Readiness assessment
Fintech & Banking

The DPDP Act for Fintech & Banking

What the Act means for banks, NBFCs and fintechs, and how it sits on top of your existing RBI and NPCI obligations.

In short

Every bank, NBFC and fintech is a Data Fiduciary under the DPDP Act. You must take clear consent, collect only the data you need, secure financial records, honour customer rights, and report breaches, all while continuing to meet RBI and NPCI rules. Penalties reach ₹250 crore.

What the Act asks of you

The obligations that shape compliance in this sector.

Consent and notice

Give a plain-language notice and take clear, purpose-specific consent before processing customer data.

Data minimization

Collect only what a product or transaction needs, nothing extra from the device.

Security safeguards

Put reasonable technical and organisational safeguards around financial records.

Breach reporting

Report personal-data breaches to affected users and the Board without delay.

Customer rights

Let customers access, correct and erase their data, and offer grievance redressal.

Dual compliance

The Act runs alongside RBI and NPCI rules, including localization; it does not replace them.

See where you stand.

Run the free readiness check for a sector-specific gap report.

Take the readiness check