6.3 Ethics & Compliance in Daily Operations: Data Privacy & Security

Key Takeaways

  • Data privacy and confidentiality in Indian research entities are governed by the Digital Personal Data Protection Act (DPDPA), 2023, establishing the research firm as a Data Fiduciary and the client as a Data Principal.

  • Under the DPDPA framework, PARS operations must adhere to four statutory pillars: obtaining verifiable affirmative consent, enforcing purpose limitation, practicing data minimization, and honoring client rights to correction and erasure.

  • Subscriber rosters and institutional contact lists are confidential business data, and pre-publication research drafts must stay confidential until release under the RA Code of Conduct.

  • Robust cybersecurity hygiene—including multi-factor authentication (MFA), end-to-end data encryption (AES-256 at rest, TLS 1.3 in transit), and enterprise password managers—insulates research entities against credential compromise and cyber breaches.

  • Exporting or selling client contact lists or unpublished models exposes the individual to IT Act liability and SEBI action, and the firm to DPDP Act penalties once its duties apply.

Last updated: October 2026

6.3 Ethics & Compliance in Daily Operations: Data Privacy & Security

Quick Answer: In modern securities research, data is a strategic, legally protected asset. Daily operational ethics require strict adherence to India's Digital Personal Data Protection Act (DPDPA), 2023, under which registered research entities operate as Data Fiduciaries and subscribers operate as Data Principals. Research entities must collect personal data only with verifiable, affirmative consent; enforce strict purpose limitation and data minimization; and implement technical safeguards including Multi-Factor Authentication (MFA), AES-256 data-at-rest encryption, and TLS 1.3 secure transit protocols. PARS professionals are strictly prohibited from exporting, sharing, or commercializing subscriber rosters or unpublished research drafts. Once the DPDPA's Data Fiduciary duties take effect in May 2027, a failure to protect personal data can draw penalties of up to ₹250 crore; misuse of data can already attract IT Act and SEBI consequences.


The Modern Regulatory Paradigm: India's DPDPA, 2023 in Securities Research

In the digital era, securities research operations rely on sophisticated digital infrastructures. Research firms collect, process, and store extensive client datasets—including Permanent Account Numbers (PAN), Aadhaar-linked mobile coordinates, residential addresses, financial transaction histories, banking details, and intellectual property access logs. Historically governed by basic provisions of the Information Technology Act, 2000, data handling in India underwent a structural overhaul with the enactment of the Digital Personal Data Protection Act, 2023 (DPDPA).

Under the DPDPA, the handling of digital personal data is governed by clear statutory definitions and legal responsibilities:

  • Data Principal: The individual subscriber, client, or authorized corporate signatory whose personal data is collected and processed.
  • Data Fiduciary: The SEBI-registered research entity or research analyst that determines the purpose and means of processing personal data.
  • Data Processor: Any third-party service provider (such as cloud hosting infrastructure, CRM platform providers, or bulk email dispatch platforms) that processes digital personal data on behalf of the Data Fiduciary.
  • Data Protection Board of India (DPBI): The statutory adjudicatory body established under the DPDPA empowered to investigate data breaches, adjudicate non-compliance, and levy civil penalties.

Important

Commencement status: The DPDP Act and the Digital Personal Data Protection Rules, 2025 were notified on November 13–14, 2025 with phased commencement. The Data Protection Board is already functioning, the Consent Manager provisions start about one year after notification (November 2026), and the core Data Fiduciary duties (notices and consent, security safeguards, breach notification and Data Principal rights) take effect 18 months after notification, in May 2027. Until then, research firms still owe confidentiality under the RA Code of Conduct, follow SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), promise in the MITC never to ask for client credentials or OTPs, and remain subject to the Information Technology Act, 2000, so they should be building DPDP-ready processes now.

