What does DPDP mean for fintechs and NBFCs?
RBI + DPDP = a two-layer compliance stack. Here's what fintechs actually need to do.
The RBI + DPDP convergence
RBI's recent Digital Lending and BCSDIR circulars already require itemised consent, secure storage, and breach notification. DPDP reinforces this and adds Data Protection Board oversight, penalties up to ₹250 crore, and explicit rights (access, erasure, correction). Fintechs must assume they are SDFs and plan for Board-level scrutiny.
Consent and retention in lending
Loan applications capture PAN, Aadhaar, credit history and bank statements. DPDP requires granular consent for each processing step (KYC, credit scoring, credit bureau sharing). After loan closure or rejection, retention limits are tight — RBI expects data deletion within prescribed periods. A retention policy that marries RBI timelines with DPDP minimisation is essential.
Vendor risk and credit bureaus
Credit bureaus, payment processors and third-party KYC vendors are your weakest link. You must have Data Processing Agreements with all of them, audit their safeguards, and control sub-processor chains. RBI expects you to vet bureau data quality and DPDP holds you accountable for their breach.
Frequently asked questions
Am I definitely an SDF if I'm a fintech?
Probably. SDFs are large-scale data processors or hold sensitive data at scale. Most fintechs meet the definition, though the Board may clarify thresholds. Assume SDF obligations and plan accordingly.
Can I retain loan application data indefinitely?
No. RBI expects deletion after a period (varies by product); DPDP demands proportionality. Retain only what a purpose requires and document your retention schedule.
What vendor compliance do I need to audit?
You are accountable for processors' security, breach response and data handling. Audit their ISO27001 status, breach history and sub-processors at least annually.
Score your fintech readiness
Run the DPDP for Fintech guide to map lending workflows against DPDP and RBI rules.
DPDP for Fintech