience Framework (CSCRF) Version 1.0, as modified by SEBI's Technical Clarifications circular of 28 August 2025.

Let's talk

Find out which rules reach your company.

Tell us who licenses you, where card numbers travel and whose personal data you keep. We'll suggest where to start, and what we can build or secure for you. We reply within one working day.