Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
DPDP Act × RBI Compliance

DPDP Compliance for NBFCs in India

How Non-Banking Financial Companies reconcile the Digital Personal Data Protection Act, 2023 with the RBI, KYC/PMLA, digital-lending and cybersecurity obligations that continue to apply alongside it.

Direct answer

The DPDP Act governs an NBFC's processing of digital personal data and applies in addition to, not in place of, RBI, PMLA/KYC, CERT-In and outsourcing rules (DPDP Act, s.38). Its main operational duties are scheduled to commence on 13 May 2027, though some institutional provisions began on 13 November 2025. The priorities are notice and lawful-basis mapping, consent where it is the basis, Data Principal rights and grievance handling, retention aligned to KYC law, processor and LSP governance, security safeguards and breach readiness. An NBFC is not automatically a Significant Data Fiduciary.

Now · since 13 Nov 2025
Institutional provisions
Early institutional provisions of the DPDP Act commenced on 13 November 2025. RBI, PMLA/KYC and CERT-In duties already apply now.
Deadline · 13 May 2027
Data Fiduciary duties
The main Data Fiduciary duties and most operative DPDP Rules are scheduled to commence. Last reviewed August 2026.

The practical question for an NBFC is not whether the DPDP Act applies — it does, to the extent you process digital personal data — but how to run it alongside the RBI, PMLA/KYC and CERT-In obligations that continue to apply under Section 38.

Last updated: 31 August 2026  ·  Primary authorities reviewed: DPDP Act · DPDP Rules · RBI · PMLA/KYC · CERT-In

Does the DPDP Act apply to NBFCs?

Quick answer

Yes, to the extent an NBFC processes digital personal data. An NBFC will ordinarily act as a Data Fiduciary for borrower and customer personal data, because it determines why and how that data is processed. The DPDP Act applies in addition to RBI, PMLA/KYC and other sector rules, which are not displaced (DPDP Act, s.38).

The Digital Personal Data Protection Act, 2023 regulates the processing of digital personal data. An NBFC that decides the purpose and means of processing borrower or customer data is a Data Fiduciary for that processing, and carries the Act's primary duties: lawful basis, notice, security, retention limits, rights and grievance handling.

Classification is activity-specific, not entity-wide. Third parties involved in lending, KYC, collections, cloud hosting or distribution may be Data Processors acting on the NBFC's instructions, independent Data Fiduciaries determining their own purposes, or separately regulated entities. The Act's role definitions turn on that factual analysis, not on the label used in a contract.

DPDP does not switch off existing obligations: RBI directions on KYC, digital lending, outsourcing and cyber incidents, and the recordkeeping duties under the Prevention of Money Laundering Act, continue to apply alongside it. How the two frameworks interact under Section 38 is set out in the DPDP × RBI crosswalk below.

Common mistake

Reading "DPDP applies to NBFCs" as "every NBFC activity now needs fresh DPDP consent." Applicability is not a single lawful basis; much NBFC processing continues under existing law with DPDP obligations layered over it.

The four frameworks an NBFC must satisfy at once

NBFC personaldata processing DPDP ActNotice, basis, rights,security, breach, retention RBI directionsDigital lending, KYC,outsourcing, conduct PMLA / KYCFive-year recordkeepingand retention baselines CERT-InSix-hour incidentreporting (if covered)

Under s.38, the DPDP Act applies in addition to, not in place of, the sector frameworks.

What is the DPDP compliance deadline for NBFCs?

Quick answer

There is no single "DPDP deadline." Commencement is phased: institutional provisions (Sections 18–26) began on 13 November 2025; Consent Manager registration provisions begin on 13 November 2026; and the main Data Fiduciary duties and most operative Rules are scheduled to commence on 13 May 2027. Existing RBI, PMLA/KYC and CERT-In duties already apply now.

Plan against the operating model that must be ready by 13 May 2027, notice, lawful basis, rights, grievance, security, breach response, processor contracts, retention and (if notified) SDF duties, while recognising that many privacy-adjacent obligations are already live under sector law.

NBFC DPDP implementation timeline
DateRegulatory eventWhat NBFCs should have completed
13 Nov 2025Sections 18–26 in force DPDP ActAwareness of the Board framework; begin the processing inventory and gap review.
13 Nov 2026Section 6(9), 27(1)(d), Rule 4 DPDP RulesDecide whether Consent Manager arrangements are relevant; design consent capture and records.
13 May 2027Main Data Fiduciary duties; Rules 3, 5–16 DPDP Act DPDP RulesOperating model live: notice, lawful-basis mapping, rights and grievance, security safeguards, breach runbook, processor contracts, retention/erasure, children's-data controls, and SDF duties if notified.
Review required

The exact commencement instruments (Gazette notification G.S.R. 843(E) and DPDP Rules, Rule 1(2)) should be checked against the current MeitY text before any dated public claim, and any provision-specific change after 31 August 2026 confirmed.

