DPDPA's Impact on Fintech: Harmonising Privacy with RBI Directives
The Indian fintech landscape, a crucible of innovation and rapid adoption, now operates under a dual regulatory mandate. With the Digital Personal Data Protection Act, 2023 (DPDPA) fully operational and its associated Rules in effect as of September 2026, fintech entities, already heavily scrutinised by the Reserve Bank of India (RBI), face a new layer of privacy obligations. The challenge and opportunity lie in harmonising the DPDPA’s comprehensive framework with RBI’s long-standing, sector-specific directives on data governance, security, and customer protection.
Navigating Consent and Legitimate Uses
The DPDPA introduces a robust, granular consent framework, stipulating that personal data can only be processed for a lawful purpose for which the Data Principal has given or is deemed to have given consent (Section 6). This is a significant shift for many fintechs, which previously relied on broad terms of service or implicit consent. The DPDPA mandates transparent and verifiable consent, requiring clear affirmative action, and the ability for Data Principals to withdraw consent at any time (Section 6(6)).
However, the Act also provides for ‘legitimate uses’ where consent is not required (Section 7). This includes processing for purposes like fulfilling legal obligations, responding to medical emergencies, or for public interest as specified by the Central Government. For fintechs, this is crucial. KYC (Know Your Customer) requirements, anti-money laundering (AML) checks, and fraud prevention, mandated by RBI, would likely fall under such legitimate uses, allowing processing without explicit consent, provided it aligns with the specified purpose. Fintechs must meticulously document the legal basis for each processing activity, ensuring that data collected for a DPDPA legitimate use is not then used for other purposes without fresh consent. The Account Aggregator framework, for instance, already relies on explicit consent for data sharing, a principle now reinforced and expanded by the DPDPA.
Data Security and Localisation: A Dual Mandate
Data security has always been a cornerstone of RBI’s regulatory approach, with detailed guidelines on cybersecurity frameworks for banks, NBFCs, and payment system operators. The DPDPA reinforces this by obligating Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches (Section 9(4)). While the DPDPA sets a general standard, RBI’s directives often provide more granular and prescriptive requirements, such as mandating specific security audits, encryption standards, and incident response protocols. Fintechs must adhere to the higher standard, ensuring their security posture satisfies both the DPDPA’s general principles and RBI’s specific mandates.
A key area of interaction is data localisation. RBI has historically imposed strict data localisation requirements, particularly for payment system operators, mandating that all payment system data be stored only in India. The DPDPA, in contrast, permits cross-border transfers of personal data to notified countries or territories unless restricted by the Central Government (Section 16). For fintechs, RBI’s localisation mandates remain paramount. Where RBI requires data to stay within India, that requirement supersedes the DPDPA’s more permissive stance on cross-border transfers. Fintechs must ensure their data architecture complies with RBI’s localisation rules, even if the DPDPA would otherwise allow transfers.
Empowering the Data Principal: New Rights and Grievance
The DPDPA significantly empowers Data Principals by granting them a suite of rights, including the right to access information about their data (Section 11), the right to correction and erasure (Section 12), and the right to grievance redressal (Section 13). Fintechs, with their vast troves of customer data, must establish robust mechanisms to facilitate these rights. This goes beyond existing customer service channels and often requires new technical capabilities for data mapping, retrieval, and deletion.
RBI already has comprehensive grievance redressal mechanisms for financial consumers. The DPDPA’s framework for Data Principal rights and grievance redressal through the Data Protection Board of India (DPBI) (Sections 13 & 21) will run parallel to, and potentially complement, RBI’s existing ombudsman schemes. Fintechs must ensure their internal grievance officers are equipped to handle DPDPA-related requests, while also being mindful of the existing RBI-mandated customer service and complaint channels. Harmonising these processes to provide a seamless experience for the customer, while meeting both regulatory requirements, is critical.
Governance Overhaul: DPOs and SDFs
Many fintech entities, given the volume and sensitivity of the personal data they process, will likely qualify as ‘Significant Data Fiduciaries’ (SDFs) under the DPDPA (Section 10(3)), based on criteria set out in the DPDP Rules. This designation brings additional obligations, including the appointment of an independent Data Protection Officer (DPO) (Section 10(2)) and undertaking periodic Data Protection Impact Assessments (DPIAs) and independent data audits.
The DPO will be a critical role, responsible for advising on DPDPA compliance, acting as a point of contact for Data Principals and the DPBI, and overseeing internal data protection policies. This role requires a deep understanding of both DPDPA and RBI norms. For fintechs, this means not just adding a new compliance function, but integrating data privacy considerations into every aspect of their product development, operations, and risk management frameworks, ensuring alignment with both privacy law and financial sector regulations.
Practical takeaway: Indian fintech businesses, General Counsels, and Data Protection Officers must adopt a converged compliance strategy. Instead of viewing DPDPA and RBI norms as separate silos, they should be treated as integrated layers of a comprehensive data governance framework. Prioritise adherence to the stricter of the two requirements where overlaps exist, particularly concerning data localisation and security. Invest in robust consent management platforms, enhance data mapping capabilities to honour Data Principal rights, and ensure your DPO possesses expertise in both privacy law and financial sector regulations. Proactive harmonisation, rather than reactive compliance, will be key to navigating this complex regulatory environment and building trust with digital-first consumers.