Two regulators, one customer, no contradictions allowed.
Financial services already had a data regime before the DPDP Act arrived. The work is not starting from zero — it is making the consent story consistent with RBI expectations, KYC retention and outsourcing rules that were written first and do not move.
Built for: Banks, NBFCs, insurers, payment companies, lending platforms and Account Aggregator participants.
The pressure points, specifically
Retention obligations point the other way
KYC records, transaction logs and audit trails are held because regulation requires it, not because a customer agreed. Erasure requests have to be answered without breaching those obligations, and the reasoning has to be documented, not improvised.
The Account Aggregator consent is its own artefact
AA consent under the RBI Master Direction has a defined structure, lifetime and revocation path. It sits alongside your DPDP consent rather than replacing it, and both have to be produceable.
Outsourcing means a processor chain you must evidence
Collections agencies, KYC vendors, cloud providers, co-lending partners. The fiduciary carries the liability for its processors, and a register that lists them is the minimum a supervisor will expect to see.
Breach reporting has two clocks
A personal data breach triggers DPDP notification duties to the Board and to affected data principals, on top of whatever incident reporting your sectoral regulator already requires. Missing either is its own finding.
The parts that matter here
An Account Aggregator purpose pack
A ready set of AA-framework purposes mapped to the RBI Master Direction for NBFC-AA, covering FIPs, FIUs and any entity exchanging financial data through an aggregator. Import it rather than drafting from a blank page.
Consent and legal obligation, held apart
Purposes carry an explicit lawful basis, so processing you do because the law requires it is never conflated with processing the customer agreed to. That distinction is what lets you answer an erasure request correctly instead of defensively.
A processor and vendor register with evidence
Every processor recorded with the contract, the assessment behind it and the data it touches, plus a vendor portal so the processor answers for itself rather than through a spreadsheet you maintain on their behalf.
Breach workflow with the clock running
Incident intake, scope assessment, and notification to the Board and to affected data principals with timestamps recorded, so the reporting position is reconstructible months later.
Sub-200ms consent writes at transaction volume
A server-side consent API held to a sub-200ms p95, because a consent check that sits in a payment or onboarding path cannot be the reason the flow times out.
This sector has a ready-made purpose pack. See what is in it.
Banking & fintech and the DPDP Act
Yes, where the data is retained to comply with another law. The Act permits continued retention where it is necessary for compliance with any law in force, which covers KYC records, transaction data and audit trails held under RBI requirements. What the bank must do is answer the request, explain which data is retained and on what basis, and erase what is not covered.
Not by itself. AA consent is a specific artefact defined by the RBI Master Direction governing the exchange of financial information through an aggregator; it does not cover the other processing a lender or insurer performs, such as marketing, analytics or servicing. The two coexist, and both need to be produceable on request.
Chiefly the data principal's rights, the consent-notice requirements and the breach notification duty to the Board. RBI rules govern how you secure and retain data; the DPDP Act governs the relationship with the individual — being told what you are doing, agreeing to it, changing their mind, and getting access, correction, erasure or a grievance heard within statutory timeframes.
Possibly. The Central Government designates Significant Data Fiduciaries based on factors including the volume and sensitivity of data processed and risk to the rights of data principals — criteria most large banks, NBFCs and insurers will meet. Designation brings additional duties: a Data Protection Officer based in India, independent audit and periodic data protection impact assessments.
General information about the DPDP Act, 2023, not legal advice. For a position specific to your organisation, talk to us or read the deep dive: DPDP Act 2023: What Banks and NBFCs Need to Know.
Find out where you actually stand.
The free self-assessment takes a few minutes and gives you a written position on your own setup, not a generic checklist.