Share 💬 💼
DPDP

DPDPA for FinTech & Banking: NBFCs, Lending Apps & Payment Aggregators

📅 Mar 26, 2026
👤 Adv. Deepak Kumar
⏱️ 13 min read
📂 DPDP
DPDPA for FinTech & Banking: NBFCs, Lending Apps & Payment Aggregators
India's financial sector faces the most complex DPDPA compliance challenge — dual obligations under both DPDPA and RBI frameworks. The April 2026 RBI advisory made data protection a board-level obligation. This complete guide covers NBFCs, lending apps, payment aggregators, credit bureau data, KYC obligations, and the 72-hour dual breach notification requirement.
DPDPA 2023 + DPDP Rules 2025 + RBI Advisory April 2026 — FinTech & BFSI Guide

India's financial sector processes the most sensitive personal data in the country — Aadhaar, PAN, bank account numbers, credit histories, income details, transaction records, and biometric KYC. The DPDPA 2023 now imposes the strictest data protection obligations in Indian legal history on every bank, NBFC, lending app, payment aggregator, and FinTech startup processing this data. And in April 2026, the RBI issued a dedicated advisory aligning its framework with DPDPA — creating a dual compliance obligation that most FinTechs are dangerously unprepared for.

⚠️ Critical Facts — DPDPA for FinTech & Banking
  • Most large NBFCs and payment aggregators will qualify as Significant Data Fiduciaries (SDFs) — with the strictest obligations under DPDPA
  • RBI's April 2026 advisory directs all regulated entities to get board-level approval for customer data policies
  • Dual compliance required: DPDPA + RBI Master Directions — non-compliance with either can trigger enforcement
  • 72-hour breach notification required to both the Data Protection Board AND the RBI simultaneously
  • Historical loan data collected before DPDPA must now comply with notice and consent requirements for continued processing
  • Penalties: up to ₹250 crore per DPDPA violation — on top of RBI enforcement powers
📋 What This Guide Covers
  1. Why FinTech & banking face unique DPDPA challenges
  2. The RBI + DPDPA dual compliance framework (April 2026 update)
  3. Which entities qualify as Significant Data Fiduciaries
  4. Consent obligations across the lending lifecycle
  5. KYC data — what DPDPA says about Aadhaar, PAN and biometric data
  6. Credit bureau data sharing — legal basis and obligations
  7. Payment aggregators — specific compliance requirements
  8. Lending apps — the most exposed category
  9. The 72-hour dual breach notification obligation
  10. Data retention — when RBI and DPDPA conflict
  11. Practical compliance roadmap for FinTechs

1. Why FinTech & Banking Face Unique DPDPA Challenges

Every business in India must comply with DPDPA — but FinTech companies, NBFCs, banks, and payment aggregators face a compliance challenge unlike any other sector. Three factors make financial services uniquely complex:

🔄

Dual Regulatory Compliance

Unlike most sectors which only face DPDPA, financial entities must simultaneously comply with RBI Master Directions, SEBI regulations, IRDAI guidelines, and now DPDPA — all with different standards, timelines, and enforcement bodies.

🔐

Highly Sensitive Data at Scale

Financial entities process Aadhaar, PAN, bank account details, credit scores, income data, and transaction histories — the most sensitive personal data categories in existence — often for millions of users simultaneously.

🏢

SDF Classification Likely

Most banks, large NBFCs, and payment aggregators will be designated as Significant Data Fiduciaries — triggering mandatory DPO appointment, annual audits, DPIAs, and algorithmic transparency requirements not applicable to other businesses.

2. The RBI + DPDPA Dual Compliance Framework — April 2026 Update

In April 2026, the Reserve Bank of India's Cyber Security and IT Risk Group issued a landmark advisory directing all RBI-regulated entities to prioritise customer data protection in alignment with DPDPA. This advisory fundamentally changes the compliance landscape for every bank, NBFC, and payment aggregator in India.

What the April 2026 RBI Advisory requires: Banks, NBFCs, and payment aggregators must now obtain formal approval at appropriate governance levels — including board level — for any policies and frameworks related to customer data security, privacy, and third-party risks. This means data protection is no longer an IT function — it is a board governance obligation.

