DPDP layers on top. It does not replace sectoral law.
For financial services, DPDP is a harmonisation problem. RBI compliance alone does not make you DPDP compliant. Where regimes overlap, the stricter requirement binds.
Who it applies to, and when the clocks start
Every entity processing digital personal data in India is a Data Fiduciary. In a fintech stack, your contracts must define who is Fiduciary vs Processor.
*Role depends on your LSP and co lending agreements.
Already in force. Explicit consent with audit trail required now.
Why BFSI carries the highest exposure
One failure becomes a breach, a regulatory violation, and a trust collapse. Penalties stack per instance, on top of RBI and SEBI action for the same incident.
Dual compliance map
You cannot resolve these one regime at a time. Select a requirement to see how sectoral law, DPDP, and your net obligation align.
RBI KYC MD: ≥5 years after relationship ends. PMLA record keeping.
Erase when purpose served or consent withdrawn (Rule 8).
Retain under legal obligation. Erase non essential fields. Document field by field.
KYC, consent, and retention lifecycle
The hardest problem is KYC retention vs erasure: retain what law requires, erase everything else field by field. Consent must be a versioned product surface, not a buried checkbox.
- PAN, KYC documents (RBI ≥5 years)
- Transaction records (PMLA)
- Investor records (SEBI periods)
- App browsing behaviour
- Marketing preferences
- Non regulatory support notes
Breach response: four clocks, one trigger
A single BFSI breach fans out to four authorities on different timelines. DPDP has no 6 hour rule; that is CERT-In. Design one runbook with pre drafted templates.
Your phased programme to May 2027
Build once to the strictest standard. RBI moved your consent deadline forward; do not re engineer twice.
- 1Data inventory across fiduciary/processor chain
- 2Field level retention matrix
- 3Consent notice redesign: standalone, versioned
- 4Fiduciary vs processor in LSP contracts
- 5Device permission audit
KYC retention vs erasure+
RBI requires ≥5 years KYC retention after relationship ends. DPDP requires erasure when purpose is served. Section 7 legitimate use resolves the conflict in law: retain what statutes require, erase everything else field by field. Data lineage across backups and vendors is the technical enabler.
Consent architecture+
Not a checkbox: a product surface satisfying RBI and DPDP. Standalone notice, per purpose consent, versioned ledger, withdrawal as easy as granting. Device permission overreach (contacts, gallery) creates double exposure under RBI Digital Lending and DPDP.
Significant Data Fiduciary+
Assume you qualify if you process financial data at scale. Requires India based DPO, DPIAs, independent audits, and algorithmic due diligence for credit and fraud models. Operate SDF ready even before designation.
Cross border transfers+
DPDP is permissive; sectoral rules are not. RBI payment data must stay in India. Overseas processing deleted within 24 hours. Audit vendor storage locations: analytics and support tools often move data offshore quietly.
What auditors ask for+
Consent versions and ledger. Field level retention matrix. Rights and grievance registers. Breach drill records. Processor contracts with breach and localisation clauses. Log retention (DPDP ≥1yr, CERT-In 180 days India stored). Erasure cascade evidence.
BFSI readiness checklist
Tap each item as you complete it. Track progress toward audit ready dual compliance.
This guide reflects the DPDP Rules, 2025 (G.S.R. 846(E)), RBI Digital Lending Directions, KYC and payment data localisation, SEBI CSCRF, PMLA, and CERT-In Directions as understood at time of writing. General information only, not legal advice.