---
title: "DPDP Compliance Decoded: Sectoral Nuances and Regulatory Expectations"
date: 2026-09-17
author: "KM Team"
url: https://acuitylaw.co.in/dpdp-compliance-decoded-sectoral-nuances-and-regulatory-expectations/
---

# DPDP Compliance Decoded: Sectoral Nuances and Regulatory Expectations

Posted On - 17 September, 2026 • By - KM Team

![](https://acuitylaw.co.in/wp-content/uploads/2026/09/pexels-alicia-christin-gerald-1447380217-37880001-scaled-e1789644327879.jpg)

**DPDP Act: The New Privacy Playbook for BFSI**

1. **Introduction** 

The Digital Personal Data Protection Act, 2023 (“**DPDP Act**”) and the Digital Personal Data Protection Rules (“**Rules**”) mark a significant shift in India’s data protection and privacy framework. Unlike the earlier data protection regime which primarily protected limited categories of “sensitive personal data”, the DPDP Act applies to all digital personal data that can identify an individual. We have previously elaborated on the provisions of the DPDP Act and the Rules in our [**FAQs**](https://acuitylaw.co.in/faqs/understanding-digital-data-protection-in-india-key-frequently-asked-questions-faqs/), which provide an overview of the framework, including its scope and applicability.  

Building on the same, we turn to the sector-specific implications of the DPDP Act in our series titled ‘*DPDP Compliance Decoded: Sectoral Nuances and Regulatory Expectations*’. The first part of this series focuses on the Banking, Financial Services and Insurance sector (“**BFSI**”), examining how the DPDP framework impacts the collection, use, retention and sharing of personal data by BFSI entities and the key compliance considerations arising within the sector. 

The implications for BFSI are profound considering the sheer volume, sensitivity and criticality of the personal data handled by entities in this sector. BFSI entities are required to collect vast amounts of personal data under numerous regulatory regimes. For instance, in the Insurance sector, under the Master Circular on Protection of Policyholders’ Interests, 2024 by the Insurance Regulatory and Development Authority of India (**“IRDAI”**)**,** a customer is required to provide information on residence, contact details, bank account details as well as the relationship of the nominee and his/her details.  

With the implementation of the DPDP Act being notified and hefty penalties up to INR 250 crores, the central challenge for BFSI is to understand whether the DPDP Act and Rules add new obligations or supplement the existing ones and ascertaining where genuine conflicts arise.  

1. **Key Compliance Considerations for the BFSI** 

1. **What does DPDP Act add to an already heavily regulated sector?**  

The existing framework provides BFSI entities, acting as Data Fiduciaries (*entities determining the purpose and means of processing digital personal data*), the legitimate basis for collection and retention of a customer’s personal data.  

However, the DPDP Act introduces obligations that are more specific than mere collection or data, such as:  

1. **Notice is a pre-requisite to seek consent: **Section 5 of the DPDP Act requires notice to be given prior to or alongside the request to seek consent of the Data Principal (*the individual to whom the digital personal data relates*). This notice shall inform the Data Principal of the purpose for which data is collected, the manner in which she may exercise her rights etc. The notice must further provide a link to the Data Fiduciary’s website/app through which, consent can be withdrawn, rights can be exercised and complaints can be made.[1](#01a40814-53af-4017-b54a-98fe96653801)  
BFSI entities would be required to revisit and re-draft their existing privacy notices to incorporate all these protections. *For example*, instead of a bank’s website simply stating that customer information may be used “for providing banking services and other purposes”, the notice would need to identify, in an itemized manner, the categories of personal data being collected and the specific purposes for which each category is processed. 

1. **Consent to be informed, free and specific:** The requirement to obtain user consent prior to data collection by BFSI entities has long been in place. *For example*, Regulation 15 of the IRDAI (Protection of Policyholders’ Interests, Operations and Allied Matters of Insurers) Regulations, 2024, expressly recognises the compliance obligations arising under applicable data protection laws. It requires insurers, “subject to ensuring compliance as per extant law on data protection,” to maintain the information and documents collected during solicitation with the utmost confidentiality. It also prohibits insurers from sharing such information with third parties without the policyholder’s explicit consent, except in certain circumstances.    
Accordingly, insurers will need to ensure compliance with Section 6 of the DPDP Act, which requires that consent from the Data Principal to be free, specific, informed, unconditional, and unambiguous, and be evidenced through a clear affirmative action. Compliance with these requirements is likely to necessitate significant revisions to insurance policies and related documentation, as personal data may only be processed for the specific purpose for which consent has been obtained. 

