Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
DPDP Act · Banking

DPDP Act Compliance for Banks in India

The Digital Personal Data Protection Act, 2023 applies to a bank’s digital processing of customer personal data, but it does not turn every banking activity into a consent workflow. Each purpose must be routed through the Act’s own structure: consent under Section 6, or one of the closed Section 7 legitimate uses. The Act sits alongside existing RBI and PMLA duties, which it does not replace. The main obligations are scheduled to commence on 13 May 2027, so the work now is mapping purposes to a lawful route and reconciling it with banking controls.

DPDP status (7 Sep 2026)
Notified, not yet in force
Core obligations commence
13 May 2027
Consent Manager registration
13 November 2026
Primary DPDP source
DPDP Act 2023; DPDP Rules 2025 (G.S.R. 846(E))
Banking overlays
RBI KYC Directions 2025; PMLA; RBI Outsourcing 2025; RBI Cyber Framework 2026
Reviewed
7 September 2026

What does the DPDP Act mean for banks?

The DPDP Act, 2023 governs the processing of digital personal data. For a bank, that covers most of the customer-data lifecycle, but the Act permits processing on only two kinds of route: consent under Section 6, or one of the enumerated Section 7 legitimate uses. There is no general "legal obligation" or "contractual necessity" basis of the kind found in some other regimes. A bank’s RBI or PMLA duty to perform an activity explains why the activity happens; it does not by itself supply the DPDP route, which must still be found in Section 6 or Section 7. Some banking activities map cleanly (for example, mandatory reporting to the State under Section 7(d)); several do not, and for those the correct answer is activity-specific analysis rather than an assumed basis. The core obligations are scheduled to commence on 13 May 2027.

What changes for banks

  • Map every customer-data purpose to a specific DPDP route (Section 6 consent, or a named Section 7 legitimate use) rather than to a generic "we are allowed to" assumption.
  • Issue Section 5 notices for processing where consent is the route, in clear language and the required Eighth Schedule options.
  • Build a consent architecture only for the purposes that genuinely rest on Section 6, such as optional marketing and profiling, kept separate from account terms.
  • Reconcile DPDP with the RBI KYC Directions 2025 and PMLA, treating the regulatory duty and the DPDP route as separate questions.
  • Stand up Data Principal rights and grievance workflows alongside the RBI Responsible Business Conduct grievance machinery.
  • Govern processors and outsourced providers under the RBI Outsourcing Directions 2025 and DPDP Section 8(2), by contract.
  • Reconcile the DPDP erasure right with mandatory RBI and PMLA retention, which continues to apply after a customer withdraws consent.
  • Align breach response with both DPDP breach duties and the RBI Cyber Framework Directions 2026 incident-reporting requirements.

Where banks process personal data

The customer-data lifecycle is wider for a bank than for most sectors. Each stage may carry a different DPDP analysis.

01ProspectAcquisition, marketing lists
02OnboardingApplication, contact data
03KYC / CDDIdentity, PAN, OVDs
04AccountDeposits, mandates
05TransactionsPayments, cards, UPI
06Digital channelsNet, mobile banking
07LendingCredit, bureau checks
08ServicingSupport, requests
09Fraud / securityMonitoring, controls
10MarketingCross-sell, profiling
11CollectionsRecovery
12ReportingRBI, FIU-IND
13RetentionRecords, archival
14ClosureExit, deletion

Banking activity and DPDP analysis

The core asset of this page. The DPDP route is the question of which Section 4 path may permit the processing. The RBI or statutory overlay is why the activity happens, kept separate. Support level uses four grades.

Statutory text what the provision expressly says Strong facts closely fit the text Interpretive plausible, not expressly resolved Uncertain no clean Section 6 or 7 answer

Scroll the table sideways on a narrow screen.

ActivityDPDP Section 4 route to assessRBI / statutory driverConsent (S6) issueSupport
Prospect / unsolicited marketingSection 6 consent (distinct optional purpose)—Unbundled opt-inStrong
Customer initiates an account or serviceSection 7(a) voluntary provision for the specified purposeBanking Regulation ActExcess data onlyInterpretive
Mandatory KYC / CDD field collectionSection 7(a) may be relevant; whether precondition data is "voluntarily provided" is openRBI KYC Directions 2025; PMLANot the organising basisUncertain
Identity verification (V-CIP, OVD, CKYCR)Section 7(a) for the step; CKYCR reliance is RBI-definedRBI KYC Directions 2025 (para 65)—Interpretive
Beneficial-owner verificationThird-party data; route not expressly resolvedPMLA; KYC Directions 2025—Uncertain
Sanctions / PEP screeningPreparatory risk processing; no clean clause until reportingKYC Directions 2025; UAPA lists—Uncertain
Internal transaction monitoring (AML detection)Not Section 7(d) by itself; preparatory processingPMLA; KYC Directions 2025—Uncertain
STR / CTR to FIU-INDSection 7(d) disclosure to the State required by lawPMLA; PML Rules 2005NoStrong
Deposits, payments, cards executionSection 7(a) voluntary provision for the requested serviceRBI; NPCIValue-adds onlyInterpretive
Net / mobile banking deliverySection 7(a) for the requested channelRBI Digital Payment Security 2026—Interpretive
Fraud prevention / security monitoringNo clean clause; the RBI mandate does not itself create a DPDP basisRBI Cyber Framework 2026; fraud-liability 2026—Uncertain
Reuse of KYC / customer data for a new purposeA new purpose needs its own route; often Section 6KYC Directions 2025 (purpose limitation)LikelyStrong (a basis is needed)
Marketing / cross-sell / profilingPurpose-specific: optional profiling points to Section 6; customer-requested product information may fit Section 7(a)RBI Responsible Business Conduct 2025OftenPurpose-specific
Collections / recoveryRoute not expressly resolvedRBI DLD 2025 (digital lending)—Uncertain
Account Aggregator flowsAA consent artefact (RBI); must be tested separately against Section 6, not assumed to satisfy itRBI NBFC-AA frameworkDistinct mechanicInterpretive
RBI regulatory returnsSection 7(d) disclosure to a State instrumentalityBanking Regulation Act; RBINoStrong
Retention vs erasure requestLaw-mandated retention continues after withdrawal (Section 6(6) carve-out)PMLA; RBI record rulesWithdrawal is not deletionStrong

Several rows are marked Uncertain on purpose. The Act does not expressly resolve those fact patterns as of 7 September 2026, and manufacturing a basis would be worse than naming the gap. Treat those as items for activity-specific legal analysis, documented, before commencement.

Does a bank need DPDP consent for KYC?

Not as a default, and the reasoning matters. KYC is performed to meet the RBI (Commercial Banks — Know Your Customer) Directions, 2025 and the PMLA. That is why the bank collects the data. It is a separate question which DPDP route permits the processing.

RBI The RBI KYC Directions 2025 (which replaced the 2016 Master Direction) and the PMLA require customer due diligence, identity verification and record-keeping. These are regulatory duties on the bank.

Law Under the DPDP Act, the regulatory duty does not itself create a lawful basis. The route must be found in Section 6 or Section 7. Section 7(a) may be relevant where a customer voluntarily provides personal data for the specified purpose of obtaining a requested banking service. Whether all mandatory KYC collection satisfies the "voluntarily provided" condition, given that KYC is a precondition to the relationship, requires activity-specific analysis. Fresh Section 6 consent is generally not the organising basis for the KYC obligation itself.

Practice Keep three questions separate: why RBI or PMLA requires the collection; which DPDP Section 4 route permits it; and whether any reuse of KYC data for an unrelated purpose (for example marketing) needs its own Section 6 consent. The last one usually does, and it cannot be folded into onboarding.

Section 6 vs Section 7 for banks

An orientation tool. Actual processing must be analysed against the exact statutory facts, not this flow.