   ┌────────────────────────────────────────────────────────────────────────┐
   │                THE FOUR PILLARS OF DPDPA COMPLIANCE FOR PARS           │
   ├────────────────────────────────────────────────────────────────────────┤
   │ 1. Free, Informed & Affirmative Consent: Clear consent notices;        │
   │    granular opt-in options; absolute prohibition on pre-ticked boxes   │
   ├────────────────────────────────────────────────────────────────────────┤
   │ 2. Strict Purpose Limitation: Personal data used solely for research   │
   │    distribution; no unauthorized repurposing for loans/cross-selling   │
   ├────────────────────────────────────────────────────────────────────────┤
   │ 3. Data Minimization: Collecting only what is legally necessary for   │
   │    KYC compliance and research servicing; zero superfluous data        │
   ├────────────────────────────────────────────────────────────────────────┤
   │ 4. Data Principal Rights: Respecting rights to access, correction,     │
   │    erasure (subject to SEBI 5-year retention), and grievance review    │
   └────────────────────────────────────────────────────────────────────────┘

The Four Operational Pillars of DPDPA in Client Servicing

For frontline PARS associates handling client onboarding and communications, DPDPA compliance requires embedding four operational principles into daily routines:

  1. Verifiable, Affirmative Consent: A Data Fiduciary cannot process personal data without obtaining free, specific, informed, unconditional, and unambiguous consent from the client through a clear affirmative action (e.g., actively clicking an unchecked consent box or digitally signing an onboarding document). Pre-ticked checkboxes, hidden terms in obscure hyperlinks, or presumed consent are unlawful.
  2. Purpose Limitation: Client data collected during subscription onboarding can only be utilized for the specific purpose disclosed in the consent notice—specifically, delivering subscribed research publications, issuing regulatory disclosures, and fulfilling statutory KYC mandates. PARS professionals cannot repurpose client phone numbers or email addresses to pitch third-party insurance products, personal loans, or speculative trading software without obtaining separate, explicit consent.
  3. Data Minimization: Research entities must collect only the minimum personal data strictly necessary to fulfill the stated purpose. Asking a research subscriber for unnecessary personal details—such as religious beliefs, biometric data, social media account credentials, or physical family details—violates data minimization mandates.
  4. Data Principal Rights: Clients maintain statutory rights under the DPDPA to access a summary of their personal data being processed, request correction of inaccurate or outdated information, and request erasure of their personal data upon termination of their subscription. However, the right to erasure is subject to statutory retention overrides: under Regulation 25 of the SEBI RA Regulations, research analysts must preserve records such as KYC documents, the client register and client correspondence for a minimum period of five (5) years.
Loading diagram...
Data Protection and Access Control Architecture under DPDPA and SEBI Guidelines

Safeguarding Proprietary Research & Client Subscription Databases

Within a securities research enterprise, confidential information falls into two high-value categories, both requiring strict defense-in-depth protection:

1. Proprietary Research Drafts & Pre-Publication Models

Draft research reports, financial valuation models, pending rating changes (e.g., upgrading a stock from 'HOLD' to 'BUY'), and revised target prices represent proprietary intellectual property. More critically, the Code of Conduct in the Third Schedule of the RA Regulations requires a report to be kept confidential until it is made public and prohibits front running of the firm's own research report.

Leaking a draft report, sharing an upcoming target price revision with a favored client over the phone, or discussing an unreleased downgrade in a public cafe creates severe legal exposure. Such conduct breaches the Code of Conduct and Regulation 22(1), enables front running, and can lead to SEBI action including debarment; if the leaked material also contains UPSI about the company, the SEBI (Prohibition of Insider Trading) Regulations, 2015 apply as well.

2. Client Subscription Rosters & Contact Lists

A research entity's subscriber roster—comprising high-net-worth individuals (HNIs), family offices, corporate treasuries, and institutional asset managers—is an invaluable trade secret. Subscriber lists contain sensitive commercial data regarding client investment preferences, risk profiles, and net-worth tiers.

Competitors, unauthorized marketing syndicates, and fraudulent boiler-room operators actively target research subscriber rosters. If a client contact database is compromised, subscribers become vulnerable to targeted phishing attacks, social engineering, fraudulent stock tip solicitations, and financial scams.