1. **Right to Erasure:** Section 12 of the DPDP Act provides ‘*right to correction and erasure of personal data*’ to the Data Principal(s) and imposes a corresponding erasure obligation under Section 8(7)(a) upon the Data Fiduciary. Unless retention is necessary for compliance with any law, the digital personal data is required to be deleted once the Data Principal withdraws her consent or the purpose for which the data was collected is no longer being served. This right to correction and erasure is not provided for in the existing regulations governing data collection and retention.    
For instance, the RBI (Non-Banking Financial Companies **(“NBFC”) –** Peer to Peer Lending Platform) Directions, 2025 require the NBFC peer to peer lending platforms (most of which are financial technology (“**FinTech**”) companies), to conduct credit assessment and risk profiling of the borrowers.[2](#852fa2e8-159f-4cb2-80d1-b42c8d3a1570) While the Directions require prior explicit consent of participants to access their credit information, there is no provision for erasure of such data.    
The DPDP Act framework therefore requires BFSI entities to go a step further requiring them to assess whether continued retention of personal data remains necessary for the purpose for which it was collected or is otherwise required by applicable law. Where neither basis for continued retention exists, such personal data must be erased. 

1. **Additional safeguards for a child’s data:** A BFSI entity processing the personal data of users below 18 years must implement measures to verify age and obtain verifiable parental consent.[3](#e93c5e60-6e30-4dee-a26e-d538f30ab0f4)

1. **How does the RBI Data Guidance supplement the DPDP Act?** 

The obligations under the DPDP Act are supplemented by the RBI’s Draft Guidance on Regulatory Expectations for Data Governance (“**RBI Guidance**”), which was open for public comments until August 17, 2026.  

The RBI Guidance establishes a lifecycle-based data architecture for the governance of data by banking and financial service companies, i.e., establishing data protection mechanisms at every stage of data lifecycle (collection, processing, retention, archival, and disposal). It requires the companies to implement a Board-approved Data Governance Framework (“**DGF”**) encompassing collection and classification to storage, sharing, retention and deletion of data while assigning responsibilities to key individuals defined as: 

1. Data Function: Senior officer acting as a central point of coordination to ensure consistent interpretation and implementation of the DGF; 
2. Data Owner: Accountable for data governance, i.e., setting up policies and standards for proper use of data within their respective domain in the regulated entity; 
3. Data Steward: Assists the Data Owner in implementing day-to-day data governance processes; 
4. Data Custodian: Responsible for managing technical aspects of data such as enforcing controls relating to data transmission, storage, backup and availability.

The Guidance also mandates clear allocation of data ownership and responsibility of data protection within each domain and at every stage of the data’s lifecycle, controls over third-party data sharing, and alignment of data processing with the DPDP Act.

1. **Legacy consent: Is re-consent necessary under the DPDP Act?**

Having outlined the key compliance requirements under the DPDP Act applicable to BFSI entities, a key question arises: what happens to the vast amounts of personal data that these entities have already collected over several decades and continue to hold? Must BFSI entities obtain fresh consent from existing customers before continuing to process such legacy data under the DPDP Act framework? 

Section 5(2) of the DPDP Act provides that where consent has been given before the date of commencement of the DPDP Act, only a fresh notice regarding (i) the purpose for which the personal data is processed, (ii) the manner in which Data Principal may exercise her rights, and (iii) the manner in which the Data Principal may make a complaint to the Data Protection Board of India, as soon as practicable. Thus, the Data Fiduciary may continue to process the personal data until the Data Principal withdraws her consent.[4](#757dac98-a63e-404a-9c9b-8df4f8032597)

1. **Can mandatory KYC data be used for cross-selling?** 

A recurring issue under the DPDP Act is whether personal data collected pursuant to a legal obligation, such as KYC information, can subsequently be used for commercial purposes, including cross-selling loans, insurance products or other financial services. KYC information is collected by BFSI to satisfy regulatory obligations arising under various acts, as enumerated in the previous sections. Using that same dataset to market insurance, wealth products, loans or partner offerings is a different purpose and thus falls foul of purpose-based data collection as envisaged under DPDP Act and explained in the previous sections.  

BFSI entities should therefore segregate datasets collected to meet mandatory regulatory requirements from those used for marketing and promotional purposes. Where personal data is sought to be used for marketing or other optional commercial purposes, the notice should provide an option to the customers to opt in or opt out of such usage without impairing their access to core financial services. 

