SDD Under Regulation 3(5): Requirements, Records & Compliance
Naapbooks Insights • SDD Under Regulation • 9 min read
SDD Under Regulation 3(5): Requirements, Records & Compliance
A company shares unpublished price sensitive information (UPSI) with a merchant banker working on a deal, a legal advisor reviewing a transaction, or an auditor examining year-end numbers. Months later, a regulator asks a simple question: who had access to this information, and when?
If the answer lives across scattered emails, personal notes and outdated spreadsheets, the compliance team is in trouble. Reconstructing an information trail after the fact (proving who shared what, with whom, and why) is exactly the problem Regulation 3(5) SDD was designed to solve.
This article explains what Regulation 3(5) actually requires, who it applies to, what an SDD should capture, and how organizations can move from fragmented manual tracking to a reliable, auditable digital record.
This article is intended for general informational purposes and should not be considered legal or regulatory advice. Organizations should evaluate their obligations against the latest applicable SEBI regulations, circulars, FAQs and professional advice.
What Is Regulation 3(5) SDD?
Regulation 3(5) of the SEBI (Prohibition of Insider Trading) Regulations, 2015 requires the board of directors or the head(s) of an organization handling UPSI to ensure that a Structured Digital Database (SDD) is maintained, capturing the nature of the UPSI and the persons who have shared it and with whom it has been shared. The requirement was introduced through the SEBI (PIT) (Amendment) Regulations, 2018, effective April 1, 2019, and refined further by the 2020 amendment.
At its core, an SDD is not just a list of names. It is meant to be a traceable digital record of how UPSI moves through an organization: who originated it, who received it, and when the sharing occurred. SEBI has been explicit that this database must be maintained with adequate internal controls, including time-stamping and audit trails, to prevent tampering.
The distinction matters. A spreadsheet that stores names is “storing information.” A system that timestamps every entry, prevents silent edits, and preserves a defensible history of who accessed what and when is closer to what Regulation 3(5) actually intends: an auditable information trail, not merely a file of records.
Who Needs to Maintain an SDD?
SEBI’s official FAQs clarify applicability directly: the requirement to maintain an SDD under Regulation 3(5) applies to listed companies, and to intermediaries and fiduciaries who handle UPSI of a listed company in the course of business operations.
Listed Companies
Every listed company routinely generates UPSI (financial results, fundraising plans, mergers, management changes) and shares it internally and externally. The board or designated compliance officer is expected to ensure this flow is captured in the company’s own SDD.
Intermediaries
Entities such as merchant bankers, stock brokers, and other market intermediaries frequently receive UPSI of listed companies as part of due diligence, deal structuring or advisory work. Where this occurs, they are expected to maintain their own internal SDD.
Fiduciaries
Auditors, law firms, consultants, credit rating agencies and other fiduciaries who come into possession of UPSI in the course of servicing a listed company fall within the same requirement.
Who Is Covered: Quick Summary
- Listed companies handling their own UPSI
- Intermediaries handling UPSI of a listed company in the course of business
- Fiduciaries (auditors, advisors, consultants, law firms) handling UPSI of a listed company
Applicability should always be assessed against the specific regulatory framework relevant to the entity. Not every organization interacting with a listed company is automatically covered, and the analysis depends on whether UPSI is actually being handled in the course of business operations.
What Information Should an SDD Capture?

SEBI’s guidance and FAQs indicate that the SDD should, at minimum, capture:
- Nature/details of the UPSI shared (SEBI’s guidance and clarifications indicate this should describe the nature of the information, not necessarily reproduce the UPSI itself)
- Persons or entities with whom the UPSI is shared, including their PAN or other legally authorized unique identifier where PAN is unavailable
- Persons who have shared the information
- Relevant timestamps marking when entries were made and when sharing occurred
Beyond these core elements, several practices strengthen the reliability of an SDD but are best understood as recommended controls rather than express statutory line items:
- Documenting the purpose or business context for sharing, to support later review
- Maintaining a change/audit history showing edits, additions or corrections
- Recording the mode of communication (where relevant to internal governance)
- Periodic internal review of entries for completeness
Each of these categories matters because, during a regulatory inquiry, the compliance team isn’t just being asked “did we maintain a database?”, it’s being asked “can you show us, with evidence, that this specific flow of information was recorded accurately and hasn’t been altered?” A database that only lists names without timestamps or an audit history struggles to answer that second question convincingly.
