Skip to main content
AIZZENTEC - DPDP, Privacy & Cybersecurity Advisory — page loaded
All articles

DPDP Act Compliance for Banks and NBFCs: The Financial Data Protection Guide

By Praveen Kumar, Practice Leader — Risk, Cyber and AnalyticsCA, CISA, CEH, CDPSE, CFEPublished
DPDP Act Compliance for Banks and NBFCs: The Financial Data Protection Guide
ShareLinkedInX

DPDP Act compliance for banks and NBFCs sits at the intersection of two demanding regulatory regimes. The Indian financial services industry — comprising banks, NBFCs (Non-Banking Financial Companies), payment aggregators, and fintech platforms — operates under a complex regulatory landscape, and the Digital Personal Data Protection Act (DPDPA) 2023 now intersects with Reserve Bank of India (RBI) guidelines to create unique compliance obligations for financial data protection.

This guide is written for compliance officers, data protection leads, and technology teams at banks, NBFCs, digital lenders, and payment aggregators. You will learn how the DPDP Act layers on top of RBI requirements, how to structure KYC data protection and consent, what digital lending data compliance looks like in practice, and which breach notification and customer-rights obligations apply to financial institutions.

Critical Intersection: The DPDP Act operates alongside the RBI Master Direction on IT Governance (2016) and RBI’s data localization requirements. Financial institutions must comply with BOTH frameworks — DPDPA for personal data protection AND RBI for financial sector-specific requirements. For a broader view of how privacy is reshaping Indian banking strategy, see our companion piece on how the DPDP Act is transforming the banking sector.

How Do RBI Rules and the DPDP Act Interact on Data Localisation?

RBI mandates that “all customer data, financial data, and transaction records must be stored on servers located in India.” DPDPA Section 5(9) reinforces this, prohibiting transfer of personal data outside India without explicit consent. If your institution moves any customer data abroad, review the rules on cross-border data transfer under the DPDP Act before doing so.

Practical Implementation of Data Localisation

Banks and NBFCs must ensure:

  • Server Location: Core banking systems and customer databases must be on India-based servers
  • Cloud Usage: If using cloud storage (AWS, Azure), must use India regions only
  • Backup Data: Even backup/disaster recovery data cannot be stored outside India without explicit consent
  • Third-Party Processors: Payment processors and analytics providers must commit to India-only storage
  • Data Processing Agreement: Written DPA specifying data location for each third party

KYC Data Protection: How Should Banks Handle Know Your Customer Data?

KYC is mandatory under RBI regulations. However, the DPDP Act requires that KYC data be handled with explicit purpose limitation.

Case Law Reference: RBI Master Direction on IT Governance specifies that KYC data forms the core of customer identity and must be protected with highest security standards. This aligns with DPDPA’s classification of identity data as sensitive personal data requiring enhanced protection.

KYC Consent Framework Under the DPDP Act

Banks and NBFCs must collect explicit consent for KYC data use.

KYC Consent Form Elements:

  • Identity Verification: Consent to collection of government ID (Aadhaar, PAN, Passport) for account opening
  • Address Verification: Consent to collect address proof (utility bill, rental agreement)
  • Financial Profile: Consent to assess income and creditworthiness through KYC
  • AML/CFT Screening: Consent to check against anti-money laundering and counter-financing terrorism lists
  • Credit Bureau Sharing: Separate consent to share KYC data with credit bureaus (CIBIL, Experian)
  • Data Retention: Notice that KYC data retained for duration of account + 10 years post-closure per RBI guidelines

Compliance Risk: Many banks combine “accept terms and conditions” with KYC consent. Under the DPDP Act, KYC consent must be separate, explicit, and specific. Customers must be able to withhold KYC consent for certain uses (like credit bureau sharing) even while opening accounts.

Digital Lending Data Compliance: Loan Servicing Consent and Credit Assessment

When banks and NBFCs extend credit, they process sensitive financial data. The DPDP Act requires specific consents for different data uses.

Loan Processing Consent Workflow

Example: Digital Lending App Processing Personal Loan Applications

At application stage, the customer consents to:

  • Credit Assessment: Pull credit score from bureaus, assess financial history
  • Income Verification: Verify employment and income through GST returns, salary slips
  • CIBIL/Equifax Inquiry: Explicit consent to credit bureau inquiry (note: hard inquiry affects credit score)
  • Bank Statement Analysis: Consent to access bank statements for financial assessment
  • Loan Servicing: During loan tenure, consent to monitor account for any defaults
  • Recovery Actions: If default occurs, consent to collection activities (not harassment)

Critically, each consent item must be separate. A customer cannot be forced to consent to all for loan approval.

Traditional Bank with Fintech Partnership

Case Study: Large Bank Offering Digital Lending through Fintech Partner

When a traditional bank partners with a fintech lender for digital lending:

  • Data Sharing Protocol: Bank shares only KYC data necessary for assessment, not entire customer profile
  • Customer Consent: Bank obtains separate consent from customer for fintech partnership data sharing
  • Data Processing Agreement: Written DPA between bank and fintech specifying: data to be shared, uses allowed, retention period, security measures
  • Fintech Compliance: Fintech platform must be DPDPA-compliant and implement required security measures
  • Data Return/Deletion: Fintech must return or delete shared data after loan decision or stated period

Credit Bureau Data Sharing Under the DPDP Act

Banks share customer financial data with credit bureaus (CIBIL, Equifax, Experian). This requires explicit consent:

  • Separate Consent Item: Cannot be bundled with the loan agreement
  • Purpose Clarity: Explain that data will be shared for creditworthiness assessment
  • Data Scope: Specify what financial data (loan amount, repayment status, defaults) will be shared
  • Bureau Identification: Name the specific credit bureaus data will be shared with
  • Withdrawal Right: If the customer withdraws consent, new data is not shared (but existing data cannot be recalled)

Payment Aggregator Data Flows and Compliance

Payment aggregators (like Razorpay, PayU, Instamojo) processing payments for merchants handle sensitive data: customer bank details, transaction amounts, merchant details.

DPDP Act for Payment Aggregators: Payment processors fall under “data processors” rather than “data controllers” for payment transactions. However, for any secondary data use (analytics, fraud detection, marketing), payment aggregators must obtain explicit customer consent.

Payment Aggregator Compliance Framework

  • Data Minimization: Aggregators should not store full bank account numbers, only tokens for re-billing.
  • Consent for Fraud Detection: Separate consent required to use transaction data for fraud detection algorithms and behavioral analysis.
  • Merchant Data Isolation: Payment data of one merchant’s customers cannot be accessed by or shared with other merchants.
  • PCI-DSS + DPDPA Alignment: While PCI-DSS covers payment card security, the DPDP Act covers all customer personal data in the payments ecosystem.

RBI Master Direction on IT Governance: How Does It Align with the DPDP Act?

RBI’s Master Direction on IT Governance specifies security measures that align with DPDP Act requirements:

RBI Requirement DPDPA Alignment
Encryption of data in transit and at rest Section 5(4) requires appropriate security measures
Access controls and user authentication Section 5(3) requires data minimization and access control
Audit trails for data access Section 5(5) requires accountability for data processing
Incident reporting to RBI within 72 hours Section 8(3) requires breach notification to affected individuals
Data localization to India Section 5(9) restricts cross-border data transfers
Customer grievance redressal Section 7 mandates mechanism to address data subject rights

What Data Subject Rights Do Bank Customers Have Under the DPDP Act?

Customers have specific rights under the DPDP Act that banks and NBFCs must facilitate:

  • Right to Access: Customer can request all personal data the bank holds about them within 30 days
  • Right to Correction: Customer can correct inaccurate KYC data and address information
  • Right to Deletion: After account closure and the 10-year retention period, customer can request data deletion (subject to RBI retention requirements)
  • Right to Opt-Out: Can opt out of marketing communications and behavioral profiling
  • Right to Grievance: Can lodge a DPDPA grievance with the bank’s Data Protection Officer

Breach Notification in the Financial Sector

When banks or NBFCs experience a data breach, heightened notification requirements apply:

  • RBI Notification: Bank must notify RBI within 72 hours of discovering the breach
  • Customer Notification: The DPDP Act requires notification of affected customers within 72 hours
  • Regulatory Disclosure: May need to disclose the breach in RBI regulatory filings if material
  • Incident Documentation: Maintain detailed logs of breach discovery, scope, mitigation

The financial stakes of getting this wrong are substantial — see our detailed breakdown of data breach penalties under the DPDP Act.

Key Takeaways for Banking and NBFC Compliance

DPDP Act Compliance Checklist for Banks & NBFCs:

  • ☒ Ensure all customer data stored in India only (RBI + DPDPA)
  • ☒ Implement separate, explicit KYC data consent
  • ☒ Obtain purpose-specific consent for loan servicing and credit assessment
  • ☒ Get separate consent for credit bureau data sharing
  • ☒ Establish Data Processing Agreements with all third parties
  • ☒ Implement encryption and access controls per RBI standards
  • ☒ Create customer data access request mechanism
  • ☒ Establish breach notification procedures for RBI and customers
  • ☒ Maintain audit trails of all data access for 3+ years
  • ☒ Conduct annual DPDPA and RBI compliance audit

Frequently Asked Questions

Do banks have to store customer data in India under the DPDP Act?

Yes. RBI mandates that all customer data, financial data, and transaction records be stored on servers located in India, and DPDPA Section 5(9) reinforces this by prohibiting transfer of personal data outside India without explicit consent. This extends to cloud regions, backups, and third-party processors, all of which must commit to India-only storage.

Can KYC consent be bundled with a bank’s terms and conditions?

No. Under the DPDP Act, KYC consent must be separate, explicit, and specific — it cannot be combined with a general “accept terms and conditions” checkbox. Customers must also be able to withhold consent for certain uses, such as credit bureau sharing, even while opening an account.

Do banks need separate consent to share data with credit bureaus like CIBIL?

Yes. Sharing customer financial data with credit bureaus (CIBIL, Equifax, Experian) requires a separate consent item that cannot be bundled with the loan agreement. The bank must explain the purpose, specify the data scope, and name the specific bureaus; if consent is withdrawn, new data is not shared, though existing data cannot be recalled.

How long must banks retain KYC data?

KYC data is retained for the duration of the account plus 10 years post-closure, per RBI guidelines, and customers must be notified of this retention period. After account closure and the 10-year retention period, a customer can request deletion, subject to RBI retention requirements.

What breach notification rules apply to banks and NBFCs?

A bank must notify RBI within 72 hours of discovering a breach, and the DPDP Act separately requires notification of affected customers within 72 hours. Material breaches may also need disclosure in RBI regulatory filings, and detailed incident documentation must be maintained.

Are payment aggregators data fiduciaries under the DPDP Act?

For payment transactions, payment aggregators fall under “data processors” rather than “data controllers.” However, for any secondary data use — analytics, fraud detection, or marketing — they must obtain explicit customer consent, minimise stored data (tokens instead of full account numbers), and keep each merchant’s customer data isolated.

Conclusion

DPDP Act compliance for banks and NBFCs requires understanding the intersection of DPDPA requirements with RBI’s existing data protection framework. Financial institutions that implement clear consent mechanisms for different financial data uses, maintain India-based data storage, and provide robust customer rights mechanisms will achieve both DPDPA and RBI compliance while building customer trust in India’s evolving financial services ecosystem.

All articles