The Reserve Bank of India (RBI) has directed Regulated Entities (REs) under RBI’s Regulatory Sandbox (RS) framework to ensure compliance with the provisions of the Digital Personal Data Protection (DPDP) Act.
“The sandbox entity must process all the data, in its possession or under its control about RS testing, by the provisions of Digital Personal Data Protection Act, 2023,” RBI said in a statement yesterday.
The bank also said that entities should have appropriate technical and organisational measures to ensure effective compliance with the provisions of the Act and rules made thereunder.
Further, it mentioned that the sandbox entity should ensure adequate safeguards to prevent any personal data breach.
The DPDP Act was notified on 11th August, 2023, but is yet to come into force.