What is the exact processing purpose?
↓
Does an enumerated Section 7 situation apply (7(a) voluntary provision, 7(d) disclosure to the State, and so on)?
↓
Yes → analyse that exact clause
Confirm the facts fit the specific wording. No balancing test, but necessity still applies.
No → assess Section 6
If consent is the route: Section 5 notice, then valid consent, proof and withdrawal.

There is no open "legitimate interest" ground. If a purpose fits neither Section 6 nor a Section 7 clause, the workflow needs redesigning, not a label. See the Consent vs Certain Legitimate Uses guide and Section 7.

DPDP and RBI crosswalk

Where the two frameworks meet. They are analysed separately; one does not satisfy the other.

IssueDPDP frameworkRBI / banking frameworkWhat the bank reconciles
NoticeSection 5 notice where consent is the routeFair-practice disclosures under Responsible Business Conduct 2025One customer-facing notice set that satisfies both
KYCRoute assessed under Section 6 or 7Mandatory CDD under KYC Directions 2025 and PMLARegulatory duty vs DPDP route kept distinct
Reporting to the StateSection 7(d)STR/CTR to FIU-IND; returns to RBIDocument the disclosure route
Outsourcing / vendorsProcessor by contract, Section 8(2)Bank stays accountable, Outsourcing Directions 2025One contract meeting both control regimes
SecurityReasonable security safeguards, Section 8Cyber Framework Directions 2026 (monitoring, VAPT, logging)Controls evidence serving both
Breach / incidentDPDP breach dutiesRBI incident reporting under the 2026 frameworkA single incident runbook, two reporting paths
RetentionErasure right, Section 6(6) carve-out for lawMandatory record retention under PMLA and RBIRetention schedule that overrides erasure where law requires
GrievanceData Principal grievance and Board escalationGrievance redressal under Responsible Business Conduct 2025One intake, correct routing

Customer confidentiality and secondary use

A bank’s duty of confidentiality over customer information sits alongside DPDP, not inside it. Information obtained to provide a banking service, to meet a regulatory duty, or to service the relationship is a different question from reusing that information for an unrelated purpose or disclosing it to an external party.

The practical rule is purpose discipline. Data collected for the requested service or for a regulatory duty should not be repurposed for marketing, cross-sell or external sharing without testing a fresh DPDP route for that new purpose, and without checking the RBI confidentiality and fair-conduct position under the Responsible Business Conduct Directions 2025.

Digital lending by banks

Banks are also regulated entities under the RBI Digital Lending Directions, 2025 where they lend through digital channels or lending service providers. Those requirements (borrower consent for data access, device-permission limits, the lender staying liable for the app’s conduct) are RBI requirements and should be analysed separately from general banking data processing, with the DPDP route tested for each lending purpose.

The detailed build sequence lives elsewhere. See the DPDP and RBI digital lending implementation and the digital lending overview. This page does not duplicate them.

Account Aggregator and financial-data sharing

Where a bank participates in the RBI Account Aggregator ecosystem as a Financial Information Provider or User, sharing runs on a standardised, RBI-prescribed consent artefact, with revocation and logging built into the framework. That artefact is an RBI mechanic.

Law An RBI Account Aggregator consent artefact should not be assumed to satisfy DPDP Section 6 on its own. The two consent constructs serve different frameworks; where consent is the DPDP route for a given flow, the Section 6 requirements are tested separately. Account Aggregators may warrant their own dedicated treatment; this page keeps the point concise.

Vendors and processors

A vendor is not automatically a Data Processor. The role turns on the processing relationship under the Act, not the label.

Core banking (CBS)
Cloud
KYC / V-CIP vendor
CRM
Contact centre
Payments / switch
Analytics
Fraud tools
Marketing tech
Collections agency
Communications
LSP / DLA

Ask three questions of each: who determines the purpose and means of the processing; what the contract says about acting on the bank’s instructions; and whether the provider processes for its own purposes. Under DPDP Section 8(2) a Data Processor acts under a valid contract, and under the RBI Outsourcing Directions 2025 the bank remains accountable for the outsourced activity regardless.

Consent withdrawal in banking

Only for processing that actually rests on Section 6. Withdrawing marketing consent does not unwind a loan, close an account, or delete records the bank must retain by law.

Practice Withdrawal request → identify the affected consent-based purpose → suppress that processing internally → update the customer preference → instruct relevant processors → preserve any processing required or authorised by law → retain evidence of the withdrawal. See the Consent withdrawal guide.

Retention vs erasure

DPDP gives Data Principals an erasure right, but Section 6(6) preserves processing that is required or authorised by law. Banks are required by the PMLA and RBI rules to retain KYC and transaction records for defined periods. That retention continues after a customer withdraws consent or asks for erasure.

Law Withdrawal and erasure apply to processing that has no independent legal footing. They do not override a statutory retention duty. The correct design is a retention schedule that maps each data category to its mandatory period and releases the data only when no legal duty remains.

Implementation roadmap

Sequenced work before the 13 May 2027 commencement.

Foundations
  • Governance and DPO scoping
  • Processing inventory across the lifecycle
  • Purpose to Section 4 route mapping
Design
  • Section 5 notices
  • Consent architecture for Section 6 purposes
  • Rights and grievance workflows
Controls
  • Processor contracts, Section 8(2) plus Outsourcing 2025
  • Retention schedule vs PMLA and RBI
  • Security and breach runbook with the Cyber Framework 2026
Evidence
  • Consent and notice records
  • Legal-basis analysis documented, including the uncertain items
  • Audit trail across systems
Vendors
  • Role classification, Fiduciary vs Processor
  • Remediation of CBS, cloud, KYC and marketing stacks
Test
  • Rights request drill
  • Withdrawal propagation test
  • Breach simulation across both reporting paths

Which rule applies

InstrumentWhat it governs hereStatus
DPDP Act, 2023Lawful route (Section 6 / 7), notice, rights, security, breachCore obligations scheduled 13 May 2027
DPDP Rules, 2025Operational detail, Consent Manager frameworkG.S.R. 846(E); phased
RBI (Commercial Banks — KYC) Directions, 2025CDD, verification, CKYCR, retention of KYC recordsNo. 169, 28 Nov 2025 (upd 29 Dec 2025); replaced 2016 MD
PMLA 2002 and PML Rules 2005KYC obligation, STR/CTR reporting to FIU-INDIn force
RBI (Commercial Banks — Managing Risks in Outsourcing) Directions, 2025Vendor accountability, confidentiality, grievanceNo. 171, 28 Nov 2025
RBI Cyber, Technology Risk, Resilience and Assurance Framework Directions, 2026Security, monitoring, logging, incident response31 Jul 2026, in force; replaced 2016 cyber framework
RBI Digital Lending Directions, 2025Digital lending by banks, LSP conductIn force

No false equivalence: an RBI requirement explains why an activity happens; the DPDP route is a separate question.

Bank readiness checklist

  • Processing inventory complete across the 14 lifecycle stages
  • Each purpose mapped to a Section 6 or named Section 7 route, with uncertain items flagged for legal analysis
  • Section 5 notices drafted for consent-based purposes
  • Consent architecture built only where Section 6 applies, unbundled from account terms
  • KYC reuse for marketing separated and consented under Section 6
  • Retention schedule reconciled with PMLA and RBI record rules
  • Processor contracts updated for Section 8(2) and Outsourcing Directions 2025
  • Breach runbook aligned to DPDP and the RBI Cyber Framework 2026
  • Rights and grievance workflow live and tested
  • Legal-basis analysis documented as auditable evidence

Reconcile DPDP with your banking controls

The readiness check maps where each customer-data purpose stands against the DPDP routes and the RBI overlays, and where the gaps and uncertain bases are.

Frequently asked questions

Does the DPDP Act apply to banks?

