Banks, NBFCs and fintechs process more personal data than almost any other sector — KYC documents, account and transaction histories, credit bureau data, device data from mobile apps. Under the Digital Personal Data Protection Act 2023, every one of them is a Data Fiduciary, and the larger institutions are strong candidates for notification as Significant Data Fiduciaries.
How DPDP interacts with RBI requirements
Financial institutions already work under RBI directions on KYC, IT governance, outsourcing, digital lending and cyber security. DPDP does not replace these. In practice:
- Retention: where another law or regulator requires records to be kept (for example KYC and transaction records), that requirement continues to apply; DPDP erasure duties apply once no such obligation remains.
- Legitimate uses: some processing needed to comply with law may not need fresh consent, but the basis should be documented for each purpose.
- Security: existing IS audit and cyber security controls are a head start, but DPDP evidence must show they protect personal data specifically — and that logs are retained and monitored.
- Outsourcing: vendor and DSA/recovery agent contracts need DPDP processor clauses, not only confidentiality clauses.
Gaps commonly found in financial services
- Bundled consent in account-opening and loan journeys, with no itemised notice per purpose
- Cross-selling and marketing using data collected for KYC or servicing
- Personal data shared with DSAs, collection agencies and fintech partners without processor terms
- Mobile apps collecting contacts, location or device data beyond what the stated purpose needs
- No working process to honour consent withdrawal across core banking, CRM and marketing systems
- Breach response plans built for CERT-In and RBI reporting, but not for notifying individuals
- Legacy data of closed accounts kept indefinitely with no documented retention basis
If you are a likely Significant Data Fiduciary
Large banks and NBFCs should plan now for the extra obligations: a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments and audits. Building these into the existing audit calendar is far cheaper than standing them up after notification.
Why a banking-background auditor helps
DPDP Audits is led by Ram Krishan Dudeja, CISA CAIIB, a former Assistant General Manager (Vigilance) at State Bank of India. That background means the audit is designed around how branches, loan operations and core banking actually work — so findings are practical to fix, not just technically correct.
Start with the DPDP audit checklist, and see DPDP Rules 2025 explained for the compliance timeline.
