
DPDP Compliance for Banks and NBFCs: The Dual RBI Rulebook Guide for 2026
No sector holds more sensitive personal data than banking, and no sector enters the DPDP era with more rulebooks already open. A single retail customer generates KYC documents, transaction histories, credit scores, loan records, biometric authentication data, and communication trails, spread across core banking systems, lending apps, credit bureaus, and dozens of vendors. For decades, RBI circulars governed all of it. The DPDP Act and its Rules now add a second, cross-sector framework on top, with the core obligations enforceable from 13 May 2027.
The result is dual compliance: every bank and NBFC must satisfy RBI's sectoral directions and the DPDP Act simultaneously, on the same data, often on different clocks. Most institutions will also be designated Significant Data Fiduciaries, which attaches a third layer of obligations. This guide maps where the two frameworks meet, where they pull in different directions, and what a workable NBFC compliance and banking compliance programme looks like in 2026.
Why BFSI Carries the Heaviest DPDP Exposure
Three characteristics concentrate risk in financial services. The first is data sensitivity: Aadhaar, PAN, income records, and biometric identifiers sit at the top of the harm scale, and India's scheduled commercial banks hold them across more than 200 crore deposit accounts. The second is the third-party web: credit bureaus, payment processors, direct selling agents, lending service providers, recovery agents, insurers, and cloud vendors all touch customer data, and each connection is now a compliance surface. The third is legacy technology: core banking systems built decades ago were never designed for purpose-level consent, automated erasure, or real-time breach scoping, and retrofitting them is a multi-year programme, which is precisely why the 2027 deadline matters in 2026.
The Dual Rulebook: Where DPDP Meets RBI
The two frameworks overlap more than they conflict, but the overlaps are not identical, and the differences are where compliance programmes fail.
RBI's KYC Master Direction mandates identity collection and verification; DPDP governs how that identity data is processed, retained, and evidenced afterwards. RBI's cyber security framework requires banks to report cyber incidents to the regulator within 2 to 6 hours; DPDP's Rule 7 adds intimation to the Data Protection Board without delay and a detailed report within 72 hours, alongside CERT-In's 6-hour cyber incident filing. RBI's Digital Lending Directions require need-based data collection with borrower consent; DPDP generalises that consent standard to every processing purpose in the institution. RBI's outsourcing directions make banks accountable for vendors; DPDP does the same through the data fiduciary and data processor split, with liability resting on the fiduciary.
Data localisation is the overlap most often misstated. RBI's 2018 directive requires payment system data to be stored only in India; it does not cover all customer data, and the DPDP Act itself contains no general localisation mandate. What DPDP adds is a government power to restrict transfers to notified countries, and, for Significant Data Fiduciaries, the possibility of specified data categories being barred from leaving India. Institutions planning cross-border data flows should build to the narrower, accurate rule rather than the folklore version, because over-localising has real cloud architecture costs.
Consent or Legitimate Use: Getting the KYC Question Right
The most common error in BFSI privacy programmes, repeated across much of the advisory content ranking on this topic, is treating every data operation as a consent problem. The DPDP Act does not work that way. Section 7 permits processing without consent for specified legitimate uses, including compliance with any law. KYC collection mandated by the PMLA and RBI directions, credit reporting obligations under the credit information framework, and regulatory disclosures are processing in performance of legal obligations. Papering them with consent requests is worse than unnecessary: a consent that cannot lawfully be refused or withdrawn is not valid at all, and it muddies the audit trail.
Where consent under the DPDP Act genuinely governs is everything discretionary: marketing and cross-selling, analytics beyond regulatory purposes, sharing with fintech partners for new products, and any use of customer data that the law does not compel. Those consents must be free, specific, informed, unconditional, and unambiguous, purpose by purpose, withdrawable as easily as they were given, and available in the Eighth Schedule languages. The operational task for a bank is therefore classification before collection: map every processing purpose, tag it as legal obligation or consent-based, and route only the second category through explicit consent journeys. Institutions that skip the classification step end up with bundled consents that fail the Act and statutory processing, wrongly exposed to withdrawal requests.

