Data Privacy in Lending: The DPDP Act and What It Means for Lenders

September 18, 2026

Table of Contents

A lender may hold identity documents, income data, bureau reports, bank statements, device information and repayment histories across several systems and service providers. The Digital Personal Data Protection Act, 2023 and the notified DPDP Rules, 2025 create a statutory framework for how that personal data is processed and protected. The Act’s Schedule permits penalties of up to ₹250 crore for failure to take reasonable security safeguards, depending on the breach and the Board’s determination; it is not a flat penalty for every incident.

Quick answer: The DPDP Act, 2023 and DPDP Rules, 2025 apply to lenders processing digital personal data within their scope and add notice, consent, security, breach-response and data-principal obligations alongside existing RBI, KYC and anti-money-laundering requirements. The Rules commence in phases through May 13, 2027. Lenders should map the lawful basis, purpose, retention rule, system location and downstream processor for each data category before the substantive obligations take effect.

What the DPDP Act and Rules Require

The DPDP Act, 2023 received presidential assent in August 2023, but stayed largely dormant until the DPDP Rules, 2025 were notified by the Ministry of Electronics and Information Technology (MeitY) on November 13, 2025.

The Rules operationalize the Act in three phases:

  • Rules 1, 2 and 17 to 21 took effect on November 13, 2025, including provisions relevant to the Board and the regulatory framework.
  • Rule 4, governing Consent Manager registration and obligations, takes effect on November 13, 2026.
  • Rules 3, 5 to 16, 22 and 23 take effect on May 13, 2027, including detailed notice, security, breach-response and data-principal provisions.

Once in force, the core obligations are straightforward to state and hard to operationalize:

  • Consent must be free, specific, informed, unambiguous, and as easy to withdraw as it was to give.
  • Data can only be used for the purpose it was collected for.
  • For a personal data breach, the Data Fiduciary must inform affected Data Principals without delay, notify the Board with an initial description without delay and provide the detailed information specified by the Rules within 72 hours, unless the Board allows a longer period.

Where Lenders Sit Under the Act: Data Fiduciary, Often a Significant One

A bank, NBFC, or housing finance company processing borrower data almost always qualifies as a Data Fiduciary. Where lending platforms, credit bureaus, or collection agencies process that data on the lender’s behalf, they typically sit as Data Processors. But the accountability for lawful processing stays with the lender regardless of who touches the data.

A lender becomes a Significant Data Fiduciary only if the Central Government designates it after considering the factors in Section 10 of the Act. A designated SDF must appoint a Data Protection Officer based in India, appoint an independent data auditor and undertake periodic DPIAs and audits as prescribed. Institutions should not assume designation solely from size or use of automated decisioning.

Banks and NBFCs should monitor designation notifications and build an evidence base that can support SDF obligations if they apply, while continuing to meet the base duties relevant to all Data Fiduciaries in scope.

Where DPDP Collides With What RBI Already Requires

This is the part lending teams tend to underestimate. DPDP and RBI’s existing frameworks do not always point the same direction.

AreaRBI requirementDPDP requirementThe friction
Data retentionKYC records retained 5 years post-relationship under PMLA and KYC Master DirectionsErase data once the purpose is served or consent is withdrawn (Section 8)Lenders need a documented legal basis for retention on every data field, not a blanket retention policy
Breach reportingApplicable RBI, CERT-In and other incident-reporting duties depend on entity and incident typeAffected people and the Board notified without delay; detailed Board information within 72 hours or an allowed extensionMultiple notification duties may run in parallel; map the trigger and clock for each applicable framework
Consent for data sharingDigital Lending Directions require consent for phone permissions, app-level data accessDPDP requires purpose-specific, unbundled consent for each processing activityA bundled screen may not provide sufficient purpose-level choice or audit evidence
Vendor and LSP data handlingRE remains liable for LSP conduct under outsourcing rulesData Fiduciary remains liable for Data Processor conduct under DPDPContracts with LSPs, KYC vendors, and collection agencies need parallel data protection clauses, not just service-level terms

None of these are contradictions a lender can resolve by picking one regulator over the other. Both apply. The practical answer is field-level documentation: for every category of borrower data, a lender needs to know which law justifies keeping it, for how long, and under what consent basis.

Consent and notice at origination should be specific to the processing purpose and presented in clear language. Lenders should distinguish processing based on consent from processing supported or required by other applicable law, and keep records of the notice, consent action, withdrawal and purpose. A single bundled checkbox may not provide sufficient granularity or audit evidence for unrelated processing activities such as cross-sell.

Data mapping is the unglamorous prerequisite. Before a lender can defend a retention period or respond to an erasure request within DPDP’s mandated timelines, it needs to know where every category of borrower data lives, which system created it, and which vendor touches it downstream. Most legacy core lending systems were not built with that visibility.

Evaluation Checklist: Is Your Lending Stack DPDP-Ready?

  • Can the platform capture separate, purpose-specific consent for KYC, bureau checks, cross-sell, and app permissions, rather than one bundled acceptance?
  • Is there a documented legal basis, RBI retention rule or DPDP purpose, for every category of borrower data still being held?
  • Can the incident workflow notify affected Data Principals and the Board without delay, then provide the detailed Board submission within 72 hours or an allowed extension?
  • Do vendor and LSP contracts include data protection clauses that assign processor-level accountability, not just service terms?
  • Is there a mechanism to honor a borrower’s erasure request without breaching a separate RBI retention obligation?
  • If the institution is designated a Significant Data Fiduciary, can it support the required DPO, independent audit and periodic DPIA obligations?

Bottom Line

The DPDP framework does not replace RBI, KYC, anti-money-laundering or other sectoral requirements. Different duties can apply to the same data or incident. Lenders should map each data field to its purpose, lawful basis, retention rule, system owner and processor, and should map each incident type to the authorities and notification clocks that apply. Legal and compliance teams should validate the final interpretation before operational controls are deployed.

Last reviewed: September 15, 2026. This article provides general information, not legal advice. Institutions should confirm applicability, commencement and operational requirements against current official instruments and professional advice.


Frequently Asked Questions (FAQs)

Any bank, NBFC, or housing finance company that determines why and how borrower data is processed qualifies as a Data Fiduciary, regardless of size. Scale affects whether an institution is additionally designated a Significant Data Fiduciary, which adds obligations like a Data Protection Officer and mandatory audits, but the base obligations apply to lenders of every size.

No. RBI’s rules focus on security, KYC retention, and operational risk, while DPDP introduces separate requirements around consent, purpose limitation, and data principal rights. A lender can be fully RBI-compliant and still fall short on DPDP obligations like purpose-specific consent or erasure handling.

The DPDP framework allows processing to continue where it is required or authorised by law. A lender should retain only the data covered by a documented legal obligation for the required period, communicate the outcome of the request and erase other data when no lawful purpose remains, subject to legal advice.

Let's talk!

left-container

Ready to transform lending

Let's discuss how Uncia can accelerate your institution's lending capabilities

Please share your details so we can get back to you soon.