India's financial sector processes the most sensitive personal data in the country — Aadhaar, PAN, bank account numbers, credit histories, income details, transaction records, and biometric KYC. The DPDPA 2023 now imposes the strictest data protection obligations in Indian legal history on every bank, NBFC, lending app, payment aggregator, and FinTech startup processing this data. And in April 2026, the RBI issued a dedicated advisory aligning its framework with DPDPA — creating a dual compliance obligation that most FinTechs are dangerously unprepared for.
- Most large NBFCs and payment aggregators will qualify as Significant Data Fiduciaries (SDFs) — with the strictest obligations under DPDPA
- RBI's April 2026 advisory directs all regulated entities to get board-level approval for customer data policies
- Dual compliance required: DPDPA + RBI Master Directions — non-compliance with either can trigger enforcement
- 72-hour breach notification required to both the Data Protection Board AND the RBI simultaneously
- Historical loan data collected before DPDPA must now comply with notice and consent requirements for continued processing
- Penalties: up to ₹250 crore per DPDPA violation — on top of RBI enforcement powers
- Why FinTech & banking face unique DPDPA challenges
- The RBI + DPDPA dual compliance framework (April 2026 update)
- Which entities qualify as Significant Data Fiduciaries
- Consent obligations across the lending lifecycle
- KYC data — what DPDPA says about Aadhaar, PAN and biometric data
- Credit bureau data sharing — legal basis and obligations
- Payment aggregators — specific compliance requirements
- Lending apps — the most exposed category
- The 72-hour dual breach notification obligation
- Data retention — when RBI and DPDPA conflict
- Practical compliance roadmap for FinTechs
1. Why FinTech & Banking Face Unique DPDPA Challenges
Every business in India must comply with DPDPA — but FinTech companies, NBFCs, banks, and payment aggregators face a compliance challenge unlike any other sector. Three factors make financial services uniquely complex:
Dual Regulatory Compliance
Unlike most sectors which only face DPDPA, financial entities must simultaneously comply with RBI Master Directions, SEBI regulations, IRDAI guidelines, and now DPDPA — all with different standards, timelines, and enforcement bodies.
Highly Sensitive Data at Scale
Financial entities process Aadhaar, PAN, bank account details, credit scores, income data, and transaction histories — the most sensitive personal data categories in existence — often for millions of users simultaneously.
SDF Classification Likely
Most banks, large NBFCs, and payment aggregators will be designated as Significant Data Fiduciaries — triggering mandatory DPO appointment, annual audits, DPIAs, and algorithmic transparency requirements not applicable to other businesses.
2. The RBI + DPDPA Dual Compliance Framework — April 2026 Update
In April 2026, the Reserve Bank of India's Cyber Security and IT Risk Group issued a landmark advisory directing all RBI-regulated entities to prioritise customer data protection in alignment with DPDPA. This advisory fundamentally changes the compliance landscape for every bank, NBFC, and payment aggregator in India.
What the April 2026 RBI Advisory requires: Banks, NBFCs, and payment aggregators must now obtain formal approval at appropriate governance levels — including board level — for any policies and frameworks related to customer data security, privacy, and third-party risks. This means data protection is no longer an IT function — it is a board governance obligation.
| Obligation | DPDPA Requirement | RBI Requirement | Who Enforces |
|---|---|---|---|
| Data breach notification | 72 hours to Data Protection Board | 72 hours to RBI | Both |
| Board governance | DPO reports to Board (SDF) | Board approval for data policies | Both |
| Data localisation | Cross-border transfer rules apply | Payment data must stay in India | Both |
| Customer consent | Free, specific, informed consent required | KYC consent & digital lending consent | Both |
| Security safeguards | Reasonable security measures | RBI IT Framework — detailed prescriptions | Both |
| Third-party oversight | Vendor DPAs required | Outsourcing directions — IT vendors | Both |
3. Which FinTech Entities Will Be Significant Data Fiduciaries
The DPDP Rules 2025 establish criteria for SDF designation. The government has not yet published the final SDF list, but the criteria strongly indicate that most large financial entities will qualify. Being designated an SDF triggers the most onerous obligations under the Act.
