Open banking in India runs on the Account Aggregator (AA) framework, where financial data flows between institutions only on explicit customer consent. The DPDP Act 2023 raises the bar further: consent must be free, specific, informed, unambiguous, linked to a clear purpose, and as easy to withdraw as to give. If you are a financial information provider or user in the AA ecosystem, your consent artefacts need to satisfy both the AA consent standard and DPDP. This checker assesses whether your open banking consent adequately meets the DPDP standard.
The Account Aggregator framework is consent-driven — but does your open banking consent also meet the DPDP Act standard? Check the adequacy of your consent now.
The Account Aggregator (AA) framework was built around consent-driven financial-data sharing, using a structured, machine-readable consent artefact that specifies the data, purpose, and duration of each share. The DPDP Act 2023 aligns closely with this model but adds enforceable requirements: consent must be free, specific, informed, unambiguous and given by a clear affirmative action, accompanied by an itemised notice, and withdrawable as easily as it was granted. Where AA already captures much of this, DPDP makes it a legal obligation with penalties attached.
The most common gap is treating consent as a one-time onboarding step rather than a per-purpose, revocable act. Under DPDP, a broad consent that tries to cover multiple future data-sharing purposes is weak, and an inability to demonstrate that valid consent existed for a specific share is a direct compliance risk in the open banking chain.
For financial information providers and users, the practical priorities are specificity, ease of withdrawal, clarity of notice, and durable consent records. Each of these maps to a DPDP requirement, and together they form the evidence you would rely on if a customer complaint or a Data Protection Board inquiry ever questioned whether a data pull was authorised.
With DPDP Rules 2025 notified and enforcement expected around May 2027, banks, NBFCs, fintechs and AAs have a limited window to align their consent artefacts with the DPDP standard. Niti Bharat helps financial-services players audit their open banking consent flows against DPDP and close the gaps through fixed-price engagements (₹75,000–₹3.2 lakh), so consent in the AA ecosystem is both technically valid and legally defensible.
A checklist and consent-notice template for Account Aggregator participants, mapping each AA consent element to the DPDP Act's requirements for valid, revocable consent.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.