Regulation 3(5) vs Regulation 3(6): What’s the Difference?
These two provisions are often confused, but they address different obligations.
Regulation 3(5) deals with the maintenance of the SDD, ensuring the database exists, is kept internally, and accurately records UPSI-sharing details as they occur.
Regulation 3(6) deals with preservation, how long the records in the SDD must be retained. Regulatory guidance associated with this provision indicates that SDD records should be preserved for a period of not less than eight years after the completion of the relevant transactions, and for longer where SEBI has initiated any investigation or enforcement proceeding relating to those records.
| Requirement | Regulation 3(5) | Regulation 3(6) |
|---|---|---|
| Primary focus | SDD maintenance | Preservation of records |
| Purpose | Record the UPSI flow as it happens | Retain records for a defined minimum period |
| Compliance concern | Accuracy and traceability of entries | Availability of historical evidence when needed |
In practice, the two work together: Regulation 3(5) determines what gets recorded and how, while Regulation 3(6) determines how long that record must remain retrievable.
Why Timestamps and Audit Trails Matter
An SDD that cannot show when an entry was made, or whether it was edited afterward, offers limited evidentiary value. SEBI’s guidance emphasizes adequate internal controls and checks, including time-stamping and audit trails, specifically to ensure the database cannot be tampered with after the fact.
In practical terms, this means:
- Every entry should have a system-generated time of creation, not a manually typed date
- Any subsequent edit should be logged, not silently overwritten
- The sequence in which information was shared should be reconstructable months or years later
- Compliance teams should be able to demonstrate, to an auditor or regulator, that the record reflects what actually happened rather than a retrospective reconstruction
Technology can support this discipline, but it doesn’t replace governance. A well-designed system still depends on people entering information promptly and accurately; timestamps and audit logs simply make it possible to verify that discipline after the fact.
Can an SDD Be Maintained on the Cloud?

This is a common question for compliance officers evaluating SaaS-based tools. SEBI’s FAQs address this directly: the SDD must not be outsourced, and it must be maintained internally with adequate internal controls and checks. Hosting the database on a cloud server, including servers located outside India, does not by itself amount to “outsourcing,” but the board and compliance officer remain fully responsible and accountable for the confidentiality, integrity and security of the data, regardless of where or how it is hosted.
In other words, cloud infrastructure is a matter of where the data sits, not who is accountable for it. Organizations evaluating cloud-hosted compliance tools should look closely at:
- Access controls and role-based permissions
- Encryption and data security practices
- Audit logging of every access and change
- Data residency and confidentiality safeguards
- Contractual clarity that the organization (not the vendor) retains compliance ownership
Choosing a technology partner does not transfer regulatory responsibility. It simply changes how that responsibility is operationalized.
