Industries/Fintech and Lending

Financial data flows need consent at every step.

NBFCs, lending platforms, and wealth apps process KYC, credit bureau data, and account-aggregator feeds across a chain of DSAs, bureaus, analytics vendors, and collection agencies. DPDP requires separate consent for each purpose and a processor contract for every link. We build that infrastructure and resolve the RBI-DPDP retention conflict in the same engagement.

SDF Risk
Large NBFCs and digital lenders likely designated
The data chain

Six entities. Each one a compliance touchpoint.

Digital lending is a multi-party data ecosystem. DPDP accountability follows actual control — not your contracts. Every entity that determines how personal data is used is a Fiduciary. Every entity that follows instructions is a Processor. Both need a legal basis.

Borrower / Customer

Data Principal

Data handled

Aadhaar, PAN, income, bank statements, device data

DPDP obligation

Separate consent required per purpose: KYC, bureau pull, analytics, marketing.

NBFC / Lender

Primary Data Fiduciary

Data handled

Full KYC, credit history, repayment behaviour, CRM notes, call recordings

DPDP obligation

Owns notice, consent, purpose limitation, rights fulfilment, and breach notification.

DSA / DMA

Data Processor

Data handled

Lead data, application forms, income documents

DPDP obligation

Responsibility for lawful notice and consent stays with the NBFC even when DSAs collect on your behalf.

Credit Bureau (CIBIL, Experian)

Independent Data Fiduciary

Data handled

Credit score, repayment history, enquiry logs

DPDP obligation

Customer must consent to bureau pull before it occurs. Consent record with timestamp required.

Account Aggregator

Consent Manager / Processor

Data handled

Bank statements, investment data, insurance data

DPDP obligation

Data sharing must flow through the AA framework with explicit, revocable consent from the customer.

Collection Agency

Data Processor

Data handled

Contact details, repayment schedules, NPA flags

DPDP obligation

Processor contract required. High-risk for DPDP complaints; intrusive collection practices are litigation-prone.

What we build

Five obligations. All of them are engineering problems.

Per-purpose consent across all journeys

DeliverableConsent flow redesign across app and web, consent ledger, purpose registry

Bundled, pre-ticked, and omnibus consent are invalid. KYC processing, credit bureau pulls, marketing, analytics, and co-lending each require a separate, affirmative consent action — and each must be independently withdrawable without blocking the core loan. We rebuild onboarding and servicing flows to capture, store, and surface purpose-specific consent at every touchpoint.

RBI and DPDP retention conflict resolution

DeliverableRetention policy, conflict resolution matrix, erasure automation

RBI mandates five-year KYC retention. PMLA mandates five-year transaction records. DPDP grants customers the right to erasure. These frameworks conflict directly. We build a retention architecture that documents the legal basis for each data category, marks consent-withdrawn records without deleting them where regulation requires retention, and automates erasure where no such basis exists.

Processor contracts at scale

DeliverableDPA templates, vendor mapping, contract execution support

DSAs, DMAs, call centres, KYC vendors, analytics providers, and collection agencies are all processors. Each needs a written agreement covering purpose limitation, security safeguards, sub-processor disclosure, and breach cooperation. We draft, implement, and maintain these at scale — covering your entire third-party ecosystem.

Data principal rights portal

DeliverableRights request portal, 7-day SLA automation, audit trail

Customers have the right to access their data, correct inaccuracies, opt out of marketing, and request erasure of data beyond retention mandates. Under Rule 14, you must respond within seven days. We ship a rights portal integrated into your product that handles requests end-to-end and generates audit trails for every response.

Breach notification — 72 hours for DPDP, 2-6 hours for RBI

DeliverableBreach runbook, dual-regulator notification templates, detection hooks

RBI's incident reporting window is tighter than DPDP's 72-hour Board notification requirement. Both apply. We build an incident response playbook that assumes the RBI timeline as the binding constraint and generates the documentation required for both regulators simultaneously.

Significant Data Fiduciary

Large NBFCs face a higher obligation tier.

Mid-sized NBFCs processing data of five lakh or more customers are prime candidates for SDF designation. That triggers five additional obligations on top of the base DPDP framework. We prepare you for both tiers in the same engagement.

Appoint a Data Protection Officer based in India

Commission an independent data protection audit annually

Conduct a Data Protection Impact Assessment every 12 months

Algorithmic accountability measures for credit scoring models

Stricter technical due diligence on all data processors

Common questions

Questions we get from fintechs and lenders.

We already comply with RBI KYC norms. Does that satisfy DPDP?

No. RBI KYC sets requirements for identity verification, anti-money laundering, and record retention. DPDP sets requirements for consent, purpose limitation, data principal rights, and breach notification. RBI mandates a legal obligation basis for KYC processing — that holds under DPDP. But marketing, analytics, cross-sell, and bureau pulls still require separate DPDP consent. The two frameworks are additive, not substitutes.

How does co-lending affect our fiduciary status?

Where you and a co-lending partner jointly determine the purpose and means of processing — for example, in credit decisioning or customer profiling — both entities may be classified as joint Data Fiduciaries. The accountability structure follows actual control, not the contract label. A clear joint-fiduciary agreement must outline each party's obligations, rights management responsibilities, and breach liability.

What is the RBI Business Conduct Direction on consent, and does it overlap with DPDP?

The RBI NBFC Responsible Business Conduct Directions, effective July 1, 2026, require per-product explicit consent with an auditable trail and prohibit bundled or pre-ticked consent. This aligns directly with DPDP's consent requirements. The same loan origination flow must now satisfy both. We build one compliant consent architecture that serves both regulators.

Do collection agencies need processor contracts?

Yes. Collection agencies receive personal data from the NBFC to carry out recovery activities. They are processors under DPDP and require a formal data processing agreement. This is also a high-risk relationship: the DPDP Board is expected to scrutinise intrusive collection practices, and complaints here carry reputational and financial exposure.

What is the penalty exposure for a mid-sized NBFC?

Penalties under the DPDP Act can reach ₹250 crore for breach of security safeguard obligations and ₹200 crore for failure to notify a breach. Large NBFCs processing data of lakhs of customers at scale are prime candidates for Significant Data Fiduciary designation, which adds mandatory DPO, annual DPIA, and independent audit obligations on top of the base framework.

Penalties under the DPDP Act can reach ₹250 crore per violation. This engagement covers the technical and product layer of DPDP compliance. Pair it with legal counsel for complete regulatory coverage across RBI, PMLA, and DPDP obligations.

Ready to build DPDP compliance into your lending product?

Take the readiness check