Tuesday, August 4


In FY 2024–2025, RBI imposed ₹54.78 crore in penalties across 353 case spanning a range of governance and cybersecurity lapses. What were many of those organizations doing wrong? The same things most still do wrong today: shared admin accounts, passwords stored in spreadsheets, credentials exchanged over email or chat, and access permissions that were rarely reviewed. These were treated as harmless shortcuts, the kind of thing every IT team quietly tolerated. Regulators no longer see it that way.

India’s cybersecurity and data protection landscape has evolved rapidly with the introduction of the Digital Personal Data Protection Act (DPDPA), the Reserve Bank of India’s IT Governance Directions, and SEBI’s Cyber Security and Cyber Resilience Framework (CSCRF). This piece covers what they actually require, why a workforce password management solution sits at the center of meeting them, and what a practical compliance checklist looks like for the months ahead.
Three frameworks, one underlying demand.

The DPDPA, RBI’s IT Governance Directions, and SEBI’s CSCRF were built by different regulators, for different sectors, on different timelines. Strip the legal language away and all three converge on one demand: Protect workforce identities, secure privileged access, and maintain full visibility over who can reach critical systems and sensitive data.

Digital Personal Data Protection Act, 2023

DPDPA is India’s first comprehensive data protection law governing how organizations collect, store, and use the personal data of Indian residents—employee data included, not just customer data. It applies to virtually any entity, public or private, processing personal data in India. Rules were notified in November 2025; the Consent Manager framework goes live in November 2026; full enforcement with per-violation penalties begins May 2027.

Penalties can run up to ₹250 crore for security failures and a separate ₹200 crore for breach notification failures. These amounts are ceilings set case-by-case by the Data Protection Board rather than automatic per-violation fines, and they can stack, so one incident can expose an organization to both.

RBI Master Directions

RBI’s Master Directions on IT Governance (2023, effective April 2024) apply to banks, NBFCs, and payment operators. They go further than DPDPA on access control specifically: no shared admin passwords, mandatory role-based access with periodic review, full audit log retention, and data localisation for payment data. In 2026, the Master Directions were tightened further:

RBI’s Authentication Mechanisms for Digital Payment Transactions Directions, 2025 (issued September 2025) made two-factor authentication, with at least one dynamic factor, mandatory for all domestic digital payment transactions from April 1, and medium-sized payment system operators had to meet RBI’s payment security directions by the same date. Both deadlines have already passed.

SEBI’s Cyber Security and Cyber Resilience Framework, 2024

Introduced in August 2024, SEBI’s CSCRF applies to 22 types of regulated entities across a five-tier model, including stock exchanges, brokers, and asset management companies. It requires organizations to implement strong identity and access management, stay accountable for cybersecurity risk introduced by third-party vendors, and report cyber incidents within specified timelines.

The framework also scales its security requirements to the size and type of each regulated entity. These entities are expected to maintain continuous compliance through ongoing cybersecurity measures and periodic cyber audits.

The most recent half-yearly cyber audit submission, due June 30, 2026, has also passed. CSCRF doesn’t define a fixed penalty schedule, but SEBI can still enforce violations under the SEBI Act, 1992, where penalties for serious non-compliance can be significant.

How workforce password management helps in compliance with DPDPA, RBI, and SEBI

A workforce password management tool addresses this gap directly and helps organizations implement several of the technical controls these regulations call for.

Password generation and vaulting removes the human tendency to create weak, memorable, reused passwords, and replaces it with strong, unique credentials stored in an encrypted vault rather than a browser, a sticky note, or a shared document. This is the practical mechanism behind RBI’s “no shared admin passwords” requirement and SEBI’s IAM mandate.

Built-in policy engines let an organization enforce password complexity, rotation, and access rules automatically rather than relying on employees to follow a written policy. This is what turns a compliance document into an operational reality, and it’s what auditors actually want to see evidence of.

Role-based password sharing controls allow credentials to move securely between team members when sharing is genuinely necessary, without ever exposing the password itself. Access can be granted and revoked without a credential changing hands insecurely, directly supporting RBI’s role-based access requirement and SEBI’s vendor access governance expectations.

Reused password monitoring and password blocklisting catch the exact insider risk scenario where an employee reuses a corporate password on a personal account, or chooses a password that’s already known to be compromised. This is a direct answer to the insider-risk obligation that runs through all three frameworks.

Dark web monitoring provides continuous visibility into whether workforce credentials have appeared in a breach dump anywhere on the internet, closing the gap between when a credential is compromised and when the organization finds out about it. Paired with an incident response plan, this shortens the runway an organization needs to meet the DPDPA’s breach notification clock.

Together, these capabilities help deliver the audit trail, access governance, and insider risk mitigation regulators are explicitly asking for, without requiring every employee to become a security expert.

A common compliance checklist

  • Use this as a working checklist to sense-check where your organization stands today. It draws together the overlapping requirements from DPDPA, RBI IT Governance, and SEBI CSCRF into a single practical list.
  • All workforce passwords are generated to meet minimum strength standards, not chosen manually.
  • Credentials are stored in an encrypted vault, not in spreadsheets, browsers, or chat tools.
  • Password sharing between employees happens through secure, revocable access, never by exposing anything in the plaintext.
  • Reused and compromised passwords are actively monitored and flagged.
  • Role-based access is defined and reviewed on a periodic, documented cycle.
  • Full audit logs are retained for access events and can be reviewed on demand.
  • Vendor and third-party access is governed under a formal agreement, with clear accountability for breaches.
  • Data retention limits are defined and enforced, not left indefinite by default.
  • An annual access review is embedded into governance, not treated as a one-off exercise.

Disclaimer: This checklist is provided for informational purposes only and does not constitute legal advice. Organizations should consult qualified legal and data privacy professionals for specific guidance under the DPDPA, RBI, and SEBI.

Going forward

Compliance with DPDPA, RBI, and SEBI isn’t a project with an end date. It’s an ongoing governance responsibility. The regulations will keep tightening, enforcement will keep getting sharper, and the frameworks will keep stacking rather than replacing one another. Don’t wait for an audit to find the gap. Put a workforce password management and other access control solutions in place now, and compliance stops being a checklist you’re chasing and becomes a default you’ve already built.

Curious to learn more? Watch our free expert-led webinar series, ‘Legal Security Counsel,’ hosted in partnership with ETLegal World and ETCISO, in association with Zoho Sign and Zoho Vault, to discover what Indian organizations need to do to strengthen workforce security while staying ahead of evolving legal and regulatory requirements.

  • Published On Aug 4, 2026 at 12:54 PM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETLegalWorld industry right on your smartphone!




Source link

Share.
Leave A Reply

Exit mobile version