Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Fintech & Banking

The DPDP Act for Fintech & Banking

What the Act means for banks, NBFCs and fintechs, and how it sits on top of your existing RBI and NPCI obligations.

Running an NBFC? NBFCs must satisfy the DPDP Act and RBI digital-lending, KYC/PMLA and CERT-In duties at once. See the dedicated DPDP compliance guide for NBFCs for the RBI crosswalk, KYC retention rules, LSP governance and the multi-regulator breach matrix.

In short

Most banks, NBFCs and fintechs are Data Fiduciaries under the DPDP Act, though the same entity can be a Data Processor when it handles data on another organisation’s behalf. Each purpose needs its own lawful basis: consent under Section 6, or a Section 7 legitimate use such as a customer-requested service or a legal obligation. Collect only what a purpose needs, honour customer rights and report breaches, while continuing to meet RBI and NPCI requirements. The core obligations are scheduled to commence on 13 May 2027; penalties can reach ₹250 crore.

What the Act asks of you

The obligations that shape compliance in this sector.

Consent and notice

Give a plain-language notice and take clear, purpose-specific consent before processing customer data.

Data minimization

Collect only what a product or transaction needs, nothing extra from the device.

Security safeguards

Put reasonable technical and organisational safeguards around financial records.

Breach reporting

Report personal-data breaches to affected users and the Board without delay.

Customer rights

Let customers access, correct and erase their data, and offer grievance redressal.

Dual compliance

The Act runs alongside RBI and NPCI rules, including localization; it does not replace them.

See where you stand.

Run the free readiness check for a sector-specific gap report.

Understand. Check. Connect.

We match you with the right DPDP implementation partner, only when you ask.

Take the readiness check →