All articles
ComplianceEpisode 5 of 5, finale· 20 min read
DPDP Rules 2025 for Fintech, BFSI & NBFC

DPDP Rules 2025 Episode 5: SDF Readiness, DPO, DPIA, Independent Audit & Algorithmic Accountability

A credit model that is statistically sound but disadvantages a demographic group now carries privacy risk, not just model risk. Rule 13, FREE-AI, and Regulation 16C.

AS
Ankita Sharma
Talk to an expert
₹150 Cr
SDF penalty head
Stacks on ₹250 Cr + ₹200 Cr
5
Extra duties
DPO · auditor · DPIA · report · algorithms
10%
Bias protocols
Of AI-using REs in RBI FREE-AI survey
16C
SEBI already binds
You own AI output, including vendors

Your credit model works. Approval rates are up, delinquency is down, the risk team is happy, and the board deck shows a clean AUC. Nobody has any complaints.

Then someone asks a question nobody in the room can answer: can you demonstrate that this model does not pose a risk to the rights of the people it decides on?

Across Episodes 1 to 4 we built the base: the law and how it collides with RBI and SEBI; continuous governance; the retention register; the four-clock breach runbook. This episode is about the tier above , and the single most under-prepared obligation in Indian financial services.

What an SDF is, and the first mistake everyone makes

Under Section 10(1), the Central Government may notify a Data Fiduciary, or an entire class of Data Fiduciaries, as a Significant Data Fiduciary, based on factors including:

01Volume and sensitivity of personal data processed
02Risk to the rights of Data Principals
03Potential impact on the sovereignty and integrity of India
04Risk to electoral democracy, security of the State, and public order

Any one factor can be enough. They are not cumulative.

The first mistake: assuming you designate yourself. You do not. SDF status is conferred only by a Central Government notification under Section 10(1). At the time of writing, no SDF list or class has been notified. That is not a reprieve. It means the designation, when it lands, lands on your existing systems.

Financial institutions process exactly the combination the section is written around , very high volume, high sensitivity, and direct impact on individuals' rights. The rational posture is to operate SDF-ready without waiting: the obligations take time to build, and most of it is converging on you anyway through RBI and SEBI.

The five obligations

Section 10(2) and Rule 13 impose five duties on an SDF, over and above everything in Episodes 1 to 4. Plus a conditional sixth: targeted localisation under Rule 13(4).

1
India-based DPOSection 10(2)(a)

Appoint a Data Protection Officer based in India, responsible to the Board.

2
Independent data auditorSection 10(2)(b)

Appoint an independent data auditor to evaluate compliance with the Act.

3
Annual DPIA and auditRule 13(1)

Undertake a DPIA and an audit once every twelve months from designation.

4
Report significant observationsRule 13(2)

Furnish significant DPIA and audit observations to the Data Protection Board.

5
Algorithmic due diligenceRule 13(3)

Verify algorithmic software is not likely to pose a risk to Data Principals' rights.

Breach of an SDF's additional obligations attracts up to ₹150 crore, a separate head from the ₹250 crore (safeguards) and ₹200 crore (breach notification) ceilings. They stack.

The DPO, the appointment most organisations get wrong

The DPO must be based in India, responsible to the Board, represent the SDF under the Act, and be the point of contact for grievance redressal. Three errors recur:

Error 01
A non-resident DPO

Fails the statutory test outright. Common in multinational banks and foreign-owned NBFCs running a global privacy function.

Error 02
An outsourced or vendor DPO

The role is a representative office with Board accountability, it does not sit comfortably with a third party on a retainer.

Error 03
DPO and auditor as the same person or firm

They must be separate; the auditor must be independent. Your DPO cannot audit their own programme.

Rule 9 requires every Data Fiduciary, not just SDFs, to publish the business contact information of the DPO (or a person able to answer processing questions) on its website or app and in every notice and response. A generic support@ address with no named contact is a live gap today.

The independent data auditor

Section 10(2)(b) requires an independent data auditor to evaluate compliance with the Act. Use the governance model your Board already understands: IS Audit under ITGRCA , risk-based, independent of the function being audited, policy approved by the Audit Committee.

