Does DPDP apply to payment data and fintech platforms?
Fintech companies and payment platforms process some of the most sensitive personal data in India. Here is how DPDP and RBI requirements interact.
What personal data do fintech companies process that is subject to DPDP?
Fintech platforms typically process: identity data (PAN, Aadhaar, passport, driving licence); financial account data (bank account numbers, IFSC codes, UPI IDs); card data (credit/debit card numbers, CVV — though PCI-DSS restricts how this is stored); transaction history (amount, merchant, date, frequency); credit bureau data (CIBIL score, credit history); KYC data (photos, video KYC recordings); income proof (salary slips, bank statements, ITRs); and behavioural data (app usage, spending patterns, repayment behaviour). Each category requires specific security controls and consent or lawful basis analysis.
How does RBI payment data localisation interact with DPDP?
RBI's 2018 mandate requires that all payment data relating to Indian customers be stored only in India — this applies to payment system operators including card networks, payment aggregators, payment gateways, and wallets. DPDP's cross-border transfer rules (approved country list) are separate from RBI's localisation mandate. For payment data, you must comply with both: keep payment data in India (RBI); and only transfer other personal data to DPDP-approved countries (DPDP). These requirements overlap but are not identical — your compliance programme must address both separately.
What consent does DPDP require for fintech data processing?
Processing necessary for the financial service — KYC, transaction processing, fraud detection for the transactions, credit assessment for a loan application — can rely on the contract and statutory obligation bases. Consent is required for: using transaction data to recommend other financial products; sharing transaction history with third-party marketing partners; using spending behaviour for advertising profiling; sharing income data with ecosystem partners for their own commercial purposes. The distinction between service-necessary processing and commercial enhancement is the key line between contract/statutory basis and consent.
How must fintech companies handle credit data under DPDP?
Credit bureau data (CIBIL reports, bureau scores) is obtained through credit information companies regulated by CICRA 2005. Under DPDP, when you pull a credit bureau report on a customer: the customer must be informed (notice); the pull must be for a legitimate credit assessment purpose (lawful basis); the report must be secured; and it must be deleted once the credit assessment is complete or within the defined retention period. Retaining credit reports beyond the purpose or using them for non-credit purposes (insurance pricing, marketing) requires additional consent.
What security standards must fintech companies implement?
DPDP requires 'appropriate technical and organisational security measures' — for fintech, this means: PCI-DSS compliance for any card data handling; AES-256 encryption for stored financial data; TLS 1.3 for data in transit; strong access controls and MFA for internal system access; regular penetration testing and vulnerability assessments; VAPT reports reviewed by senior management; fraud detection systems; and a security operations centre or equivalent monitoring function. Fintech companies are among the most targeted by cybercriminals — security investment is both a DPDP requirement and a fundamental business necessity.
What breach notification requirements apply to fintech companies?
Fintech companies are subject to both DPDP breach notification (notify the Data Protection Board within the prescribed period, expected 72 hours) and RBI's own incident reporting requirements (report cyber security incidents to RBI within 6 hours for the initial report; SEBI, IRDAI, and NPCI have their own incident reporting requirements depending on the activity). Build a breach response plan that covers all applicable notification obligations simultaneously — the 72-hour DPDP window is shorter than most other notification deadlines, making it the pacing constraint.
Frequently asked questions
Does DPDP change anything about Aadhaar-based eKYC for fintech?
Aadhaar eKYC for fintech is primarily regulated by UIDAI under the Aadhaar Act — separate from DPDP. Under DPDP, the fact that Aadhaar data is processed adds to the sensitivity of the processing. DPDP's security obligations and breach notification requirements apply to all systems that hold Aadhaar-linked KYC data. Ensure your Aadhaar eKYC systems are covered by your DPDP security framework and breach response plan.
If a customer closes their fintech account, how long can we retain their data?
On account closure: delete all data that has no ongoing lawful basis; retain only what is required by law — Anti-Money Laundering (PMLA) requires 5 years retention of customer records; income tax records must be retained as per the IT Act; PPI records per RBI guidelines. After all statutory retention periods expire, delete completely. Inform the customer at account closure which data you will retain and for how long, and under what legal basis.
Does using a payment aggregator like Razorpay make us a Data Processor?
When Razorpay processes payments on your behalf, Razorpay is a Data Processor and you are the Data Fiduciary for your customers' payment data. Execute a DPA with Razorpay — Razorpay provides a data processing agreement as part of its terms. Similarly, if you provide payment aggregation services to merchants, you are a Data Processor for merchant transaction data but the Data Fiduciary for your own customer and employee data. The role analysis depends on who determines the purpose of processing.
Build your fintech DPDP compliance programme
Niti Bharat's Fintech DPDP Compliance Pack covers privacy notice, consent framework, credit data handling, RBI-DPDP overlap, security obligations, and breach response for payment platforms.
Get the Fintech DPDP Pack