SEBI investor data governance and DPDPA create overlapping consent obligations for investment platforms — and most cannot prove purpose-specific, withdrawal-honoured consent for investor data today.
KYC data vs advisory data — separate consent events
India's investment platforms — brokers, wealth managers, robo-advisors, and mutual fund platforms — are navigating a dual regulatory reality in 2026: SEBI's investor protection framework on one side and DPDPA's consent governance obligations on the other.
The consent collected at KYC for identity verification cannot be extended to cover ongoing investment advisory, behavioural analytics, product recommendation, and marketing. Each of these is a distinct processing purpose under DPDPA requiring its own consent event.
Algorithmic profiling — the consent most platforms skip
Platforms using automated models to recommend funds, risk profiles, or portfolio adjustments are conducting algorithmic processing. DPDPA requires that investors be informed of this processing, its basis, and the right to opt out. Most platforms today present this as a buried terms-of-service clause — not an explicit, retrievable consent event that a regulator can examine.
Third-party sharing in the investment ecosystem
Investor data flows from brokerage platforms to depositories, RTAs, AMCs, research providers, payment gateways, and analytics vendors. Each sharing event must have a traceable consent basis. "It is necessary for service delivery" does not cover all of these without a clear purpose tag per recipient — and a Processor Registry the platform can produce on regulator request.
Marketing and cross-sell consent — the SEBI-DPDPA overlap
SEBI is increasingly scrutinising cross-selling to investors. Under DPDPA, using investment account data for marketing insurance, loans, or credit cards requires a separate, explicit, opt-in consent that investors can withdraw at any time without affecting their primary investment account access. Bundling cross-sell consent into the account opening agreement is a documented violation under both frameworks.
Grievance resolution — two obligations, one process
Investment platforms already handle SEBI grievance workflows via SCORES. DPDPA adds a separate grievance obligation specific to data processing complaints — with a 90-day resolution timeline and a documented, auditable trail distinct from the SCORES process. Most platforms do not have a data-specific grievance workflow separate from their general customer complaint mechanism.
How Consentica solves the investment platform consent stack
Consentica by OpenBlockAI integrates into investment platform onboarding and ongoing investor interactions. KYC consent, advisory consent, profiling consent, and marketing consent are captured as separate, purpose-tagged events — not bundled into a single agreement. Withdrawal from marketing does not affect account access. Every consent event and withdrawal is logged, timestamped, and retrievable for SEBI or DPDPA Board examination.
SEBI and DPDPA enforcement are both active. Platforms that can demonstrate consent governance at the purpose level will have a structurally different regulatory exposure than those relying on bundled sign-up agreements.
