Your go-to hub for Expert Insights,
Publications, and Resources
on
data privacy and compliance

Our resources provide the essential tools, guides, and insights to help your business stay ahead of data privacy regulations. From practical templates to expert articles, we ensure you have everything you need to navigate compliance with confidence.

Last Updated: 2026-06-17 ~ DPDP Consultants

Impact of DPDPA on Banks & NBFCs

DPDP Act compliance guide for banks and NBFCs in India with data protection shield and banking building illustration

Introduction: Banking on Data, Bound by Law

India's banking and financial services industry processes more personal data than almost any other sector in the economy. Every time a customer opens an account, applies for a loan, swipes a card, makes a UPI payment, or even walks into a bank branch, a trail of personal data is created, stored, shared, and analysed. For decades, this data was governed primarily by RBI circulars and sector-specific guidelines. That era is now over.

The Digital Personal Data Protection Act, 2023 (DPDPA), along with the DPDP Rules notified in 2025, introduces a comprehensive, cross-sector data protection framework that sits on top of existing RBI regulations. For banks and Non-Banking Financial Companies (NBFCs), this creates a dual compliance obligation that is both more complex and more consequential than anything the sector has faced before.

This blog explores how the DPDPA reshapes the way banks and NBFCs collect, process, store, and share personal data. It examines the specific operational challenges, the intersection with RBI regulations, the penalties for non-compliance, and the practical steps financial institutions must take to become compliant before the enforcement deadlines arrive.


 

1. Why the DPDPA Hits Banking Harder Than Most Sectors

p class="MsoNormal" style="margin-bottom:7.5pt;text-align:justify;line-height: 115%">Banks and NBFCs are not ordinary data processors. They sit at the intersection of financial trust, regulatory oversight, and massive data volumes. Several characteristics make the banking sector uniquely impacted by the DPDPA:

        Volume and sensitivity of data: A single bank customer generates data across dozens of touchpoints: KYC documents (Aadhaar, PAN, passport), financial transactions, credit scores, loan histories, insurance policies, investment portfolios, biometric data for authentication, and communication records. This is among the most sensitive personal data any organisation can hold.

        Vast customer base: India's scheduled commercial banks serve over 200 crore deposit accounts. Large private banks individually hold data on tens of millions of customers. NBFCs, especially those in digital lending, often process thousands of loan applications daily, each carrying detailed personal and financial information.

        Extensive third-party sharing: Banks routinely share personal data with credit bureaus (CIBIL, Experian, Equifax), payment processors, insurance partners, fintech aggregators, recovery agents, correspondent banking partners, and government agencies. Each sharing point is now a compliance obligation under the DPDPA.

        Legacy technology stacks: Many public sector banks still run core banking systems built decades ago, with limited ability to implement granular consent management, automated data erasure, or real-time breach detection without significant modernisation.

        Regulatory intersection: Unlike most sectors, banks must comply with both the DPDPA and a layered set of RBI regulations covering cybersecurity, data localisation, digital lending, and outsourcing. The two frameworks sometimes overlap and occasionally create tension.


 

2. Key DPDPA Obligations for Banks and NBFCs

2.1 Consent Redesign at Institutional Scale

The DPDPA requires that consent be free, specific, informed, unconditional, and unambiguous. For banks, this means fundamentally rethinking how consent is obtained at every customer touchpoint.

Today, most banks bundle consent into lengthy terms and conditions documents that customers sign (or click through) without reading. Under the DPDPA, each distinct purpose of data processing requires its own clearly stated consent. A bank that collects Aadhaar for KYC cannot automatically use that same data for marketing analytics or cross-selling insurance products without obtaining separate, purpose-specific consent.

The Act also introduces the concept of a Consent Manager, a registered intermediary that allows customers to view, manage, and withdraw their consents from a single platform. Banks must integrate their systems with these Consent Managers, enabling customers to exercise real control over how their data is used. The November 2026 deadline for the Consent Manager framework makes this an urgent priority.