1. **How are Data Fiduciary responsibilities allocated within the UPI and multi-party ecosystem?** 

The Unified Payments Interface (“**UPI**”) ecosystem presents a unique challenge under the DPDP Act because a single transaction involves multiple entities, including the payer’s bank, the payment service provider (“**PSP**”), the National Payments Corporation of India (“**NPCI**”), the beneficiary’s bank and numerous consent managers.    
*For example:* a UPI transaction may involve the payer’s app (such as PhonePe, Google Pay or Paytm), the payer’s bank, the payee’s bank and NPCI.  

Any fintech entity that determines the purpose and means of processing personal data will qualify as a Data Fiduciary under the DPDP Act. This may include digital lending platforms that determine what borrower information to collect for credit assessment, payment aggregators that process merchant and transaction data, UPI-enabled applications that process users’ payment information, neobanks that handle KYC and transaction data, and insurance technology platforms that process personal data for underwriting. Even a fintech operating as a technology intermediary may qualify as a Data Fiduciary where it exercises independent control over how personal data is processed rather than merely processing the data on the instructions of another entity. 

The volume and frequency of data processed within the UPI ecosystem make fintech entities particularly exposed to the DPDP Act’s compliance requirements. Each entity will need to identify what personal data it collects, the purpose and legal basis for processing it, the third parties with whom it is shared, how long it is retained, and the safeguards used to protect it. These requirements will, however, differ depending on the volume and purpose of data collection. A neobank, lending platform, payment gateway, and wealth management platform may each collect different categories of user data for varied purposes and, consequently, be subject to distinct regulatory requirements and DPDP Act compliance risks. 

Importantly, while banks can rely on statutory and regulatory obligations for a substantial portion of their processing activities, fintechs and other non-bank payment intermediaries generally have fewer such exemptions and are therefore significantly more dependent on obtaining valid consent for their processing activities. 

1. **Can the RBI’s Account Aggregator framework coexist with the DPDP Act’s Consent Manager?** 

The RBI Account Aggregator (“**AA**”) framework under RBI NBFC-Account Aggregator Directions, 2025 creates a consent-based financial data sharing infrastructure under which customers can share their financial data (bank statements, insurance policies, tax data) with financial information users (lenders, insurers, wealth managers) through a licensed AA. The framework has its own consent architecture, consent lifecycle management, and consent withdrawal mechanism and imposes obligations on the AAs to protect customer’s data, disclose purpose of collecting information under the consent artefact and inform the customers of their right to file complaints. 

The DPDP Act introduces a parallel concept: Consent Managers, as defined under Section 2(g) of the DPDP Act, are entities registered with the Data Protection Board that enable Data Principals to give, withdraw, review, and manage consent across multiple Data Fiduciaries. The Rules set minimum technical and governance requirements for Consent Managers. 

The critical question is whether the AA (already a functional consent infrastructure for financial data) can or will be recognised as a Consent Manager under the DPDP Act or whether BFSI entities will need to build a separate consent layer alongside the AA infrastructure. Currently, no formal notification has been announced as to how compliance with AA and Consent Manager frameworks will be streamlined  

1. **Can credit bureaus collect more data for better credit scoring? ** 

Credit information companies and lenders process significant volumes of personal data for credit assessment, risk scoring, and credit reporting. Where the collection and reporting of credit information is mandated under the Credit Information Companies (Regulation) Act, 2005 (“**CICRA**”) and other applicable laws, processing may be undertaken based on the legal obligation under Section 7 of the DPDP Act without requiring the Data Principal’s consent.  

However, the use of behavioural, alternative or other non-traditional data to enhance credit scores or underwriting models must be assessed against the principles of purpose limitation and data minimisation. Under the DPDP Act, data minimisation is evaluated with reference to the specified purpose of processing rather than an obligation to collect the least amount of data possible. Accordingly, while personal data necessary for assessing creditworthiness may be processed, lenders and credit bureaus would have to  demonstrate why each category of data is necessary and identify an appropriate legal basis for processing non-mandatory inputs. 

Credit bureaus are also likely to be designated as Significant Data Fiduciaries under Section 10 of the DPDP Act, given the volume and sensitivity of personal data they process. Consequently, they will be subject to enhanced compliance obligations as enumerated under Rule 13. This includes Data Protection Impact Assessments, independent audits and due diligence to,ascertain compliance with the DPDP Act.  

