SEBI

Topic63 PIT Structured Digital Database SDD

Structured Digital Database (SDD) — Mandatory Requirement & Compliance

Topic 63 — PIT Regulation 3(5): SDD Architecture, Data Requirements, Tamper-Proofing & SEBI Inspection | SEBI Law Officer

The Structured Digital Database (SDD) is one of the most significant compliance innovations introduced by the SEBI (PIT) Regulations, 2015 — made mandatory from 2018-19 onwards through SEBI amendments and circulars. The SDD creates a digital audit trail of every UPSI communication within a listed company or intermediary — enabling SEBI to trace the flow of price-sensitive information and identify the source of UPSI leakages that led to insider trading. For SEBI Law Officer aspirants, the SDD's legal basis, data requirements, technical architecture, and enforcement implications are all examination-relevant topics.

1. Legal Basis of SDD — Regulation 3(5)

Regulation 3(5): The board of directors of every listed company and the board of directors or head(s) of the organisation of every intermediary shall maintain a Structured Digital Database, with adequate internal controls and checks such as time stamping and audit trails to ensure non-tampering of the database, to preserve the information shared with such persons, along with the applicable restrictions on communication thereof.

Regulation 3(5) was initially in the 2015 Regulations but became a headline compliance requirement after the 2018 and 2019 SEBI amendments and subsequent SEBI circulars. Key mandatory elements:

  • Who must maintain the SDD: Every LISTED COMPANY (obligation on board of directors) + every SEBI-registered INTERMEDIARY (obligation on board/head of organisation). Both must have separate SDDs for their own operations.
  • Board responsibility: The obligation rests on the board — not merely the compliance officer. If the SDD is not maintained, individual directors and the company can both be held liable.

2. Data That Must Be Captured in the SDD

SEBI has prescribed the minimum data elements that every SDD entry must capture:

SDD Data Field

Why Required

Name of the person with whom UPSI is shared

Identifies the recipient — enables SEBI to trace who received UPSI before a suspicious trade

PAN of the recipient

Unique identifier enabling SEBI to link the SDD entry to trading records (PAN is also linked to demat accounts)

Category/nature of UPSI shared

Identifies what specific UPSI was shared — financial results, M&A information, etc.

Date and time of sharing

Time-stamped — establishes the chronology of UPSI flow relative to trading activity

Nature of the person's connection

Whether the recipient is a director, adviser, legal counsel, banker, etc. — establishes the nature of connection

Applicable restrictions communicated

Documents that the recipient was informed of the UPSI nature and trading restrictions

3. Technical Requirements for SDD

3.1 Time-Stamping

Every entry in the SDD must be time-stamped — meaning the date and exact time of the entry must be automatically recorded by the system. Time-stamping requirements:

  • The timestamp must be system-generated — not manually entered by the user.
  • Timestamps must be in IST (Indian Standard Time) and must be accurate.
  • The system must record both the time of UPSI sharing (if known) and the time of SDD entry.
  • Timestamps are critical for SEBI's investigation — they establish whether a person received UPSI BEFORE a trade and thus had advance access.

3.2 Audit Trail

The SDD must maintain a complete audit trail:

  • Every addition, modification, and deletion of any record must be logged — with user identity and timestamp.
  • No record can be deleted without leaving a trace in the audit log.
  • The audit trail must itself be tamper-proof — even system administrators should not be able to alter audit logs without detection.

3.3 Tamper-Proofing

The SDD must be resistant to unauthorised modification:

  • Technical controls — cryptographic hashing, digital signatures, or blockchain-based immutability for critical records.
  • Access controls — only authorised personnel (compliance officer and limited others) can view or enter data; no general user access to modify records.
  • Backup and redundancy — regular backups to prevent data loss; disaster recovery mechanisms.
  • Vendor/cloud database: many listed companies use SDD software from approved vendors — the vendor must ensure the technical specifications are met.

4. SDD for Listed Companies vs Intermediaries — Key Differences

Feature

Listed Company SDD

Intermediary SDD

Scope of UPSI recorded

UPSI about the listed company itself shared with advisers, bankers, employees, board members

UPSI received from ALL clients — multiple listed companies' UPSI in the intermediary's possession

Who accesses SDD

Compliance Officer + limited board members

Compliance Officer + heads of specific business divisions (on need-to-know basis)

Chinese wall interaction

Not directly applicable

Chinese walls prevent cross-division SDD access — research analyst cannot access investment banking SDD

Complexity

Simpler — single company's UPSI

More complex — multi-client UPSI; must segregate each client's UPSI records

5. SDD and SEBI's Investigation Process

The SDD is SEBI's primary investigative tool for tracing UPSI leakages. How SEBI uses the SDD in investigations:

  • Step 1 — Suspicious trade detection: SEBI's IMSS detects unusual trading ahead of a corporate announcement (e.g., heavy buying before a positive earnings surprise).
  • Step 2 — Trade data analysis: SEBI identifies the persons who traded — by PAN, demat account, broker records.
  • Step 3 — SDD query: SEBI requests the listed company's SDD to check if any of the suspicious traders' PANs appear as UPSI recipients in the period before the trade.
  • Step 4 — Insider identification: If a suspicious trader's PAN appears in the SDD (as a recipient of UPSI about the relevant corporate event before trading), SEBI has strong evidence of insider trading.
  • Step 5 — Further investigation: SEBI investigates the chain — who communicated the UPSI to the trader (tipper), whether the tipper is in the company's SDD, and the full flow of UPSI.

