All articles
Compliance12 min read· Interactive guide

DPDP Rules 2025 for Fintech, BFSI & NBFCs: The Dual Compliance Playbook

For banks, NBFCs, digital lenders, payment aggregators, wealthtech and broking firms. Explore timelines, compliance maps, breach clocks, and a readiness checklist you can track as you go.

AS
Ankita Sharma
Talk to an expert
5
Regimes to harmonise
DPDP · RBI · SEBI · PMLA · CERT-In
₹250Cr
Max DPDP penalty
Per security failure instance
6h
Tightest breach clock
CERT-In from detection
May '27
Full DPDP regime
RBI consent already live

DPDP layers on top. It does not replace sectoral law.

For financial services, DPDP is a harmonisation problem. RBI compliance alone does not make you DPDP compliant. Where regimes overlap, the stricter requirement binds.

Compliance stackTop = newest · Bottom = base
1
DPDP Rules 2025Newest
Consent, rights, erasure, breach to DPB
2
RBI / Digital Lending
KYC, consent audit trail, localisation
3
SEBI CSCRF
Cyber framework for market entities
4
PMLA
Transaction record keeping
5
CERT-InBase
6h incident reporting, log retention

Who it applies to, and when the clocks start

Every entity processing digital personal data in India is a Data Fiduciary. In a fintech stack, your contracts must define who is Fiduciary vs Processor.

Data sharing chain
Regulated lender
Fiduciary
Technology LSP
Processor*
Co lending bank
Joint*
Credit bureau
Processor
Collections agent
Processor

*Role depends on your LSP and co lending agreements.

Deadline map (click a milestone)

Already in force. Explicit consent with audit trail required now.

Why BFSI carries the highest exposure

One failure becomes a breach, a regulatory violation, and a trust collapse. Penalties stack per instance, on top of RBI and SEBI action for the same incident.

Sensitive data concentration
Identity92% exposure weight
PAN, Aadhaar eKYC, photographs
Financial88% exposure weight
Statements, scores, repayments
Behavioural74% exposure weight
Device, location, call logs
DPDP maximum penalties (₹ crore)
Security safeguards250 Cr
Breach notification200 Cr
Children's data200 Cr
Other violations50 Cr

Dual compliance map

You cannot resolve these one regime at a time. Select a requirement to see how sectoral law, DPDP, and your net obligation align.

Sectoral (RBI / SEBI / PMLA)

RBI KYC MD: ≥5 years after relationship ends. PMLA record keeping.

DPDP position

Erase when purpose served or consent withdrawn (Rule 8).

Net obligation

Retain under legal obligation. Erase non essential fields. Document field by field.

KYC, consent, and retention lifecycle

The hardest problem is KYC retention vs erasure: retain what law requires, erase everything else field by field. Consent must be a versioned product surface, not a buried checkbox.

Retention lifecycleScroll →
1Collect
2Purpose tag
3Store in India
4Monitor
5Legal hold
6Retain
7Erase
8Log
✓ Retain (legal obligation)
  • PAN, KYC documents (RBI ≥5 years)
  • Transaction records (PMLA)
  • Investor records (SEBI periods)
✕ Erase when permissible
  • App browsing behaviour
  • Marketing preferences
  • Non regulatory support notes

Breach response: four clocks, one trigger

A single BFSI breach fans out to four authorities on different timelines. DPDP has no 6 hour rule; that is CERT-In. Design one runbook with pre drafted templates.

6h
CERT-In
9 field initial cyber incident report
2 to 6h
RBI / SEBI
Sectoral cyber incident report
ASAP
DPB + users
Intimation without delay
72h
DPB
Detailed breach report

Your phased programme to May 2027

Build once to the strictest standard. RBI moved your consent deadline forward; do not re engineer twice.

  • 1Data inventory across fiduciary/processor chain
  • 2Field level retention matrix
  • 3Consent notice redesign: standalone, versioned
  • 4Fiduciary vs processor in LSP contracts
  • 5Device permission audit
Deep dives (expand for detail)
KYC retention vs erasure+

RBI requires ≥5 years KYC retention after relationship ends. DPDP requires erasure when purpose is served. Section 7 legitimate use resolves the conflict in law: retain what statutes require, erase everything else field by field. Data lineage across backups and vendors is the technical enabler.

Consent architecture+

Not a checkbox: a product surface satisfying RBI and DPDP. Standalone notice, per purpose consent, versioned ledger, withdrawal as easy as granting. Device permission overreach (contacts, gallery) creates double exposure under RBI Digital Lending and DPDP.

Significant Data Fiduciary+

Assume you qualify if you process financial data at scale. Requires India based DPO, DPIAs, independent audits, and algorithmic due diligence for credit and fraud models. Operate SDF ready even before designation.

Cross border transfers+

DPDP is permissive; sectoral rules are not. RBI payment data must stay in India. Overseas processing deleted within 24 hours. Audit vendor storage locations: analytics and support tools often move data offshore quietly.

What auditors ask for+

Consent versions and ledger. Field level retention matrix. Rights and grievance registers. Breach drill records. Processor contracts with breach and localisation clauses. Log retention (DPDP ≥1yr, CERT-In 180 days India stored). Erasure cascade evidence.

BFSI readiness checklist

Tap each item as you complete it. Track progress toward audit ready dual compliance.

0%

This guide reflects the DPDP Rules, 2025 (G.S.R. 846(E)), RBI Digital Lending Directions, KYC and payment data localisation, SEBI CSCRF, PMLA, and CERT-In Directions as understood at time of writing. General information only, not legal advice.

See how Bugmetrics maps DPDP + RBI + SEBI into one control set

Harmonise five compliance regimes into one evidence base. Consent, retention, rights, and breach readiness tracked continuously.

Book a demo

Or explore Bugmetrics for Fintech & BFSI

Keep reading

Episode 2 · 14 min

Continuous data governance for BFSI: why your regulator already requires it

Episode 3 · 16 min

Data retention & deletion for BFSI: the field-level register

Episode 5 · 20 min

SDF readiness: DPO, DPIA, independent audit & algorithmic accountability