DPDP compliance for credit bureaus and credit scoring companies
Credit bureaus hold the most sensitive financial data for hundreds of millions of Indians. Here is how the DPDP Act applies alongside CIC regulations.
Is credit data sensitive personal data under the DPDP Act?
Credit data — including loan account history, repayment behaviour, defaults, credit enquiries, and credit scores — is financial data and is treated as sensitive personal data under the Act. The consequences of its misuse or inaccuracy are severe: wrongful denial of loans, insurance, or employment decisions that rely on credit checks. Credit bureaus must apply the highest security standards and the most rigorous data accuracy processes to this data.
How does DPDP interact with CIC (Regulation) Act?
The Credit Information Companies (Regulation) Act, 2005 and the Credit Information Companies Rules already require CICs to: maintain data accuracy, allow individuals to dispute errors, and restrict data sharing to licensed members. DPDP adds: explicit disclosure in a privacy notice, a broader right to access (not just credit reports but all personal data held), and breach notification obligations. The DPDP rights framework reinforces and extends the CIC's existing access and dispute framework — align the two systems.
How must credit bureaus handle individual data access requests?
Under both CIC regulations and DPDP, individuals have the right to access their credit report. Under DPDP, this right extends to all personal data held by the bureau — not just the standard credit report format. Bureaus must be able to produce a comprehensive data export covering credit history, enquiry records, dispute logs, and the member institutions that have accessed the individual's data. Build a data access portal that satisfies both regulatory frameworks with a single interface.
What happens when an individual disputes inaccurate credit data?
The CIC's dispute resolution process already requires bureaus to investigate and correct inaccurate data within 30 days. DPDP reinforces this: the right to correct inaccurate personal data is a fundamental right under the Act. When a dispute is raised, the bureau must: acknowledge receipt, investigate with the reporting member institution, correct the data if the dispute is upheld, and inform the individual of the outcome. Keep a dispute register with resolution timelines for audit purposes.
How does DPDP apply to credit scoring algorithms?
Credit scoring algorithms make automated decisions that significantly affect individuals — loan approval, interest rate, credit limit. Under DPDP, individuals have the right to contest such decisions. Credit bureaus should: document the factors used in score computation; make the key factors available to individuals when they receive an adverse credit decision (e.g., high utilisation, recent defaults); and build a process for reviewing score disputes that goes beyond just correcting the underlying data to also re-running the score on corrected data.
What security obligations do credit bureaus face under DPDP?
Given the volume and sensitivity of credit data, DPDP's security safeguard requirement is demanding. Credit bureaus must: implement encryption at rest and in transit for all credit data; enforce strict member access controls (lenders should only pull data for individuals who have consented to a credit check); log every data access by member institutions; monitor for anomalous access patterns; and maintain a breach response plan that can trigger Board notification within the DPDP timeline. PCI DSS and ISO 27001 provide a reasonable security baseline.
Frequently asked questions
Can a credit bureau share individual credit data with employers for background checks?
Sharing credit data with employers for employment background checks requires the individual's explicit consent — a credit enquiry for employment purposes must be separately disclosed and consented to, distinct from a loan enquiry. The individual must understand that a credit check will be performed as part of the hiring process, who will see the results, and how it will affect the hiring decision. Pre-employment credit checks without explicit consent are likely unlawful under DPDP.
How long can credit bureaus retain credit data?
CIC regulations specify retention periods for different credit events — typically 7 years for negative information such as defaults, and shorter periods for closed accounts. DPDP's principle of storage limitation requires deletion of data beyond the statutory retention period. Bureaus should not retain indefinitely 'just in case' — implement automated data archival and deletion aligned to CIC retention rules. When retention periods are met and no ongoing dispute or legal requirement exists, data should be deleted.
Are credit bureau data security breaches covered by CERT-In?
Yes. Credit bureaus are covered by CERT-In's 6-hour mandatory breach notification requirement for cybersecurity incidents, in addition to DPDP's Board notification obligation. A breach exposing credit data triggers both. Credit bureaus should also notify affected individuals promptly, given the direct financial harm a credit data breach can cause — identity theft, fraudulent loan applications, account takeovers. Your breach response plan should run CERT-In, Board, and individual notifications in parallel.
Assess your credit bureau DPDP compliance
Niti Bharat's DPDP Readiness Assessment covers credit bureaus and scoring companies — CIC overlap, scoring algorithm explainability, data access portals, dispute management, and breach response.
Start Credit Bureau DPDP Assessment