What DPDP Act 2023 obligations apply to fintech companies? Fintech companies process highly sensitive personal data including financial transactions, credit history, PAN and Aadhaar details, and bank account information, making them high-risk Data Fiduciaries under the DPDP Act 2023. Key obligations include obtaining explicit, purpose-specific consent for each type of financial data processing, maintaining a detailed data inventory, implementing strong encryption and access controls, responding to data principal access and erasure requests within 30 days, and notifying the Data Protection Board of any breach within 72 hours.
Fintech companies process India's most sensitive financial data. Here's your complete DPDP compliance guide — from payment processors to BNPL platforms.
Financial data sits at the intersection of every DPDP obligation. Here's what makes your sector uniquely exposed.
Account details, transaction history, credit scores, income statements, and KYC documents all qualify as personal data under DPDP. Processing them requires explicit, granular consent — not a buried checkbox in your T&C. Violations here attract penalties up to ₹200 Cr.
You must simultaneously comply with RBI's data localisation mandates and DPDP's consent and minimisation requirements. The overlap creates systematic gaps that most fintech companies don't even know they have — and both regulators can act independently.
BNPL, co-lending, insurance distribution, and fraud-detection models all share customer data with multiple external parties. Under DPDP Section 9, every such relationship requires a written Data Processing Agreement. Verbal understandings are not compliant.
International payment gateways, global cloud providers (AWS, GCP, Azure), and overseas fraud detection systems create cross-border data transfer obligations. The DPDP Act restricts transfers to non-notified jurisdictions — your cloud architecture may already be non-compliant.
Select your segment to see the specific obligations, relevant DPDP sections, penalty exposure, and the most common gaps we find during assessments.
| Obligation | DPDP Section | Max Penalty | Typical Gap |
|---|---|---|---|
| Consent for transaction data processing | S.6 | Up to ₹50 Cr | No explicit consent captured at onboarding — users click "Agree to T&C" without knowing their transaction data is being processed for analytics and cross-sell. |
| Purpose limitation for UPI / card data | S.7 | Up to ₹50 Cr | Transaction data originally collected for payment processing is repurposed for personalised offers without obtaining fresh consent for the new purpose. |
| Grievance Officer appointment | S.13 | Up to ₹10 Cr | Officer not publicly named or contactable on the website. Many companies have an internal DPO but haven't published the required contact details. |
| Data retention limits | S.8(7) | Up to ₹50 Cr | Retaining customer data indefinitely citing RBI audit requirements — but DPDP requires deletion once the stated purpose is fulfilled. |
| Data Processing Agreements with payment networks | S.9 | Up to ₹50 Cr | No written DPA in place with Visa, Mastercard, NPCI, or payment gateway providers. Existing contracts are service agreements, not DPDP-compliant DPAs. |
| Obligation | DPDP Section | Max Penalty | Typical Gap |
|---|---|---|---|
| Consent for credit bureau pulls | S.6 | Up to ₹50 Cr | Consent buried in loan application T&C. DPDP requires free, specific, and informed consent — a multi-page document doesn't qualify as explicit consent for a credit pull. |
| Sensitive data processing — income and assets | S.4 | Up to ₹200 Cr | Income, employment, and asset data collected for underwriting but no data minimisation policy exists. More data is collected than the stated purpose requires. |
| Automated credit decisioning disclosure | S.12 | Up to ₹50 Cr | Applicants not informed that their loan decision was made by an algorithm. DPDP requires disclosure when automated processing produces decisions that significantly affect data principals. |
| Co-lending data sharing agreements | S.9 | Up to ₹50 Cr | Co-lending arrangements with NBFCs and partner banks governed only by the RBI Co-Lending Model guidelines — no DPDP-compliant DPA specifying processing purposes and obligations. |
| Right to erasure implementation | S.12 | Up to ₹50 Cr | No documented process to handle Data Subject Access Requests. Customers who want their data deleted have no mechanism to request it — and the company has no defined response timeline. |
| Obligation | DPDP Section | Max Penalty | Typical Gap |
|---|---|---|---|
| Health data as sensitive personal data | S.4 | Up to ₹200 Cr | Health and medical data collected for policy underwriting is treated as standard KYC. Under DPDP, it's sensitive personal data requiring heightened protection and explicit purpose-specific consent. |
| Claim processing data retention | S.8(7) | Up to ₹50 Cr | No defined retention schedule for claim documents, medical reports, and supporting data. Data is retained indefinitely in case of future disputes — DPDP requires a documented and justified retention period. |
| Third-party underwriter data sharing | S.9 | Up to ₹50 Cr | Customer health and financial data shared with reinsurers and underwriting partners under verbal or informal arrangements. Each sharing relationship needs a DPDP-compliant written DPA. |
| Policyholder consent for renewal upsell | S.6 | Up to ₹50 Cr | Marketing for add-on covers, policy upgrades, and related products conducted without fresh consent. Purchasing a policy is not implicit consent to receive promotional communications or have data used for upsell targeting. |
Answer honestly. This takes 2 minutes and gives you a directional read on your penalty exposure.
1 Do you have a DPDP-compliant consent mechanism at the point of data collection — not buried in your Terms & Conditions?
2 Do you have written Data Processing Agreements with all third-party processors — payment gateways, credit bureaus, co-lenders, or underwriters?
3 Is your Grievance Officer's name and email address publicly listed on your website?
4 Do you have a documented process to handle Data Subject Access Requests — corrections, access, and erasure — within 30 days?
5 Have your technology, product, and operations teams received DPDP awareness training in the last 12 months?
You have the foundational controls in place. But a strong baseline isn't the same as full compliance. Edge cases in consent freshness, third-party DPAs, and cross-border transfers are where penalty exposure typically hides. An independent gap assessment will surface what your internal checks may have missed.
Get an Independent Gap Assessment →You're partially compliant but have material gaps that create real penalty exposure. Given the May 2027 enforcement deadline, a structured full assessment is recommended now — remediation typically takes 3–4 months. Don't leave this for Q1 2027.
Book a Full DPDP Assessment →Your current setup creates significant risk of regulatory action. Processing financial data without DPDP-compliant consent mechanisms, DPAs, and a Grievance Officer can result in penalties of ₹50–200 Cr per violation. Immediate action is required — start with a readiness assessment to understand the full scope.
Get Emergency Compliance Help →Two regulators. Different mandates. One set of customer data. Here's where they collide.
India's fintech sector has spent years building compliance infrastructure around RBI guidelines — data localisation, audit trails, reporting requirements. It's rigorous, well-understood, and operationally embedded.
DPDP changes the equation. The Act sits on top of sectoral regulation, and it creates three structural conflicts that RBI compliance cannot resolve:
Fixed-price engagements. No hourly billing surprises. Purpose-built for the Indian fintech regulatory environment.
Tell us about your fintech company and your biggest DPDP concern. We'll come prepared with specific observations for your model — not generic advice.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.