Compliance

Where Lineage stands against every Indian regulation that applies to a personal-data-processing platform.

This page is the single map of where we stand against every Indian regulation that applies to a platform processing personal data and presenting financial information. We update it whenever our posture changes.

Regulation Status Detail
Digital Personal Data Protection Act, 2023 + DPDP Rules, 2025 Compliant Privacy Notice published; consent captured at signup with version pinning; Data Subject Requests via /account/data-rights; 90-day SLA; breach-notification process documented. Read more →
Information Technology Act, 2000 (Intermediary safe harbor + SPDI Rules) Compliant Terms of Use published; reasonable security practices documented; intermediary takedown process in place. Read more →
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 Compliant Grievance Officer published with 24-hour ack and 15-day resolution. Physical India address published. Prohibited-content rules incorporated into Terms. Read more →
CERT-In Cyber Security Directions, 2022 Compliant 180-day request-log retention in India; 6-hour incident reporting commitment; time-sync via Cloudflare NTP. Read more →
Consumer Protection (E-Commerce) Rules, 2020 Compliant Refund / cancellation / shipping policy published; grievance route published; entity details on /contact. Read more →
SEBI (Investment Advisers) Regulations, 2013 Not applicable Lineage does not provide investment advice. We are not a SEBI-registered Investment Adviser; the Platform shows information and tools, not personalised recommendations. See Disclaimer for the full posture. Read more →
RBI Master Directions (NBFC, Account Aggregator, Payment Aggregator) Not applicable Lineage is not RBI-regulated. We do not lend, take deposits, hold funds, or operate a payment system.
IRDAI Insurance Brokers / Web Aggregator Regulations Not applicable We do not solicit, sell, or distribute insurance. Insurance information shown is for tracking only.
AMFI Registration (Mutual Fund Distributor) Not applicable We do not distribute mutual funds. The Platform shows holdings you import; we earn no commission from fund houses.
Prevention of Money-Laundering Act, 2002 Not applicable Lineage is not a Reporting Entity under PMLA. We do not handle funds, take deposits, or enable financial transactions on our own books.
e-Return Intermediary (ERI) Scheme — Income Tax Department Not applicable We do not file tax returns on your behalf. AIS / ITR / Form 26AS data is user-uploaded; the marketplace introduces you to ERI-registered auditors (e-Return Intermediaries) if you want assistance.
Sahamati Technical Service Provider (TSP) certification In progress Sahamati certifies the technical infrastructure of platforms participating in the Account Aggregator framework. We are pursuing TSP certification to enable B2B2C partners to fetch live data via AA.
ISO 27001 / SOC 2 Roadmap Formal certification is on our roadmap. We currently run internal quarterly reviews against the ISO 27001 control set. Read more →
TCCCPR / DLT registration (commercial communication) In progress Email is sent via a transactional provider; SMS uses DLT-registered headers when an SMS provider is wired. Marketing-channel consent is separate from transactional consent.

Questions

Compliance correspondence: [email protected]. Partner-onboarding due-diligence questionnaires: [email protected].

If anything on this page conflicts with the current law of India, the law applies. We update this page when the law or our practices change. The version + effective date above tell you which iteration you are reading.

For questions about this page, write to [email protected] .