2.2 Purpose Limitation and Data Minimisation

Banks have historically collected far more data than strictly necessary, operating on the logic that more data enables better risk assessment and product personalisation. The DPDPA disrupts this approach by mandating that data collection must be limited to what is necessary for the specified purpose.

For NBFCs in digital lending, this is especially relevant. Many lending apps have faced criticism for accessing phone contacts, gallery photos, SMS messages, and location data well beyond what is needed for credit assessment. The DPDPA, reinforced by the RBI's Digital Lending Directions, now makes such overcollection a compliance violation with penalties of up to Rs. 250 crore.

2.3 Data Retention and the Right to Erasure

Under the DPDPA, personal data must be erased once the purpose of collection is fulfilled, unless retention is required by another law. For banks, this creates a complex matrix. RBI regulations require certain records to be retained for specific periods: KYC records must be maintained for at least five years after the business relationship ends, transaction records are required under anti-money laundering rules, and tax-related data must be retained per Income Tax Act requirements.

Banks must therefore build systems that can distinguish between data that must be retained under regulatory mandate and data that should be erased under the DPDPA. This requires a detailed data classification exercise mapped against every applicable retention obligation.

2.4 Breach Notification Within 72 Hours

The DPDPA mandates that Data Fiduciaries notify both the Data Protection Board of India (DPB) and affected individuals within 72 hours of becoming aware of a personal data breach. Given the scale of banking operations and the sophistication of cyberattacks targeting financial institutions, this is a formidable requirement.

The RBI confirmed that 248 data breaches were reported across scheduled commercial banks between 2018 and 2022, with 205 of those in private sector banks. As the DPDPA raises the stakes for breach reporting, banks that lack real-time breach detection and automated notification systems will face both regulatory penalties and reputational damage.

2.5 Significant Data Fiduciary (SDF) Obligations

Large banks and major NBFCs will almost certainly be designated as Significant Data Fiduciaries by the Central Government. SDFs face enhanced obligations beyond standard compliance. They must appoint an India-based Data Protection Officer (DPO), conduct annual Data Protection Impact Assessments (DPIAs), undergo independent audits of their data processing practices, and submit to algorithmic fairness assessments for any automated decision-making, including AI-driven credit scoring models.

These SDF provisions are expected to come into force by May 2027, but banks should begin preparations now, given the scale of operational changes involved.


 

3. Data Touchpoints: Where Personal Data Flows in Banking

Mapping every touchpoint where personal data is collected, processed, shared, or stored is the foundation of DPDPA compliance. In banking, the number of touchpoints is vast:

Title: data_touchpoints.png - Description: data_touchpoints.png

Touchpoint

Personal Data Collected

Shared With

Risk Level

KYC and Account Opening

Aadhaar, PAN, photo, address proof, income details

UIDAI, CKYC Registry

High

Loan Origination and Credit Scoring

Income, employment, credit history, bank statements

Credit bureaus (CIBIL, Experian)

High

Mobile and Internet Banking

Login credentials, device info, transaction history, location

Payment gateways, UPI systems

High

UPI and Card Payments

Transaction data, merchant details, spending patterns

NPCI, acquiring banks, merchants

Medium

Third-Party Vendor APIs

Customer data shared for analytics, marketing, or operations

Fintech partners, data processors

High

Customer Call Centre and CRM

Call recordings, complaint details, personal identifiers

BPO vendors, CRM platforms

Medium

CCTV and Branch Surveillance

Facial images, movement patterns

Security vendors

Medium

Employee HRMS and Payroll

Employee Aadhaar, PAN, bank details, medical records

Payroll vendors, insurance companies

High

Insurance and Investment Cross-sell

Financial profile, risk appetite, nominee details

Insurance companies, AMCs

Medium

Recovery and Collections

Borrower details, contact information, financial status

Recovery agents, legal firms

High


 

4. The Dual Compliance Challenge: DPDPA Meets RBI Regulations

5. Data Breaches in Indian Banking: A Wake-Up Call

What makes compliance uniquely complex for banks and NBFCs is that the DPDPA does not replace existing RBI regulations. Instead, it adds a new, comprehensive layer on top of them. Here is how the two frameworks intersect:

