A lender may hold identity documents, income data, bureau reports, bank statements, device information and repayment histories across several systems and service providers. The Digital Personal Data Protection Act, 2023 and the notified DPDP Rules, 2025 create a statutory framework for how that personal data is processed and protected. The Act’s Schedule permits penalties of up to ₹250 crore for failure to take reasonable security safeguards, depending on the breach and the Board’s determination; it is not a flat penalty for every incident.
Quick answer: The DPDP Act, 2023 and DPDP Rules, 2025 apply to lenders processing digital personal data within their scope and add notice, consent, security, breach-response and data-principal obligations alongside existing RBI, KYC and anti-money-laundering requirements. The Rules commence in phases through May 13, 2027. Lenders should map the lawful basis, purpose, retention rule, system location and downstream processor for each data category before the substantive obligations take effect.
What the DPDP Act and Rules Require
The DPDP Act, 2023 received presidential assent in August 2023, but stayed largely dormant until the DPDP Rules, 2025 were notified by the Ministry of Electronics and Information Technology (MeitY) on November 13, 2025.
The Rules operationalize the Act in three phases:
- Rules 1, 2 and 17 to 21 took effect on November 13, 2025, including provisions relevant to the Board and the regulatory framework.
- Rule 4, governing Consent Manager registration and obligations, takes effect on November 13, 2026.
- Rules 3, 5 to 16, 22 and 23 take effect on May 13, 2027, including detailed notice, security, breach-response and data-principal provisions.
Once in force, the core obligations are straightforward to state and hard to operationalize:
- Consent must be free, specific, informed, unambiguous, and as easy to withdraw as it was to give.
- Data can only be used for the purpose it was collected for.
- For a personal data breach, the Data Fiduciary must inform affected Data Principals without delay, notify the Board with an initial description without delay and provide the detailed information specified by the Rules within 72 hours, unless the Board allows a longer period.
Where Lenders Sit Under the Act: Data Fiduciary, Often a Significant One
A bank, NBFC, or housing finance company processing borrower data almost always qualifies as a Data Fiduciary. Where lending platforms, credit bureaus, or collection agencies process that data on the lender’s behalf, they typically sit as Data Processors. But the accountability for lawful processing stays with the lender regardless of who touches the data.
A lender becomes a Significant Data Fiduciary only if the Central Government designates it after considering the factors in Section 10 of the Act. A designated SDF must appoint a Data Protection Officer based in India, appoint an independent data auditor and undertake periodic DPIAs and audits as prescribed. Institutions should not assume designation solely from size or use of automated decisioning.
Banks and NBFCs should monitor designation notifications and build an evidence base that can support SDF obligations if they apply, while continuing to meet the base duties relevant to all Data Fiduciaries in scope.
Where DPDP Collides With What RBI Already Requires
This is the part lending teams tend to underestimate. DPDP and RBI’s existing frameworks do not always point the same direction.
| Area | RBI requirement | DPDP requirement | The friction |
| Data retention | KYC records retained 5 years post-relationship under PMLA and KYC Master Directions | Erase data once the purpose is served or consent is withdrawn (Section 8) | Lenders need a documented legal basis for retention on every data field, not a blanket retention policy |
| Breach reporting | Applicable RBI, CERT-In and other incident-reporting duties depend on entity and incident type | Affected people and the Board notified without delay; detailed Board information within 72 hours or an allowed extension | Multiple notification duties may run in parallel; map the trigger and clock for each applicable framework |
| Consent for data sharing | Digital Lending Directions require consent for phone permissions, app-level data access | DPDP requires purpose-specific, unbundled consent for each processing activity | A bundled screen may not provide sufficient purpose-level choice or audit evidence |
| Vendor and LSP data handling | RE remains liable for LSP conduct under outsourcing rules | Data Fiduciary remains liable for Data Processor conduct under DPDP | Contracts with LSPs, KYC vendors, and collection agencies need parallel data protection clauses, not just service-level terms |
None of these are contradictions a lender can resolve by picking one regulator over the other. Both apply. The practical answer is field-level documentation: for every category of borrower data, a lender needs to know which law justifies keeping it, for how long, and under what consent basis.
What This Means for Lending Platforms and Workflows
Consent and notice at origination should be specific to the processing purpose and presented in clear language. Lenders should distinguish processing based on consent from processing supported or required by other applicable law, and keep records of the notice, consent action, withdrawal and purpose. A single bundled checkbox may not provide sufficient granularity or audit evidence for unrelated processing activities such as cross-sell.
Data mapping is the unglamorous prerequisite. Before a lender can defend a retention period or respond to an erasure request within DPDP’s mandated timelines, it needs to know where every category of borrower data lives, which system created it, and which vendor touches it downstream. Most legacy core lending systems were not built with that visibility.
Evaluation Checklist: Is Your Lending Stack DPDP-Ready?
- Can the platform capture separate, purpose-specific consent for KYC, bureau checks, cross-sell, and app permissions, rather than one bundled acceptance?
- Is there a documented legal basis, RBI retention rule or DPDP purpose, for every category of borrower data still being held?
- Can the incident workflow notify affected Data Principals and the Board without delay, then provide the detailed Board submission within 72 hours or an allowed extension?
- Do vendor and LSP contracts include data protection clauses that assign processor-level accountability, not just service terms?
- Is there a mechanism to honor a borrower’s erasure request without breaching a separate RBI retention obligation?
- If the institution is designated a Significant Data Fiduciary, can it support the required DPO, independent audit and periodic DPIA obligations?
Bottom Line
The DPDP framework does not replace RBI, KYC, anti-money-laundering or other sectoral requirements. Different duties can apply to the same data or incident. Lenders should map each data field to its purpose, lawful basis, retention rule, system owner and processor, and should map each incident type to the authorities and notification clocks that apply. Legal and compliance teams should validate the final interpretation before operational controls are deployed.
Last reviewed: September 15, 2026. This article provides general information, not legal advice. Institutions should confirm applicability, commencement and operational requirements against current official instruments and professional advice.
Frequently Asked Questions (FAQs)
Any bank, NBFC, or housing finance company that determines why and how borrower data is processed qualifies as a Data Fiduciary, regardless of size. Scale affects whether an institution is additionally designated a Significant Data Fiduciary, which adds obligations like a Data Protection Officer and mandatory audits, but the base obligations apply to lenders of every size.
No. RBI’s rules focus on security, KYC retention, and operational risk, while DPDP introduces separate requirements around consent, purpose limitation, and data principal rights. A lender can be fully RBI-compliant and still fall short on DPDP obligations like purpose-specific consent or erasure handling.
The DPDP framework allows processing to continue where it is required or authorised by law. A lender should retain only the data covered by a documented legal obligation for the required period, communicate the outcome of the request and erase other data when no lawful purpose remains, subject to legal advice.