Why DPDP Applies to Kiosks & ATMs
The DPDP Act, 2023 applies to all processing of digital personal data within India
(Sec 3). Kiosks, ATMs, and CSPs process digital personal data every transaction — Aadhaar
numbers, fingerprints, account numbers, names, balances, and transaction histories are all
“personal data” under the Act.
The bank is the Data Fiduciary — it determines why and how data is
processed. The Business Correspondent (BC) / CSP operator is a Data Processor
(Sec 8) — they process data on the bank’s instructions. The bank is liable for the
CSP’s compliance failures.
Large banks processing millions of customer records are likely to be notified as
Significant Data Fiduciaries (SDF) under Sec 10, triggering additional obligations:
DPO appointment, annual DPIA, independent audit, and algorithmic due diligence.
Sec 3 · Application
Applies to Digital Personal Data
Kiosks collect data in digital form (Aadhaar, biometrics, account data). DPDP applies.
Sec 8(1)-(2) · Data Processor
Bank = Fiduciary, CSP = Processor
The bank is liable for the CSP/operator’s data handling. A DPA contract is mandatory.
Sec 8(5) + Rule 6 · Security
Reasonable Security Safeguards
Encryption, access control, logging (1-year retention), backups. Mandatory for all kiosks.
Sec 8(6)-(7) + Rule 7 · Breach
72-Hour Breach Notification
Any data breach (including receipt leakage) must be reported to the Board within 72 hours.
Sec 5 · Notice
Privacy Notice at Every Touchpoint
Every kiosk/CSP must display what data is collected, why, and the customer’s rights.
Sec 10 · SDF
Significant Data Fiduciary
Large banks likely to be notified as SDFs — DPO, DPIA, audit, algorithmic due diligence.
DPDP Rules 2025 Timeline: Notified on 13 November 2025. Rules 1, 2, 17–21
effective immediately. Rule 4 (Consent Manager) effective after 1 year. Rules 3, 5–16, 22–23
effective after 18 months (May 2027). Banks should begin compliance now — the 18-month window
is for implementation, not waiting.