Our resources provide the essential tools, guides, and insights to help your business stay ahead of data privacy regulations. From practical templates to expert articles, we ensure you have everything you need to navigate compliance with confidence.
Table of content
Last Updated: 2026-06-17 ~ DPDP Consultants
India's banking and financial services industry processes more personal
data than almost any other sector in the economy. Every time a customer opens
an account, applies for a loan, swipes a card, makes a UPI payment, or even
walks into a bank branch, a trail of personal data is created, stored, shared,
and analysed. For decades, this data was governed primarily by RBI circulars
and sector-specific guidelines. That era is now over.
The Digital Personal Data Protection Act, 2023 (DPDPA), along with
the DPDP Rules notified in 2025, introduces a comprehensive, cross-sector data
protection framework that sits on top of existing RBI regulations. For banks
and Non-Banking Financial Companies (NBFCs), this creates a dual compliance
obligation that is both more complex and more consequential than anything
the sector has faced before.
This blog explores how the DPDPA reshapes the way banks and NBFCs
collect, process, store, and share personal data. It examines the specific
operational challenges, the intersection with RBI regulations, the penalties
for non-compliance, and the practical steps financial institutions must take to
become compliant before the enforcement deadlines arrive.
•
Volume and sensitivity of data: A single bank
customer generates data across dozens of touchpoints: KYC documents (Aadhaar,
PAN, passport), financial transactions, credit scores, loan histories,
insurance policies, investment portfolios, biometric data for authentication,
and communication records. This is among the most sensitive personal data any
organisation can hold.
•
Vast customer base: India's scheduled commercial
banks serve over 200 crore deposit accounts. Large private banks individually
hold data on tens of millions of customers. NBFCs, especially those in digital
lending, often process thousands of loan applications daily, each carrying
detailed personal and financial information.
•
Extensive third-party sharing: Banks routinely
share personal data with credit bureaus (CIBIL, Experian, Equifax), payment
processors, insurance partners, fintech aggregators, recovery agents,
correspondent banking partners, and government agencies. Each sharing point is
now a compliance obligation under the DPDPA.
•
Legacy technology stacks: Many public sector
banks still run core banking systems built decades ago, with limited ability to
implement granular consent management, automated data erasure, or real-time
breach detection without significant modernisation.
•
Regulatory intersection: Unlike most sectors,
banks must comply with both the DPDPA and a layered set of RBI regulations
covering cybersecurity, data localisation, digital lending, and outsourcing.
The two frameworks sometimes overlap and occasionally create tension.
The DPDPA requires that consent be free, specific, informed,
unconditional, and unambiguous. For banks, this means fundamentally rethinking
how consent is obtained at every customer touchpoint.
Today, most banks bundle consent into lengthy terms and conditions
documents that customers sign (or click through) without reading. Under the
DPDPA, each distinct purpose of data processing requires its own clearly stated
consent. A bank that collects Aadhaar for KYC cannot automatically use that
same data for marketing analytics or cross-selling insurance products without
obtaining separate, purpose-specific consent.
The Act also introduces the concept of a Consent Manager, a registered
intermediary that allows customers to view, manage, and withdraw their consents
from a single platform. Banks must integrate their systems with these Consent
Managers, enabling customers to exercise real control over how their data is
used. The November 2026 deadline for the Consent Manager framework makes this
an urgent priority.
Banks have historically collected far more data than strictly necessary,
operating on the logic that more data enables better risk assessment and
product personalisation. The DPDPA disrupts this approach by mandating that
data collection must be limited to what is necessary for the specified purpose.
For NBFCs in digital lending, this is especially relevant. Many lending
apps have faced criticism for accessing phone contacts, gallery photos, SMS
messages, and location data well beyond what is needed for credit assessment.
The DPDPA, reinforced by the RBI's Digital Lending Directions, now makes such
overcollection a compliance violation with penalties of up to Rs. 250 crore.
Under the DPDPA, personal data must be erased once the purpose of
collection is fulfilled, unless retention is required by another law. For
banks, this creates a complex matrix. RBI regulations require certain records
to be retained for specific periods: KYC records must be maintained for at
least five years after the business relationship ends, transaction records are
required under anti-money laundering rules, and tax-related data must be
retained per Income Tax Act requirements.
Banks must therefore build systems that can distinguish between data that
must be retained under regulatory mandate and data that should be erased under
the DPDPA. This requires a detailed data classification exercise mapped against
every applicable retention obligation.
The DPDPA mandates that Data Fiduciaries notify both the Data Protection
Board of India (DPB) and affected individuals within 72 hours of becoming aware
of a personal data breach. Given the scale of banking operations and the
sophistication of cyberattacks targeting financial institutions, this is a
formidable requirement.
The RBI confirmed that 248 data breaches were reported across scheduled
commercial banks between 2018 and 2022, with 205 of those in private sector
banks. As the DPDPA raises the stakes for breach reporting, banks that lack
real-time breach detection and automated notification systems will face both
regulatory penalties and reputational damage.
Large banks and major NBFCs will almost certainly be designated as
Significant Data Fiduciaries by the Central Government. SDFs face enhanced
obligations beyond standard compliance. They must appoint an India-based Data
Protection Officer (DPO), conduct annual Data Protection Impact Assessments
(DPIAs), undergo independent audits of their data processing practices, and
submit to algorithmic fairness assessments for any automated decision-making,
including AI-driven credit scoring models.
These SDF provisions are expected to come into force by May 2027, but
banks should begin preparations now, given the scale of operational changes
involved.
Mapping every touchpoint where personal data is collected, processed,
shared, or stored is the foundation of DPDPA compliance. In banking, the number
of touchpoints is vast:
|
Touchpoint |
Personal Data Collected |
Shared With |
Risk Level |
|
KYC and Account Opening |
Aadhaar, PAN, photo, address proof, income details |
UIDAI, CKYC Registry |
High |
|
Loan Origination and Credit
Scoring |
Income, employment, credit
history, bank statements |
Credit bureaus (CIBIL,
Experian) |
High |
|
Mobile and Internet Banking |
Login credentials, device info, transaction history, location |
Payment gateways, UPI systems |
High |
|
UPI and Card Payments |
Transaction data, merchant
details, spending patterns |
NPCI, acquiring banks,
merchants |
Medium |
|
Third-Party Vendor APIs |
Customer data shared for analytics, marketing, or operations |
Fintech partners, data processors |
High |
|
Customer Call Centre and
CRM |
Call recordings, complaint
details, personal identifiers |
BPO vendors, CRM platforms |
Medium |
|
CCTV and Branch Surveillance |
Facial images, movement patterns |
Security vendors |
Medium |
|
Employee HRMS and Payroll |
Employee Aadhaar, PAN, bank
details, medical records |
Payroll vendors, insurance
companies |
High |
|
Insurance and Investment Cross-sell |
Financial profile, risk appetite, nominee details |
Insurance companies, AMCs |
Medium |
|
Recovery and Collections |
Borrower details, contact
information, financial status |
Recovery agents, legal
firms |
High |
What makes compliance uniquely complex for banks and NBFCs is that the
DPDPA does not replace existing RBI regulations. Instead, it adds a new,
comprehensive layer on top of them. Here is how the two frameworks intersect:
|
Area |
DPDPA Requirement |
RBI Requirement |
|
Data Retention |
Erase data once purpose is fulfilled |
Retain KYC records for 5+ years, transaction data per AML norms |
|
Consent |
Purpose-specific, freely
given, withdrawable consent |
KYC consent implied by
regulatory mandate under Section 7 |
|
Data Localisation |
No specific localisation (allows transfers to notified countries) |
Payment system data must be stored exclusively in India |
|
Breach Notification |
Notify DPB and individuals
within 72 hours |
Report incidents to CERT-In
within 6 hours; notify RBI per circular |
|
Third-Party Sharing |
Written agreement with Data Processors; limit sub-processing |
Outsourcing guidelines with audit rights and risk assessment |
|
Automated Decisions |
SDFs must assess
algorithmic fairness |
RBI guidelines on
responsible AI in lending (evolving) |
The critical takeaway is that banks cannot treat DPDPA compliance and RBI
compliance as separate workstreams. They must be harmonised into a single,
integrated governance framework that satisfies both sets of requirements
simultaneously.
The urgency of DPDPA compliance becomes clear when viewed against the
backdrop of actual data breaches in India's financial sector:
The 273,000-Document
Banking Data Exposure (2025)
In September 2025, cybersecurity researchers discovered one of the most
significant banking data exposures in Indian history. A publicly accessible
Amazon-hosted storage server contained 273,000 PDF documents relating to bank
transfers of Indian customers, linked to at least 38 different banks and
financial institutions. The documents contained names, account numbers,
transaction details, and other sensitive personal information. The breach was
caused by a simple misconfiguration of cloud storage permissions.
HDFC Life Data Breach
HDFC Life Insurance faced a significant data breach where a cybercriminal
claimed to have accessed the personal data of over 1.5 crore customers,
including names, policy numbers, addresses, and phone numbers. The incident
highlighted the vulnerabilities in data handling practices across the BFSI
sector and the cascading reputational damage that follows such breaches.
Digital Lending NBFC
Privacy Violations
The Delhi High Court sought the RBI's response on a Public Interest
Litigation alleging widespread violation of borrowers' privacy rights by NBFCs
and their digital lending applications. The petition highlighted how certain
lending apps were accessing phone contacts, photos, and SMS messages to harass
borrowers and their contacts during recovery efforts. This practice directly
violates both the DPDPA's purpose limitation principle and the RBI's Digital
Lending Directions.
Under the DPDPA, each of these incidents would attract penalties of up to
Rs. 250 crore for security safeguard failures, plus Rs. 200 crore for
notification failures. The financial and reputational consequences are
existential.
Begin by mapping every system, database, application, and third-party
integration that processes personal data. This includes core banking systems,
CRM platforms, mobile banking apps, HRMS, CCTV systems, and all vendor
relationships. Classify data by type, sensitivity, purpose, and retention
requirement. Identify every Data Processor in your ecosystem.
Move from blanket, bundled consent to granular, purpose-specific consent.
Build consent management systems that allow customers to view what they have
consented to, withdraw consent for specific purposes, and receive clear notice
about new processing activities. Prepare for integration with external Consent
Managers as the framework rolls out. Ensure consent flows are available in
multiple languages.
Implement or strengthen encryption at rest and in transit across all
systems. Deploy breach detection and response tools capable of identifying
incidents and triggering the 72-hour notification workflow. Conduct penetration
testing with specific focus on cloud configurations, API security, and
third-party access points. Implement Data Loss Prevention (DLP) tools that
monitor and restrict unauthorized data transfers. Segment networks to limit the
blast radius of any breach.
Review and renegotiate contracts with every Data Processor to include
DPDPA-mandated clauses covering data protection obligations, breach
notification responsibilities, audit rights, sub-processing restrictions, and
data return or deletion upon contract termination. Establish a vendor risk
assessment framework that evaluates data protection practices before onboarding
and periodically during the relationship.
Appoint or designate a Data Protection Officer. Establish a data
governance committee with board-level visibility. Conduct annual DPIAs for
high-risk processing activities such as credit scoring, automated lending
decisions, and behavioural analytics. Implement training programs tailored to
different roles across branches, headquarters, IT, and operations. Monitor
regulatory developments from both the DPB and the RBI to adapt compliance
practices as guidance evolves.
|
Violation |
DPDPA Penalty |
RBI Action |
|
Failure to implement security safeguards |
Up to Rs.
250 Cr |
Monetary
penalty |
|
Failure to notify breach to
DPB and individuals |
Up to Rs.
200 Cr |
Enhanced
reporting |
|
Non-compliance with SDF obligations |
Up to Rs.
150 Cr |
Regulatory
scrutiny |
|
Children's data violations |
Up to Rs.
200 Cr |
N/A |
|
Other provision violations |
Up to Rs.
50 Cr |
Operational
restrictions |
|
Severe or repeated
non-compliance |
Cumulative
penalties |
License
cancellation |
For banks and NBFCs, the stakes are doubled. A data breach or compliance
failure triggers scrutiny from both the Data Protection Board under the DPDPA
and the Reserve Bank of India under its existing regulatory framework. The
RBI's enforcement powers include monetary penalties, enhanced compliance
reporting requirements, restrictions on new business activities, and in extreme
cases, cancellation of the banking licence or NBFC registration.
While the compliance burden is real, forward-thinking banks and NBFCs are
recognizing that DPDPA compliance can be a competitive differentiator:
•
Customer trust as a brand asset: In an era of
data breaches and growing consumer awareness, a bank that demonstrably protects
customer data builds deeper trust and loyalty. Trust translates directly into
deposits, lending relationships, and cross-selling opportunities.
•
Operational efficiency: The data audit and
classification exercise required for compliance often reveals redundant
systems, duplicate databases, and inefficient data flows. Cleaning up this
infrastructure reduces costs and improves operational agility.
•
Global readiness: Indian banks with
international operations or aspirations benefit from DPDPA compliance as it
aligns broadly with GDPR standards, facilitating cross-border data transfer
agreements and international partnerships.
•
Reduced breach costs: The security safeguards
implemented for compliance also reduce the likelihood and impact of data
breaches, which cost the global banking industry billions annually in direct
costs, regulatory fines, and customer attrition.
•
Regulatory goodwill: Banks that proactively
demonstrate strong data protection practices are more likely to receive
favourable treatment from both the DPB and the RBI, including faster approvals
for new products, licences, and market expansions.
Q1: Does the DPDPA apply to all banks and NBFCs in India?
Yes. The DPDPA applies to every entity that processes digital personal
data within India. This includes public sector banks, private sector banks,
foreign banks operating in India, NBFCs (including microfinance institutions
and housing finance companies), payment banks, small finance banks, and
cooperative banks.
Q2: How does the DPDPA affect KYC processes?
KYC data collected under regulatory mandate (RBI's KYC Directions) falls
under Section 7 of the DPDPA, which permits processing for compliance with any
law. This means separate consent is not required for mandatory KYC. However, if
the bank uses KYC data for any purpose beyond regulatory compliance, such as
marketing or analytics, it must obtain separate, purpose-specific consent under
the DPDPA.
Q3: Can customers demand deletion of their loan records?
The right to erasure under the DPDPA is not absolute. Banks are required
by RBI regulations, AML laws, and tax legislation to retain certain records for
specified periods. During these mandated retention periods, the bank must
retain the data regardless of any erasure request. Once the statutory retention
period expires and the purpose has been fulfilled, the bank must then erase the
data.
Q4: Will all banks be classified as Significant Data Fiduciaries?
Not necessarily all, but most large banks and major NBFCs will likely be
designated as SDFs based on the volume and sensitivity of personal data they
process. The Central Government will notify the specific criteria and
designations. Smaller NBFCs and cooperative banks may not be classified as SDFs
but must still comply with all standard Data Fiduciary obligations under the
DPDPA.
Q5: How should banks handle the tension between data erasure and
regulatory retention?
The DPDPA explicitly provides an exception for retention required by law.
Section 8(5) states that data fiduciaries may retain personal data for longer
periods when required by any law in force. Banks should create a comprehensive
retention matrix mapping every data type against all applicable retention
obligations from the RBI, SEBI, Income Tax Act, PMLA, and other regulators, and
erase data only after all mandated retention periods have expired.
Q6: What about data shared with credit bureaus like CIBIL?
Sharing data with credit bureaus is mandated by the Credit Information
Companies (Regulation) Act, 2005, and RBI directions. This falls under the
lawful processing exemption of the DPDPA. However, banks must ensure that only
the data required under these regulations is shared and that their agreements
with credit bureaus include DPDPA-compliant data protection clauses.
Q7: Are digital lending apps by NBFCs under additional scrutiny?
Yes. Digital lending apps face dual scrutiny under both the DPDPA and the
RBI's Digital Lending Directions. These apps must limit data collection to what
is strictly necessary for credit assessment and loan servicing. Accessing phone
contacts, gallery, SMS, or other phone data beyond legitimate requirements is a
direct violation. The Delhi High Court has taken cognisance of privacy
violations by digital lending platforms, signalling increased judicial and
regulatory attention.
Q8: What is the compliance timeline for banks?
Core DPDPA obligations including consent management, security safeguards,
and breach notification are enforceable now. The Consent Manager framework
deadline is November 2026. SDF-specific obligations including DPO appointment,
annual DPIAs, and independent audits are expected to be enforced from May 2027.
Banks that have not started compliance work are already behind schedule.
The DPDPA is not just another regulatory requirement for banks and NBFCs
to file away. It represents a fundamental shift in how financial institutions
must think about personal data. The days of collecting everything, retaining it
indefinitely, and sharing it freely are over.
The dual compliance challenge with RBI regulations, the massive penalty
framework, the 72-hour breach notification requirement, and the growing threat
landscape all point to one conclusion: banks and NBFCs that delay will pay
dearly, in fines, in customer trust, and in competitive standing.
The good news is that the compliance roadmap is clear. It begins with a
comprehensive data audit, moves through consent redesign and security upgrades,
and culminates in an ongoing governance framework that keeps the institution
compliant as regulations evolve. The institutions that invest in this now will
not only avoid penalties but will emerge as more trusted, more efficient, and
more resilient financial organisations.
With penalties up to Rs. 250 crore and RBI scrutiny
intensifying, the cost of inaction far exceeds the cost of compliance.
At DPDP Consultants, we
specialise in DPDPA compliance for banks, NBFCs, and financial institutions.
Our team understands both the DPDPA framework and the RBI regulatory landscape,
ensuring your compliance programme satisfies both sets of requirements without
duplication or gaps.
Our services for banks
and NBFCs:
•
DPDPA and RBI Dual Compliance Assessment
•
Data Flow Mapping Across Core Banking, Mobile Apps, and
Third-Party Integrations
•
Consent Architecture Design and Consent Manager
Integration
•
Breach Response Planning and 72-Hour Notification
Workflow Design
•
DPO-as-a-Service and Annual DPIA Support
•
Role-Specific Training for Branch Staff, IT Teams, and
Senior Leadership
Contact us today for a free compliance
readiness assessment.
Email:
info@dpdpconsultants.com
Website: www.dpdpconsultants.com
Secure your data. Strengthen your
compliance. Safeguard your licence.
Disclaimer: This document is for informational
purposes only and does not constitute legal or financial advice. Banks and
NBFCs should consult qualified legal and regulatory professionals for advice
specific to their circumstances. Information is accurate as of June 2026.