Yes. The DPDP Act, 2023 applies to the processing of digital personal data, which covers most of a bank’s customer-data lifecycle. It applies alongside existing RBI and PMLA obligations rather than replacing them. The core obligations are scheduled to commence on 13 May 2027.

Do banks need consent for KYC?

Not as a default. KYC is performed to meet RBI KYC Directions 2025 and PMLA obligations. Under the DPDP Act, Section 7(a) voluntary provision may be relevant, but whether all mandatory KYC collection fits that clause requires activity-specific analysis. The regulatory duty to perform KYC does not itself make Section 6 consent the DPDP basis.

Does every use of customer data require consent?

No. Consent under Section 6 is one route. Many banking activities are assessed under a Section 7 legitimate use instead, such as 7(a) voluntary provision for a requested service or 7(d) disclosure to the State. There is no general legitimate-interest ground, so a purpose that fits neither Section 6 nor a Section 7 clause needs to be redesigned.

Can banks use KYC information for marketing?

Not without a separate analysis. Marketing and cross-sell are distinct purposes from the KYC obligation. Reusing KYC or customer-profile data for optional marketing generally requires its own Section 6 consent and cannot be folded into onboarding.

What happens if a customer withdraws consent?

Only processing that actually relied on Section 6 stops. Withdrawal is prospective and does not unwind lawful past processing, close accounts, or delete records the bank must retain under PMLA or RBI rules. The bank suppresses the consent-based processing, instructs relevant processors, and preserves anything required by law.

How do DPDP rules interact with RBI Digital Lending requirements?

They are separate. The RBI Digital Lending Directions 2025 set borrower-consent, device-permission and lender-liability requirements. The DPDP route for each lending purpose is assessed on its own under Section 6 or 7. One does not satisfy the other.

Are banks Data Fiduciaries?

For most customer-facing processing a bank determines the purpose and means, which makes it a Data Fiduciary. But the same bank can be a Data Processor for data it handles on another organisation’s behalf, and its vendors are not automatically Processors. Role depends on the processing relationship, not the label.

What should banks record to prove consent?

Where Section 6 applies, keep a reconstructable record of each consent event: identity, purpose, notice version, consent wording, the affirmative action, timestamp, channel, current state and withdrawal history. The Act sets the proof burden but does not prescribe a schema.

When do the DPDP obligations apply to banks?

The Act is notified but not yet in force. The core obligations are scheduled to commence on 13 May 2027, with Consent Manager registration from 13 November 2026, under the phased commencement of the DPDP Rules 2025. Dates should be confirmed against the current official notification.

Primary sources

Digital Personal Data Protection Act, 2023
MeitY, Gazette of India
Sections 4 to 8: lawful routes, notice, consent, legitimate uses, obligations. Official text (PDF)
Digital Personal Data Protection Rules, 2025
MeitY, G.S.R. 846(E), 13 November 2025
Operational detail and phased commencement; core obligations scheduled 13 May 2027.
RBI (Commercial Banks — Know Your Customer) Directions, 2025
RBI/DOR/2025-26/169, 28 Nov 2025 (updated 29 Dec 2025)
Entity-specific KYC framework; replaced the 2016 KYC Master Direction.
RBI (Commercial Banks — Managing Risks in Outsourcing) Directions, 2025
RBI/DOR/2025-26/171, 28 Nov 2025
Vendor accountability, confidentiality and grievance; bank remains responsible.
RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
RBI, 31 July 2026, in force
Security, monitoring, logging and incident response; replaced the 2016 cyber framework.
PMLA 2002 and PML (Maintenance of Records) Rules 2005
Government of India
KYC obligation and mandatory reporting to FIU-IND (STR/CTR).

This page is legal information about the DPDP Act, 2023 as it applies to banks, not legal advice. Several banking fact patterns are not expressly resolved by the Act as of 7 September 2026 and are marked for activity-specific analysis. Statutory provisions, commencement dates and the current RBI Directions should be confirmed against official Government and RBI sources before you rely on them. Reviewed 7 September 2026.