/ Case Studies / Banking & Financial Services

DPDP Act Readiness for a Private-Sector Bank From data sprawl to audit-ready assurance

Banking compliance workspace with data governance dashboards

At a Glance

Geo

Mumbai, India

Scale

12,000 employees

Focus

DPDP Act 2023 readiness

“CoSol turned an ambiguous regulatory deadline into a concrete, board-reportable program. We now know exactly what personal data we hold, why, and how we honour every data-principal request.”

– Chief Information Security Officer, Private-Sector Bank

The Challenge

  • DPDP Act 2023 obligations demanded verifiable consent and lawful-basis tracking.

  • Personal data was scattered across core banking, CRM and lending systems with no unified inventory.

  • CERT-In mandated 180-day log retention and rapid breach notification.

  • Data-principal rights requests had no defined workflow or turnaround SLA.

Action

1

Built a data inventory and Records of Processing Activities (RoPA) across all systems.

2

Implemented consent capture and a data-principal rights workflow for access, correction and erasure.

3

Enabled 180-day centralized logging aligned to CERT-In directions.

4

Delivered a tested breach-response playbook with defined roles and notification timelines.

Outcome

The bank became audit-ready with documented RoPA and evidence of consent.

Data subject request (DSR) handling time fell by around 70% with a structured workflow.

Board-level assurance through periodic compliance reporting and metrics.