Not sure where your NBFC stands?

Map your DPDP obligations against RBI, KYC and digital-lending rules in about 10 minutes.

Check your DPDP readiness

Where personal data enters an NBFC: the borrower lifecycle

Personal data enters an NBFC at every stage of the loan, and each stage carries a different privacy risk and a different regulatory overlay. Mapping the lifecycle is the fastest way to see where DPDP duties, RBI rules and KYC retention actually bite.

NBFC borrower-data lifecycle
Lifecycle stageTypical personal dataMain privacy riskApplicable overlayPriority control
LeadName, mobile, email, campaign/ad sourceMarketing use without a clear basis; lead provenanceRBI conduct/communicationsSeparate enquiry from marketing consent; lead-source register
ApplicationIdentity, address, income, employment, bank, declarationsOver-collection; unclear lawful basis; retentionRBI KYC/DLD PMLAField-by-field purpose review; application data dictionary
KYC / CKYCPAN, ID documents, photo, address, customer IDAssuming a single "consent" basis; excess collectionRBI KYC PMLALegal-basis register per field; access restriction; retention lock
UnderwritingBureau, bank, income, device, alternative dataPurpose creep; accuracy; automated decisionsRBI credit/DLDInput allow-list; model governance; human escalation; decision evidence
Approval / KFSDecision data, Key Fact Statement acknowledgementPrivacy notice buried inside loan termsRBI KFS/DLDKeep privacy notice separate from the loan agreement and KFS
DisbursementBank details, loan account, transaction dataThird-party processing; storage locationRBI DLD/payment (where applicable)Payment-data segregation; India-storage analysis in the DLD context
ServicingAccount, repayment, communications, complaintsService vs marketing purpose separation; rightsRBI conduct/KYC refreshRole-based access; channel-preference management
CollectionsContact, repayment status, field/call notesExcessive disclosure; harassment riskRBI recovery/fair-practicesNeed-to-know data packs; no contact-list misuse; agent monitoring
ClosureIdentity, loan and repayment records, NOCErasure request vs statutory retentionRBI KYC PMLAClosure-triggered retention clock; segregated archive; marketing suppression
Retention / DeletionRecords under statutory retention or legal holdDeleting records a law requires kept, or keeping data with no basisPMLA/KYC DPDP s.8(7)Retention schedule by authority; delete non-required data; legal-hold override

Not every NBFC uses every stage or data category; treat this as a mapping template, not a claim about a specific lender.

DPDP Act vs RBI requirements for NBFCs

How does the DPDP Act interact with RBI requirements for NBFCs?

They operate concurrently. An NBFC generally has to satisfy both frameworks; RBI obligations are not displaced by the DPDP Act. DPDP s.8(7) expressly accommodates retention required by other laws, and DPDP s.38 states the Act applies in addition to and not in derogation of other laws. Only where an actual conflict exists does s.38(2) make DPDP prevail, and then only to the extent of that conflict. Most differences between RBI and DPDP are not conflicts.

DPDP and RBI often regulate the same processing for different reasons: DPDP for personal-data protection, RBI for prudential, conduct and financial-integrity purposes. The crosswalk below maps common issues, and names which regulator creates each obligation. RBI Digital Lending Directions apply to digital-lending activity, not to every NBFC operation.

