Post

Navigating the Data Labyrinth: DPDPA's Impact on India's Fintech Sector Under RBI Scrutiny

Navigating the Data Labyrinth: DPDPA's Impact on India's Fintech Sector Under RBI Scrutiny

The Digital Personal Data Protection Act, 2023 (DPDPA), now fully operational in September 2026, has ushered in a new era of data governance in India. For the burgeoning fintech sector, this legislation presents a complex interplay with the Reserve Bank of India’s (RBI) robust regulatory framework. Fintechs, by their very nature, are data-intensive, handling sensitive financial and personal information. Harmonising the DPDPA’s data principal-centric approach with the RBI’s prudential norms for financial stability and consumer protection is the paramount challenge.

At the heart of the DPDPA lies the principle of consent. Fintech entities must now secure clear, specific, and unambiguous consent from data principals for processing their personal data (Section 6(1)). This goes beyond mere acceptance of terms and conditions, requiring granular consent for different processing activities, such as onboarding, credit scoring, product cross-selling, and data sharing with third parties. For existing customers, many fintechs have had to re-evaluate and re-obtain consent, ensuring it meets the DPDPA’s stringent standards.

However, the DPDPA also acknowledges “legitimate uses” where consent may not be strictly necessary (Section 7). Crucially for fintechs, this includes processing for purposes related to the performance of a legal obligation or for compliance with any judgment or order issued under law. This provision is vital for financial institutions, allowing them to process data to comply with RBI mandates on Know Your Customer (KYC), Anti-Money Laundering (AML), Combating the Financing of Terrorism (CFT), and fraud prevention without explicit consent for each specific regulatory requirement. The challenge lies in clearly delineating what falls under “legitimate use” versus what requires explicit consent, particularly for value-added services or marketing.

Data Retention and Localisation: A Dual Regulatory Lens

One of the most significant areas of overlap and potential friction concerns data retention and localisation. The DPDPA mandates that data fiduciaries retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or for legal or business purposes (Section 9(4)). Once this purpose is served, data must be deleted. This contrasts with RBI’s directives, which often require financial entities to retain KYC records and transaction data for extended periods, typically five to ten years post-account closure, to comply with AML/CFT norms.

Fortunately, the DPDPA’s inclusion of “legal purposes” as a ground for retention provides the necessary leeway for fintechs to comply with RBI’s longer retention periods. However, this does not absolve them of the responsibility to clearly document the legal basis for such retention and to delete data once both the DPDPA’s purpose fulfilment and the RBI’s extended retention periods have elapsed.

Regarding data localisation, the RBI has long mandated that payment system data be stored exclusively in India. The DPDPA, in Section 16, permits cross-border transfers of personal data to notified jurisdictions, unless restricted by other laws. While the DPDPA offers a more liberal stance on data transfers than some global regimes like GDPR, RBI’s specific directives for critical financial data remain paramount. Fintechs must navigate this carefully, ensuring that any cross-border data flows comply with both the DPDPA’s framework for permitted jurisdictions and any more restrictive sectoral norms from the RBI.

Operationalising Data Principal Rights and SDF Obligations

The DPDPA empowers data principals with several rights, including the right to access information, correct data, and erase personal data (Sections 13, 14, 15). For fintechs, operationalising these rights requires robust internal processes. The “right to erasure” (Section 15), for instance, must be balanced against RBI’s mandatory data retention periods. As discussed, the DPDPA explicitly allows for retention where required by law, providing a clear carve-out for financial institutions. However, fintechs must still be prepared to erase data that falls outside these legal obligations upon a data principal’s request.

Many larger fintechs, due to the volume and sensitivity of data they process, are likely to be designated as Significant Data Fiduciaries (SDFs) under Section 10 of the DPDPA. This designation brings additional obligations, including the appointment of a Data Protection Officer (DPO), conducting Data Protection Impact Assessments (DPIAs), and undergoing periodic data audits. These requirements mirror some of the best practices seen in global privacy regimes like the GDPR but are now legally binding in India. The DPO, in particular, will play a crucial role in bridging the gap between DPDPA compliance and existing RBI guidelines, ensuring a holistic approach to data governance.

Practical Takeaway

Indian fintech businesses, General Counsels, and Data Protection Officers must undertake a comprehensive review of their data processing activities. This involves meticulously mapping data flows, from collection to storage, processing, and eventual deletion, against both DPDPA principles and RBI’s sectoral norms. Priority areas include re-engineering consent mechanisms to be granular and verifiable, aligning data retention policies with the DPDPA’s “purpose fulfilment” while respecting RBI’s legal obligations, and enhancing data security measures to meet the DPDPA’s “reasonable security safeguards” (Section 9(5)) in addition to RBI’s robust cybersecurity guidelines. For designated Significant Data Fiduciaries, establishing a dedicated DPO function, integrating DPIAs into product development cycles, and preparing for independent data audits are non-negotiable steps towards building a compliant and trusted digital financial ecosystem.

This post is licensed under CC BY 4.0 by the author.