1. **DPDP Act Readiness Roadmap for the BFSI Sector** 

To ensure compliance with the DPDP Act, BFSI entities may adopt a structured approach: 

*Step 1: Map Personal Data:* Conduct a data mapping exercise to identify all categories of all digital personal data collected and processed.  

*Step 2: Segregate Mandatory and Commercial Data:* Classify the purpose for collection of digital personal data into two categories, (1) compliance with statutory obligations; and (2) data used for business functions like analytics, profiling, marketing, cross-selling etc. 

*Step 3: Review Legacy Data:* Review digital personal data collected under notices and other documents before the commencement of the DPDP Act.  

*Step 4: Consent:* Where the above-mentioned steps conclude that digital personal data is being processed for a purpose for which the Data Principal has not given her consent or consent is in derogation of the DPDP Act framework, draft new notices to seek fresh consent.  

*Step 5: Review Third-Party Arrangements:* Evaluate contracts with cloud service providers, credit bureaus, fintech partners, payment service providers and other data processors to regulate sharing of digital personal data with such third parties. 

*Step 6: Implement Board-Level Policy:* Implement a Board-level policy that encompasses data protection framework, retention and erasure obligations, data monitoring and sharing mechanisms, etc, and review the policy periodically. 

*Step 7: Update Privacy Notices:* Update privacy notices to clearly disclose the categories of personal data collected, purposes of processing, third-party disclosures, retention practices, grievance redressal mechanisms and the rights available to Data Principals as prescribed under the Rules. 

1. **Conclusion** 

With the rapid digitisation of BFSI services in India, compliance with data protection regulations has assumed increasing significance for BFSI entities. The sector has traditionally operated within a highly regulated framework, and the DPDP Act now adds another layer of regulation governing the collection, use, sharing, retention and protection of personal data. 

For BFSI entities, DPDP Act readiness therefore requires a structured approach: identifying what data is held and why, mapping the legal basis for each processing activity, separating regulatory from commercial uses, reviewing legacy consent and notices and establishing appropriate retention and erasure mechanisms. The interaction between these regimes will be particularly important in areas such as KYC, cross-selling, digital lending, UPI, Account Aggregators, and credit reporting, where multiple entities and regulatory obligations may apply to the same dataset.  

Ultimately, the practical question for BFSI entities is no longer simply “Can we collect this data?”, but “Why are we collecting it, what are we using it for, who else is the personal data shared with, how long do we need it, and when must we delete it?” A comprehensive DPDP Act compliance policy will require BFSI entities to address these questions at each stage of the data lifecycle while continuing to meet their existing statutory and regulatory obligations. This makes DPDP Act readiness an opportunity to build a more structured, accountable, and sustainable data-governance framework across the BFSI sector. 

**Extending the Conversation: Webinar on DPDP Act ** 

In a [webinar](https://acuitylaw.co.in/webinar-indias-dpdpa-sectoral-analysis-of-bfsi-healthcare-entertainment-gccs/) held on 29 July 2026, Acuity Law, in association with Legal 500, explored the practical impact of the DPDP Act and shared sector-specific insights to help organisations navigate the new framework with confidence. 

**Contributors & Disclaimer**

**Authors: **Souvik Ganguly and Srividya M S

For any queries or further engagement on the matters discussed in this paper, please reach out to Acuity Law at [*[email protected]*](/cdn-cgi/l/email-protection#c7868b87a6a4b2aeb3beaba6b0e9a4a8e9aea9).

***The information contained in this document is not legal advice or legal opinion. The contents recorded in the said document are for informational purposes only and should not be used for commercial purposes. Acuity Law LLP disclaims all liability to any person for any loss or damage caused by errors or omissions, whether arising from negligence, accident, or any other cause.*** 

1. Rule 3 of the DPDP Rules, 2025. [↩︎](#01a40814-53af-4017-b54a-98fe96653801-link)
2. Direction 23 of RBI (Non-Banking Financial Companies- Peer to Peer Lending Platform) Directions, 2025. [↩︎](#852fa2e8-159f-4cb2-80d1-b42c8d3a1570-link)
3. Section 9 of the DPDP Act. [↩︎](#e93c5e60-6e30-4dee-a26e-d538f30ab0f4-link)
4. Section 5(2)(b) of the DPDP Act [↩︎](#757dac98-a63e-404a-9c9b-8df4f8032597-link)

---

## Acuity Law

- Website: https://acuitylaw.co.in
- Contact: richagotech@gmail.com