How the layers stack

DPDP Act — personal-data layerApplies across every activity below s.38 · in addition to SECTOR FRAMEWORKS — CONTINUE TO APPLY RBI PMLA / KYC CERT-In
DPDP × RBI compliance crosswalk
Processing issueDPDP positionRBI / other positionPractical NBFC controlAuthority
NoticeClear notice for processing, once Rules operativeDigital lending: DLA/LSP must publish a privacy policyKeep the DPDP notice separate from the loan agreementRule 3 RBI DLD
ConsentWhere consent is the basis, meet the s.6 conditionsDigital lending: prior and explicit borrower consent with audit trail for DLA data collectionBuild a consent record meeting RBI's requirement; separately confirm the DPDP basiss.6 RBI DLD
Contacts, call logs, filesNo DPDP list of prohibited phone permissionsDigital lending: DLAs must not access contacts, call logs, files/media or telephony functionsTechnically block these permissions in the DLA; verify SDKs and third-party codeRBI DLD
Camera, microphone, locationLawful, purpose-limited processing; no general one-time-access ruleDigital lending: one-time access only where necessary for onboarding/KYC, with explicit consentJust-in-time permission screens; no background or persistent accessRBI DLD
LSP data storageFiduciary is responsible for processing carried out by a processorDigital lending: LSP may store only minimal borrower data per the NBFC–LSP agreementDocument permitted fields, location, retention and deletion; prohibit shadow databasess.8 RBI DLD
India storageNo general localisation; s.16 permits transfer unless restrictedDigital lending: DLA/LSP data on servers in India; payment-system rules where the entity/activity is coveredMap production, backups, logs, support and sub-processors; attest the architectures.16 RBI DLD
KYC retentions.8(7) permits retention necessary for compliance with lawRBI KYC / PMLA: five-year retention baselinesRetention schedule by authority; restrict access to retained recordss.8(7) RBI KYC/PMLA
Grievance handlingEffective grievance mechanism and a published contactRBI borrower grievance and escalation frameworkKeep DPDP privacy grievances and RBI lending grievances distinguishable but coordinateds.8, s.13 RBI
Recovery conductPurpose and security constraints on processingRBI recovery-agent and fair-practices expectationsMinimise shared data; prohibit contact-list misuse; monitor agentss.8 RBI
SecurityReasonable security safeguards; Rule 6 detail once operativeRBI outsourcing / IT / cyber standardsMap each control to its source; do not claim a control is DPDP-mandated when it is good practices.8(5) Rule 6 RBI
Breach reportingNotify Board and affected persons once Rule 7 operativeCERT-In 6-hour reporting for covered incidents; RBI reporting in outsourcing/cyber contextsOne runbook with a separate clock per regulatorRule 7 CERT-In RBI
Cross-sellingSeparate purpose; consent and withdrawal where consent is relied onRBI conduct and fair-practice requirementsSeparate opt-in; no coercive bundling; propagate withdrawal downstreams.4, 6, 8 RBI
Common mistake

Attributing RBI's device-permission and India-storage rules to the DPDP Act. Those are RBI Digital Lending Directions requirements that apply to digital-lending activity. The DPDP Act does not itself prohibit an app from accessing contacts or mandate India-only storage.

Which rule applies? An NBFC privacy decision table

A fast reference for the situations NBFC teams meet most often. It shows which framework drives each obligation, so responsibility is assigned to the correct regulator rather than defaulting everything to "DPDP."

Which rule applies? — NBFC privacy decision table
SituationDPDP ActRBIPMLA/KYCCERT-InWhat the NBFC should do
Collecting borrower KYCLawful basis via s.4/s.7; notice—Required due diligence and records—Map the DPDP basis (often s.7, not consent); keep records per PMLA/KYC
Loan-app device permissionsLawful, purpose-limited onlyProhibits contacts/logs/files; one-time cam/mic/location——Follow RBI DLD in the DLA; DPDP does not create these permission rules
Credit underwritingPurpose limit; accuracy; automated-decision governanceCredit / digital-lending rules——Allow-list inputs; document decisions; enable correction
LSP receives borrower dataFiduciary stays responsible (s.8)LSP oversight and minimal storage (digital lending)——Assess the role; contract and audit; do not assume "processor" automatically
Marketing / cross-sellingSeparate purpose; consent and withdrawalConduct / fair-practice——Separate opt-in; suppress on withdrawal
Borrower requests erasureErase when purpose ends, unless law requires retention (s.8(7))—Five-year retention may apply—Delete non-required data; retain and restrict what a law requires
Loan closesRe-evaluate retention under s.8(7)—Retention clock starts—Start the closure retention clock; suppress marketing; archive the minimum
Security incidentReasonable-safeguards dutyOutsourcing/cyber expectations—6-hour report if a covered incidentAssess CERT-In coverage; follow applicable RBI incident expectations
Personal-data breachNotify Board and affected persons (Rule 7)Context-dependent (outsourcing/cyber)—6-hour if coveredRun every applicable clock in parallel; one deadline does not cover all
Overseas cloud / vendors.16 transfer unless restrictedIndia storage (digital lending); payment rules if covered——Localisation analysis by workload; DPA and sub-processor controls

Can an NBFC delete KYC data when a customer asks?

Quick answer

No, not where a law requires the data to be kept. DPDP s.8(7) requires erasure when consent is withdrawn or the purpose is served, unless retention is necessary for compliance with law. RBI KYC Directions require transaction records for at least five years from the transaction date, and customer-identification and address records for at least five years after the business relationship ends. Retained data should be access-restricted and not repurposed; non-required data should be deleted.

Erasure request — what to do

Erasure request /purpose ended Law requiresretention? Yes Retain minimum;restrict access;log basis & period No Purpose stillserved? Yes Retain for purpose No Delete / de-identify
NBFC retention decision matrix
RecordWhy retainedLegal / regulatory basisMinimum / required periodDPDP treatment after purpose ends
Transaction recordsReconstruct transactions; AMLRBI KYC para 46(a); PMLA≥ 5 years from transaction dateRetain under s.8(7); restrict access
Identity / address recordsCustomer due diligenceRBI KYC para 46(b); PMLA≥ 5 years after relationship endsDo not delete solely on an erasure request while the clock runs
PAN / ID documents / photosIdentificationRBI KYC; PMLAWithin identity-record analysisRestrict; never repurpose for marketing
Loan agreement / repayment evidenceContract, limitation, tax, litigationPMLA + limitation/tax/contractData-by-data scheduleMap each category to an authority; no single "financial data" bucket
Credit-bureau enquiry / reportUnderwriting, audit, disputeCICRA/CIC + contractPurpose / necessity basedKeep enough for audit and dispute; not indefinite by default
Account Aggregator dataConsented underwriting/servicingRBI AA framework + s.8(7)Consent + legal retentionNo reuse beyond the consented purpose
Marketing preferences / consent evidenceHonour withdrawalDPDP (no PMLA rule)Minimal do-not-contact tokenDelete after a defensible period; keep only the suppression token
Device / behavioural / analyticsFraud, security, analyticsDPDP s.8(7) + designShort unless fraud/legal basisDelete when the purpose ends and no hold applies
Quotable

DPDP erasure does not require deleting records that another law requires the NBFC to retain. Retain only what the law requires, restrict access and reuse, document the basis and period, and delete or irreversibly de-identify the rest once no continuing purpose or legal obligation exists.

Outdated-content warning

Older sources may state a ten-year KYC/PMLA retention period. The current RBI KYC baseline is five years as described above; validate against the consolidated RBI KYC Directions and PML Rules current for your NBFC category before publishing a period.

Who is responsible for personal data handled by an LSP or DSA?

Who is liable if an LSP leaks borrower data?

The NBFC remains responsible. Under DPDP, a Data Fiduciary is responsible for processing carried out on its behalf by a Data Processor, so contractual recovery from an LSP does not remove the NBFC's regulatory exposure. RBI's digital-lending and outsourcing directions also place independent oversight duties on the NBFC. Whether a given party is a processor, an independent Data Fiduciary, or a separately regulated entity depends on what it actually determines and does, not on the label in a contract.

Do not classify every counterparty as a processor. Role follows function: some parties process only on the NBFC's instructions, others determine their own purposes, and some are separately regulated.

LSP / DSA / vendor role and governance
Third partyLikely DPDP roleKey riskRequired NBFC governance
NBFCData Fiduciary (usually)Owns the lending journeyFull programme: basis, notice, rights, security, breach, contracts
Lending Service ProviderProcessor or independent FiduciaryReuse or independent decisions change the roleRole assessment; DLD minimal-storage terms; audit and access controls
DSAProcessor, Fiduciary, or bothMay source and use leads independentlyLead provenance; permitted-use terms; no unauthorised reuse
Recovery agencyUsually processorAccesses debtor dataMinimum data pack; conduct rules; call/field monitoring; deletion on assignment end
Cloud / SaaS providerUsually processorIndependent telemetry, analytics, data locationDPA; sub-processor approval; India-storage review; encryption; exit/deletion
KYC providerProcessor or independent FiduciaryMay run its own regulated servicePurpose restriction; authentication/audit evidence; retention terms
Credit Information CompanyUsually separate/independent FiduciaryHas its own statutory purposesClear notices; lawful sharing; route disputes to the CIC process
Account AggregatorSeparate regulated entityManages consent artefacts and FI-data flowConsent-artefact validation; minimisation; retention limits
Co-lending partnerSeparate or joint FiduciaryMakes independent lending decisionsRole-allocation schedule; rights routing; breach protocol
RBI overlay

RBI outsourcing directions require the NBFC to preserve the confidentiality and security of customer information with providers, restrict access on a need-to-know basis, monitor provider controls, and be told of breaches, with immediate RBI notification for security or confidentiality breaches. Outsourcing does not remove NBFC accountability.

Contract controls (permitted purpose, no reuse, India-storage where DLD applies, MFA/logging, sub-processor approval, incident notice, deletion at termination, audit rights) are implementation controls informed by DPDP processor accountability and RBI oversight, not word-for-word DPDP text.

Are large NBFCs automatically Significant Data Fiduciaries?

Quick answer

No. An NBFC is not automatically a Significant Data Fiduciary because of its size, digital-lending model or use of financial data. SDF status arises only when the Central Government notifies a Data Fiduciary, or a class, after assessing the s.10 factors: volume and sensitivity of data, risks to Data Principals' rights, and risks to sovereignty, electoral democracy, state security and public order. If notified, extra duties apply.

Section 10 lists the factors the Central Government weighs. It does not say all NBFCs, all large NBFCs, or all entities processing financial data are SDFs. Size and financial-data processing may be relevant to a risk assessment, but neither is an automatic trigger.

Once notified, an SDF must appoint an India-based Data Protection Officer answerable to its board, appoint an independent data auditor, and run periodic Data Protection Impact Assessments and audits (at least once every 12 months under Rule 13). A non-SDF Data Fiduciary does not need a statutory DPO, but must publish the contact of a person able to answer questions about its processing (s.8).

Common mistake

Declaring that a particular large NBFC "is" or "will be" an SDF. Use SDF exposure and readiness language; designation is a Central Government decision that has not been made merely because an entity is big or digital.

How should an NBFC implement Data Principal rights?

Handle each request as: DPDP requirement, then regulatory limitation, then operational workflow. Keep DPDP personal-data rights distinct from RBI consumer-grievance routes, even if a single portal collects both.

Data Principal request scenarios
RequestDPDP treatmentRBI / other overlayOperating response
Access to informationProvide a summary of data, processing and recipientsCIC/AA disclosure mechanics may be separateCentral rights workflow; identify categories, purpose and recipients
CorrectionCorrect, complete or updateKYC update; CIC dispute is a separate processVerify; update source systems; notify processors/recipients
Credit-bureau disputeAccuracy request may intersect the CIC processCICRA/CIC dispute mechanismRoute to the formal CIC dispute process; preserve evidence
Erasure during active loanData may remain necessary for servicing and regulationRBI KYC/PMLA; active contractExplain retained categories and basis; delete optional data
Erasure after closureEvaluate each dataset; preserve required recordsFive-year KYC/PMLA baselineArchive the minimum; erase the rest; confirm transparently
GrievanceEffective grievance mechanism requiredRBI grievance/ombudsman may apply independentlySeparate privacy case type; clear escalation pathway
NominationRecognised under DPDPEstate/succession rules affect actual servicingCapture/verify nomination separately from any loan nominee
Withdraw marketing consentStop consent-based marketingService communications may continueSuppress across CRM, SMS, WhatsApp and LSP systems
Withdraw optional app permissionCease optional collection; assess necessityRBI DLD governs permitted permissionsStop optional collection; explain any KYC/onboarding impact

What security safeguards should an NBFC implement for DPDP?

Separate what the law requires from what is good practice. DPDP sets a duty of reasonable security safeguards; the Rules add detail once operative; RBI adds sector controls; and everything else is implementation practice that helps satisfy those duties.

NBFC security requirements by source
RequirementStatus / source
Protect personal data by taking reasonable security safeguards to prevent a breachDPDP s.8(5)
Prescribed safeguards: encryption/masking, access control, logging and monitoring, backups, incident-response, processor-contract safeguardsDPDP Rule 6 (from 13 May 2027)
Notify the Board and affected Data Principals of a breach in the manner/time prescribedDPDP s.8(6) Rule 7
Preserve confidentiality/security with providers; need-to-know access; monitoring; breach disclosureRBI outsourcing
NBFC/LSP technology and cybersecurity standards for digital lendingRBI DLD
Report designated cyber incidents within six hours; retain logsCERT-In
Zero trust, MFA, DLP, red-team testing, tabletop exercises, data classification, independent assuranceImplementation / good practice
Common mistake

Presenting a specific control (for example a named encryption standard or MFA everywhere) as individually mandated by the DPDP Act. The Act requires reasonable safeguards; the specific control is usually a sensible way to meet that duty, not statutory text.

What happens when an NBFC suffers a personal-data breach?

What is the breach-reporting deadline for an NBFC?

There is no single deadline; multiple clocks can run at once. Once DPDP Rule 7 is operative, notify affected Data Principals and the Data Protection Board without delay, with a detailed Board report generally within 72 hours unless extended. CERT-In requires covered cyber incidents within six hours. RBI reporting depends on the applicable outsourcing or cyber direction and the NBFC's category. Run each applicable clock in parallel.

