Fintech and banking
You can answer to RBI or SEBI through your license, to PCI DSS because card data crosses your systems, and to a bank customer's SOC 2 request, all at once. We help you work out which apply before you choose any assessment.
Industry compliance rules in India
Some security rules come with a license or registration from a regulator such as RBI or SEBI. Others follow the card numbers and personal data you hold, whatever your sector, and customers abroad can bring their own, such as HIPAA or GDPR. We help you work out which apply, then build and secure your software to meet them.
Industries
Each sector page covers what that sector adds to the data rules, and what we build and secure for companies in it. No sector regulator? The card and personal data rules still apply.
You can answer to RBI or SEBI through your license, to PCI DSS because card data crosses your systems, and to a bank customer's SOC 2 request, all at once. We help you work out which apply before you choose any assessment.
Patient data leaves a hospital through labs, imaging, claims and the patient app. HIPAA's business associate rules and India's DPDP Act follow it into every vendor that handles it.
No regulator of your own, but customers' security questionnaires ask for SOC 2, ISO 27001 or, once AI is in the product, ISO 42001. Each of those audits reads records that must already exist.
A store sets its PCI DSS scope when it builds the checkout and chooses how the payment page is delivered. India's DPDP Act and E-Commerce Rules add more.
Logistics, hospitality, education, travel and smart home. With no sector regulator, compliance starts from the card and personal data you hold.
Systems that never touch a card number can fall inside PCI DSS v4.0.1 scope by connecting to ones that do. The DPDP Act, 2023 puts its duties on the company that decides how personal data is used; its processors aren't addressed directly.
Looking for a service rather than a sector? See GRC and compliance or all our services.
License or data
Who licensed you and what you store matter more than your industry label.
Ask what a fintech has to comply with and you're asking two questions at once. One is about the company: RBI and SEBI write their directions for the businesses they license or register. The other is about the data: card numbers and personal records bring their own rules into any company that keeps them.
The mistake to avoid is filing a data rule under a sector. PCI DSS v4.0.1 applies to any business that stores, processes or transmits card account data. A software company whose own servers receive card numbers is in scope, though nobody would call it a payments business.
Sector rules can reach outside their sector too. RBI's Payment Aggregator Directions, 2025 require the aggregator to meet PCI DSS, and clause 9(a) makes it answerable for whether each merchant's infrastructure complies. So an online shop that RBI doesn't regulate still meets the rule when its aggregator onboards it.
Which rules apply to us?
Each line leads to the page that explains the rule and what we do about it. You may fit more than one.
Before you scope
Run them in order. The answers point to the pages you need.
Check whether a regulator has licensed or registered your company in its own name.
Trace a card number from entry and list every system of yours it touches.
List the digital personal data you keep on customers, staff and job applicants.
Read contracts with banks, brokers, aggregators and hospitals for clauses that pass their duties to you.
Separate what a regulator requires from what a customer's questionnaire asks. Only the first binds you without a signature.
No sector regulator
If you run a restaurant, a logistics firm, a school or a property business, start with our card data and personal data pages. Those rules work the same way in a delivery app as in a bank.
The DPDP Act, 2023 covers digital personal data only, so a paper register that was never digitized sits outside it.
What we don't decide for you. We don't give legal advice, so your counsel confirms whether a rule binds you. We're also neither a PCI QSA Company nor an Approved Scanning Vendor: we prepare you for those sign-offs.
FAQ
Who each rule binds, and when. For anything else, ask us directly.
Yes. PCI DSS v4.0.1 attaches to card account data, whatever the industry, so a hotel or a school is covered once its systems store, process or transmit that data. Size changes only how you validate: card brands set merchant levels by transaction volume, and your acquirer picks the route. The result is an Attestation of Compliance, which isn't a certificate.
The Act doesn't sort companies by industry. It binds whoever decides why and how digital personal data is processed, which it calls a Data Fiduciary, whether that's a lender or a logistics firm. Duties owed to individuals, such as notice and breach reporting, commence in May 2027 under the DPDP Rules, 2025.
Not directly. RBI writes its directions for the entities it regulates: its cybersecurity directions of 31 July 2026 cover commercial banks, with separate sets for small finance banks and payments banks. A fintech without its own RBI license isn't the addressee, though a partner bank can write the same duties into their contract.
No. It's addressed to entities SEBI regulates, and a firm comes under it through its SEBI registration. A software vendor serving brokers holds no such registration for that work, so the framework isn't addressed to it. The framework is CSCRF Version 1.0, as modified by SEBI's Technical Clarifications circular of 28 August 2025.
Data rules still reach the business. A restaurant group or an education platform comes under PCI DSS v4.0.1 once its systems handle card account data. It also comes under the DPDP Act, 2023 for the digital personal data it keeps, with duties from May 2027. Customers can add more rules by contract.
No. The DPDP Act, 2023 has no separate category for sensitive or health data, so patient records and a retailer's mailing list start from the same duties. Any health-specific obligations come from other laws layered on top of the Act.
Let's talk
Tell us who licenses you, where card numbers travel and whose personal data you keep. We'll suggest where to start, and what we can build or secure for you. We reply within one working day.