DPDP Act for NBFCs and Fintech Apps
How the DPDP Act sits alongside RBI rules for lenders and fintechs: consent for bureau pulls and app permissions, KYC retention, vendors, breaches and Consent Managers.

Fintechs already follow RBI rules on KYC, digital lending and data storage. The DPDP Act adds a general privacy law on top. Where a sector regulator's rule is stricter, you follow both; the Act expressly allows other laws to require more, such as longer retention.
Consent, purpose by purpose
Fintech onboarding often asks for everything on one screen. The Act requires consent to be specific to each purpose and limited to the data necessary for it.
App permissions
RBI's digital lending rules already prohibit lending apps from accessing phone resources such as files and media, contact lists, call logs and telephony functions, and allow one-time access to camera, microphone and location for onboarding and KYC with the borrower's explicit consent. The DPDP principle of data minimisation points the same way for all fintech apps: do not request a permission the feature does not need.
If you cannot explain to a user why the app needs a permission, the app should not ask for it.
Retention: delete, unless a law says keep
The Act requires erasure when the purpose is over or consent is withdrawn, unless retention is necessary to comply with a law. KYC and transaction records have mandatory retention periods under PMLA and RBI rules, so they stay. Data from applicants who were rejected or who dropped off has no such basis for long retention. Define a period, and automate deletion.
Vendors and loan service providers
Lenders work through loan service providers, collection agencies, KYC vendors, cloud and messaging providers. Under the Act the lender is the Data Fiduciary and answerable for all of them. Contracts need security safeguards, breach notification to the lender, restrictions on use and deletion at the end of the engagement. RBI's outsourcing and digital lending rules require similar controls.
Breaches and security
A breach triggers several clocks: the DPDP requirement to inform users and the Board without delay with a detailed report within 72 hours, CERT-In's six-hour incident reporting direction, and RBI's own incident reporting timelines for regulated entities. Prepare one incident process that satisfies all three.
Consent Managers and Significant Data Fiduciaries
Consent Managers are entities registered with the Data Protection Board that let users give, review and withdraw consent across businesses through one interface. Registration opens from 13 November 2026. The model resembles Account Aggregators in finance. Larger fintechs may also be notified as Significant Data Fiduciaries, which brings a Data Protection Officer based in India, an annual data protection impact assessment and audit, and checks that algorithms do not put users' rights at risk.
- Digital Personal Data Protection Act, 2023 (MeitY)
- Digital Personal Data Protection Rules, 2025: notification summary (Press Information Bureau)
- Reserve Bank of India: Master Directions
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





