Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Fintech & Banking · Digital Lending

The DPDP Act for Digital Lending

For banks, NBFCs, LSPs and loan apps, the Act reshapes consent, data collection and vendor liability across the lending workflow.

In short

The DPDP Act reshapes digital lending around clear, purpose-specific consent, strict data minimization, and borrower rights. Lenders must separate loan-underwriting consent from marketing, halt excessive device-data harvesting, and face penalties up to ₹250 crore for misuse or breaches.

Core impacts

What changes for this sub-sector.

Consent architecture

An RBI Key Fact Statement is not a DPDP notice. Consent must be granular, affirmative and easy to withdraw, for each specific purpose.

Data minimization

Lenders cannot harvest contacts, media files or call logs beyond strict, one-time KYC needs, in line with RBI limits.

Third-party and vendor oversight

Lending apps (LSPs) and outsourced recovery agents act as processors. If they mishandle data, liability lands on the lender.

Borrower rights

Borrowers can access and correct their profiles, and request erasure once mandatory RBI and tax retention periods have lapsed.

Breach and incident reporting

Run parallel reporting: notify the RBI or CERT-In and the Data Protection Board during a security event.

Go deeper

Niche guides for this area, each naming the specific regulation.

Check your lending flow.

The readiness check surfaces consent-splitting, device-data and vendor-liability gaps.

Take the readiness check →