Strict Prohibitions Against Data Exfiltration and Monetization

Frontline PARS professionals are legally and contractually bound by uncompromising data security covenants:

  • Prohibition on Data Exporting: Associates must never download, export, copy, or screenshot client databases or subscription lists to personal devices, flash drives, personal email accounts, or unauthorized external cloud storage (e.g., personal Google Drive or Dropbox accounts).
  • Prohibition on Commercialization: Selling, sharing, leasing, or trading subscriber contact lists with external third parties—such as stockbroking marketing affiliates, uncertified algorithmic trading vendors, or social media financial influencers—is strictly illegal.
  • Statutory Penalties under DPDPA: Under Section 33 and the Schedule of the DPDPA, the Data Protection Board can impose a penalty of up to ₹250 crore on a Data Fiduciary that fails to take reasonable security safeguards to prevent a personal data breach, once those duties take effect in May 2027.

Warning

Employees who take client databases when they resign face serious consequences: compensation claims and criminal prosecution for unauthorised copying under Sections 43 and 66 of the Information Technology Act, 2000, disciplinary and civil action by the employer, and possible SEBI action. The firm itself faces data-protection liability for the breach.


Technological Safeguards & Cybersecurity Best Practices

Adhering to ethical data practices requires combining disciplined individual conduct with the technical safeguards expected under SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), which applies to regulated entities, including research analysts, in a graded manner.

1. Multi-Factor Authentication (MFA / 2FA)

Single-factor password protection is obsolete in professional financial environments. Research portals, corporate email accounts, and CRM repositories must enforce mandatory Multi-Factor Authentication (MFA). PARS professionals should utilize enterprise Time-based One-Time Password (TOTP) authenticator applications or FIDO2 hardware security keys. Relying solely on SMS-based authentication is discouraged due to systemic vulnerabilities to SIM-swapping fraud and cellular interception.

2. Encryption Protocols: Data-at-Rest & Data-in-Transit

All client databases, KYC repositories, and research files must be protected using industry-standard cryptographic protocols:

  • Data-in-Transit: Communications between client web browsers, mobile applications, and internal research distribution servers must be encrypted using Transport Layer Security (TLS 1.3). Unencrypted plain-text transmissions (HTTP) across public internet networks are strictly prohibited.
  • Data-at-Rest: All customer demographic data, PAN records, and archived research models stored on servers, cloud storage buckets, and employee workstation hard disks must be encrypted using Advanced Encryption Standard (AES-256).

3. Enterprise Password Management & Credential Hygiene

Weak, reused, or shared passwords represent the single greatest vulnerability in financial enterprise security. PARS associates must adhere to strict credential rules:

  • Passwords must be a minimum of 12 to 16 characters in length, incorporating a complex combination of uppercase letters, lowercase letters, numerals, and special characters.
  • Master passwords must never be shared among team members, written on sticky notes attached to workstation monitors, or stored in unencrypted spreadsheets.
  • The firm should deploy enterprise-grade, encrypted password managers that generate and auto-fill unique cryptographic passwords for every internal system.

4. Preventing Phishing, Spear-Phishing & Social Engineering

Cybercriminals frequently target securities research firms using sophisticated spear-phishing campaigns designed to harvest login credentials or install ransomware. Common attack vectors include emails disguised as official communications from SEBI, exchange compliance notices, or urgent earnings attachments from listed corporations.

PARS professionals must exercise vigilance:

  • Verify the sender's authentic domain name before opening attachments or clicking embedded links (e.g., distinguishing between sebi.gov.in and fraudulent lookalikes like sebi-compliance-portal.com).
  • Never open unexpected .exe, .scr, or macro-enabled .xlsm files received from external sources.
  • Report all suspicious emails immediately to the firm's Chief Information Security Officer (CISO) and compliance department.

