Annapurna Agentic Solutions / Pramana (प्रमाण) / Bank Kiosks & ATM Compliance
All Showcases Request Demo →
PRAMANA

Kiosk & ATM DPDP Compliance

Real scenarios from self-service banking. Real risks under the DPDP Act.

Annapurna Agentic Solutions

Interactive Compliance Demonstration

Your Kiosks and ATMs Process Personal Data — DPDP Applies

Bank kiosks, ATMs, Customer Service Points (CSPs), and self-service machines all collect and process digital personal data — Aadhaar numbers, biometrics, account details, transaction history. Under the Digital Personal Data Protection Act, 2023, the bank is the Data Fiduciary and is responsible for every machine, every operator, and every receipt. Select a scenario below to see the risks and how Pramana helps.

1
Stage 1
The Situation
2
Stage 2
The Risk
3
Stage 3
How Pramana Helps

Why DPDP Applies to Kiosks & ATMs

The DPDP Act, 2023 applies to all processing of digital personal data within India (Sec 3). Kiosks, ATMs, and CSPs process digital personal data every transaction — Aadhaar numbers, fingerprints, account numbers, names, balances, and transaction histories are all “personal data” under the Act.

The bank is the Data Fiduciary — it determines why and how data is processed. The Business Correspondent (BC) / CSP operator is a Data Processor (Sec 8) — they process data on the bank’s instructions. The bank is liable for the CSP’s compliance failures.

Large banks processing millions of customer records are likely to be notified as Significant Data Fiduciaries (SDF) under Sec 10, triggering additional obligations: DPO appointment, annual DPIA, independent audit, and algorithmic due diligence.

Sec 3 · Application
Applies to Digital Personal Data
Kiosks collect data in digital form (Aadhaar, biometrics, account data). DPDP applies.
Sec 8(1)-(2) · Data Processor
Bank = Fiduciary, CSP = Processor
The bank is liable for the CSP/operator’s data handling. A DPA contract is mandatory.
Sec 8(5) + Rule 6 · Security
Reasonable Security Safeguards
Encryption, access control, logging (1-year retention), backups. Mandatory for all kiosks.
Sec 8(6)-(7) + Rule 7 · Breach
72-Hour Breach Notification
Any data breach (including receipt leakage) must be reported to the Board within 72 hours.
Sec 5 · Notice
Privacy Notice at Every Touchpoint
Every kiosk/CSP must display what data is collected, why, and the customer’s rights.
Sec 10 · SDF
Significant Data Fiduciary
Large banks likely to be notified as SDFs — DPO, DPIA, audit, algorithmic due diligence.
DPDP Rules 2025 Timeline: Notified on 13 November 2025. Rules 1, 2, 17–21 effective immediately. Rule 4 (Consent Manager) effective after 1 year. Rules 3, 5–16, 22–23 effective after 18 months (May 2027). Banks should begin compliance now — the 18-month window is for implementation, not waiting.