What the Act means for banks, NBFCs and fintechs, and how it sits on top of your existing RBI and NPCI obligations.
In short
Every bank, NBFC and fintech is a Data Fiduciary under the DPDP Act. You must take clear consent, collect only the data you need, secure financial records, honour customer rights, and report breaches, all while continuing to meet RBI and NPCI rules. Penalties reach ₹250 crore.
The obligations that shape compliance in this sector.
Give a plain-language notice and take clear, purpose-specific consent before processing customer data.
Collect only what a product or transaction needs, nothing extra from the device.
Put reasonable technical and organisational safeguards around financial records.
Report personal-data breaches to affected users and the Board without delay.
Let customers access, correct and erase their data, and offer grievance redressal.
The Act runs alongside RBI and NPCI rules, including localization; it does not replace them.
Each sub-sector has its own data flows and its own version of the rules.
Wherever you are, start there and move through to a certifiable posture.
Run the free readiness check for a sector-specific gap report.
Take the readiness check →