5. Clean Desk & Clean Screen Policies

Physical operational hygiene is just as critical as digital defenses:

  • Clean Screen Policy: Workstations must be configured to automatically lock with a password-protected screensaver after 2 to 3 minutes of inactivity. When stepping away from their desk—even for a brief coffee break—PARS associates must manually lock their terminal (e.g., Windows Key + L or Command + Control + Q).
  • Clean Desk Policy: Physical documents containing client personal details (KYC dossiers, PAN copies, signed agreements) or draft research notes must never be left unattended on desks. Physical files must be stored in locked filing cabinets when not in active use and shredded using cross-cut document shredders when retention periods expire.
Operational Security DomainCommon Risk / VulnerabilityMandatory Security StandardRegulatory & Statutory Framework
Client Contact ManagementExfiltration of subscriber phone numbers and emails to external marketing syndicatesStrict Role-Based Access Control (RBAC); automated Data Loss Prevention (DLP) blocking USB and external email transfersDPDPA, 2023 (Section 8, from May 2027); RA Code of Conduct (Third Schedule)
Workstation AccessUnauthorized physical or remote access to CRM terminals during associate absenceShort auto-lock timers; strong, unique passwords; no credential sharing or written passwordsSEBI Cybersecurity and Cyber Resilience Framework (CSCRF)
Research DisseminationPremature leaks of rating upgrades or target price changes to favored subscribersTime-stamped broadcast dispatch portals; Chinese Walls between research desk and sales; simultaneous client releaseSEBI RA Regulations (Regulation 22(1) and the Code of Conduct)
Authentication SecurityCredential harvesting through phishing attacks and SIM-swapping schemesMulti-Factor Authentication (MFA) via authenticator apps or hardware tokens; avoid SMS-only OTPs where possibleSEBI CSCRF
Client KYC RetentionIndefinite hoarding of personal data vs premature document destructionEncrypted archival; retention for the periods SEBI and PMLA require (at least five years), then secure deletionPMLA, 2002 (Section 12); SEBI Master Circular on KYC; DPDPA, 2023
Test Your Knowledge

A SEBI-registered research entity collects subscriber names, Permanent Account Numbers (PAN), email addresses, and phone numbers during client onboarding solely to deliver equity research reports. Under the Digital Personal Data Protection Act (DPDPA), 2023, which of the following operational actions is legally compliant?

A

Processing personal data strictly for research dissemination and KYC compliance as stated in the consent notice, while barring any unauthorized sharing with third-party marketing entities.

B

Transferring the subscriber contact roster to an affiliated insurance brokerage firm to cross-sell life insurance policies without obtaining fresh client consent.

C

Requiring prospective clients to agree to a mandatory pre-ticked checkbox granting the research firm unconditional rights to commercialize their personal data.

D

Refusing to delete or update an existing subscriber's outdated residential address upon their formal written request after their subscription has been terminated.

Test Your Knowledge

Which of the following technological safeguards best aligns with SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) for protecting client CRM databases and research distribution portals against credential theft?

A

Allowing team members to share a single universal administrative password written on a whiteboard in the office to avoid login lockouts.

B

Relying exclusively on single-factor 6-character alphabetic passwords that never expire to maximize convenience for mobile users.

C

Storing all subscriber contact lists, PAN numbers, and KYC records in unencrypted plain-text spreadsheet files on a public shared network drive.

D

Enforcing mandatory Multi-Factor Authentication (MFA) using enterprise authenticator applications or hardware tokens, combined with AES-256 encryption for data at rest and TLS 1.3 for data in transit.

Test Your Knowledge

A PARS associate resigns from a registered research firm to join a competing market intermediary. Prior to departing, the associate exports the entire subscriber contact database of 5,000 high-net-worth investors to a personal USB flash drive to solicit them at the new employer. What are the legal and regulatory consequences of this action?

A

The action is considered standard industry commercial practice and carries no civil or regulatory liability under Indian law.

B

The associate is only required to pay an administrative fee of ₹500 to the original employer to purchase the database rights.

C

The action is unauthorised data exfiltration, exposing the individual to liability under the Information Technology Act, 2000, employer action and possible SEBI action, and exposing the firm to data-protection liability.

D

The associate is completely exempt from liability provided they only use the contact list for sending educational macroeconomic newsletters.

Sections you finish are checked off in the contents.