For NBFCs, lending apps, fintech and cooperative banks
DPDP compliance for NBFCs and fintech
Lending needs data, and RBI rules already tell you how to handle much of it. The DPDP Act adds a layer on top: specific consent for each purpose, limits on reuse, rights for borrowers and a 72-hour breach clock. ConsentKit fits the DPDP layer alongside your existing RBI and KYC processes.
- KYC retention
- Still as RBI and PMLA require
- Cross-selling
- Needs its own consent
- Breach report
- Within 72 hours
SwiftCredit asks for your consent
We need some data to assess and service your loan. The rest is your choice.
Where the DPDP Act touches a loan
Some data you keep because RBI or PMLA says so. Some needs the borrower’s consent. Pick a stage to see which is which.
What changes for lenders on 13 May 2027
RBI compliance does not equal DPDP compliance. These duties sit on top of what you already do.
Consent per purpose, not per agreementSections 5 and 6
Loan servicing, bureau checks, cross-selling and partner sharing are separate purposes. One signature for all of them won’t hold up.
Itemised notices in your app and journeys, with a consent record per purpose.
Collect only what the loan needsSection 6(1)
Consent is limited to data necessary for the specified purpose. Broad app permissions are hard to justify.
A purpose register that maps each data point to its use.
DSAs, agencies and partners are coveredSection 8
DSAs, collection agencies, co-lenders and tech vendors process borrower data for you. You remain responsible.
A partner register, processor contracts and consent checks before sharing.
Borrowers can ask for their dataSections 11 to 14
Borrowers can request access, correction and erasure where law allows, and file grievances.
A rights portal that respects RBI retention while handling DPDP requests.
Security and breach reportingSection 8(5) and Rules 6 and 7
Access logs kept for at least a year, and breaches reported to the Board and to borrowers, alongside CERT-In and RBI reporting.
A breach workflow that produces the DPDP report next to your other filings.
Large lenders may be Significant Data FiduciariesSection 10 and Rule 13
If notified, you need a DPO in India, annual audits and impact assessments.
Audit trail and evidence exports for your DPO and auditors.
When the law requires you to keep data
The DPDP Act does not override other laws. Where RBI, PMLA, IRDAI or tax rules require you to collect or keep records, that duty stands, and a customer’s erasure request does not remove it. What changes is that you must be clear about which data you keep for which law, and stop using it for anything else.
This is general guidance, not legal advice. Confirm how it applies to you with your counsel.
A plan that fits alongside RBI compliance
Most lenders already have KYC and grievance processes. Build the DPDP layer on top rather than from scratch.
Purpose and data inventory
Map every data point to a purpose and a basis: RBI or PMLA, contract, or consent.
Rework journeys
Split consents in app and web journeys and reduce app permissions.
Partners and DSAs
Update DSA, collection agency and co-lending contracts and add consent checks.
Rights and breach readiness
Connect rights requests to your grievance desk and rehearse breach reporting.
For every kind of lender
Templates for your lending model.
NBFCs
Branch and digital journeys, DSAs and collections.
Digital lending apps
App permissions and lending service providers.
Microfinance
Group lending and field officers.
Cooperative banks
Branch-heavy, legacy core banking systems.
Payments and wallets
Transaction data and merchant sharing.
Wealth and broking
Investor KYC and advisory data.
DPDP compliance for lenders near you
Local guidance and onboarding in these cities, with support from our team in Kolkata.
Related sectors
Questions lenders are asking
For the full picture, read our DPDP Act guide or compliance checklist.
Do RBI rules override the DPDP Act?
No, they sit side by side. Where RBI or PMLA requires you to keep data, you keep it. The DPDP Act adds consent, purpose limits, rights and breach duties on top.
Can a borrower ask us to delete their KYC?
You can refuse to erase data you must keep by law, but you should explain that, stop any other use of it and delete it when the legal period ends.
Can we cross-sell insurance to borrowers?
Only with separate consent for that purpose. It cannot be a condition of the loan.
Are our DSAs covered?
Yes. When DSAs act for you, they are your processors and you remain responsible. Bind them by contract and audit them.
Do we need a Data Protection Officer?
Only if you are notified as a Significant Data Fiduciary. Every lender must publish a contact for data questions and grievances.
Add the DPDP layer before May 2027
The readiness check takes about ten minutes and gives you a gap report built for lenders.