NBFC multi-regulator breach matrix
AuthorityTriggerInitial notificationFollow-upSource
Data Protection Board of IndiaPersonal-data breachWithout delay after becoming awareDetailed report within 72 hours, unless extended by the BoardDPDP Rule 7
Affected Data PrincipalsPersonal-data breachWithout delay, in clear and plain languageOngoing updates as appropriateDPDP Rule 7
CERT-InCovered cyber incidents (Annexure I)Within 6 hours of noticing or being made awareCooperation as sought; retain logs as directedCERT-In Directions 2022
RBISecurity/confidentiality breach; applicable incidentsContext-dependent (outsourcing: immediate; certain directions: a six-hour vendor-to-NBFC escalation)Per the applicable RBI direction and NBFC categoryRBI outsourcing/cyber

There is no single "RBI breach deadline" for every NBFC. The applicable RBI clock depends on the specific instrument and the class or activity of the NBFC.

The breach clocks run in parallel

DPDP: notify affected + Board — without delay Aware (T0) 6hCERT-In (if covered) 72hDPDP detailed report RBI: context-dependent — depends on instrument and NBFC category
Regulatory deadline DPDP notification RBI (varies)

Coordinated response chronology

  • T+0 — Activate incident commander; preserve evidence; isolate affected systems; classify the incident and its DPDP, RBI, CERT-In, payment and vendor implications. Recommended internal target
  • T+1 hour — Obtain preliminary facts from cloud/LSP/DLA/payment/collection vendors; open a regulator-clock tracker; engage legal, security, compliance, operations and communications leads. Recommended internal target
  • T+6 hours — Submit the CERT-In report where an Annexure I incident applies; assess whether an RBI six-hour route applies to your category. Regulatory deadline (CERT-In, if covered)
  • T+24 hours — Refine the affected-data and affected-person analysis; prepare customer and Board notification drafts; preserve logs and chain of custody. Recommended internal target
  • T+72 hours — Provide the detailed DPDP Board report if Rule 7 applies and no extension is granted; submit RBI/CERT-In follow-up material required by the applicable framework. Regulatory deadline (DPDP detailed report)
Review required

Do not publish a universal RBI six-hour external-reporting deadline for every NBFC incident. RBI supports immediate notification for security/confidentiality breaches in outsourcing contexts and a vendor-to-NBFC six-hour escalation in certain directions; confirm the exact clock against your NBFC category and the current RBI instrument.

Does the DPDP Act require NBFC customer data to remain in India?

Quick answer

No. The DPDP Act does not impose general India-only storage. Section 16 permits cross-border transfer unless the Central Government restricts destinations. Separate RBI rules do the localising: the Digital Lending Directions require India-server storage for covered digital-lending data, and the payment-system data direction requires India storage for covered payment-system providers. Applicability turns on the entity and activity, not on being an NBFC.

Localisation and cross-border, by source
QuestionPositionSource
Does DPDP require all NBFC data in India?No; s.16 permits transfer unless the Central Government restricts destinationsDPDP s.16 / Rule 15
Must digital-lending data be stored in India?Yes for covered digital-lending data; an RBI requirement, not a general DPDP ruleRBI DLD
Are payment-system data India-stored?Yes for covered payment-system providers; applicability turns on being such a providerRBI payment-system direction
Can an NBFC use foreign cloud/SaaS?Requires an activity-, data-, role- and regulator-specific analysisAssessment
Do backups, monitoring and support count?Yes; map production, backups, DR, logs, support access, analytics and sub-processorsImplementation
Common mistake

Applying payment-system localisation to an NBFC simply because payments occur during a loan. Payment-system storage rules apply to relevant authorised or approved payment-system providers, and must be assessed against the entity and activity.

DPDP penalties and parallel regulatory exposure

The DPDP Schedule sets different maximum penalties for different failures. A flat "250 crore" figure is wrong: that is the maximum for a security-safeguards failure resulting in a breach, decided by the Board (s.33) after a process, not an automatic fine for any lapse.

DPDP maximum penalties (Schedule)
Failure typeMaximum penaltyNBFC relevanceQualification
Failure to take reasonable security safeguards resulting in a breachUp to ₹250 croreCyber, vendor governance, cloud/DLA/LSP access, breach preventionMaximum, not automatic; the Board determines the penalty
Failure to notify a breachUp to ₹200 croreIncident response and notification readinessApplies to breach-notification failure
Failure re children's dataUp to ₹200 croreWhere the NBFC processes children's dataNot universal to standard adult lending
Failure re SDF additional obligationsUp to ₹150 croreOnly after SDF notificationDoes not apply to all NBFCs
Failure re other Act/Rules provisionsUp to ₹50 croreNotice, rights, grievance, processor obligationsProvision and facts matter
Data Principal breach of dutiesUp to ₹10,000Not central to NBFC exposureDo not use this to discourage complaints

An incident can create parallel exposure under DPDP enforcement, RBI outsourcing/digital-lending/cyber supervision, CERT-In directions, PMLA/KYC duties, payment-system requirements where applicable, and contractual or consumer claims. Compliance with one regulator does not resolve another's requirements.

NBFC DPDP compliance checklist

An operating checklist in eight phases. Each control is labelled by its source so responsibility is assigned to the right framework, and nothing good-practice is mistaken for statutory text.

1. Governance & accountability

  • Assign a privacy owner and board-level reporting line. Implementation
  • Assess SDF exposure against the s.10 factors; do not assume designation. DPDP Act
  • Publish a contact able to answer processing queries. DPDP s.8
  • Appoint an India-based DPO and independent auditor only if notified as an SDF. DPDP s.10

2. Data discovery & mapping

  • Inventory processing across the borrower lifecycle. Implementation
  • Record the lawful basis per activity (s.4 / s.6 / s.7). DPDP Act
  • Map storage and cross-border locations, including backups and support. DPDP s.16 RBI DLD

3. Notice & consent

  • Provide a clear notice, separate from the loan agreement and KFS. DPDP Rule 3
  • Unbundle consent; keep consent records where consent is the basis. DPDP s.6
  • Align app consent and permission flows for digital lending. RBI DLD

4. Rights & grievance

  • Build access, correction, erasure and nomination workflows. DPDP Act
  • Operate an effective grievance mechanism with escalation. DPDP s.8, s.13
  • Route credit-report disputes to the CIC process. CICRA/CIC

5. Retention & erasure

  • Maintain a retention schedule by authority (five-year KYC/PMLA baseline). RBI KYC/PMLA
  • Apply the s.8(7) legal-retention override to erasure requests. DPDP s.8(7)
  • Delete or de-identify non-required data when the purpose ends. DPDP Act

6. Vendors & processors

  • Run a DPDP role assessment for each counterparty. DPDP Act
  • Put processor contracts in place (purpose, security, sub-processors, deletion, audit). DPDP s.8 RBI outsourcing
  • Enforce LSP minimal storage and India storage where DLD applies. RBI DLD

7. Security

  • Implement reasonable security safeguards. DPDP s.8(5)
  • Apply Rule 6 prescribed controls once operative. DPDP Rule 6
  • Meet RBI IT/cyber standards; retain logs and keep six-hour readiness. RBI CERT-In

8. Evidence & breach readiness

  • Maintain a multi-regulator breach runbook with a separate clock per regulator. DPDP Rule 7 CERT-In RBI
  • Run periodic DPIA and audit if notified as an SDF. DPDP Rule 13
  • Keep records and evidence of compliance. Implementation

Download the NBFC DPDP compliance checklist

A printable version of the eight-phase checklist, labelled by DPDP, RBI, PMLA/KYC and CERT-In.

Request the checklist

NBFC DPDP compliance: frequently asked questions

Does the DPDP Act apply to NBFCs?

Yes, to the extent an NBFC processes digital personal data. An NBFC is ordinarily a Data Fiduciary for borrower and customer data because it decides why and how that data is processed, and it carries the Act's duties in addition to RBI, PMLA/KYC and other sector rules (s.38).

Is DPDP compliance mandatory for NBFCs, and by when?

Yes, and it is phased. Institutional provisions began on 13 November 2025 and Consent Manager registration provisions begin on 13 November 2026, but the main Data Fiduciary duties and most operative Rules are scheduled to commence on 13 May 2027. RBI, PMLA/KYC and CERT-In duties already apply now.

Does an NBFC need consent for KYC under DPDP?

Not automatically. KYC is performed because RBI and PMLA require it, so the NBFC should identify the DPDP basis for the specific activity, often a certain legitimate use under s.7 or consent under s.6, rather than assuming consent is the only route. A duty to perform KYC does not by itself create a standalone DPDP lawful basis.

Can an NBFC delete KYC data when a customer requests erasure?

Not where a law requires retention. DPDP s.8(7) requires erasure once consent is withdrawn or the purpose is served, unless retention is necessary for compliance with law. RBI KYC and PMLA require records for at least five years, so the NBFC retains and restricts those records and deletes non-required data.

Does the DPDP Act override RBI requirements?

Generally no. Under s.38 the DPDP Act applies in addition to, not in derogation of, other laws. Both frameworks usually operate together. Only where there is an actual conflict does s.38(2) make DPDP prevail, and then only to the extent of that conflict.