Common SDD Compliance Gaps
In practice, several recurring risk areas and operational weaknesses show up in SDD implementations. These are not automatically regulatory violations, but they increase risk and make audit readiness harder:
- Reliance on manual spreadsheets with no system-generated timestamps
- Incomplete descriptions of the UPSI shared
- Missing PAN or unique identifiers for recipients
- Poor or inconsistent documentation of who shared information and when
- No reliable, tamper-evident audit trail
- Uncontrolled or untracked editing of existing entries
- Records fragmented across departments, emails and personal files
- Difficulty reconstructing historical information flows during a review
- Weak access controls allowing unauthorized viewing or editing
- Inadequate preservation practices that risk records becoming unavailable
- Lack of a standardized, repeatable workflow for logging UPSI sharing
- No centralized visibility for the compliance officer or board
Manual SDD vs Digital Compliance Workflow
| Manual Approach | Digital SDD Workflow |
|---|---|
| Spreadsheet-based tracking | Centralized, structured records |
| Manually typed timestamps | System-generated timestamps |
| Difficult to track changes | Logged audit history |
| Evidence scattered across emails/files | Centralized information trail |
| Heavy dependency on individual diligence | Standardized, repeatable workflow |
| Slow, manual compliance reporting | Faster reporting and retrieval |
| Higher risk of inconsistent records | More controlled data capture |
How Technology Can Strengthen SDD Compliance
Once the regulatory picture is clear, the practical question becomes: how do organizations actually operationalize it day to day, across multiple departments and dozens of UPSI events a year?
A dedicated SDD or compliance platform can help organizations operationalize their compliance controls by supporting:
- Structured, consistent data capture for every UPSI-sharing event
- Automated, system-generated timestamps
- Role-based access controls
- Categorization of UPSI by type or event
- Tracking of persons and entities involved in each disclosure
- A searchable, centralized history of information-sharing records
- Audit trails that log every entry and edit
- Faster retrieval of historical records during a review or inquiry
- Standardized workflows that reduce dependency on individual memory
It’s worth being precise here: software supports compliance controls, it does not itself constitute compliance. The organization’s governance, internal policies and the diligence of the people entering data remain central.
Where InsiderQ Fits
InsiderQ is a compliance technology platform built to help listed companies, intermediaries and fiduciaries manage insider-trading compliance workflows, including structured UPSI record-keeping, in a more centralized and auditable way. It’s designed around the same problems this article has walked through.
Capture
Structured digital forms reduce the manual data entry that leads to incomplete or inconsistent SDD records, prompting for the details SEBI’s guidance points to, such as the nature of UPSI and recipient identifiers.
Track
UPSI-sharing events are logged as they happen, creating a running record of who shared information, with whom, and when, instead of reconstructing it from memory later.
Control
Role-based access and permission settings support internal governance around who can view, enter or amend SDD records.
Audit
System-generated timestamps and logged edit histories create a defensible trail that compliance teams can produce during a review or regulatory inquiry.
Report
Centralized data makes it faster to pull historical records and prepare periodic compliance certifications and reports.
If your organization still manages UPSI records through spreadsheets, emails or fragmented systems, it may be worth evaluating a centralized SDD workflow. You can explore InsiderQ’s compliance platform or request a demonstration to see how structured digital record-keeping fits your existing processes.
Practical SDD Compliance Checklist
- Identify the UPSI being generated or shared
- Identify the relevant persons/entities involved
- Record required identifiers (PAN or authorized unique identifier)
- Document the flow of information: who shared, who received
- Capture applicable timestamps for each entry
- Maintain appropriate access controls internally
- Preserve records for the applicable retention period
- Maintain a reliable, tamper-evident audit trail
- Restrict unauthorized changes to existing entries
- Regularly review internal controls and processes (recommended practice)
- Ensure historical records can be retrieved on demand
- Keep the process aligned with current SEBI regulations and FAQs
Items above reflect a mix of express regulatory expectations and recommended operational practices. Organizations should map each to their specific obligations rather than treating the checklist as a uniform statutory list.
Final Takeaway
Regulation 3(5) SDD is fundamentally about creating a reliable, traceable record of UPSI and how it moves through an organization, not simply about having a database that exists on paper. Meaningful compliance rests on accuracy, traceability, accountability, integrity, security, preservation and auditability, backed by real internal governance.
For organizations still relying on spreadsheets, email trails and disconnected records, replacing that fragmentation with a structured digital workflow is a practical next step. If you’d like to see how InsiderQ approaches SDD compliance, explore the platform or request a demo to discuss your organization’s specific requirements.