The DPDP Act is live. Fines reach ₹250 Cr, and every day matters.Run a free check
BANKING, NBFC & FINTECH

Two regulators, one customer, no contradictions allowed.

Financial services already had a data regime before the DPDP Act arrived. The work is not starting from zero — it is making the consent story consistent with RBI expectations, KYC retention and outsourcing rules that were written first and do not move.

Built for: Banks, NBFCs, insurers, payment companies, lending platforms and Account Aggregator participants.

WHAT MAKES THIS SECTOR DIFFERENT

The pressure points, specifically

01

Retention obligations point the other way

KYC records, transaction logs and audit trails are held because regulation requires it, not because a customer agreed. Erasure requests have to be answered without breaching those obligations, and the reasoning has to be documented, not improvised.

02

The Account Aggregator consent is its own artefact

AA consent under the RBI Master Direction has a defined structure, lifetime and revocation path. It sits alongside your DPDP consent rather than replacing it, and both have to be produceable.

03

Outsourcing means a processor chain you must evidence

Collections agencies, KYC vendors, cloud providers, co-lending partners. The fiduciary carries the liability for its processors, and a register that lists them is the minimum a supervisor will expect to see.

04

Breach reporting has two clocks

A personal data breach triggers DPDP notification duties to the Board and to affected data principals, on top of whatever incident reporting your sectoral regulator already requires. Missing either is its own finding.

WHAT SAMMATI DOES

The parts that matter here

  • An Account Aggregator purpose pack

    A ready set of AA-framework purposes mapped to the RBI Master Direction for NBFC-AA, covering FIPs, FIUs and any entity exchanging financial data through an aggregator. Import it rather than drafting from a blank page.

  • Consent and legal obligation, held apart

    Purposes carry an explicit lawful basis, so processing you do because the law requires it is never conflated with processing the customer agreed to. That distinction is what lets you answer an erasure request correctly instead of defensively.

  • A processor and vendor register with evidence

    Every processor recorded with the contract, the assessment behind it and the data it touches, plus a vendor portal so the processor answers for itself rather than through a spreadsheet you maintain on their behalf.

  • Breach workflow with the clock running

    Incident intake, scope assessment, and notification to the Board and to affected data principals with timestamps recorded, so the reporting position is reconstructible months later.

  • Sub-200ms consent writes at transaction volume

    A server-side consent API held to a sub-200ms p95, because a consent check that sits in a payment or onboarding path cannot be the reason the flow times out.

This sector has a ready-made purpose pack. See what is in it.

QUESTIONS WE GET ASKED

Banking & fintech and the DPDP Act

General information about the DPDP Act, 2023, not legal advice. For a position specific to your organisation, talk to us or read the deep dive: DPDP Act 2023: What Banks and NBFCs Need to Know.

Where to start

Find out where you actually stand.

The free self-assessment takes a few minutes and gives you a written position on your own setup, not a generic checklist.