Post

Fintech Privacy: Navigating Global Frameworks from an Indian Lens

Fintech Privacy: Navigating Global Frameworks from an Indian Lens

As of September 15, 2026, India’s Digital Personal Data Protection Act (DPDPA) 2023 is fully operational, establishing a robust general data protection framework. For the burgeoning fintech sector, this means a dual compliance mandate: adhering to the DPDPA and the sector-specific directives from the Reserve Bank of India (RBI), particularly the Digital Lending Guidelines (DLG) 2022. This analysis compares India’s approach to fintech privacy against the US Gramm-Leach-Bliley Act (GLBA) and the EU’s combination of the General Data Protection Regulation (GDPR) and Payment Services Directive 2 (PSD2), highlighting key distinctions for Indian businesses.

India’s DPDPA 2023 mandates that personal data processing must be based on lawful grounds, with consent being a primary basis (Section 6). This consent must be free, specific, informed, unambiguous, and can be withdrawn. The RBI DLG 2022 significantly tightens this for digital lending, specifying that data collection by Regulated Entities (REs) and Lending Service Providers (LSPs) must be strictly “need-based” and with explicit consent (Section 3.1.2). This includes granular consent for accessing specific mobile phone resources, explicitly prohibiting access to contacts, call logs, or media without a clear, auditable trail and user permission. This makes India’s framework particularly stringent on the scope and nature of data collection.

In contrast, the US GLBA primarily governs the collection and disclosure of nonpublic personal information (NPI) by financial institutions. Its core privacy rule requires institutions to provide customers with a privacy notice and an opportunity to “opt out” of sharing NPI with non-affiliated third parties (15 U.S.C. § 6802(b)). Sharing with affiliates is generally permitted without an opt-out. This “opt-out” model is considerably looser than India’s “opt-in” requirement, especially when compared to the DPDPA’s explicit consent mandate and the RBI DLG’s granular controls.

The EU’s GDPR (Article 7) also requires explicit, freely given, specific, informed, and unambiguous consent for data processing, akin to the DPDPA. PSD2, which facilitates open banking, reinforces this for payment services. It mandates explicit consent from payment service users before Payment Initiation Service Providers (PISPs) or Account Information Service Providers (AISPs) can access or process their payment account data (Article 94). This aligns closely with India’s DPDPA and RBI DLG in demanding explicit, granular consent for data access and processing in the financial sector.

Data Sharing and Purpose Limitation

The DPDPA (Section 5) establishes the principles of purpose limitation and data minimisation, requiring data to be processed only for the purpose for which consent was obtained and limited to what is necessary. The RBI DLG further restricts data sharing, stipulating that customer data collected by LSPs must be stored on Indian servers and shared only with explicit consent for specific purposes (Section 3.1.2). This makes the Indian regime quite strict on data localization and sharing.

GLBA’s approach to data sharing, as noted, is more permissive, allowing sharing with affiliates without customer opt-out. For non-affiliates, an opt-out mechanism is sufficient (15 U.S.C. § 6802(b)). This means that financial institutions in the US have broader latitude to share customer data within their corporate group and with third parties, provided the opt-out mechanism is in place, compared to the explicit consent required under Indian law.

GDPR (Article 5(1)(b) and (c)) also mandates purpose limitation and data minimisation, ensuring data is collected for specified, explicit, and legitimate purposes and is adequate, relevant, and limited to what is necessary. PSD2 (Article 94(2)) is particularly stringent for TPPs, prohibiting them from using, accessing, or storing any data for purposes other than for providing the requested payment service. This specific prohibition on TPPs is a strong example of purpose limitation, mirroring the spirit of RBI DLG’s “need-based” collection and use.

Data Principal Rights and Retention

The DPDPA grants data principals several rights, including the right to access information, correction, erasure, and grievance redressal (Sections 11-14). The RBI DLG enhances this with a specific requirement for LSPs to provide borrowers with an option to delete their data, with a clear audit trail (Section 3.1.3). It also mandates data retention only for the necessary period, after which it must be securely deleted.

GLBA, while requiring privacy notices, does not explicitly grant consumers rights to access, correct, or delete their NPI in the same comprehensive manner as DPDPA or GDPR. Its focus is primarily on transparency regarding data sharing practices and the right to opt out of certain disclosures.

GDPR provides comprehensive data subject rights, including the right to information (Articles 12-14), access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and objection (Article 21). These rights are broadly aligned with the DPDPA, with GDPR often being considered the benchmark for individual control over personal data. PSD2 integrates these GDPR rights, ensuring payment service users can exercise them concerning their payment data.

Regulatory Scope and Enforcement Nuances

The DPDPA applies broadly to the processing of digital personal data within India, with extra-territorial application in certain cases (Section 3). The RBI DLG provides a sector-specific layer of regulation for digital lending, enforced by the RBI. Penalties under DPDPA can be substantial, up to INR 250 crore (Section 33).

GLBA’s scope is confined to financial institutions, with enforcement by various agencies like the Federal Trade Commission (FTC) and the Consumer Financial Protection Bureau (CFPB). Its focus is narrower than a general data protection law.

GDPR’s scope is broad, applying to all entities processing personal data of EU residents, with extra-territorial reach (Article 3). PSD2 applies specifically to payment service providers. Enforcement is handled by national Data Protection Authorities (DPAs) for GDPR and national competent authorities for PSD2, with significant fines up to €20 million or 4% of global annual turnover for GDPR breaches (Article 83).

Practical takeaway: Indian businesses, particularly in fintech, must recognise that the DPDPA and RBI DLG create a compliance environment that is often more prescriptive and stringent than GLBA, particularly concerning explicit consent, data minimisation, and data sharing controls. While GDPR/PSD2 share similarities with DPDPA in terms of consent and data principal rights, the RBI DLG introduces unique, granular requirements for digital lending that demand meticulous attention. Companies operating globally must integrate these Indian specificities into their privacy-by-design frameworks, ensuring that their global privacy policies are adapted to meet or exceed India’s higher bar for consumer data protection in fintech.

This post is licensed under CC BY 4.0 by the author.