Digital Lending: Where the Two Frameworks Bite Together
Digital lending is the sharpest intersection. RBI's Digital Lending Directions already require that data collection by lenders and their lending service providers be need-based, with the borrower's explicit consent, and they prohibit blanket access to phone contacts, call logs, and media. DPDP reinforces every one of those constraints and adds rights on top: a borrower can demand access to what was collected, correction of what is wrong, and erasure of what is no longer needed.
The structural risk sits with lending service providers and DSAs. Under DPDP, they are data processors, but the NBFC remains the data fiduciary, which means an LSP scraping more than the sanctioned data, or a recovery agent misusing contact information, lands as the NBFC's violation. Contracts need purpose-scoped data clauses, deletion obligations at loan decision or closure, and breach notification duties running back to the fiduciary without delay. Vendor onboarding and monitoring stops being procurement hygiene and becomes the front line of vendor risk management under both rulebooks.
India's account aggregator framework is worth studying here, because it is the consent architecture DPDP now generalises. The AA ecosystem moves financial data between institutions only on granular, purpose-bound, time-limited consent artefacts. An institution that already operates AA rails has a working reference model for what DPDP-grade consent looks like; one that does not can treat the AA design as the target state for its own consent journeys.
Significant Data Fiduciary: Banks Are the Archetype
The Central Government designates Significant Data Fiduciaries based on data volume, sensitivity, and risk of harm. On every criterion, large banks and NBFCs are the archetype, and prudent institutions are building to SDF obligations now rather than waiting for the notification. Those obligations include appointing a data protection officer based in India who reports to the board, an annual data protection impact assessment, an annual independent audit filed with the Board, and, notably for lenders, verification that algorithmic systems do not pose risks to data principals' rights. Credit scoring, collections prioritisation, and fraud models all sit inside that last obligation, which pulls model governance into the privacy programme for the first time.
The Retention Collision
DPDP requires erasure once the purpose is served or consent is withdrawn. RBI and PMLA record-keeping rules require the same data to be kept for years after the relationship ends. There is no contradiction in law, because DPDP's erasure duty yields to retention required by legislation, but there is a hard operational problem: the institution must know, record by record, which retention clock applies and why. The answer is purpose-tagged retention schedules, where every data category carries its legal basis and its expiry, and deletion executes automatically when the longest applicable clock runs out. The DPDP Rules add a floor of their own: logs and associated data retained at least one year. None of this is achievable while personal data lives in undocumented spreadsheets and orphaned databases, which is why data discovery is the unglamorous prerequisite for the entire retention regime.
A Breach Means Three Regulators on Three Clocks
A cyber incident at a bank now triggers parallel reporting: RBI within 2 to 6 hours under the cybersecurity framework, CERT-In within 6 hours, and the DPDP track, intimation to the Data Protection Board without delay with a detailed report inside 72 hours, plus notification to every affected data principal without delay. DPDP sets no materiality threshold, so a small exposure reports the same way as a mass exfiltration. Pre-drafted templates for each regulator, a rehearsed escalation path, and the ability to scope affected records fast are the difference between orderly incident management and a weekend of guesswork. The penalty stack is the steepest in the law: up to ₹250 crore for failing security safeguards and up to ₹200 crore for failing to notify, and one incident can attract both.

Building the Dual Compliance Stack
Sequencing for 2026 follows from everything above. Discover and classify personal data across core banking, lending platforms, CRMs, and endpoints, because scoping, retention, and breach response all depend on that inventory. Classify processing purposes into legal obligation and consent, and rebuild consent journeys only where consent genuinely applies. Contract the vendor web to DPDP standard, LSPs and DSAs first. Stand up the SDF layer: DPO, DPIA cadence, audit readiness, algorithm review. And wire breach response to all three clocks with templates and named owners. A step-by-step DPDP compliance checklist helps sequence the programme; the sector-specific overlay above tells you where BFSI diverges from the generic path.
Where Privy Fits
Privy by IDfy runs this exact stack for India's most regulated institutions: Axis Bank, HSBC, Federal Bank, Shriram Finance, and multiple Aditya Birla Capital businesses among the 30+ enterprises on the platform. Its Consent Governance Platform manages purpose-level consent journeys, multilingual notices, and immutable consent artifacts, 60M+ of them generated to date, giving banks the evidence layer the Act assumes. Data Compass discovers and classifies Indian PII across systems and endpoints, including the field-agent laptops where Aadhaar and PAN copies quietly accumulate, which is the inventory every retention schedule and breach scoping exercise depends on. Third-party risk, privacy impact assessments, and incident workflows run on the same connected platform, so DPDP evidence and RBI evidence come from one record rather than two reconciled ones. IDfy also won MeitY's DPDP Innovation Challenge, a government-run validation of the consent infrastructure at the centre of all of it, and brings 14 years of KYC and identity verification infrastructure that already runs inside Indian banking.

Conclusion
For banks and NBFCs, DPDP is less a new subject than a new standard of proof applied to an old one. The sector has always been accountable for customer data; it now has to demonstrate that accountability record by record, purpose by purpose, across two rulebooks and three breach clocks, with the steepest penalties in the Act attached. The institutions treating 2026 as the build year- inventory first, classification second, vendor web and SDF layer after, will meet May 2027 as a filing date rather than a fire drill.
To see how Privy by IDfy runs dual DPDP and RBI compliance for banks and NBFCs on one platform, write to shivani@idfy.com for a walkthrough.
FAQ's
Do banks need consent for KYC under the DPDP Act?
No. KYC mandated by the PMLA and RBI directions is processing for compliance with law, a legitimate use under Section 7, so no consent request is required for it. Consent applies to discretionary processing such as marketing, cross-selling, analytics beyond regulatory needs, and data sharing with partners.
Will banks and NBFCs be Significant Data Fiduciaries?
Designation is by government notification, but large banks and NBFCs meet every stated criterion: volume, sensitivity, and risk of harm. Institutions should build to SDF obligations, including a DPO, annual DPIA, annual audit, and algorithmic risk review, rather than waiting to be named.
Does the DPDP Act require all banking data to stay in India?
No. RBI's 2018 directive localises payment system data specifically. The DPDP Act permits cross-border transfers except to countries the government notifies, and the Rules allow additional transfer restrictions for Significant Data Fiduciaries. Blanket localisation of all customer data is not a current legal requirement.
How does DPDP interact with RBI's data retention rules?
DPDP's erasure duty gives way where another law requires retention, so sectoral record-keeping periods continue to apply. The obligation is to know which basis applies to each data category, retain for exactly that period, and erase when it lapses, which requires purpose-tagged retention schedules rather than blanket keep-everything policies.
What are the breach reporting timelines for a bank under DPDP?
Three tracks run in parallel: RBI's cyber security framework requires reporting within 2 to 6 hours, CERT-In requires filing within 6 hours, and DPDP's Rule 7 requires intimation to the Data Protection Board without delay followed by a detailed report within 72 hours, plus notification to affected data principals without delay.
Search Here
Explore More
.png)
Jul 03, 2026
DPDPA for E-Commerce: The 2026 Compliance Guide for Data Fiduciaries
.png)
Jul 06, 2026
DPDPA for Marketers: The 2026 Guide to Consent-Led Digital Marketing
Share






