India's financial sector processes the most sensitive personal data in the economy. DPDP Act 2023 adds a new compliance layer — on top of RBI, IRDAI, and SEBI — with penalties up to ₹250 Cr per incident.
The DPDP Act 2023 applies fully to banks, NBFCs, insurance companies, payment aggregators, and stock brokers — all of which qualify as Data Fiduciaries processing personal data of Indian customers. BFSI entities must obtain explicit, purpose-specific consent for processing KYC documents, credit data, transaction records, and insurance information, while simultaneously satisfying RBI, IRDAI, and SEBI data governance requirements. The enforcement deadline is May 13, 2027, and penalties for BFSI violations can reach ₹250 crore per incident, independent of any sectoral regulator penalties.
Financial services firms sit at the intersection of multiple regulators and data categories. Here's what you're navigating.
Aadhaar, PAN, passport, photographs, and address proofs are personal data under DPDP Act 2023. While RBI's KYC Master Direction mandates collection, DPDP still requires a documented legal basis, purpose limitation, and data minimisation. Mandatory collection does not remove the obligation to protect, minimise, and govern KYC data within DPDP's framework — and the consent framework must be designed even where consent is not the chosen legal basis.
CIBIL, Experian, CRIF, and Equifax data sharing for credit assessment requires DPDP-compliant consent and strict purpose limitation. Pulling a credit report for a loan application does not automatically authorise using that score for insurance underwriting, marketing, or cross-sell targeting. Each new use requires a documented purpose — and fresh consent if the original purpose doesn't cover it.
RBI's data localisation mandate, IT Act obligations, RBI Master Directions on data governance, and DPDP Rules apply simultaneously. These frameworks create structural conflicts — particularly on data retention periods (RBI mandates 5–8 years; DPDP requires deletion once purpose is fulfilled) and third-party data sharing (RBI's fraud network obligations vs. DPDP's third-party data processing restrictions). An integrated compliance framework is essential.
Health insurance and life insurance companies collect health data, medical history, and claims documentation — categories that attract DPDP's highest protection obligations. Policyholder data, claims data, and underwriting information must each have documented consent and purpose limitation. IRDAI's data management and cyber security guidelines add another compliance layer that must be reconciled with DPDP's requirements.
Every category below is personal data under the DPDP Act. Each requires a valid legal basis, purpose documentation, and Data Principal rights enablement.
A structured approach built for the complexity of regulated financial services — not a generic compliance checklist.
Document every point at which personal data is collected, stored, processed, or shared — from loan origination through servicing to account closure. This includes KYC collection, credit bureau pulls, CBS data flows, third-party processor integrations (insurance, investments), and data warehouse pipelines. Without a complete data inventory, consent architecture and rights mechanisms cannot be designed correctly. This step surfaces where RBI retention obligations conflict with DPDP erasure rights, enabling you to document legal justifications before enforcement begins.
Design purpose-specific consent mechanisms for every product line — savings accounts, loans, credit cards, insurance policies, investment accounts. DPDP requires that consent be free, specific, informed, and unambiguous. For BFSI entities, this means separating mandatory data collection (where a legitimate use basis applies, such as RBI-mandated KYC) from optional processing (cross-sell, marketing, analytics) which requires explicit opt-in consent. Consent records must be maintained and be withdrawable at any point — implement a consent management dashboard for customers.
DPDP gives customers the right to access their data, correct inaccuracies, and request erasure — balanced against RBI retention requirements. Build a documented DSAR (Data Subject Access Request) process with defined response timelines (30 days). For erasure requests, prepare a legal-basis matrix that maps each data category to its retention justification (RBI regulation, ongoing credit obligation, court order) so that justified retention is documented and refusal of erasure requests is defensible. Appoint and publicly name a Grievance Officer to handle requests.
BFSI entities face two critical milestone dates. Planning must begin now — implementation typically takes 6–9 months for organisations of meaningful size.
Fixed-price tools and expert engagements built for India's financial sector. Start with a free assessment or jump straight to a paid deep-dive.
Tell us about your organisation and your biggest DPDP concern. We'll come prepared with observations specific to your sector and data profile — not generic advice.
Answers to the questions we hear most from banks, NBFCs, and insurance compliance teams.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.