Obligation DPDPA Requirement RBI Requirement Who Enforces
Data breach notification 72 hours to Data Protection Board 72 hours to RBI Both
Board governance DPO reports to Board (SDF) Board approval for data policies Both
Data localisation Cross-border transfer rules apply Payment data must stay in India Both
Customer consent Free, specific, informed consent required KYC consent & digital lending consent Both
Security safeguards Reasonable security measures RBI IT Framework — detailed prescriptions Both
Third-party oversight Vendor DPAs required Outsourcing directions — IT vendors Both

3. Which FinTech Entities Will Be Significant Data Fiduciaries

The DPDP Rules 2025 establish criteria for SDF designation. The government has not yet published the final SDF list, but the criteria strongly indicate that most large financial entities will qualify. Being designated an SDF triggers the most onerous obligations under the Act.

🏦 Banks (Scheduled Commercial Banks, Small Finance Banks, Co-operative Banks)
Almost certain to be designated SDFs. Process financial data of tens of millions of customers including sensitive payment data, credit history, and biometric KYC. SDF obligations: mandatory DPO, annual data audit, DPIA for new products, algorithmic transparency.
💳 Payment Aggregators & Payment Gateways
Razorpay, PayU, Cashfree, CCAvenue and similar entities process payment data for lakhs of merchants and crores of end customers. RBI already requires strict data localisation for payment data. DPDPA adds consent, breach notification, and data principal rights obligations on top.
🏢 Large NBFCs (Upper & Middle Layer)
Scale-Based Regulation upper and middle layer NBFCs processing data at scale will likely qualify as SDFs. Housing Finance Companies (HFCs) and systemically important NBFCs face triple compliance: NHB/RBI legacy obligations + RBI IT Framework + DPDPA.
📱 Digital Lending Apps (DLAs) at Scale
Large digital lending platforms processing data for lakhs of borrowers may qualify. RBI's Digital Lending Directions 2025 already impose strict data obligations — DPDPA adds a separate enforcement layer with far higher penalties.
🚀 FinTech Startups & Small NBFCs (Base Layer)
Likely not SDFs — but all standard DPDPA obligations apply fully. Consent, security safeguards, breach notification, data retention, vendor DPAs, grievance officer — all mandatory regardless of size. No exemption for early-stage companies.

4. Consent Obligations Across the Lending Lifecycle

For NBFCs and digital lenders, consent is the most operationally complex DPDPA requirement. The lending lifecycle involves multiple data collection points — each requiring its own specific, purpose-bound consent.

Stage 1 — Lead Generation & App Install
  • Separate consent required for: app permissions (camera, contacts, location), marketing communications, and credit bureau inquiry
  • Pre-ticked consent boxes are invalid under DPDPA — each consent must be actively given
  • Cannot bundle loan application consent with marketing consent
  • Common violation: Asking for contacts/location access without specific purpose disclosure
Stage 2 — KYC & Onboarding
  • Aadhaar-based KYC: separate consent for Aadhaar use — cannot be implicit in the loan application
  • Video KYC consent must be specific — cannot use video footage for any purpose other than KYC verification
  • Bank statement analysis via Account Aggregator: specific consent to each data fetch required
  • PAN verification: consent for sharing PAN with income tax department and credit bureaus
Stage 3 — Credit Assessment & Bureau Query
  • CIBIL/Experian/Equifax query: specific informed consent required — borrower must know their bureau report is being accessed
  • Alternative data scoring (social media, spending patterns): each data source requires specific consent
  • Credit bureau data received is subject to DPDPA once in your systems — purpose limitation applies strictly
  • Cannot use credit bureau data for marketing or cross-selling without separate consent
Stage 4 — Loan Servicing & Collections
  • Collections calls: contacting references/family members requires their separate consent — RBI Digital Lending Directions 2025 explicitly prohibit privacy-intrusive collection conduct
  • SMS/WhatsApp communication: separate consent for each channel
  • Third-party collections agencies: vendor DPA required; agency cannot process borrower data beyond what's needed for collections
Stage 5 — Account Closure & Post-Closure
  • After loan closure, data must be deleted per your retention policy — unless RBI requires longer retention (conflict resolution — see Section 10)
  • Borrower has the right to request data deletion after the retention period
  • Credit bureau reporting of closed accounts: must cease beyond legally required period

5. KYC Data — Aadhaar, PAN & Biometric Data Under DPDPA

KYC data represents the most legally complex data category for financial entities under DPDPA. Financial institutions collect KYC data under regulatory compulsion (RBI/PMLA) but must also comply with DPDPA's consent and purpose limitation requirements for how that data is used beyond the mandatory regulatory purpose.