6. SDD Retention Period & SEBI Access

SEBI circulars prescribe:

  • Retention period: SDD records must be preserved for a minimum of 8 years from the date of entry. This allows SEBI to investigate older cases and examine long-term UPSI communication patterns.
  • SEBI access right: SEBI can call for and inspect the SDD at any time — as part of a specific investigation or as a routine inspection. The listed company/intermediary must provide access within the time specified by SEBI.
  • Third-party access: The SDD is not publicly accessible — it is internal and available only to SEBI (and the company's own compliance function). Leaking SDD data to outsiders would itself be a UPSI-related violation.

7. Consequences of SDD Non-Compliance

Failure to maintain a compliant SDD or failure to produce it to SEBI attracts regulatory action:

  • Section 15HB SEBI Act: Civil penalty up to ₹1 crore for failure to comply with SEBI Regulations (including PIT Regulations) for which no specific penalty is prescribed.
  • Section 15A SEBI Act: ₹1 lakh per day + ₹1 crore ceiling for failure to furnish information/documents to SEBI within specified time (if SEBI requests SDD and it is not provided).
  • Section 11B SEBI Act: SEBI can issue cease and desist directions and debarment orders if SDD non-compliance is part of a larger insider trading framework failure.
  • Criminal consequences: Failure to maintain SDD as required, when it enables insider trading to flourish, may be seen as an abetment of insider trading attracting Section 24 criminal liability.

8. Model Examination Questions

Q1. What is the Structured Digital Database (SDD) under the PIT Regulations 2015? What data must it capture and how does SEBI use it in investigations?

SDD — Legal Basis, Data Requirements & Investigative Use

Model Answer — SDD (Regulation 3(5)): Every listed company (board obligation) and every SEBI-registered intermediary must maintain a Structured Digital Database with adequate internal controls including time-stamping and audit trails. LEGAL BASIS: Regulation 3(5) PIT 2015 + SEBI circulars mandating SDD from 2018-19 onwards. DATA REQUIREMENTS: (i) Name of UPSI recipient; (ii) PAN; (iii) nature/category of UPSI; (iv) date-time stamp of sharing; (v) nature of connection; (vi) restrictions communicated. TECHNICAL REQUIREMENTS: Time-stamping (system-generated; IST); audit trail (every change logged); tamper-proofing (cryptographic controls; restricted access; backup). RETENTION: Minimum 8 years. SEBI ACCESS: SEBI can call for SDD at any time; must be produced within specified period. INVESTIGATIVE USE: SEBI detects suspicious trades → identifies traders by PAN → queries SDD for those PANs as UPSI recipients → SDD match = evidence of insider trading. The SDD is the digital spine connecting UPSI communication to trading activity. CONSEQUENCES OF NON-COMPLIANCE: Section 15HB (₹1 crore); Section 15A (₹1 lakh/day); Section 11B directions; possible criminal abetment liability. In SEBI v. Sourabh Lohia (2020), SEBI penalised a Compliance Officer personally for failure to maintain SDD.

🎯 EXAM POINTERS — Topic 63: Structured Digital Database (SDD)

  • Legal basis: Regulation 3(5) PIT 2015 — MANDATORY for every listed company + every SEBI-registered intermediary.
  • Board's obligation — not just compliance officer. Individual directors can be liable for SDD failures.
  • SDD data: Name + PAN + UPSI category + date-time stamp + connection nature + restrictions communicated.
  • Technical: TIME-STAMPING (system-generated); AUDIT TRAIL (all changes logged); TAMPER-PROOF (cryptographic controls; restricted access).
  • RETENTION: Minimum 8 YEARS from entry date.
  • SEBI access: can call for SDD at any time. Must be produced in specified timeframe.
  • SDD investigation use: suspicious trade → trader PAN → SDD query → PAN match = evidence of IT.
  • Listed company SDD: one company's UPSI. Intermediary SDD: multiple clients' UPSI (segregated).
  • Chinese walls apply to intermediary SDD — research analyst cannot access investment banking SDD.
  • Non-compliance penalties: Section 15HB (₹1 crore); Section 15A (₹1 lakh/day + ₹1 crore); Section 11B directions.

← Topic 62: Code of Conduct for Insiders [Schedules B & C] | Next → Topic 64: Due Diligence & Legitimate Purpose Test [Regulation 3(3)]

Published on The Legal Bridge — Study Notes for SEBI Law Officer, Judiciary Aspirants, AIBE, CLAT & University Exams