Table of Contents
- Introduction & Core Objectives
- Overview of CSITE Advisory (Core Security Domains & Key Requirements)
- Key Imperatives for Supervised Entities (SEs) – 3-Part Framework
- Integrated Data Protection Model (People, Processes & Technology)
- Way Forward: How JTS LEX Can Help
- Acknowledgements & Contact Details
1. Introduction
RBI ADVISORY: "The RBI Advisory directs banks and other regulated entities to improve customer data protection through strong governance, board oversight, automated data management, centralized consent handling, and enhanced security measures in line with the DPDP Act."
What Are the Objectives?
- Protect Data: Safeguarding sensitive customer personal and financial information.
- Cyber Security: Implementing resilient controls against sophisticated digital threats and vulnerabilities.
- Regulatory Compliance: Strict operational alignment with the Digital Personal Data Protection (DPDP) Act, 2023.
- Trust: Fostering institutional transparency, accountability, and customer confidence.
How Should It Be Achieved?
- Governance and Compliance: Board-level oversight, policy enforcement, and regulatory alignment.
- Protection of Data: Standardized classification, encryption, and lifecycle management.
- Incident Management: Continuous monitoring by dedicated SOC (Security Operations Center) Teams.
- Security Controls: Robust access limits, endpoint monitoring, and third-party risk controls.
Who Does It Apply To?
- Commercial, Small Finance, and Co-operative Banks
- Non-Banking Financial Companies (NBFCs)
- Primary Financial Institutions & Regulated Entities (SEs)
Key Impacted Stakeholders:
- Board of Directors: Strategic oversight, policy approval, and accountability.
- Steering Committee: Inter-departmental execution, risk tracking, and compliance management.
- Senior Management: CISO, CIO, and operational heads driving technical implementation.
2. Overview of the CSITE Advisory
The Reserve Bank of India (RBI) Cyber Security and IT Risk (CSITE) Group mandates core security requirements structured across fundamental and advanced domains:
Core Security Domains & Key Requirements:
Advanced Security Domains & Operational Controls:
- Incident Response: Detect and respond to security incidents | Conduct cyber crisis simulations | Follow documented recovery procedures | Ensure timely communication and escalation.
- Data Retention: Define data retention periods | Secure deletion of obsolete data | Maintain audit records | Follow regulatory standards.
- Customer Empowerment: Enable complaint registration | Track grievance resolution | Notify customers on requests | Promote transparency.
- Audit & Testing: Perform regular security audits | Conduct vulnerability assessments | Test security controls | Review policy compliance.
- Emerging Technologies: Secure AI and API environments | Monitor AI-driven risks | Detect anomalies automatically | Validate emerging technology controls.
- Cloud Security: Secure cloud infrastructure | Implement identity & access management | Protect shared cloud environments | Continuously monitor cloud risks.
3. Key Imperatives for Supervised Entities (SEs)
The RBI Advisory details a structured 3-part implementation framework mapping challenges to prescribed RBI actions and strategic outcomes:
Strengthening Customer Data Protection Framework (1/3)
Strengthening Customer Data Protection Framework (2/3)
Strengthening Customer Data Protection Framework (3/3)
Figure 1: RBI Advisory Model - Strengthening Customer Data Protection Framework (3/3)
4. Integrated Data Protection Model (People, Processes & Technology)
The advisory prescribes an integrated ecosystem aligning organizational stakeholders, operational workflows, and technology components across the data lifecycle:
PEOPLE & KEY STAKEHOLDERS:
👥 Customers: Consent providers & data subjects.
👩💻 Employees: Operational compliance & secure data handling.
👨💼 Management: Governance oversight, policy approval & Board accountability.
🤝 Third Parties: Vendor compliance & secure data sharing protocols.
PROCESSES & GOVERNANCE:
Data governance policies | Board oversight | Roles & responsibilities | Compliance framework | Security Operations (SOC) | Incident response | Risk monitoring | Root cause analysis | Crisis management.
Data Lifecycle: Collect → Classify → Store → Use → Archive → Delete.
TECHNOLOGY INFRASTRUCTURE:
🗄 Databases | 🖥 Business Applications | ☁ Cloud Platforms | 🔐 Encryption Solutions | 📊 Monitoring & SIEM Tools.
Data Protection Hub: Access Management | Encryption | Continuous Monitoring | Threat Detection | Incident Response.
5. Way Forward: How JTS LEX Can Help
At JTS Lex Advocates & Consultants, we provide a structured three-phase transformation model to ensure Supervised Entities achieve seamless compliance with the RBI CSITE Advisory and DPDPA 2023:
ASSESSMENT
Key Activities:
- Review existing data protection framework.
- Assess data lifecycle practices.
- Evaluate monitoring and security controls.
- Identify gaps in data classification and DLP measures.
- Benchmark compliance with RBI Advisory and DPDP Act.
REMEDIATION
Key Activities:
- Prioritize risks and compliance gaps.
- Design data governance enhancements.
- Recommend security and technology improvements.
- Define implementation timelines.
- Develop policy and control frameworks.
IMPLEMENTATION
Key Activities:
- Implement security and monitoring controls.
- Strengthen consent and data governance mechanisms.
- Support process optimization.
- Establish incident response procedures.
- Enable continuous monitoring and reporting.
Figure 2: JTS Lex 3-Stage Transformation Model: Assessment, Remediation & Implementation
Why JTS LEX in India?
We Listen. We Care. We Deliver.
At JTS Lex, we serve as a strategic partner for organisations navigating the complexities of the modern regulatory landscape. Our firm is built on the principle that robust legal integrity is the foundation of sustainable growth.
We specialise in providing high-level compliance oversight and comprehensive due diligence designed to mitigate risk and fortify corporate governance. By blending deep statutory expertise with a proactive approach, we ensure our clients operate with absolute clarity and institutional accountability.
6. Acknowledgements & Contact Details
This comprehensive RBI Advisory report and strategic compliance guide was compiled by the leadership and expert practice groups at JTS Lex Law Firm:
FOUNDING PARTNERS
- • Prashant Kumar
- • Vineet Kumar
- • Sachin Tulsi
- • Sarvesh Tiwari
- • Kushagra Dixit
- • Fuhar Gupta
ASSOCIATE PARTNERS
- • H.A.V Sinha
- • Devika Singh
- • Devesh Srivastava
- • Hemant Tiwari
- • Ankit Srivastava
- • Inderpreet Kaur
OVERSEAS CONSULTANTS
- • Raghav Chandra
- • Agrima Shankar
- • Vikram Bhalla
CONSULTANTS
- • Adhar Notiyal
- • Soumitra Dwivedi
- • Sachi
Precision in Every Argument.
CONTACT US :-
Cyber Heights, 312, 3rd Floor, Vibhuti Khand, Gomti Nagar, Lucknow – 226010, Uttar Pradesh
Phone: +91 72689 39995 | Email: contact@jtslex.com
Office Hours: Monday – Friday: 9:00 AM – 9:00 PM | Saturday: 1:00 PM – 6:00 PM | Sunday: 10:30 AM – 7:00 PM