Are large NBFCs automatically Significant Data Fiduciaries?

No. SDF status arises only when the Central Government notifies a Data Fiduciary or class after assessing the s.10 factors. Size, a digital-lending model or the use of financial data may be relevant to that assessment but do not trigger designation automatically.

Does every NBFC need a Data Protection Officer?

No. A DPO is a statutory requirement for a notified SDF, who must appoint an India-based DPO answerable to the board. A non-SDF NBFC does not need a statutory DPO but must publish the contact of a person who can answer questions about its processing.

Is a Lending Service Provider a data processor, and who is liable for an LSP breach?

Not automatically. An LSP may be a processor, an independent Data Fiduciary or another relationship depending on what it decides and does. Either way, the NBFC remains responsible under DPDP for processing carried out on its behalf, and RBI oversight duties also apply.

What is the breach-reporting deadline for an NBFC?

There is no single deadline. DPDP Rule 7 requires notifying affected people and the Board without delay, with a detailed Board report generally within 72 hours unless extended. CERT-In requires covered incidents within six hours. RBI reporting depends on the applicable direction and NBFC category. Run each clock in parallel.

Can a loan app access a borrower's contacts?

For digital lending, RBI's Digital Lending Directions prohibit lending apps from accessing contacts, call logs and files/media, and allow one-time access to camera, microphone or location only where necessary for onboarding or KYC and with consent. This is an RBI requirement; the DPDP Act does not itself create these permission rules.

Must an NBFC store customer data in India?

The DPDP Act does not impose general India-only storage; s.16 permits transfer unless the Central Government restricts destinations. India storage comes from RBI rules: the Digital Lending Directions for covered digital-lending data, and the payment-system data direction for covered payment-system providers.

About this guide

This guide is written for compliance, legal, risk, technology and product teams at NBFCs preparing for the DPDP Act alongside their existing RBI, PMLA/KYC and CERT-In obligations. The editorial approach is to label every requirement by source, separate statutory duties from good practice, and name the specific regulator behind each obligation rather than blending them.

Methodology

Last updated: 31 August 2026. Primary authorities reviewed: DPDP Act, 2023; DPDP Rules, 2025; RBI directions (KYC, digital lending, outsourcing, payment-system data); PMLA and PML (Maintenance of Records) Rules; and CERT-In Directions. Each material statement is classified as a DPDP Act requirement, a DPDP Rules requirement, another regulator's requirement (RBI, PMLA/KYC or CERT-In), or an implementation recommendation.

Important note. This page is general information about the interaction between the DPDP Act and NBFC regulation. It is not legal advice and does not create a client relationship. Commencement dates, RBI instruments and retention periods change; verify each point against the current official text before relying on it, and take qualified advice for your specific entity, category and activities. No external legal review of this page is claimed; if a qualified reviewer later reviews it, a named attribution will be added.

Sources & primary authorities

  • DPDP Act, 2023 — sections referenced on this site: DPDP Act (s.8, s.10, s.16, s.38). Official text: MeitY.
  • DPDP Rules, 2025 — DPDP Rules overview: notice, security (Rule 6), breach (Rule 7), SDF DPIA/audit (Rule 13).
  • RBI — Master Direction on Know Your Customer; Digital Lending Directions; outsourcing directions; payment-system data requirements; Account Aggregator framework. Official: rbi.org.in.
  • PMLA / KYC recordkeeping — Prevention of Money Laundering Act and PML (Maintenance of Records) Rules; five-year retention baselines reflected in the RBI KYC Directions.
  • CERT-In — Directions dated 28 April 2022: six-hour incident reporting and log retention. Official: cert-in.org.in.
  • Credit information — Credit Information Companies (Regulation) Act and the RBI CIC framework, for credit-report accuracy and disputes.

Validation required before publication

Confirm the following against current official texts before this page is published or relied upon:

  • The exact DPDP commencement instrument (Gazette G.S.R. 843(E)) and Rule 1(2) phasing.
  • PMLA and PML (Maintenance of Records) Rules retention wording, and any five- versus ten-year nuances by record type.
  • RBI six-hour or immediate reporting applicability by NBFC category and instrument.
  • RBI Digital Lending Directions current text on permissions, India storage and LSP controls.
  • RBI Account Aggregator and payment-system data scope for the specific entity.
  • Any RBI, MeitY or CERT-In change after 31 August 2026.

Need implementation support?

Turn this into a mapped remediation plan with a DPDP compliance assessment for your NBFC.

Start with an assessment