Scope covers consent, notice, purpose limitation, retention and erasure, rights fulfilment, breach handling, security safeguards, processor governance, and algorithmic due diligence.

Under Rule 13(2), significant observations go to the Data Protection Board, from the auditor. This is proactive disclosure. An SDF cannot afford an audit finding it has no remediation plan for. The finding and the plan should arrive together.

The DPIA, annual, not one-time

A DPIA is a structured process: rights of Data Principals, purpose of processing, and assessment and management of risk to those rights. Rule 13(1) is explicit: once every twelve months from designation. Not once. Annually, on the clock.

What a BFSI DPIA must actually cover
01Every processing activity, mapped to purpose, onboarding, KYC, underwriting, servicing, collections, fraud, marketing, analytics
02The lawful basis per activity, including where you rely on legal obligation rather than consent
03Risks to rights, not risks to the business. Wrong framing produces an operational risk register that fails on its face
04The full data-sharing chain, LSPs, co-lenders, bureaus, Account Aggregators, collections, KYC vendors
05Automated decision-making, which decisions about people are made or materially influenced by a model
06Mitigations, with owners and dates

Run a DPIA before you launch, not just annually. The Rules do not mandate a pre-processing DPIA, but a new credit model, co-lending partner, or data source is exactly when risk enters the system. Discovering it eleven months later is an expensive way to find out.

Rule 13(3), algorithmic due diligence. This is the one.

An SDF shall observe due diligence to verify that algorithmic software deployed by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data are not likely to pose a risk to the rights of Data Principals.

This is the first provision in Indian law to explicitly mandate due diligence on algorithmic and AI/ML systems processing personal data. A rule, in the Gazette, with a ₹150 crore penalty head behind it. And it is the obligation Indian financial services is least prepared for, because RBI measured it.

RBI already surveyed you, FREE-AI, 13 August 2025

REs deploying AI in production20.8%
NBFCs (of 171 surveyed) using AI in some form27%
Entities with board-level AI oversight~one-third, mainly large banks
Of 127 AI-using entities: validated for bias and fairness35%, mostly only at early development
Had bias mitigation protocols10%
Maintained audit logs for AI systems18%
Monitored for data or model drift21%
Conducted real-time performance monitoring14%
Used interpretability tools15%
15.6%
Customer support
13.7%
Credit underwriting
11.8%
Sales and marketing
10.6%
Cybersecurity

Credit underwriting is the second-largest AI use case in Indian finance, and 90% of entities using AI have no bias mitigation protocol. That is the gap Rule 13(3) is about to be enforced against.

A model can be statistically sound and still pose a risk to rights

Accuracy is not fairness. A model that maximises AUC by learning that applicants from certain pincodes, devices, phone-number series or employer categories default more often may be statistically correct and simultaneously a proxy for caste, religion, region, or gender. The model never sees the protected attribute. It does not need to. It reconstructs it. That is proxy discrimination, and alternative-data sources Indian fintech relies on are unusually rich in those proxies.

FREE-AI is advisory, not binding. But it is the clearest signal of where RBI supervision is heading. Building to it now is cheap. Retrofitting after a Master Direction is not.

If you are SEBI-regulated, this is already binding

Regulation 16C (SEBI Intermediaries Amendment, 10 February 2025): a regulated entity using AI/ML, whether in-house or procured, irrespective of scale, is solely responsible for the privacy, security and integrity of data, and for the output of those tools. "The vendor's model did it" is not a defence.

Three regulators, three instruments, one destination: you must be able to show that your models are governed, tested for bias, explainable, monitored, and owned by a named human being.

What an algorithmic due-diligence file contains

Model inventory entry

Name, owner, version, purpose, deployment date, in-house vs procured

Two collisions from earlier episodes: erasure of training data (Episode 3) and purpose limitation when fraud data trains a collections model (Episode 2). Silence is the worst answer to either.

Rule 13(4), targeted localisation, not blanket localisation

Not universal localisation

Only categories the Government specifies. All other personal data follows the general cross-border rule. Reading Rule 13(4) as blanket localisation is a common and expensive error.

