Post

Navigating Dual Mandates: DPDPA and Fintech's Regulatory Tightrope

Navigating Dual Mandates: DPDPA and Fintech's Regulatory Tightrope

The Digital Personal Data Protection Act, 2023 (DPDPA), now fully operational with its associated rules, marks a pivotal shift in India’s data governance landscape. For the burgeoning fintech sector, this new regime presents a unique challenge: harmonising the DPDPA’s overarching principles of data protection with the stringent, sector-specific directives issued by the Reserve Bank of India (RBI). As of August 2026, fintech entities are grappling with the practical implications of this dual regulatory oversight, demanding a re-evaluation of their data processing frameworks.

The DPDPA’s Foundation for Financial Data

At its core, the DPDPA establishes a comprehensive framework for processing personal data, defining “personal data” broadly (Section 2(k)) to encompass virtually all information handled by fintech companies. Key principles such as lawful processing, purpose limitation, data minimisation, and accountability are central. Fintech companies, acting as Data Fiduciaries, must ensure that personal data is processed fairly and lawfully, primarily based on the explicit, informed, and unambiguous consent of the Data Principal (Section 6(1)). However, the Act also provides for “legitimate uses” (Section 7), which are particularly relevant for regulated sectors like finance. This includes processing for compliance with any law (Section 7(d)), or for the performance of any function under any law (Section 7(e)), offering a crucial legal basis for data collection mandated by the RBI without requiring separate consent under the DPDPA. This provision is vital for activities like Know Your Customer (KYC) verification and Anti-Money Laundering (AML) checks, which are non-negotiable regulatory obligations. Furthermore, the DPDPA imposes significant obligations on Data Fiduciaries, including implementing reasonable security safeguards (Section 8(5)) and notifying the Data Protection Board of India (DPBI) and affected Data Principals in the event of a personal data breach (Section 8(6)).

RBI Directives: The Bedrock of Financial Data Governance

Long before the DPDPA, the RBI had established robust guidelines for data management within the financial sector. These directives often dictate the what, how, and where of data handling for regulated entities. For instance, the Master Direction on KYC (2016, updated periodically) mandates the collection and retention of extensive personal data for identity verification, a clear example where DPDPA’s “legitimate uses” (Section 7(d)) aligns perfectly. Similarly, the Master Direction on Storage of Payment System Data (2018) requires all payment system data to be stored exclusively in India, a stringent data localisation requirement that predates and, in some aspects, supersedes the DPDPA’s more flexible approach to cross-border data transfers (Section 16).

Furthermore, the RBI’s Guidelines on Managing Risks in Outsourcing of Financial Services (2006, updated) place significant responsibility on regulated entities for the data security practices of their third-party service providers. This now directly intersects with the DPDPA’s mandate for Data Fiduciaries to ensure their Data Processors also comply with the Act’s provisions (Section 8(5)). The RBI’s Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023) also reinforces the need for robust data security, incident management, and audit trails, complementing the DPDPA’s general security obligations.

Harmonising Conflicting Mandates and Operational Realities

The primary challenge for fintechs lies in reconciling potential overlaps and conflicts between DPDPA and RBI norms. While the DPDPA provides a legal basis for processing data required by law, the specific details of data retention periods often differ. RBI norms frequently stipulate longer retention periods (e.g., 5-10 years for KYC records post-account closure) than what might be considered “necessary for the purpose” under DPDPA’s storage limitation principle (Section 8(4)). Fintechs must interpret “purpose” broadly to include ongoing regulatory compliance, retaining data for the duration mandated by the RBI, even if the immediate service purpose has concluded.

Another critical area is cross-border data transfer. While DPDPA Section 16 allows transfers to notified jurisdictions, the RBI’s payment data localisation mandate remains absolute for payment system data. For non-payment financial data, fintechs must carefully assess whether the destination country is among those notified by the Central Government under the DPDPA, and ensure adequate safeguards are in place, aligning with global best practices seen in GDPR’s adequacy decisions or standard contractual clauses. This nuanced approach contrasts with the stricter localisation stance often adopted by the RBI.

Lastly, data breach reporting mechanisms require careful integration. Both the DPDPA (Section 8(6)) and various RBI circulars (e.g., on cyber security incident reporting) mandate timely notification. Fintechs need a unified incident response framework that satisfies both regulators, ensuring prompt reporting to the DPBI, CERT-In, and the RBI without duplication or conflicting timelines.

Practical Takeaway

For Indian fintech businesses, General Counsels, and Data Protection Officers, navigating this evolving landscape requires a proactive and integrated approach. Begin by conducting a thorough data mapping exercise to identify all personal data processed, its purpose, legal basis (DPDPA Section 6 or 7), and retention periods. Review and update consent mechanisms to ensure DPDPA compliance, even while relying on “legitimate uses” for regulatory mandates. Critically, re-evaluate all third-party contracts to ensure Data Processors are contractually bound to DPDPA obligations (Section 8(5)). Develop a unified data security and incident response plan that addresses both DPDPA’s breach notification requirements (Section 8(6)) and RBI’s specific reporting protocols. Finally, closely monitor guidance from the DPBI and any further clarifications from the RBI regarding DPDPA harmonisation, as these will shape the future of data governance in India’s dynamic financial sector.

This post is licensed under CC BY 4.0 by the author.