Aadhaar Data
  • Aadhaar-based authentication is regulated by UIDAI — separate from DPDPA
  • Once Aadhaar data is in your system, DPDPA governs its protection and use
  • Cannot use Aadhaar data for purposes beyond the specific KYC purpose without fresh consent
  • Aadhaar number must be masked/tokenised in all downstream systems
PAN & Income Tax Data
  • PAN collection for KYC is a regulatory requirement — legitimate use basis under DPDPA Section 7
  • Using PAN data for marketing profiling requires separate consent
  • Sharing PAN data with data aggregators or analytics vendors requires vendor DPA
  • Form 26AS data accessed via consent must be used only for stated purpose
Biometric Data (Video KYC, Face Match)
  • Biometric data is not expressly categorised as "sensitive" under DPDPA (unlike GDPR) — but carries significant breach risk
  • Video KYC recordings must be stored securely with strict access controls
  • Cannot repurpose video KYC footage for liveness training or AI models without explicit separate consent
  • Highest penalty exposure if biometric data is breached — up to ₹250 crore

6. Credit Bureau Data Sharing — Legal Basis & Obligations

Credit bureau data sharing — submitting borrower repayment data to CIBIL, Experian, Equifax, and CRIF High Mark — is one of the most data-intensive activities in the NBFC ecosystem. DPDPA imposes specific requirements on this process that most lenders are currently not meeting.

✅ What has a valid legal basis
  • Submitting repayment data to bureaus — legitimate use under Section 7 (statutory obligation)
  • Querying a bureau with borrower's knowledge and consent — valid
  • Sharing data with RBI under regulatory reporting — legitimate use
❌ What requires separate DPDPA consent
  • Sharing bureau data with analytics or marketing partners
  • Using bureau data for cross-selling other financial products
  • Sharing bureau pull reports with group companies for their own lending decisions
  • Retaining bureau data beyond the specific loan assessment purpose

7. Payment Aggregators — Specific Compliance Requirements

Payment aggregators occupy a unique position — they process personal and payment data of both merchants and end customers, often running the payment infrastructure for thousands of businesses. This creates layered data fiduciary obligations.

Obligation 1 — Data Fiduciary for End Customer Data
When a customer pays through Razorpay/PayU/Cashfree, that customer's payment data — name, card/UPI details, transaction history — is processed by the PA. The PA is a Data Fiduciary for this data. RBI already requires all payment data to be stored in India. DPDPA adds consent, security, and breach notification obligations on top.
Obligation 2 — Data Processor for Merchant Data
For merchant businesses using the PA, the PA also processes the merchant's own customer data on behalf of the merchant. This makes the PA a Data Processor — requiring a signed DPA with every merchant. Merchants must inform their customers that payment processing is handled by a PA (a Data Processor disclosure requirement).
Obligation 3 — Sub-Processor Chain
PAs use acquiring banks, switch networks, fraud detection vendors, and analytics platforms — all sub-processors that must be covered by appropriate DPAs. The chain of accountability flows from the merchant → PA → sub-processors. The PA is liable for its sub-processors' data handling.
Obligation 4 — Transaction Data Retention
RBI requires payment data to be retained for audit and dispute resolution purposes. DPDPA's data minimisation and deletion requirements must be reconciled with RBI's retention mandates. The solution: retain only what RBI mandates, for only as long as mandated, with documented justification.

8. Lending Apps — The Most Exposed Category in India

Digital lending apps are the most exposed category under combined RBI-DPDPA compliance — and the most frequently non-compliant. The RBI's Digital Lending Directions 2025 (issued May 8, 2025) created a comprehensive rulebook that operates alongside DPDPA, with severe enforcement consequences for violations of either.

🚨 Most Common Violations by Lending Apps
Accessing phone contacts without specific consent and purpose
Bundling marketing consent with loan application consent
Retaining data after loan repayment without legal basis
Contacting borrower's contacts during collections
No account deletion feature in the app
Sharing borrower data with marketing partners
No grievance officer published in app
Dark patterns in consent flows — pre-ticked boxes

RBI enforcement reality: The RBI's Digital Lending Directions 2025 already prohibit privacy-intrusive collection conduct, dark patterns in digital lending, and contact access without specific consent. The RBI can suspend or cancel lending licences for violations. DPDPA adds ₹250 crore in additional penalty exposure. The combined enforcement risk for non-compliant lending apps is existential.

