Fintech companies are subject to both DPDP Act 2023 and RBI sector-specific data guidelines. Customer financial data, credit bureau queries, KYC information, and payment transaction data all require DPDP-compliant consent and handling. Non-compliance risks penalties from both the DPB and RBI.
DPDP + RBI compliance for fintech — customer consent, data sharing agreements, loan app privacy policy, and breach response in one pack.
Fintech companies operating in India face a dual compliance challenge: RBI sector-specific data guidelines (Master Direction on IT, Payment Aggregator Guidelines, NBFC guidelines) AND the DPDP Act 2023. These frameworks largely complement each other, but gaps exist — and non-compliance with either can attract significant penalties.
Key Overlap Areas: (a) Data Localisation — RBI requires certain payment data to be stored exclusively in India; DPDP S.16 allows cross-border transfers to notified countries. For payment data, the more restrictive RBI rule governs. (b) Customer Consent — RBI requires customer notices for data use; DPDP requires specific, withdrawable consent. The DPDP standard is higher — meet DPDP and you meet RBI on this dimension. (c) Security Safeguards — RBI IT Master Direction security controls and DPDP S.8(5) security safeguards are largely aligned — implement ISO 27001 or equivalent and document both compliance purposes.
Key Gap Areas: (a) KYC Data — PMLA-mandated KYC conflicts with DPDP consent withdrawal rights. KYC data cannot be deleted on user request if PMLA mandates retention. Document this legal basis clearly. (b) Third-Party Credit Bureau Pulls — each credit bureau query should be pre-consented; single omnibus consent at onboarding may not cover subsequent bureau pulls. (c) Co-lending and DSA arrangements — data sharing with co-lending banks or Direct Selling Agents requires explicit disclosure in consent notices.
A robust fintech consent framework must cover multiple consent events across the customer lifecycle. A single sign-up consent is insufficient for all subsequent data uses. This framework provides a layered consent architecture for the full customer journey.
Layer 1 — Onboarding Consent: Covers: identity verification (KYC), credit bureau queries (CIBIL, Experian, CRIF), account-related communications, and basic transaction processing. Notice must be in plain language, in the user's preferred language (DPDP S.6(1) — consent notice to be in the language specified in the Eighth Schedule of the Constitution, if requested).
Layer 2 — Contextual Consent: Triggered at the point of new data use: marketing communications (distinct from service communications), sharing data with insurance partners, sharing with credit life insurers, and analytics-based personalisation. Each must be separately consented to — bundling is not permitted.
Layer 3 — Withdrawal Infrastructure: Users must be able to withdraw any layer of consent independently without losing access to the core financial service. Withdrawal of marketing consent cannot trigger account suspension. Implement a consent management dashboard in your app within the account settings section.
Fintech companies in India are subject to one of the most complex dual-regulatory data environments globally. The RBI has issued multiple data-related guidelines over the past five years — digital lending guidelines (2022), payment aggregator guidelines (2022), IT Master Direction — and the DPDP Act 2023 adds a comprehensive privacy law overlay.
The good news: DPDP and RBI requirements are largely complementary. Meeting DPDP consent standards typically exceeds RBI customer notice requirements. Meeting RBI data localisation rules for payment data also satisfies DPDP cross-border restrictions for that data category. A unified compliance programme covering both frameworks is more efficient than treating them separately.
Digital lending apps face specific DPDP risks that the RBI Digital Lending Guidelines (2022) partially address but do not fully resolve. Key risk areas: (1) multiple credit bureau pulls without specific consent for each pull; (2) data sharing with third-party loan service providers not disclosed in the privacy policy; (3) aggressive collection practices using personal data beyond the original consent scope; (4) insufficient data deletion practices post-loan closure.
The DPDP Rules 2025 are expected to address some of these through Significant Data Fiduciary designations and sector-specific rules. Fintech companies with large consumer bases should prepare for SDF designation and the enhanced obligations that come with it.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.