Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsThe Digital Personal Data Protection Act, 2023 applies to a bank’s digital processing of customer personal data, but it does not turn every banking activity into a consent workflow. Each purpose must be routed through the Act’s own structure: consent under Section 6, or one of the closed Section 7 legitimate uses. The Act sits alongside existing RBI and PMLA duties, which it does not replace. The main obligations are scheduled to commence on 13 May 2027, so the work now is mapping purposes to a lawful route and reconciling it with banking controls.
The DPDP Act, 2023 governs the processing of digital personal data. For a bank, that covers most of the customer-data lifecycle, but the Act permits processing on only two kinds of route: consent under Section 6, or one of the enumerated Section 7 legitimate uses. There is no general "legal obligation" or "contractual necessity" basis of the kind found in some other regimes. A bank’s RBI or PMLA duty to perform an activity explains why the activity happens; it does not by itself supply the DPDP route, which must still be found in Section 6 or Section 7. Some banking activities map cleanly (for example, mandatory reporting to the State under Section 7(d)); several do not, and for those the correct answer is activity-specific analysis rather than an assumed basis. The core obligations are scheduled to commence on 13 May 2027.
The customer-data lifecycle is wider for a bank than for most sectors. Each stage may carry a different DPDP analysis.
The core asset of this page. The DPDP route is the question of which Section 4 path may permit the processing. The RBI or statutory overlay is why the activity happens, kept separate. Support level uses four grades.
Scroll the table sideways on a narrow screen.
| Activity | DPDP Section 4 route to assess | RBI / statutory driver | Consent (S6) issue | Support |
|---|---|---|---|---|
| Prospect / unsolicited marketing | Section 6 consent (distinct optional purpose) | — | Unbundled opt-in | Strong |
| Customer initiates an account or service | Section 7(a) voluntary provision for the specified purpose | Banking Regulation Act | Excess data only | Interpretive |
| Mandatory KYC / CDD field collection | Section 7(a) may be relevant; whether precondition data is "voluntarily provided" is open | RBI KYC Directions 2025; PMLA | Not the organising basis | Uncertain |
| Identity verification (V-CIP, OVD, CKYCR) | Section 7(a) for the step; CKYCR reliance is RBI-defined | RBI KYC Directions 2025 (para 65) | — | Interpretive |
| Beneficial-owner verification | Third-party data; route not expressly resolved | PMLA; KYC Directions 2025 | — | Uncertain |
| Sanctions / PEP screening | Preparatory risk processing; no clean clause until reporting | KYC Directions 2025; UAPA lists | — | Uncertain |
| Internal transaction monitoring (AML detection) | Not Section 7(d) by itself; preparatory processing | PMLA; KYC Directions 2025 | — | Uncertain |
| STR / CTR to FIU-IND | Section 7(d) disclosure to the State required by law | PMLA; PML Rules 2005 | No | Strong |
| Deposits, payments, cards execution | Section 7(a) voluntary provision for the requested service | RBI; NPCI | Value-adds only | Interpretive |
| Net / mobile banking delivery | Section 7(a) for the requested channel | RBI Digital Payment Security 2026 | — | Interpretive |
| Fraud prevention / security monitoring | No clean clause; the RBI mandate does not itself create a DPDP basis | RBI Cyber Framework 2026; fraud-liability 2026 | — | Uncertain |
| Reuse of KYC / customer data for a new purpose | A new purpose needs its own route; often Section 6 | KYC Directions 2025 (purpose limitation) | Likely | Strong (a basis is needed) |
| Marketing / cross-sell / profiling | Purpose-specific: optional profiling points to Section 6; customer-requested product information may fit Section 7(a) | RBI Responsible Business Conduct 2025 | Often | Purpose-specific |
| Collections / recovery | Route not expressly resolved | RBI DLD 2025 (digital lending) | — | Uncertain |
| Account Aggregator flows | AA consent artefact (RBI); must be tested separately against Section 6, not assumed to satisfy it | RBI NBFC-AA framework | Distinct mechanic | Interpretive |
| RBI regulatory returns | Section 7(d) disclosure to a State instrumentality | Banking Regulation Act; RBI | No | Strong |
| Retention vs erasure request | Law-mandated retention continues after withdrawal (Section 6(6) carve-out) | PMLA; RBI record rules | Withdrawal is not deletion | Strong |
Several rows are marked Uncertain on purpose. The Act does not expressly resolve those fact patterns as of 7 September 2026, and manufacturing a basis would be worse than naming the gap. Treat those as items for activity-specific legal analysis, documented, before commencement.
Not as a default, and the reasoning matters. KYC is performed to meet the RBI (Commercial Banks — Know Your Customer) Directions, 2025 and the PMLA. That is why the bank collects the data. It is a separate question which DPDP route permits the processing.
RBI The RBI KYC Directions 2025 (which replaced the 2016 Master Direction) and the PMLA require customer due diligence, identity verification and record-keeping. These are regulatory duties on the bank.
Law Under the DPDP Act, the regulatory duty does not itself create a lawful basis. The route must be found in Section 6 or Section 7. Section 7(a) may be relevant where a customer voluntarily provides personal data for the specified purpose of obtaining a requested banking service. Whether all mandatory KYC collection satisfies the "voluntarily provided" condition, given that KYC is a precondition to the relationship, requires activity-specific analysis. Fresh Section 6 consent is generally not the organising basis for the KYC obligation itself.
Practice Keep three questions separate: why RBI or PMLA requires the collection; which DPDP Section 4 route permits it; and whether any reuse of KYC data for an unrelated purpose (for example marketing) needs its own Section 6 consent. The last one usually does, and it cannot be folded into onboarding.
Consent is not the backbone of banking data processing, but it is decisive for a defined set of optional purposes. These are the activities to design a genuine consent flow around, rather than every touchpoint.
Promotional messaging the customer has not requested, separate from service communication.
Offering unrelated products using customer data beyond the original purpose.
Optional personalisation or analytics not necessary to deliver the requested service.
Disclosures not supported by another route such as Section 7(d).
Value-added features a customer can choose to switch on.
Channel and frequency choices for non-essential contact.
Where Section 6 applies, the requirements are the same as anywhere else: a Section 5 notice, valid consent, evidence and an easy withdrawal route. Read the Section 6 statutory page, the Valid Consent guide, and How to prove consent.
An orientation tool. Actual processing must be analysed against the exact statutory facts, not this flow.
There is no open "legitimate interest" ground. If a purpose fits neither Section 6 nor a Section 7 clause, the workflow needs redesigning, not a label. See the Consent vs Certain Legitimate Uses guide and Section 7.
Where the two frameworks meet. They are analysed separately; one does not satisfy the other.
| Issue | DPDP framework | RBI / banking framework | What the bank reconciles |
|---|---|---|---|
| Notice | Section 5 notice where consent is the route | Fair-practice disclosures under Responsible Business Conduct 2025 | One customer-facing notice set that satisfies both |
| KYC | Route assessed under Section 6 or 7 | Mandatory CDD under KYC Directions 2025 and PMLA | Regulatory duty vs DPDP route kept distinct |
| Reporting to the State | Section 7(d) | STR/CTR to FIU-IND; returns to RBI | Document the disclosure route |
| Outsourcing / vendors | Processor by contract, Section 8(2) | Bank stays accountable, Outsourcing Directions 2025 | One contract meeting both control regimes |
| Security | Reasonable security safeguards, Section 8 | Cyber Framework Directions 2026 (monitoring, VAPT, logging) | Controls evidence serving both |
| Breach / incident | DPDP breach duties | RBI incident reporting under the 2026 framework | A single incident runbook, two reporting paths |
| Retention | Erasure right, Section 6(6) carve-out for law | Mandatory record retention under PMLA and RBI | Retention schedule that overrides erasure where law requires |
| Grievance | Data Principal grievance and Board escalation | Grievance redressal under Responsible Business Conduct 2025 | One intake, correct routing |
A bank’s duty of confidentiality over customer information sits alongside DPDP, not inside it. Information obtained to provide a banking service, to meet a regulatory duty, or to service the relationship is a different question from reusing that information for an unrelated purpose or disclosing it to an external party.
The practical rule is purpose discipline. Data collected for the requested service or for a regulatory duty should not be repurposed for marketing, cross-sell or external sharing without testing a fresh DPDP route for that new purpose, and without checking the RBI confidentiality and fair-conduct position under the Responsible Business Conduct Directions 2025.
Banks are also regulated entities under the RBI Digital Lending Directions, 2025 where they lend through digital channels or lending service providers. Those requirements (borrower consent for data access, device-permission limits, the lender staying liable for the app’s conduct) are RBI requirements and should be analysed separately from general banking data processing, with the DPDP route tested for each lending purpose.
The detailed build sequence lives elsewhere. See the DPDP and RBI digital lending implementation and the digital lending overview. This page does not duplicate them.
Where a bank participates in the RBI Account Aggregator ecosystem as a Financial Information Provider or User, sharing runs on a standardised, RBI-prescribed consent artefact, with revocation and logging built into the framework. That artefact is an RBI mechanic.
Law An RBI Account Aggregator consent artefact should not be assumed to satisfy DPDP Section 6 on its own. The two consent constructs serve different frameworks; where consent is the DPDP route for a given flow, the Section 6 requirements are tested separately. Account Aggregators may warrant their own dedicated treatment; this page keeps the point concise.
A vendor is not automatically a Data Processor. The role turns on the processing relationship under the Act, not the label.
Ask three questions of each: who determines the purpose and means of the processing; what the contract says about acting on the bank’s instructions; and whether the provider processes for its own purposes. Under DPDP Section 8(2) a Data Processor acts under a valid contract, and under the RBI Outsourcing Directions 2025 the bank remains accountable for the outsourced activity regardless.
Only for processing that actually rests on Section 6. Withdrawing marketing consent does not unwind a loan, close an account, or delete records the bank must retain by law.
Practice Withdrawal request → identify the affected consent-based purpose → suppress that processing internally → update the customer preference → instruct relevant processors → preserve any processing required or authorised by law → retain evidence of the withdrawal. See the Consent withdrawal guide.
DPDP gives Data Principals an erasure right, but Section 6(6) preserves processing that is required or authorised by law. Banks are required by the PMLA and RBI rules to retain KYC and transaction records for defined periods. That retention continues after a customer withdraws consent or asks for erasure.
Law Withdrawal and erasure apply to processing that has no independent legal footing. They do not override a statutory retention duty. The correct design is a retention schedule that maps each data category to its mandatory period and releases the data only when no legal duty remains.
Sequenced work before the 13 May 2027 commencement.
| Instrument | What it governs here | Status |
|---|---|---|
| DPDP Act, 2023 | Lawful route (Section 6 / 7), notice, rights, security, breach | Core obligations scheduled 13 May 2027 |
| DPDP Rules, 2025 | Operational detail, Consent Manager framework | G.S.R. 846(E); phased |
| RBI (Commercial Banks — KYC) Directions, 2025 | CDD, verification, CKYCR, retention of KYC records | No. 169, 28 Nov 2025 (upd 29 Dec 2025); replaced 2016 MD |
| PMLA 2002 and PML Rules 2005 | KYC obligation, STR/CTR reporting to FIU-IND | In force |
| RBI (Commercial Banks — Managing Risks in Outsourcing) Directions, 2025 | Vendor accountability, confidentiality, grievance | No. 171, 28 Nov 2025 |
| RBI Cyber, Technology Risk, Resilience and Assurance Framework Directions, 2026 | Security, monitoring, logging, incident response | 31 Jul 2026, in force; replaced 2016 cyber framework |
| RBI Digital Lending Directions, 2025 | Digital lending by banks, LSP conduct | In force |
No false equivalence: an RBI requirement explains why an activity happens; the DPDP route is a separate question.
The readiness check maps where each customer-data purpose stands against the DPDP routes and the RBI overlays, and where the gaps and uncertain bases are.
Yes. The DPDP Act, 2023 applies to the processing of digital personal data, which covers most of a bank’s customer-data lifecycle. It applies alongside existing RBI and PMLA obligations rather than replacing them. The core obligations are scheduled to commence on 13 May 2027.
Not as a default. KYC is performed to meet RBI KYC Directions 2025 and PMLA obligations. Under the DPDP Act, Section 7(a) voluntary provision may be relevant, but whether all mandatory KYC collection fits that clause requires activity-specific analysis. The regulatory duty to perform KYC does not itself make Section 6 consent the DPDP basis.
No. Consent under Section 6 is one route. Many banking activities are assessed under a Section 7 legitimate use instead, such as 7(a) voluntary provision for a requested service or 7(d) disclosure to the State. There is no general legitimate-interest ground, so a purpose that fits neither Section 6 nor a Section 7 clause needs to be redesigned.
Not without a separate analysis. Marketing and cross-sell are distinct purposes from the KYC obligation. Reusing KYC or customer-profile data for optional marketing generally requires its own Section 6 consent and cannot be folded into onboarding.
Only processing that actually relied on Section 6 stops. Withdrawal is prospective and does not unwind lawful past processing, close accounts, or delete records the bank must retain under PMLA or RBI rules. The bank suppresses the consent-based processing, instructs relevant processors, and preserves anything required by law.
They are separate. The RBI Digital Lending Directions 2025 set borrower-consent, device-permission and lender-liability requirements. The DPDP route for each lending purpose is assessed on its own under Section 6 or 7. One does not satisfy the other.
For most customer-facing processing a bank determines the purpose and means, which makes it a Data Fiduciary. But the same bank can be a Data Processor for data it handles on another organisation’s behalf, and its vendors are not automatically Processors. Role depends on the processing relationship, not the label.
Where Section 6 applies, keep a reconstructable record of each consent event: identity, purpose, notice version, consent wording, the affirmative action, timestamp, channel, current state and withdrawal history. The Act sets the proof burden but does not prescribe a schema.
The Act is notified but not yet in force. The core obligations are scheduled to commence on 13 May 2027, with Consent Manager registration from 13 November 2026, under the phased commencement of the DPDP Rules 2025. Dates should be confirmed against the current official notification.
This page is legal information about the DPDP Act, 2023 as it applies to banks, not legal advice. Several banking fact patterns are not expressly resolved by the Act as of 7 September 2026 and are marked for activity-specific analysis. Statutory provisions, commencement dates and the current RBI Directions should be confirmed against official Government and RBI sources before you rely on them. Reviewed 7 September 2026.
Consultant-led and partner-backed.