9. The 72-Hour Dual Breach Notification Obligation

For financial entities, a data breach triggers the most demanding notification obligation in Indian law — simultaneous reporting to two separate regulators within the same 72-hour window.

DPDPA Notification — Data Protection Board
  • Notify Board within 72 hours of discovering breach
  • Notify all affected Data Principals without undue delay
  • Describe: nature of breach, data affected, number of persons
  • Detail: measures taken and planned
  • Failure to notify: up to ₹200 crore penalty
RBI Notification — Reserve Bank of India
  • Notify RBI within 72 hours of discovering breach (cyber incident)
  • Notify affected customers as per RBI guidance
  • Submit detailed incident report within 7 days
  • File in RBI's CIMS portal for cyber incidents
  • Material breaches: disclose in regulatory filings

Practical reality: 72 hours is not enough time to investigate a breach, prepare regulatory filings, notify customers, and manage internal escalation — unless you have a pre-built breach response plan. Financial entities that wait until a breach occurs to build their response infrastructure will fail both notification deadlines simultaneously.

10. Data Retention — When RBI and DPDPA Conflict

One of the most practically complex issues for financial entities is reconciling DPDPA's data minimisation and deletion requirements with RBI's mandatory retention periods. The resolution framework is as follows:

Data Type RBI Retention Requirement DPDPA Position Resolution
Loan records 10 years from closure Delete when purpose ends Retain 10 years — RBI prevails (Section 7 legitimate use)
KYC documents 5 years post-relationship Delete when purpose ends Retain 5 years — statutory obligation prevails
Payment transaction data 5 years (payment systems) Minimise and delete Retain 5 years — RBI prevails
Marketing data / profiles No specific requirement Delete when consent withdrawn Delete immediately on consent withdrawal — DPDPA applies
App usage analytics No specific requirement Minimise and delete Delete per your stated retention policy — DPDPA applies
Collections call recordings 90 days (RBI guidance) Delete when purpose ends Retain 90 days, delete after — document the policy

11. Practical Compliance Roadmap for FinTechs & NBFCs

Phase 1 — Foundation (Month 1–2)
Immediate
  • Map all personal data: what you collect, from whom, why, where it's stored, who has access
  • Audit all consent flows in your app and website — identify pre-ticked boxes, bundled consents, missing notices
  • List all vendors touching customer data — identify which have DPAs and which don't
  • Designate a Grievance Officer and publish details in app and website
  • Pass a board resolution acknowledging DPDPA obligations (per April 2026 RBI advisory)
Phase 2 — Legal Documents (Month 2–4)
High priority
  • Draft DPDPA-compliant Privacy Policy covering all data types, purposes, and third-party sharing
  • Rebuild consent notices for each data collection point in the lending lifecycle
  • Execute DPAs with credit bureaus, collections agencies, analytics vendors, cloud providers
  • Draft a data retention schedule reconciling RBI requirements with DPDPA
  • Build account deletion functionality into the lending app
Phase 3 — Technical & Process (Month 4–6)
Operational
  • Implement consent management platform or in-house consent logging system
  • Build data subject rights mechanism — access, correction, deletion request handling
  • Conduct security audit of all systems processing personal data
  • Build and test breach response plan — 72-hour dual notification capability for RBI and DPB
  • Train collections team on lawful contact limitations under DPDPA + RBI Digital Lending Directions
Phase 4 — SDF Preparation (Month 6–12, if applicable)
For large entities
  • Appoint a qualified Data Protection Officer reporting to the Board
  • Commission an independent data audit by a certified auditor
  • Conduct DPIAs for high-risk processing: credit scoring algorithms, customer profiling
  • Implement algorithmic transparency documentation for automated credit decisions
  • Establish regular board-level data protection reporting cadence

The RBI Has Spoken — DPDPA Compliance is Now a Board Obligation

The April 2026 RBI advisory removed any ambiguity that might have existed — data protection governance in financial services is no longer an IT function. It is a board-level obligation with dual regulatory enforcement. FinTechs and NBFCs that continue to treat DPDPA as a legal technicality are exposing their boards, their licences, and their businesses to the most significant regulatory risk in India's financial services history.

Our advocates have deep experience in both RBI regulatory compliance and DPDPA obligations — and specifically in the intersection of both frameworks that creates unique challenges for financial entities. We advise NBFCs, lending apps, payment aggregators, and FinTech startups on building integrated compliance programmes that satisfy the Data Protection Board, the RBI, and the board of directors simultaneously.

AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp