Compliance & Regulation

DPDP Act for NBFCs and Fintech Apps

How the DPDP Act sits alongside RBI rules for lenders and fintechs: consent for bureau pulls and app permissions, KYC retention, vendors, breaches and Consent Managers.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
8 min read
Financial data on screens

Fintechs already follow RBI rules on KYC, digital lending and data storage. The DPDP Act adds a general privacy law on top. Where a sector regulator's rule is stricter, you follow both; the Act expressly allows other laws to require more, such as longer retention.

01

Consent, purpose by purpose

Fintech onboarding often asks for everything on one screen. The Act requires consent to be specific to each purpose and limited to the data necessary for it.

KYCRequired by law under PMLA and RBI rules; say so in the notice
Credit bureau pullSpecific consent, already required under credit information rules
Bank statement or Account Aggregator dataPurpose and duration stated; AA consent artefact kept
Marketing and cross-sellSeparate, optional, and easy to withdraw
Sharing with partnersNamed categories of recipients and purposes
02

App permissions

RBI's digital lending rules already prohibit lending apps from accessing phone resources such as files and media, contact lists, call logs and telephony functions, and allow one-time access to camera, microphone and location for onboarding and KYC with the borrower's explicit consent. The DPDP principle of data minimisation points the same way for all fintech apps: do not request a permission the feature does not need.

If you cannot explain to a user why the app needs a permission, the app should not ask for it.

03

Retention: delete, unless a law says keep

The Act requires erasure when the purpose is over or consent is withdrawn, unless retention is necessary to comply with a law. KYC and transaction records have mandatory retention periods under PMLA and RBI rules, so they stay. Data from applicants who were rejected or who dropped off has no such basis for long retention. Define a period, and automate deletion.

CustomersRetain KYC and transaction records for the period the law requires after the relationship ends
Rejected or abandoned applicationsShort, documented retention, then delete
Marketing leadsDelete on withdrawal of consent
LogsAt least one year under the DPDP Rules
04

Vendors and loan service providers

Lenders work through loan service providers, collection agencies, KYC vendors, cloud and messaging providers. Under the Act the lender is the Data Fiduciary and answerable for all of them. Contracts need security safeguards, breach notification to the lender, restrictions on use and deletion at the end of the engagement. RBI's outsourcing and digital lending rules require similar controls.

05

Breaches and security

A breach triggers several clocks: the DPDP requirement to inform users and the Board without delay with a detailed report within 72 hours, CERT-In's six-hour incident reporting direction, and RBI's own incident reporting timelines for regulated entities. Prepare one incident process that satisfies all three.

Encryption at rest and in transitTokenised card dataAccess logs for one yearMaker-checker on data exportsIncident runbookUser notification templates
06

Consent Managers and Significant Data Fiduciaries

Consent Managers are entities registered with the Data Protection Board that let users give, review and withdraw consent across businesses through one interface. Registration opens from 13 November 2026. The model resembles Account Aggregators in finance. Larger fintechs may also be notified as Significant Data Fiduciaries, which brings a Data Protection Officer based in India, an annual data protection impact assessment and audit, and checks that algorithms do not put users' rights at risk.

Both
RBI rules and the DPDP Act apply together
72 hours
Detailed breach report to the Board
13 May 2027
Main DPDP obligations apply
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact