Financial data flows need consent at every step.
NBFCs, lending platforms, and wealth apps process KYC, credit bureau data, and account-aggregator feeds across a chain of DSAs, bureaus, analytics vendors, and collection agencies. DPDP requires separate consent for each purpose and a processor contract for every link. We build that infrastructure and resolve the RBI-DPDP retention conflict in the same engagement.
Six entities. Each one a compliance touchpoint.
Digital lending is a multi-party data ecosystem. DPDP accountability follows actual control — not your contracts. Every entity that determines how personal data is used is a Fiduciary. Every entity that follows instructions is a Processor. Both need a legal basis.
Borrower / Customer
Data Principal
Data handled
Aadhaar, PAN, income, bank statements, device data
DPDP obligation
Separate consent required per purpose: KYC, bureau pull, analytics, marketing.
NBFC / Lender
Primary Data Fiduciary
Data handled
Full KYC, credit history, repayment behaviour, CRM notes, call recordings
DPDP obligation
Owns notice, consent, purpose limitation, rights fulfilment, and breach notification.
DSA / DMA
Data Processor
Data handled
Lead data, application forms, income documents
DPDP obligation
Responsibility for lawful notice and consent stays with the NBFC even when DSAs collect on your behalf.
Credit Bureau (CIBIL, Experian)
Independent Data Fiduciary
Data handled
Credit score, repayment history, enquiry logs
DPDP obligation
Customer must consent to bureau pull before it occurs. Consent record with timestamp required.
Account Aggregator
Consent Manager / Processor
Data handled
Bank statements, investment data, insurance data
DPDP obligation
Data sharing must flow through the AA framework with explicit, revocable consent from the customer.
Collection Agency
Data Processor
Data handled
Contact details, repayment schedules, NPA flags
DPDP obligation
Processor contract required. High-risk for DPDP complaints; intrusive collection practices are litigation-prone.
Five obligations. All of them are engineering problems.
Per-purpose consent across all journeys
Bundled, pre-ticked, and omnibus consent are invalid. KYC processing, credit bureau pulls, marketing, analytics, and co-lending each require a separate, affirmative consent action — and each must be independently withdrawable without blocking the core loan. We rebuild onboarding and servicing flows to capture, store, and surface purpose-specific consent at every touchpoint.
RBI and DPDP retention conflict resolution
RBI mandates five-year KYC retention. PMLA mandates five-year transaction records. DPDP grants customers the right to erasure. These frameworks conflict directly. We build a retention architecture that documents the legal basis for each data category, marks consent-withdrawn records without deleting them where regulation requires retention, and automates erasure where no such basis exists.
Processor contracts at scale
DSAs, DMAs, call centres, KYC vendors, analytics providers, and collection agencies are all processors. Each needs a written agreement covering purpose limitation, security safeguards, sub-processor disclosure, and breach cooperation. We draft, implement, and maintain these at scale — covering your entire third-party ecosystem.
Data principal rights portal
Customers have the right to access their data, correct inaccuracies, opt out of marketing, and request erasure of data beyond retention mandates. Under Rule 14, you must respond within seven days. We ship a rights portal integrated into your product that handles requests end-to-end and generates audit trails for every response.
Breach notification — 72 hours for DPDP, 2-6 hours for RBI
RBI's incident reporting window is tighter than DPDP's 72-hour Board notification requirement. Both apply. We build an incident response playbook that assumes the RBI timeline as the binding constraint and generates the documentation required for both regulators simultaneously.
Large NBFCs face a higher obligation tier.
Mid-sized NBFCs processing data of five lakh or more customers are prime candidates for SDF designation. That triggers five additional obligations on top of the base DPDP framework. We prepare you for both tiers in the same engagement.
Appoint a Data Protection Officer based in India
Commission an independent data protection audit annually
Conduct a Data Protection Impact Assessment every 12 months
Algorithmic accountability measures for credit scoring models
Stricter technical due diligence on all data processors
Questions we get from fintechs and lenders.
We already comply with RBI KYC norms. Does that satisfy DPDP?
No. RBI KYC sets requirements for identity verification, anti-money laundering, and record retention. DPDP sets requirements for consent, purpose limitation, data principal rights, and breach notification. RBI mandates a legal obligation basis for KYC processing — that holds under DPDP. But marketing, analytics, cross-sell, and bureau pulls still require separate DPDP consent. The two frameworks are additive, not substitutes.
How does co-lending affect our fiduciary status?
Where you and a co-lending partner jointly determine the purpose and means of processing — for example, in credit decisioning or customer profiling — both entities may be classified as joint Data Fiduciaries. The accountability structure follows actual control, not the contract label. A clear joint-fiduciary agreement must outline each party's obligations, rights management responsibilities, and breach liability.
What is the RBI Business Conduct Direction on consent, and does it overlap with DPDP?
The RBI NBFC Responsible Business Conduct Directions, effective July 1, 2026, require per-product explicit consent with an auditable trail and prohibit bundled or pre-ticked consent. This aligns directly with DPDP's consent requirements. The same loan origination flow must now satisfy both. We build one compliant consent architecture that serves both regulators.
Do collection agencies need processor contracts?
Yes. Collection agencies receive personal data from the NBFC to carry out recovery activities. They are processors under DPDP and require a formal data processing agreement. This is also a high-risk relationship: the DPDP Board is expected to scrutinise intrusive collection practices, and complaints here carry reputational and financial exposure.
What is the penalty exposure for a mid-sized NBFC?
Penalties under the DPDP Act can reach ₹250 crore for breach of security safeguard obligations and ₹200 crore for failure to notify a breach. Large NBFCs processing data of lakhs of customers at scale are prime candidates for Significant Data Fiduciary designation, which adds mandatory DPO, annual DPIA, and independent audit obligations on top of the base framework.
Penalties under the DPDP Act can reach ₹250 crore per violation. This engagement covers the technical and product layer of DPDP compliance. Pair it with legal counsel for complete regulatory coverage across RBI, PMLA, and DPDP obligations.