Title: dual_compliance.png - Description: dual_compliance.png

Area

DPDPA Requirement

RBI Requirement

Data Retention

Erase data once purpose is fulfilled

Retain KYC records for 5+ years, transaction data per AML norms

Consent

Purpose-specific, freely given, withdrawable consent

KYC consent implied by regulatory mandate under Section 7

Data Localisation

No specific localisation (allows transfers to notified countries)

Payment system data must be stored exclusively in India

Breach Notification

Notify DPB and individuals within 72 hours

Report incidents to CERT-In within 6 hours; notify RBI per circular

Third-Party Sharing

Written agreement with Data Processors; limit sub-processing

Outsourcing guidelines with audit rights and risk assessment

Automated Decisions

SDFs must assess algorithmic fairness

RBI guidelines on responsible AI in lending (evolving)

 

The critical takeaway is that banks cannot treat DPDPA compliance and RBI compliance as separate workstreams. They must be harmonised into a single, integrated governance framework that satisfies both sets of requirements simultaneously.


 

5. Data Breaches in Indian Banking: A Wake-Up Call

The urgency of DPDPA compliance becomes clear when viewed against the backdrop of actual data breaches in India's financial sector:

Title: breach_stats.png - Description: breach_stats.png

Notable Incidents

The 273,000-Document Banking Data Exposure (2025)

In September 2025, cybersecurity researchers discovered one of the most significant banking data exposures in Indian history. A publicly accessible Amazon-hosted storage server contained 273,000 PDF documents relating to bank transfers of Indian customers, linked to at least 38 different banks and financial institutions. The documents contained names, account numbers, transaction details, and other sensitive personal information. The breach was caused by a simple misconfiguration of cloud storage permissions.

HDFC Life Data Breach

HDFC Life Insurance faced a significant data breach where a cybercriminal claimed to have accessed the personal data of over 1.5 crore customers, including names, policy numbers, addresses, and phone numbers. The incident highlighted the vulnerabilities in data handling practices across the BFSI sector and the cascading reputational damage that follows such breaches.

Digital Lending NBFC Privacy Violations

The Delhi High Court sought the RBI's response on a Public Interest Litigation alleging widespread violation of borrowers' privacy rights by NBFCs and their digital lending applications. The petition highlighted how certain lending apps were accessing phone contacts, photos, and SMS messages to harass borrowers and their contacts during recovery efforts. This practice directly violates both the DPDPA's purpose limitation principle and the RBI's Digital Lending Directions.

Under the DPDPA, each of these incidents would attract penalties of up to Rs. 250 crore for security safeguard failures, plus Rs. 200 crore for notification failures. The financial and reputational consequences are existential.


 

6. Compliance Roadmap: A Practical Guide for Banks and NBFCs

Title: roadmap.png - Description: roadmap.png

Step 1: Comprehensive Data Audit

Begin by mapping every system, database, application, and third-party integration that processes personal data. This includes core banking systems, CRM platforms, mobile banking apps, HRMS, CCTV systems, and all vendor relationships. Classify data by type, sensitivity, purpose, and retention requirement. Identify every Data Processor in your ecosystem.

Step 2: Consent Architecture Redesign

Move from blanket, bundled consent to granular, purpose-specific consent. Build consent management systems that allow customers to view what they have consented to, withdraw consent for specific purposes, and receive clear notice about new processing activities. Prepare for integration with external Consent Managers as the framework rolls out. Ensure consent flows are available in multiple languages.

Step 3: Security Infrastructure Upgrade

Implement or strengthen encryption at rest and in transit across all systems. Deploy breach detection and response tools capable of identifying incidents and triggering the 72-hour notification workflow. Conduct penetration testing with specific focus on cloud configurations, API security, and third-party access points. Implement Data Loss Prevention (DLP) tools that monitor and restrict unauthorized data transfers. Segment networks to limit the blast radius of any breach.

Step 4: Vendor and Third-Party Governance

Review and renegotiate contracts with every Data Processor to include DPDPA-mandated clauses covering data protection obligations, breach notification responsibilities, audit rights, sub-processing restrictions, and data return or deletion upon contract termination. Establish a vendor risk assessment framework that evaluates data protection practices before onboarding and periodically during the relationship.

Step 5: Ongoing Monitoring and Governance

Appoint or designate a Data Protection Officer. Establish a data governance committee with board-level visibility. Conduct annual DPIAs for high-risk processing activities such as credit scoring, automated lending decisions, and behavioural analytics. Implement training programs tailored to different roles across branches, headquarters, IT, and operations. Monitor regulatory developments from both the DPB and the RBI to adapt compliance practices as guidance evolves.


 

7. The Penalty Framework: What Is at Stake

Violation

DPDPA Penalty

RBI Action

Failure to implement security safeguards

Up to Rs. 250 Cr

Monetary penalty

Failure to notify breach to DPB and individuals

Up to Rs. 200 Cr

Enhanced reporting

Non-compliance with SDF obligations

Up to Rs. 150 Cr

Regulatory scrutiny

Children's data violations

Up to Rs. 200 Cr

N/A

Other provision violations

Up to Rs. 50 Cr

Operational restrictions

Severe or repeated non-compliance

Cumulative penalties

License cancellation

 

For banks and NBFCs, the stakes are doubled. A data breach or compliance failure triggers scrutiny from both the Data Protection Board under the DPDPA and the Reserve Bank of India under its existing regulatory framework. The RBI's enforcement powers include monetary penalties, enhanced compliance reporting requirements, restrictions on new business activities, and in extreme cases, cancellation of the banking licence or NBFC registration.


 

8. The Strategic Upside: Why Compliance Is a Competitive Advantage

While the compliance burden is real, forward-thinking banks and NBFCs are recognizing that DPDPA compliance can be a competitive differentiator:

        Customer trust as a brand asset: In an era of data breaches and growing consumer awareness, a bank that demonstrably protects customer data builds deeper trust and loyalty. Trust translates directly into deposits, lending relationships, and cross-selling opportunities.

        Operational efficiency: The data audit and classification exercise required for compliance often reveals redundant systems, duplicate databases, and inefficient data flows. Cleaning up this infrastructure reduces costs and improves operational agility.

        Global readiness: Indian banks with international operations or aspirations benefit from DPDPA compliance as it aligns broadly with GDPR standards, facilitating cross-border data transfer agreements and international partnerships.

        Reduced breach costs: The security safeguards implemented for compliance also reduce the likelihood and impact of data breaches, which cost the global banking industry billions annually in direct costs, regulatory fines, and customer attrition.

        Regulatory goodwill: Banks that proactively demonstrate strong data protection practices are more likely to receive favourable treatment from both the DPB and the RBI, including faster approvals for new products, licences, and market expansions.


 

Frequently Asked Questions (FAQs)

Q1: Does the DPDPA apply to all banks and NBFCs in India?

Yes. The DPDPA applies to every entity that processes digital personal data within India. This includes public sector banks, private sector banks, foreign banks operating in India, NBFCs (including microfinance institutions and housing finance companies), payment banks, small finance banks, and cooperative banks.

Q2: How does the DPDPA affect KYC processes?

KYC data collected under regulatory mandate (RBI's KYC Directions) falls under Section 7 of the DPDPA, which permits processing for compliance with any law. This means separate consent is not required for mandatory KYC. However, if the bank uses KYC data for any purpose beyond regulatory compliance, such as marketing or analytics, it must obtain separate, purpose-specific consent under the DPDPA.

Q3: Can customers demand deletion of their loan records?

The right to erasure under the DPDPA is not absolute. Banks are required by RBI regulations, AML laws, and tax legislation to retain certain records for specified periods. During these mandated retention periods, the bank must retain the data regardless of any erasure request. Once the statutory retention period expires and the purpose has been fulfilled, the bank must then erase the data.

Q4: Will all banks be classified as Significant Data Fiduciaries?

Not necessarily all, but most large banks and major NBFCs will likely be designated as SDFs based on the volume and sensitivity of personal data they process. The Central Government will notify the specific criteria and designations. Smaller NBFCs and cooperative banks may not be classified as SDFs but must still comply with all standard Data Fiduciary obligations under the DPDPA.

Q5: How should banks handle the tension between data erasure and regulatory retention?

The DPDPA explicitly provides an exception for retention required by law. Section 8(5) states that data fiduciaries may retain personal data for longer periods when required by any law in force. Banks should create a comprehensive retention matrix mapping every data type against all applicable retention obligations from the RBI, SEBI, Income Tax Act, PMLA, and other regulators, and erase data only after all mandated retention periods have expired.

Q6: What about data shared with credit bureaus like CIBIL?

Sharing data with credit bureaus is mandated by the Credit Information Companies (Regulation) Act, 2005, and RBI directions. This falls under the lawful processing exemption of the DPDPA. However, banks must ensure that only the data required under these regulations is shared and that their agreements with credit bureaus include DPDPA-compliant data protection clauses.

Q7: Are digital lending apps by NBFCs under additional scrutiny?

Yes. Digital lending apps face dual scrutiny under both the DPDPA and the RBI's Digital Lending Directions. These apps must limit data collection to what is strictly necessary for credit assessment and loan servicing. Accessing phone contacts, gallery, SMS, or other phone data beyond legitimate requirements is a direct violation. The Delhi High Court has taken cognisance of privacy violations by digital lending platforms, signalling increased judicial and regulatory attention.

Q8: What is the compliance timeline for banks?

Core DPDPA obligations including consent management, security safeguards, and breach notification are enforceable now. The Consent Manager framework deadline is November 2026. SDF-specific obligations including DPO appointment, annual DPIAs, and independent audits are expected to be enforced from May 2027. Banks that have not started compliance work are already behind schedule.


 

Conclusion: The Compliance Clock Is Ticking

The DPDPA is not just another regulatory requirement for banks and NBFCs to file away. It represents a fundamental shift in how financial institutions must think about personal data. The days of collecting everything, retaining it indefinitely, and sharing it freely are over.

The dual compliance challenge with RBI regulations, the massive penalty framework, the 72-hour breach notification requirement, and the growing threat landscape all point to one conclusion: banks and NBFCs that delay will pay dearly, in fines, in customer trust, and in competitive standing.

The good news is that the compliance roadmap is clear. It begins with a comprehensive data audit, moves through consent redesign and security upgrades, and culminates in an ongoing governance framework that keeps the institution compliant as regulations evolve. The institutions that invest in this now will not only avoid penalties but will emerge as more trusted, more efficient, and more resilient financial organisations.


 

Protect Your Institution. Start Your DPDPA Compliance Journey Today.

With penalties up to Rs. 250 crore and RBI scrutiny intensifying, the cost of inaction far exceeds the cost of compliance.

 

At DPDP Consultants, we specialise in DPDPA compliance for banks, NBFCs, and financial institutions. Our team understands both the DPDPA framework and the RBI regulatory landscape, ensuring your compliance programme satisfies both sets of requirements without duplication or gaps.

 

Our services for banks and NBFCs:

        DPDPA and RBI Dual Compliance Assessment

        Data Flow Mapping Across Core Banking, Mobile Apps, and Third-Party Integrations

        Consent Architecture Design and Consent Manager Integration

        Breach Response Planning and 72-Hour Notification Workflow Design

        DPO-as-a-Service and Annual DPIA Support

        Role-Specific Training for Branch Staff, IT Teams, and Senior Leadership

 

Contact us today for a free compliance readiness assessment.

Email: info@dpdpconsultants.com

Website: www.dpdpconsultants.com

 

Secure your data. Strengthen your compliance. Safeguard your licence.

 

Disclaimer: This document is for informational purposes only and does not constitute legal or financial advice. Banks and NBFCs should consult qualified legal and regulatory professionals for advice specific to their circumstances. Information is accurate as of June 2026.