DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Open banking in India runs on the Account Aggregator (AA) framework, where financial data flows between institutions only on explicit customer consent. The DPDP Act 2023 raises the bar further: consent must be free, specific, informed, unambiguous, linked to a clear purpose, and as easy to withdraw as to give. If you are a financial information provider or user in the AA ecosystem, your consent artefacts need to satisfy both the AA consent standard and DPDP. This checker assesses whether your open banking consent adequately meets the DPDP standard.

Open Banking Consent Checker — Account Aggregator & DPDP

The Account Aggregator framework is consent-driven — but does your open banking consent also meet the DPDP Act standard? Check the adequacy of your consent now.

Check your open banking consent adequacy

Open banking / Account Aggregator consent checklist under DPDP

How the Account Aggregator consent standard meets DPDP

The Account Aggregator (AA) framework was built around consent-driven financial-data sharing, using a structured, machine-readable consent artefact that specifies the data, purpose, and duration of each share. The DPDP Act 2023 aligns closely with this model but adds enforceable requirements: consent must be free, specific, informed, unambiguous and given by a clear affirmative action, accompanied by an itemised notice, and withdrawable as easily as it was granted. Where AA already captures much of this, DPDP makes it a legal obligation with penalties attached.

The most common gap is treating consent as a one-time onboarding step rather than a per-purpose, revocable act. Under DPDP, a broad consent that tries to cover multiple future data-sharing purposes is weak, and an inability to demonstrate that valid consent existed for a specific share is a direct compliance risk in the open banking chain.

Building DPDP-grade consent into open banking flows

For financial information providers and users, the practical priorities are specificity, ease of withdrawal, clarity of notice, and durable consent records. Each of these maps to a DPDP requirement, and together they form the evidence you would rely on if a customer complaint or a Data Protection Board inquiry ever questioned whether a data pull was authorised.

With DPDP Rules 2025 notified and enforcement expected around May 2027, banks, NBFCs, fintechs and AAs have a limited window to align their consent artefacts with the DPDP standard. Niti Bharat helps financial-services players audit their open banking consent flows against DPDP and close the gaps through fixed-price engagements (₹75,000–₹3.2 lakh), so consent in the AA ecosystem is both technically valid and legally defensible.

Get the open banking consent audit template (free)

A checklist and consent-notice template for Account Aggregator participants, mapping each AA consent element to the DPDP Act's requirements for valid, revocable consent.

Frequently Asked Questions

Is Account Aggregator consent enough to satisfy the DPDP Act?+
The AA framework already captures much of what DPDP requires — purpose, data scope and duration in a structured consent artefact. But DPDP adds legal obligations: consent must be free, specific, informed, unambiguous and as easy to withdraw as to grant, backed by a clear notice. AA participants should confirm their consent flows meet every DPDP element, not just the AA technical standard.
Does financial data get special treatment under the DPDP Act?+
The Act does not label a separate 'sensitive' category, but financial data is high-value personal data and a breach can cause significant harm. In practice you should apply strong safeguards and rigorous consent to it. General-obligation and consent failures can attract penalties up to ₹50 crore, and a security failure leading to a breach up to ₹250 crore.
How easy does consent withdrawal have to be under DPDP?+
Withdrawal must be as easy as giving consent. If a customer can grant a data-sharing consent with one tap, they should be able to withdraw it with comparable ease, and the withdrawal should take effect for future processing. A harder-to-find or slower withdrawal path is a compliance gap.
Who is responsible if consent is inadequate in an AA data pull?+
Each entity that determines the purpose of processing — typically the financial information user requesting the data — acts as a Data Fiduciary and is responsible for ensuring valid consent underpins the pull. Contracts across the AA chain should make these responsibilities explicit.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Parental Consent Implementation Cost Calculator DPDPPrivacy Culture Maturity CheckerPrivacy Investment ROI Calculator (DPDP) for CFOsDPDP Privacy Awareness Poster Pack IndiaSee all Calculators tools →📝 DPDP Compliance Deal Risk📝 DPDP Compliance Pricing What Fixed Price Packages Cost