4. Consent Obligations Across the Lending Lifecycle
For NBFCs and digital lenders, consent is the most operationally complex DPDPA requirement. The lending lifecycle involves multiple data collection points — each requiring its own specific, purpose-bound consent.
- Separate consent required for: app permissions (camera, contacts, location), marketing communications, and credit bureau inquiry
- Pre-ticked consent boxes are invalid under DPDPA — each consent must be actively given
- Cannot bundle loan application consent with marketing consent
- Common violation: Asking for contacts/location access without specific purpose disclosure
- Aadhaar-based KYC: separate consent for Aadhaar use — cannot be implicit in the loan application
- Video KYC consent must be specific — cannot use video footage for any purpose other than KYC verification
- Bank statement analysis via Account Aggregator: specific consent to each data fetch required
- PAN verification: consent for sharing PAN with income tax department and credit bureaus
- CIBIL/Experian/Equifax query: specific informed consent required — borrower must know their bureau report is being accessed
- Alternative data scoring (social media, spending patterns): each data source requires specific consent
- Credit bureau data received is subject to DPDPA once in your systems — purpose limitation applies strictly
- Cannot use credit bureau data for marketing or cross-selling without separate consent
- Collections calls: contacting references/family members requires their separate consent — RBI Digital Lending Directions 2025 explicitly prohibit privacy-intrusive collection conduct
- SMS/WhatsApp communication: separate consent for each channel
- Third-party collections agencies: vendor DPA required; agency cannot process borrower data beyond what's needed for collections
- After loan closure, data must be deleted per your retention policy — unless RBI requires longer retention (conflict resolution — see Section 10)
- Borrower has the right to request data deletion after the retention period
- Credit bureau reporting of closed accounts: must cease beyond legally required period
5. KYC Data — Aadhaar, PAN & Biometric Data Under DPDPA
KYC data represents the most legally complex data category for financial entities under DPDPA. Financial institutions collect KYC data under regulatory compulsion (RBI/PMLA) but must also comply with DPDPA's consent and purpose limitation requirements for how that data is used beyond the mandatory regulatory purpose.
- Aadhaar-based authentication is regulated by UIDAI — separate from DPDPA
- Once Aadhaar data is in your system, DPDPA governs its protection and use
- Cannot use Aadhaar data for purposes beyond the specific KYC purpose without fresh consent
- Aadhaar number must be masked/tokenised in all downstream systems
- PAN collection for KYC is a regulatory requirement — legitimate use basis under DPDPA Section 7
- Using PAN data for marketing profiling requires separate consent
- Sharing PAN data with data aggregators or analytics vendors requires vendor DPA
- Form 26AS data accessed via consent must be used only for stated purpose
- Biometric data is not expressly categorised as "sensitive" under DPDPA (unlike GDPR) — but carries significant breach risk
- Video KYC recordings must be stored securely with strict access controls
- Cannot repurpose video KYC footage for liveness training or AI models without explicit separate consent
- Highest penalty exposure if biometric data is breached — up to ₹250 crore
6. Credit Bureau Data Sharing — Legal Basis & Obligations
Credit bureau data sharing — submitting borrower repayment data to CIBIL, Experian, Equifax, and CRIF High Mark — is one of the most data-intensive activities in the NBFC ecosystem. DPDPA imposes specific requirements on this process that most lenders are currently not meeting.
- Submitting repayment data to bureaus — legitimate use under Section 7 (statutory obligation)
- Querying a bureau with borrower's knowledge and consent — valid
- Sharing data with RBI under regulatory reporting — legitimate use
- Sharing bureau data with analytics or marketing partners
- Using bureau data for cross-selling other financial products
- Sharing bureau pull reports with group companies for their own lending decisions
- Retaining bureau data beyond the specific loan assessment purpose
7. Payment Aggregators — Specific Compliance Requirements
Payment aggregators occupy a unique position — they process personal and payment data of both merchants and end customers, often running the payment infrastructure for thousands of businesses. This creates layered data fiduciary obligations.
8. Lending Apps — The Most Exposed Category in India
Digital lending apps are the most exposed category under combined RBI-DPDPA compliance — and the most frequently non-compliant. The RBI's Digital Lending Directions 2025 (issued May 8, 2025) created a comprehensive rulebook that operates alongside DPDPA, with severe enforcement consequences for violations of either.