Traffic data is included

Metadata about the flow, not just the data itself. That reaches your logging, monitoring and observability stack, not just your database.

RBI and SEBI already bind harder

Payment-data localisation and SEBI data-residency expectations are stricter and already in force. Rule 13(4) is an additional layer, not a replacement.

The six SDF mistakes

01

Assuming you self-designate. Only a Central Government notification under Section 10(1) confers SDF status.

02

A non-resident or vendor DPO. Fails Section 10(2)(a).

03

DPO and data auditor as one appointment. They must be separate; the auditor must be independent.

04

A one-time DPIA. Rule 13(1) requires a fresh one every twelve months.

05

Ignoring Rule 13(3). Algorithmic due diligence applies to scoring models, fraud engines, ranking systems, any automated system processing personal data.

06

Reading Rule 13(4) as blanket localisation. It is targeted, category-specific.

The 12-month SDF-readiness plan

Against a 13 May 2027 commencement for the SDF regime, a twelve-month build started now finishes with time to spare. Started in 2027, it does not finish at all.

0%

The argument for doing this even if you are never designated

RBI is heading here regardless

FREE-AI's recommendations, board-approved AI policy, lifecycle governance, independent validation, AI incident reporting, annual-report disclosures, are advisory today and plausibly Master Direction material tomorrow.

SEBI is already here

Regulation 16C makes you solely liable for AI outputs, including procured models. Today.

Enterprise customers and bank partners will ask

Model governance is entering vendor due-diligence questionnaires. An evidenced answer closes deals faster than a promise.

A model you cannot explain is a model you cannot defend

To a regulator, to a court, or to a customer who was declined. Explainability for Rule 13(3) is the same explainability you will want the first time a lending decision is challenged.

It is genuinely good risk management

Drift monitoring, bias testing and audit logs are things a well-run credit function should want anyway. Rule 13(3) is mostly asking you to do what you already claim you do.

The series, in one line

DPDP does not ask whether you have controls. It asks whether you can prove they work, on a timeline, in a format your regulator accepts.

How Bugmetrics helps
  • Map DPDP Rule 13, RBI ITGRCA, SEBI CSCRF, CERT-In, ISO 27001 and SOC 2 onto one control backbone
  • Collect DPIA and audit evidence continuously, annual cycle as review, not scramble
  • Track model governance as live state: inventory, bias testing, drift, explainability, vendor due diligence
  • Produce a Cyber Maturity Score substantiated by linked evidence, because a score an auditor cannot verify is worse than none at all

Compliance stopped being a document exercise. It is an evidence exercise. That is the whole story.

Sources: DPDP Act, 2023 (Sections 10, and the Schedule for penalties) and DPDP Rules, 2025 (G.S.R. 846(E), 13 Nov 2025), particularly Rules 9 and 13; RBI FREE-AI Committee Report, "Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector," 13 August 2025 (advisory, not binding); RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023; SEBI (Intermediaries) (Amendment) Regulations, 2025 (notified 10 February 2025, inserting Regulation 16C) and parallel SECC and Depositories amendments (binding); SEBI AI/ML reporting circulars, 2019; and SEBI's Consultation Paper on guidelines for responsible usage of AI/ML in Indian securities markets, 20 June 2025 (a proposal, not yet binding).

At the time of writing, no Significant Data Fiduciary has been notified under Section 10(1). Obligations vary by entity class and the regulatory position on AI is moving quickly , verify against the primary instrument applicable to your entity before relying on any of this. General information only; not legal advice.

See how Bugmetrics turns SDF readiness into evidence

One control library. Continuous DPIA evidence. Model governance as live state, not a spreadsheet that ages badly.

Book a demo

Or explore Bugmetrics for Fintech & BFSI

Keep reading

Episode 4 · 18 min

Breach readiness & the four-clock incident runbook

Episode 3 · 16 min

Data retention & deletion for BFSI: the field-level register

Episode 1 · 12 min

DPDP Rules 2025: The Dual Compliance Playbook