8 October 2026 · DPDP Act · Co-operative Banks
DPDP Readiness for Co-operative Banks: A Practical Roadmap
By CA Ratan Singh Tanwar · Chartered Accountant, Bhilwara
Urban and district co-operative banks serve customers who often know the branch staff personally. That trust is an asset, but it also creates privacy risk: account details shared informally, KYC copies kept in branch drawers, and customer data sitting with outsourced core banking and IT vendors.
The DPDP Act applies to co-operative banks in the same way it applies to any other organisation processing digital personal data. Size or co-operative status does not create an exemption.
Why co-operative banks need special attention
- Outsourced technology: Many co-operative banks run core banking through a service provider. The bank remains responsible for how that vendor protects customer data.
- Limited IT teams: Security responsibilities often rest with one or two people, making documented processes even more important.
- Graded cyber security expectations: RBI already applies a graded cyber security framework to urban co-operative banks. DPDP controls should be built on the same foundation.
- Branch practices: Photocopies, WhatsApp sharing of statements and shared user IDs are common weak points.
A 90-day starting plan
- Days 1–30: Data inventory across CBS, loan files, locker records, CCTV and staff data. Identify every vendor that receives personal data.
- Days 31–60: Update customer notices and account opening forms, review vendor agreements for confidentiality, breach notification and data return clauses, and remove shared user IDs.
- Days 61–90: Approve a board-level privacy policy, set up a grievance and data-request process, run staff awareness at every branch, and test the breach response plan.
Board and audit committee role
Directors of co-operative banks should ask for a simple quarterly dashboard: data requests received and resolved, incidents reported, vendor reviews completed and training coverage. This creates evidence of governance, which is what regulators and auditors look for.
Key takeaway: A co-operative bank does not need an expensive programme to start. It needs a clear inventory, strong vendor contracts, disciplined branch practices and a system audit that checks these controls regularly.
Planning DPDP for your bank?
System audit, cyber security review and DPDP implementation for co-operative banks.