RBI enforcement reality: The RBI's Digital Lending Directions 2025 already prohibit privacy-intrusive collection conduct, dark patterns in digital lending, and contact access without specific consent. The RBI can suspend or cancel lending licences for violations. DPDPA adds ₹250 crore in additional penalty exposure. The combined enforcement risk for non-compliant lending apps is existential.
9. The 72-Hour Dual Breach Notification Obligation
For financial entities, a data breach triggers the most demanding notification obligation in Indian law — simultaneous reporting to two separate regulators within the same 72-hour window.
Practical reality: 72 hours is not enough time to investigate a breach, prepare regulatory filings, notify customers, and manage internal escalation — unless you have a pre-built breach response plan. Financial entities that wait until a breach occurs to build their response infrastructure will fail both notification deadlines simultaneously.
10. Data Retention — When RBI and DPDPA Conflict
One of the most practically complex issues for financial entities is reconciling DPDPA's data minimisation and deletion requirements with RBI's mandatory retention periods. The resolution framework is as follows:
| Data Type | RBI Retention Requirement | DPDPA Position | Resolution |
|---|---|---|---|
| Loan records | 10 years from closure | Delete when purpose ends | Retain 10 years — RBI prevails (Section 7 legitimate use) |
| KYC documents | 5 years post-relationship | Delete when purpose ends | Retain 5 years — statutory obligation prevails |
| Payment transaction data | 5 years (payment systems) | Minimise and delete | Retain 5 years — RBI prevails |
| Marketing data / profiles | No specific requirement | Delete when consent withdrawn | Delete immediately on consent withdrawal — DPDPA applies |
| App usage analytics | No specific requirement | Minimise and delete | Delete per your stated retention policy — DPDPA applies |
| Collections call recordings | 90 days (RBI guidance) | Delete when purpose ends | Retain 90 days, delete after — document the policy |
11. Practical Compliance Roadmap for FinTechs & NBFCs
- Map all personal data: what you collect, from whom, why, where it's stored, who has access
- Audit all consent flows in your app and website — identify pre-ticked boxes, bundled consents, missing notices
- List all vendors touching customer data — identify which have DPAs and which don't
- Designate a Grievance Officer and publish details in app and website
- Pass a board resolution acknowledging DPDPA obligations (per April 2026 RBI advisory)
- Draft DPDPA-compliant Privacy Policy covering all data types, purposes, and third-party sharing
- Rebuild consent notices for each data collection point in the lending lifecycle
- Execute DPAs with credit bureaus, collections agencies, analytics vendors, cloud providers
- Draft a data retention schedule reconciling RBI requirements with DPDPA
- Build account deletion functionality into the lending app
- Implement consent management platform or in-house consent logging system
- Build data subject rights mechanism — access, correction, deletion request handling
- Conduct security audit of all systems processing personal data
- Build and test breach response plan — 72-hour dual notification capability for RBI and DPB
- Train collections team on lawful contact limitations under DPDPA + RBI Digital Lending Directions
- Appoint a qualified Data Protection Officer reporting to the Board
- Commission an independent data audit by a certified auditor
- Conduct DPIAs for high-risk processing: credit scoring algorithms, customer profiling
- Implement algorithmic transparency documentation for automated credit decisions
- Establish regular board-level data protection reporting cadence
The RBI Has Spoken — DPDPA Compliance is Now a Board Obligation
The April 2026 RBI advisory removed any ambiguity that might have existed — data protection governance in financial services is no longer an IT function. It is a board-level obligation with dual regulatory enforcement. FinTechs and NBFCs that continue to treat DPDPA as a legal technicality are exposing their boards, their licences, and their businesses to the most significant regulatory risk in India's financial services history.
Our advocates have deep experience in both RBI regulatory compliance and DPDPA obligations — and specifically in the intersection of both frameworks that creates unique challenges for financial entities. We advise NBFCs, lending apps, payment aggregators, and FinTech startups on building integrated compliance programmes that satisfy the Data Protection Board, the RBI, and the board of directors simultaneously.